Microsoft Security Operations Analyst SC-200 Dumps in PDF

Free Microsoft SC-200 Real Questions (page: 52)

You are responsible for responding to Microsoft Defender for Key Vault alerts.
During an investigation of an alert, you discover unauthorized attempts to access a key vault from a Tor exit node.
What should you configure to mitigate the threat?

  1. Key Vault firewalls and virtual networks
  2. Microsoft Entra ID permissions
  3. role-based access control (RBAC) for the key vault
  4. the access policy settings of the key vault

Answer(s): A


Reference:

https://docs.microsoft.com/en-us/azure/key-vault/general/network-security



You have an Azure subscription that contains a Log Analytics workspace.
You need to enable just-in-time (JIT) VM access and network detections for Azure resources.
Where should you enable Microsoft Defender for Cloud?

  1. at the subscription level
  2. at the workspace level
  3. at the resource level

Answer(s): A


Reference:

https://docs.microsoft.com/en-us/azure/security-center/enable-azure-defender



You use Microsoft Defender for Cloud.
You have an Azure Storage account that contains sensitive information.
You need to run a PowerShell script if someone accesses the storage account from a suspicious IP address.
Which two actions should you perform? Each correct answer presents part of the solution.
Note: Each correct selection is worth one point.

  1. From Microsoft Defender for Cloud, add workflow automation.
  2. Create an Azure logic app that has a manual trigger.
  3. Create an Azure logic app that has a Microsoft Defender for Cloud alert trigger.
  4. Create an Azure logic app that has an HTTP trigger.
  5. From Microsoft Entra ID, add an app registration.

Answer(s): A,C


Reference:

https://docs.microsoft.com/en-us/azure/storage/common/azure-defender-storage-configure?tabs=azure-security-center https://docs.microsoft.com/en-us/azure/security-center/workflow-automation



HOTSPOT (Drag and Drop is not supported)
You manage the security posture of an Azure subscription that contains two virtual machines name vm1 and vm2.
The secure score in Azure Security Center is shown in the Security Center exhibit. (Click the Security Center tab.)

Azure Policy assignments are configured as shown in the Policies exhibit. (Click the Policies tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://techcommunity.microsoft.com/t5/azure-security-center/security-control-restrict-unauthorized-network-access/ba-p/1593833
https://techcommunity.microsoft.com/t5/azure-security-center/security-control-secure-management-ports/ba-p/1505770



DRAG DROP (Drag and Drop is not supported)
You are informed of a new common vulnerabilities and exposures (CVE) vulnerability that affects your environment.
You need to use Microsoft Defender portal to request remediation from the team responsible for the affected systems if there is a documented active exploit available.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/microsoft-defender-atp-remediate-apps-using-mem/ba-p/1599271



You use Azure Security Center.
You receive a security alert in Security Center.
You need to view recommendations to resolve the alert in Security Center.
What should you do?

  1. From Security alerts, select the alert, select Take Action, and then expand the Prevent future attacks section.
  2. From Security alerts, select Take Action, and then expand the Mitigate the threat section.
  3. From Regulatory compliance, download the report.
  4. From Recommendations, download the CSV report.

Answer(s): B


Reference:

https://docs.microsoft.com/en-us/azure/security-center/security-center-managing-and-responding-alerts



You have a suppression rule in Microsoft Defender for Cloud for 10 virtual machines that are used for testing. The virtual machines run Windows Server.
You are troubleshooting an issue on the virtual machines.
In Microsoft Defender for Cloud, you need to view the alerts generated by the virtual machines during the last five days.
What should you do?

  1. Change the rule expiration date of the suppression rule.
  2. Change the state of the suppression rule to Disabled.
  3. Modify the filter for the Security alerts page.
  4. View the Windows event logs on the virtual machines.

Answer(s): C



HOTSPOT (Drag and Drop is not supported)
You have an Azure Storage account that will be accessed by multiple Azure Functions apps during the development of an application.
You need to hide Microsoft Defender for Cloud alerts for the storage account.
Which entity type and field should you use in a suppression rule? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://techcommunity.microsoft.com/t5/azure-security-center/suppression-rules-for-azure-security-center-alerts-are-now/ba-p/1404920



Share your comments for Microsoft SC-200 exam with other users:

B
Brijesh kr
6/29/2023 4:07:00 AM

awesome contents

AI Tutor 👋 I’m here to help!