Exam Details

  • Exam Code
    :SC-200
  • Exam Name
    :Microsoft Security Operations Analyst
  • Certification
    :Role-based
  • Vendor
    :Microsoft
  • Total Questions
    :260 Q&As
  • Last Updated
    :

Microsoft Role-based SC-200 Questions & Answers

  • Question 1:

    You have an Azure subscription that uses Microsoft Sentinel.

    You need to create a custom report that will visualise sign-in information over time.

    What should you create first?

    A. a workbook

    B. a hunting query

    C. a notebook

    D. a playbook

  • Question 2:

    You have a Microsoft 365 subscription that uses Microsoft 365 Defender.

    A remediation action for an automated investigation quarantines a file across multiple devices.

    You need to mark the file as safe and remove the file from quarantine on the devices.

    What should you use in the Microsoft 365 Defender portal?

    A. From Threat tracker, review the queries.

    B. From the History tab in the Action center, revert the actions.

    C. From the investigation page, review the AIR processes.

    D. From Quarantine from the Review page, modify the rules.

  • Question 3:

    DRAG DROP

    You need to add notes to the events to meet the Azure Sentinel requirements.

    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.

    Select and Place:

  • Question 4:

    DRAG DROP

    You need to configure DC1 to meet the business requirements.

    Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Select and Place:

  • Question 5:

    HOTSPOT

    You need to create the analytics rule to meet the Azure Sentinel requirements.

    What should you do? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

    Hot Area:

  • Question 6:

    HOTSPOT

    You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.

    What should you include in the solution? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

    Hot Area:

  • Question 7:

    HOTSPOT

    You need to recommend remediation actions for the Azure Defender alerts for Fabrikam.

    What should you recommend for each threat? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

    Hot Area:

  • Question 8:

    HOTSPOT

    You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.

    What should you include in the solution? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

    Hot Area:

  • Question 9:

    HOTSPOT

    You need to configure the Azure Sentinel integration to meet the Azure Sentinel requirements.

    What should you do? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

    Hot Area:

  • Question 10:

    HOTSPOT

    You have an Azure subscription that contains an Microsoft Sentinel workspace.

    You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:

    Identifies an anomalous number of changes to the rules of a network security group (NSG) made by the same security principal

    Automatically associates the security principal with an Microsoft Sentinel entity

    How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

    Hot Area:

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-200 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.