FEFreeExamDumps.in

SC-200 Practice Questions — Page 19

Question 181

Open question ↗

You have the resources shown in the following table.

You have an Azure subscription that uses Microsoft Defender for Cloud.

You need to use Defender for Cloud to protect VM1 and Server1. The solution must meet the following requirements:

• Support Advanced Threat Protection and vulnerability assessment.

• Register each SQL Server 2022 instance as a SQL virtual machine.

• Minimize implementation and administrative effort.

What should you deploy to each server? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 181

Question 182

Open question ↗

You have a Microsoft 365 subscription named contoso.com that contains a Windows 11 device named Device1. Device1 is onboarded to Microsoft Defender for Endpoint.

You perform the following actions:

• From Defender for Endpoint, create the device groups shown in the following table.

• Onboard an Android device named Device2 to Defender for Endpoint.

To which device groups will each device be added? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 182

Question 183

Open question ↗

Case study

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.

Overview

A company named Contoso Ltd. has a main office and five branch offices located throughout North America. The main office is in Seattle. The branch offices are in Toronto, Miami, Houston, Los Angeles, and Vancouver.

Contoso has a subsidiary named Fabrikam, Ltd. that has offices in New York and San Francisco.

Existing Environment

End-User Environment

All users at Contoso use Windows 11 devices. Each user is licensed for Microsoft 365. In addition, iOS devices are distributed to the members of the sales team at Contoso.

Cloud and Hybrid Infrastructure

All Contoso applications are deployed to Azure.

You enable Microsoft Defender for Cloud Apps.

Contoso and Fabrikam have different Microsoft Entra tenants. Fabrikam recently purchased an Azure subscription and enabled Microsoft Defender for Cloud for all supported resource types.

Current Problems

The security team at Contoso receives a large number of cybersecurity alerts. The security team spends too much time identifying which cybersecurity alerts are legitimate threats, and which are not.

The Contoso sales team uses only iOS devices. The sales team members exchange files with customers by using a variety of third-party tools. In the past, the sales team experienced phishing attacks on their devices.

The marketing team at Contoso has several Microsoft SharePoint Online sites for collaborating with external vendors. The marketing team has had several incidents in which vendors uploaded files that contain malware.

The executive team at Contoso suspects a security breach. The executive team requests that you identify which files had more than five activities during the past 48 hours, including data access, download, or deletion for Microsoft Defender for Cloud Apps-protected applications.

Requirements

Planned Changes

Contoso plans to integrate the security operations of both companies and manage all security operations centrally.

Technical Requirements

Contoso identifies the following technical requirements:

• Receive alerts if an Azure virtual machine is under brute force attack.

• Use Microsoft Sentinel to reduce organizational risk by rapidly remediating active attacks on the environment.

• Implement Microsoft Sentinel queries that correlate data across the Microsoft Entra tenants of Contoso and Fabrikam.

• Develop a procedure to remediate Microsoft Defender for Key Vault alerts for Contoso in case of external and internal threats. The solution must minimize the impact on legitimate attempts to access the key vault content.

• Identify all cases of users who failed to sign in to an Azure resource for the first time from a given country. A junior security administrator provides you with the following incomplete query.

BehaviorAnalytics

| where ActivityType == "FailedLogOn"

| where ________ == True

You need to recommend remediation actions for the Microsoft Defender for Cloud alerts for Contoso.

What should you recommend for each threat? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 183

Question 184

Open question ↗

You have an Azure subscription that uses Microsoft Security Copilot.

You need to temporarily increase the number of security compute units.

What is the smallest interval of time you can be billed for?

  • A.1 second
  • B.1 minute
  • C.1 hour ✓
  • D.1 day

Question 185

Open question ↗

You have a Microsoft Sentinel workspace named Workspace1.

The AzureActivity table in Workspace1 has the following retention periods:

• Interactive: 180 days

• Total: 180 days

You need to modify the retention periods to meet the following requirements:

• Minimize the costs associated with storing data in the table.

• Maximize the period during which the table data remains available.

How should you configure each retention period? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 185

Question 186

Open question ↗

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. The subscription contains 500 devices that are joined to Microsoft Entra, are in the Microsoft Defender for Endpoint default device group, and are managed by using Microsoft Intune.

You need to implement Microsoft Defender Vulnerability Management. The solution must minimize the administrative effort.

What should you do first in the Microsoft Defender portal?

  • A.From Configuration management, configure the Enforcement scope settings.
  • B.Configure auto remediation for the default device group.
  • C.Set Microsoft Intune connection to On. ✓
  • D.Set Live Response to On.

Question 187

Open question ↗

You have a Microsoft 365 E5 subscription.

You need to configure Microsoft Sentinel to collect logs from Microsoft Entra.

Which two nodes should you use in the Microsoft Defender portal? To answer, select the appropriate nodes in the answer area.

NOTE: Each correct answer is worth one point.

Question 187

Question 188

Open question ↗

You have three Azure subscriptions. Each subscription contains multiple virtual machines that run Windows Server.

You have a Microsoft Sentinel workspace.

You need to ensure that failed sign-in attempts from all the virtual machines can be analyzed by using Microsoft Sentinel. The solution must minimize administrative effort.

What should you do first?

  • A.From the Microsoft Defender portal, install the Windows Security Events solution.
  • B.On each virtual machine, create an event subscription.
  • C.On each virtual machine, install the Azure Connected Machine agent.
  • D.From the Microsoft Defender portal, install the Syslog solution.

Question 189

Open question ↗

You have a Microsoft Sentinel workspace that contains Common Event Format (CEF) data.

You need to run a query against the CEF data.

Which table should you query?

  • A.Syslog
  • B.SecurityEvent
  • C.CommonSecurityLog ✓
  • D.TrreatIntelligentIndicator

Question 190

Open question ↗

You have a Microsoft 365 subscription that contains the following resources:

• 100 users that are assigned a Microsoft 365 E5 license

• 100 Windows 11 devices that are joined to the Microsoft Entra tenant

The users access their Microsoft Exchange Online mailbox by using Outlook on the web.

You need to ensure that if a user account is compromised, the Outlook on the web session token can be revoked. What should you configure?

  • A.security defaults in Microsoft Entra
  • B.Microsoft Entra Verified ID
  • C.a Conditional Access policy in Microsoft Entra
  • D.Microsoft Entra ID Protection