You are responsible for responding to Microsoft Defender for Key Vault alerts.During an investigation of an alert, you discover unauthorized attempts to access a key vault from a Tor exit node.What should you configure to mitigate the threat?
Answer(s): A
https://docs.microsoft.com/en-us/azure/key-vault/general/network-security
You have an Azure subscription that contains a Log Analytics workspace.You need to enable just-in-time (JIT) VM access and network detections for Azure resources.Where should you enable Microsoft Defender for Cloud?
https://docs.microsoft.com/en-us/azure/security-center/enable-azure-defender
You use Microsoft Defender for Cloud.You have an Azure Storage account that contains sensitive information.You need to run a PowerShell script if someone accesses the storage account from a suspicious IP address.Which two actions should you perform? Each correct answer presents part of the solution.Note: Each correct selection is worth one point.
Answer(s): A,C
https://docs.microsoft.com/en-us/azure/storage/common/azure-defender-storage-configure?tabs=azure-security-center https://docs.microsoft.com/en-us/azure/security-center/workflow-automation
HOTSPOT (Drag and Drop is not supported)You manage the security posture of an Azure subscription that contains two virtual machines name vm1 and vm2.The secure score in Azure Security Center is shown in the Security Center exhibit. (Click the Security Center tab.)Azure Policy assignments are configured as shown in the Policies exhibit. (Click the Policies tab.)For each of the following statements, select Yes if the statement is true. Otherwise, select No.Note: Each correct selection is worth one point.Hot Area:
https://techcommunity.microsoft.com/t5/azure-security-center/security-control-restrict-unauthorized-network-access/ba-p/1593833https://techcommunity.microsoft.com/t5/azure-security-center/security-control-secure-management-ports/ba-p/1505770
DRAG DROP (Drag and Drop is not supported)You are informed of a new common vulnerabilities and exposures (CVE) vulnerability that affects your environment.You need to use Microsoft Defender portal to request remediation from the team responsible for the affected systems if there is a documented active exploit available.Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.Select and Place:
https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/microsoft-defender-atp-remediate-apps-using-mem/ba-p/1599271
You use Azure Security Center.You receive a security alert in Security Center.You need to view recommendations to resolve the alert in Security Center.What should you do?
Answer(s): B
https://docs.microsoft.com/en-us/azure/security-center/security-center-managing-and-responding-alerts
You have a suppression rule in Microsoft Defender for Cloud for 10 virtual machines that are used for testing. The virtual machines run Windows Server.You are troubleshooting an issue on the virtual machines.In Microsoft Defender for Cloud, you need to view the alerts generated by the virtual machines during the last five days.What should you do?
Answer(s): C
HOTSPOT (Drag and Drop is not supported)You have an Azure Storage account that will be accessed by multiple Azure Functions apps during the development of an application.You need to hide Microsoft Defender for Cloud alerts for the storage account.Which entity type and field should you use in a suppression rule? To answer, select the appropriate options in the answer area.Note: Each correct selection is worth one point.Hot Area:
https://techcommunity.microsoft.com/t5/azure-security-center/suppression-rules-for-azure-security-center-alerts-are-now/ba-p/1404920
Share your comments for Microsoft SC-200 exam with other users:
awesome contents