FEFreeExamDumps.in

SC-200 Practice Questions — Page 15

Question 141

Open question ↗

You have an Azure subscription that uses Microsoft Sentinel and contains a user named User1.

You need to ensure that User1 can enable User and Entity Behavior Analytics (UEBA) for entity behavior in Azure AD. The solution must use the principle of least privilege.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 141

Question 142

Open question ↗

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant.

You have a Microsoft Sentinel workspace named Sentinel1.

You need to enable User and Entity Behavior Analytics (UEBA) for Sentinel1 and collect security events from the AD DS domain.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question 142

Question 143

Open question ↗

You have a Microsoft Sentinel workspace.

You enable User and Entity Behavior Analytics (UEBA) by using Audit Logs and Signin Logs.

The following entities are detected in the Azure AD tenant:

• App name: App1

• IP address: 192.168.1.2

• Computer name: Device1

• Used client app: Microsoft Edge

• Email address: [email protected]

• Sign-in URL: https://www.company.com

Which entities can be investigated by using UEBA?

  • A.IP address and email address only
  • B.app name, computer name, IP address, email address, and used client app only
  • C.IP address only
  • D.used client app and app name only

Question 144

Open question ↗

You have a Microsoft Sentinel workspace.

You need to configure a report visual for a custom workbook. The solution must meet the following requirements:

• The count and usage trend of AppDisplayName must be included.

• The TrendList column must be useable in a sparkline visual.

How should you complete the KQL query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 144

Question 145

Open question ↗

You have an Azure subscription that contains two users named User1 and User2 and a Microsoft Sentinel workspace named workspace1.

You need to ensure that the users can perform the following tasks in workspace1:

• User1 must be able to dismiss incidents and assign incidents to users.

• User2 must be able to modify analytics rules.

The solution must use the principle of least privilege.

Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question 145

Question 146

Open question ↗

You have a Microsoft Sentinel workspace that uses the Microsoft 365 Defender data connector.

From Microsoft Sentinel, you investigate a Microsoft 365 incident.

You need to update the incident to include an alert generated by Microsoft Defender for Cloud Apps.

What should you use?

  • A.the entity side panel of the Timeline card in Microsoft Sentinel
  • B.the Timeline tab on the incidents page of Microsoft Sentinel
  • C.the investigation graph on the incidents page of Microsoft Sentinel
  • D.the Alerts page in the Microsoft 365 Defender portal

Question 147

Open question ↗

You have an Azure subscription that is linked to a hybrid Azure AD tenant and contains a Microsoft Sentinel workspace named Sentinel1.

You need to enable User and Entity Behavior Analytics (UEBA) for Sentinel and configure UEBA to use data collected from Active Directory Domain Services (AD DS).

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 147

Question 148

Open question ↗

You have four Azure subscriptions. One of the subscriptions contains a Microsoft Sentinel workspace.

You need to deploy Microsoft Sentinel data connectors to collect data from the subscriptions by using Azure Policy. The solution must ensure that the policy will apply to new and existing resources in the subscriptions.

Which type of connectors should you provision, and what should you use to ensure that all the resources are monitored? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 148

Question 149

Open question ↗

You have 50 Microsoft Sentinel workspaces.

You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort.

Which page should you use in the Azure portal?

  • A.Microsoft Sentinel - Incidents
  • B.Microsoft Sentinel - Workbooks
  • C.Microsoft Sentinel
  • D.Log Analytics workspaces

Question 150

Open question ↗

Case study

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.

Overview

Adatum Corporation is a United States-based financial services company that has regional offices in New York, Chicago, and San Francisco.

Existing Environment

Identity Environment

The on-premises network contains an Active Directory Domain Services (AD DS) forest named corp.adatum.com that syncs with an Azure AD tenant named adatum.com. All user and group management tasks are performed in corp.adatum.com. The corp.adatum.com domain contains a group named Group1 that syncs with adatum.com.

Licensing Status

All the users at Adatum are assigned a Microsoft 365 ES license and an Azure Active Directory Premium P2 license.

Cloud Environment

The cloud environment contains a Microsoft 365 subscription, an Azure subscription linked to the adatum.com tenant, and the resources shown in the following table.

On-premises Environment

The on-premises network contains the resources shown in the following table.

Requirements

Planned changes

Adatum plans to perform the following changes:

• Implement a query named rulequery1 that will include the following KQL query.

• Implement a Microsoft Sentinel scheduled rule that generates incidents based on rulequery1.

Microsoft Defender for Cloud Requirements

Adatum identifies the following Microsoft Defender for Cloud requirements:

• The members of Group1 must be able to enable Defender for Cloud plans and apply regulatory compliance initiatives.

• Microsoft Defender for Servers Plan 2 must be enabled on all the Azure virtual machines.

• Server2 must be excluded from agentless scanning.

Microsoft Sentinel Requirements

Adatum identifies the following Microsoft Sentinel requirements:

• Implement an Advanced Security Information Model (ASIM) query that will return a count of DNS requests that results in an NXDOMAIN response from Infoblox1.

• Ensure that multiple alerts generated by rulequery1 in response to a single user launching Azure Cloud Shell multiple times are consolidated as a single incident.

• Implement the Windows Security Events via AMA connector for Microsoft Sentinel and configure it to monitor the Security event log of Server1.

• Ensure that incidents generated by rulequery1 are closed automatically if Azure Cloud Shell is launched by the company’s SecOps team.

• Implement a custom Microsoft Sentinel workbook named Workbook1 that will include a query to dynamically retrieve data from Webapp1.

• Implement a Microsoft Sentinel near-real-time (NRT) analytics rule that detects sign-ins to a designated break glass account.

• Ensure that HuntingQuery1 runs automatically when the Hunting page of Microsoft Sentinel in the Azure portal is accessed.

• Ensure that higher than normal volumes of password resets for corp.adatum.com user accounts are detected.

• Minimize the overhead associated with queries that use ASIM parsers.

• Ensure that the Group1 members can create and edit playbooks.

• Use built-in ASIM parsers whenever possible.

Business Requirements

Adatum identifies the following business requirements:

• Follow the principle of least privilege whenever possible.

• Minimize administrative effort whenever possible.

You need to implement the scheduled rule for incident generation based on rulequery1.

What should you configure first?

Question 150
  • A.custom details
  • B.entity mapping
  • C.event grouping
  • D.alert details