FEFreeExamDumps.in

SC-200 Practice Questions — Page 3

You have a Microsoft 365 subscription that uses Microsoft 365 Defender.

You need to identify all the entities affected by an incident.

Which tab should you use in the Microsoft 365 Defender portal?

  • A.Investigations
  • B.Devices
  • C.Evidence and Response
  • D.Alerts

You have a Microsoft 365 E5 subscription that is linked to a hybrid Azure AD tenant.

You need to identify all the changes made to Domain Admins group during the past 30 days.

What should you use?

  • A.the Modifications of sensitive groups report in Microsoft Defender for Identity
  • B.the identity security posture assessment in Microsoft Defender for Cloud Apps
  • C.the Azure Active Directory Provisioning Analysis workbook
  • D.the Overview settings of Insider risk management

You have a Microsoft 365 subscription. The subscription uses Microsoft 365 Defender and has data loss prevention (DLP) policies that have aggregated alerts configured.

You need to identify the impacted entities in an aggregated alert.

What should you review in the DLP alert management dashboard of the Microsoft 365 compliance center?

  • A.the Events tab of the alert
  • B.the Sensitive Info Types tab of the alert
  • C.Management log
  • D.the Details tab of the alert

You have a Microsoft 365 subscription that uses Microsoft 365 Defender.

You plan to create a hunting query from Microsoft Defender.

You need to create a custom tracked query that will be used to assess the threat status of the subscription.

From the Microsoft 365 Defender portal, which page should you use to create the query?

  • A.Threat analytics
  • B.Advanced Hunting
  • C.Explorer
  • D.Policies & rules

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.

You need to add threat indicators for all the IP addresses in a range of 171.23.34.32-171.23.34.63. The solution must minimize administrative effort.

What should you do in the Microsoft 365 Defender portal?

  • A.Create an import file that contains the individual IP addresses in the range. Select Import and import the file.
  • B.Create an import file that contains the IP address of 171.23.34.32/27. Select Import and import the file.
  • C.Select Add indicator and set the IP address to 171.23.34.32-171.23.34.63.
  • D.Select Add indicator and set the IP address to 171.23.34.32/27.

You have an Azure subscription that uses Microsoft Defender for Endpoint.

You need to ensure that you can allow or block a user-specified range of IP addressed and URLs.

What should you enable first in the Advanced features from the Endpoints Settings in the Microsoft 365 Defender portal?

  • A.custom network indicators
  • B.live response for servers
  • C.endpoint detection and response (EDR) in block mode
  • D.web content filtering

You have an Azure subscription that contains the users shown in the following table.

You need to delegate the following tasks:

• Enable Microsoft Defender for Servers on virtual machines.

• Review security recommendations and enable server vulnerability scans.

The solution must use the principle of least privilege.

Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question 27

You have a Microsoft 365 E5 subscription.

You need to create a hunting query that will return every email that contains an attachment named Document.pdf. The query must meet the following requirements:

• Only show emails sent during the last hour.

• Optimize query performance.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 28

Your company has an on-premises network that uses Microsoft Defender for Identity.

The Microsoft Secure Score for the company includes a security assessment associated with unsecure Kerberos delegation.

You need remediate the security risk.

What should you do?

  • A.Disable legacy protocols on the computers listed as exposed entities.
  • B.Enforce LDAP signing on the computers listed as exposed entities.
  • C.Modify the properties of the computer objects listed as exposed entities.
  • D.Install the Local Administrator Password Solution (LAPS) extension on the computers listed as exposed entities.

You have a Microsoft 365 subscription that uses Microsoft 365 Defender.

A remediation action for an automated investigation quarantines a file across multiple devices.

You need to mark the file as safe and remove the file from quarantine on the devices.

What should you use in the Microsoft 365 Defender portal?

  • A.From the History tab in the Action center, revert the actions.
  • B.From the investigation page, review the AIR processes.
  • C.From Quarantine from the Review page, modify the rules.
  • D.From Threat tracker, review the queries.