Exam Details

  • Exam Code
    :SC-200
  • Exam Name
    :Microsoft Security Operations Analyst
  • Certification
    :Role-based
  • Vendor
    :Microsoft
  • Total Questions
    :260 Q&As
  • Last Updated
    :May 13, 2024

Microsoft Role-based SC-200 Questions & Answers

  • Question 41:

    You have an Azure subscription that has Microsoft Defender for Cloud enabled.

    You have a virtual machine named Server1 that runs Windows Server 2022 and is hosted in Amazon Web Services (AWS).

    You need to collect logs and resolve vulnerabilities for Server1 by using Defender for Cloud.

    What should you install first on Server1?

    A. the Microsoft Monitoring Agent

    B. the Azure Monitor agent

    C. the Azure Arc agent

    D. the Azure Pipelines agent

  • Question 42:

    You have a Microsoft 365 subscription that uses Microsoft 365 Defender.

    You plan to create a hunting query from Microsoft Defender.

    You need to create a custom tracked query that will be used to assess the threat status of the subscription.

    From the Microsoft 365 Defender portal, which page should you use to create the query?

    A. Threat analytics

    B. Advanced Hunting

    C. Explorer

    D. Policies and rules

  • Question 43:

    You have a Microsoft 365 subscription. The subscription uses Microsoft 365 Defender and has data loss prevention (DLP) policies that have aggregated alerts configured.

    You need to identify the impacted entities in an aggregated alert.

    What should you review in the DLP alert management dashboard of the Microsoft 365 compliance center?

    A. the Events tab of the alert

    B. the Sensitive Info Types tab of the alert

    C. Management log

    D. the Details tab of the alert

  • Question 44:

    You have a Microsoft Sentinel workspace.

    You need to identify which rules are used to detect advanced multistage attacks that comprise two or more alerts or activities. The solution must minimize administrative effort.

    Which rule type should you query?

    A. Fusion

    B. Microsoft Security

    C. ML Behavior Analytics

    D. Scheduled

  • Question 45:

    You have a Microsoft 365 subscription that uses Microsoft 365 Defender.

    You need to identify all the entities affected by an incident.

    Which tab should you use in the Microsoft 365 Defender portal?

    A. Investigations

    B. Devices

    C. Evidence and Response

    D. Alerts

  • Question 46:

    You have an Azure subscription that has the enhanced security features in Microsoft Defender for Cloud enabled and contains a user named User1.

    You need to ensure that User1 can export alert data from Defender for Cloud. The solution must use the principle of least privilege.

    Which role should you assign to User1?

    A. User Access Administrator

    B. Owner

    C. Contributor

    D. Reader

  • Question 47:

    You have an Azure subscription that uses Microsoft Sentinel.

    You detect a new threat by using a hunting query.

    You need to ensure that Microsoft Sentinel automatically detects the threat. The solution must minimize administrative effort.

    What should you do?

    A. Create a playbook.

    B. Create a watchlist.

    C. Create an analytics rule.

    D. Add the query to a workbook.

  • Question 48:

    You have a Microsoft Sentinel workspace.

    You have a query named Query1 as shown in the following exhibit.

    You plan to create a custom parser named Parser 1. You need to use Query1 in Parser1.

    What should you do first?

    A. Remove line 2.

    B. In line 4. remove the TimeGenerated predicate.

    C. Remove line 5.

    D. In line 3, replace the 'contains operator with the !has operator.

  • Question 49:

    You have an Azure subscription that contains a Microsoft Sentinel workspace. The workspace contains a Microsoft Defender for Cloud data connector.

    You need to customize which details will be included when an alert is created for a specific event.

    What should you do?

    A. Modify the properties of the connector.

    B. Create a Data Collection Rule (DCR).

    C. Create a scheduled query rule.

    D. Enable User and Entity Behavior Analytics (UEBA)

  • Question 50:

    Your company has an on-premises network that uses Microsoft Defender for Identity.

    The Microsoft Secure Score for the company includes a security assessment associated with unsecure Kerberos delegation.

    You need remediate the security risk.

    What should you do?

    A. Install the Local Administrator Password Solution (LAPS) extension on the computers listed as exposed entities.

    B. Modify the properties of the computer objects listed as exposed entities.

    C. Disable legacy protocols on the computers listed as exposed entities.

    D. Enforce LDAP signing on the computers listed as exposed entities.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-200 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.