Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

SC-200 Reviews Questions

Page: 7 / 10
Total 388 questions

Microsoft Security Operations Analyst Questions and Answers

Question 25

You have an on-premises Linux server that runs a background process named App1 and has the Azure Connected Machine agent installed.

You have a Microsoft Sentinel workspace named WS1.

You need to configure a data collection rule (DCR) named DCR1 that will use the Syslog via AMA connector to collect messages related to App1. The solution must meet the following requirements:

• Only collect messages that have a priority level of critical.

• Minimize the volume of data collected.

Which facility and log level should you configure for DCR1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 26

You have an Azure subscription.

You need to delegate permissions to meet the following requirements:

    Enable and disable Azure Defender.

    Apply security recommendations to resource.

The solution must use the principle of least privilege.

Which Azure Security Center role should you use for each requirement? To answer, drag the appropriate roles to the correct requirements. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE : Each correct selection is worth one point.

Options:

Question 27

You have a Microsoft Sentinel workspace named Workspacel that contains a table named CommonSecurityLog. You ingest logs into CommonSecurityLog. CommonSecurityLog has an average log ingestion time of five minutes.

You need to create an analytics rule that has a lookback period of seven minutes and uses the data in the CommonSecurityLog table. The solution must meet the following requirements:

• Prevent the same event from being processed twice.

• Minimize the number of missed events due to log ingestion delays.

How should you complete the KQL query that defines the rule? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 28

You have a Microsoft 365 B5 subscription that contains a user named User1. The subscription uses Microsoft 365 Copilot for Security. Copilot for Security uses the Sentinel plugin. User1 is assigned the Copilot Contributor role.

During an investigation, User1 submits a prompt and receives a notification that Copilot for Security cannot respond to requests because the security compute unit (SCU) usage is nearing the provisioned capacity limit.

You need to ensure that User1 can use Copilot for Security to generate a successful response.

What should User1 do?

Options:

A.

Open a second Copilot for Security session and submit the prompt.

B.

Wait one hour and resubmit the prompt.

C.

Run the Microsoft Sentinel Optimization Workbook.

D.

Update the provisioned SCUs.

Page: 7 / 10
Total 388 questions