wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

SC-200 Quiz

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

There are various components in DLP. Which among the following classifies as a document, and which component can protect content in locations like SharePoint Online?

a)

Sensitive info types and Access Policy

b)

Access Policy and DLP Policy

c)

Sensitivity label and DLP Policy

d)

DLP Policy and Retention Policy

2.

Your organization uses Microsoft defender for cloud. In Microsoft defender for cloud, you want to see the topology of your workloads. Which feature of Defender enables you to see it:

a)

Secure Score

b)

Inventory

c)

Network map

d)

Biometric analytics

3.

Your organization has Microsoft 365 Defender, Microsoft Defender for Endpoint. Your organization need you to do an in-depth investigation and take immediate response action on identified threats in real-time? What should you use:

a)

Hunt for emerging threats

b)

Live device investigation manager

c)

Live response

d)

Security operations

4.

Which live response basic command is used to Initiates a live response session to the device?

a)

connect

b)

 processes

c)

 connections

d)

Init

5.

You have Microsoft Defender for Endpoint. In Indicators, which file type and type is used to upload and accepted type?

a)

CSV and Certificates

b)

CSV and Code data

c)

XML and Certificates

d)

JSON and Email subject line

6.

What types of risks are there in Azure AD?

a)

User and sign-in risks

b)

Credentials and identity risks

c)

Sign-in and identity risk

d)

User and identity risks

7.

Your organization has Microsoft Defender for Cloud. You need to protect against identity risk. Your organization’s specialist expertise is in retail and not a security specialist. What can you use to protect against identity risk?

a)

Security Center

b)

Security manager

c)

Identity manager

d)

Azure AD Identity Protection

8.

Your organization have Microsoft Defender and Microsoft Cloud App Security. You have sensitive data which contain users details such as card numbers, etc. You plan to create a policy that can help to protect sensitive information. You plan to use a data loss prevention (DLP) policy to protect.

What will you use to detect sensitive information/data, and in which document is it?

a)

SharePoint search

b)

Document Scanner

c)

Hunting query in Microsoft Defender

d)

Microsoft Purview

9.

Your organization has Microsoft defender for cloud. You need to investigate potential cyberattack, and the sooner you identify better off your organization will be. You are receiving alerts. What will you use to investigate automatically and respond with a set of security playbooks when an alert triggered?

a)

Threat mitigation

b)

Automated investigation and response (AIR)

c)

Remediate

d)

Automated alert and response (AAR)

10.

Your organization has a Microsoft 365 subscription that uses Microsoft Defender for Office 365. You have configured Cloud App Security, and you have sensitive information, so you have used DLP to protect. Which type of policy is used?

a)

Access Policy

b)

Session Policy

c)

Anomaly detection policy

d)

File Policy

11.

You have an Azure subscription that has Microsoft Defender for Cloud. You want to safeguards encryption secrets and key. Ex: Passwords. Which service will use for secrets?

a)

Advanced Threat Protection

b)

Microsoft Defender for Key Vault

c)

Microsoft Defender for Secret storage

d)

Microsoft Defender for servers

12.

Your company has an Azure subscription that uses Microsoft Defender for Cloud. You want to ensure that Microsoft Defender for Cloud covers all resources in Azure subscription by Enabling the Automatic provisioning option. What if you started a new Azure Windows VM without using auto-provisioning? What should you install in the new VM?

a)

Auto Log generator

b)

Sysmon

c)

Windows firewall

d)

Log Analytics Agent

13.

You are planning to automate remediation in your subscription. Which Azure technology will be used?

a)

Azure Batch

b)

Azure Functions

c)

Log Analytics Agent

d)

Azure Logic Apps

14.

Which render operator is used to creating a visualization of time series in the KQL query?

a)

timechart

b)

 areachart

c)

datetimechart

d)

 Piechart

15.

Your company has an Azure subscription. You have Microsoft Sentinel. Security operations could be included when you use Microsoft Sentinel. Which of the following is not included in Security operations?

a)

Anomaly detection

b)

Security patch detection

c)

Visualization of log data

d)

Threat hunting

16.

Your organization has an Azure subscription, and you want to collect event data from various sources and perform security operations on that data to identify suspicious activity. What service will you plan to use to identify suspicious activity?

a)

Security Center

b)

Microsoft Sentinel

c)

Security Manager

d)

None of above

17.

You have a Microsoft Sentinel. You can create a query using Kusto Query Language(KQL). Which table will you query to view your indicators?

a)

Indicator

b)

ThreatIntelligenceIndicator

c)

Watchlist

d)

IT Indicator

18.

You have Microsoft Sentinel. Next, you must configure a Linux machine to forward the logs from your security solution to your Microsoft Sentinel workspace. You want to connect an external solution. You plan to use the CEF connector.  What needs to be installed in the Linux machine?

a)

Log collector for Linux

b)

Azure monitor agent for Linux

c)

Ext-connector for Linux

d)

CEF connector agent for Linux

19.

Your organization uses Microsoft Sentinel, and you have a Sentinel workspace. Where can you test in Microsoft Sentinel from, as you want to try a playbook manually in the Azure portal?

a)

Incidents

b)

Threat intelligence

c)

Analytics

d)

Playbooks

20.

When a user attempts to sign in from a location that was never used by the other users in your organization to sign in, you need to receive a security alert when user attempts to sign in from unused location by users in organization. Which anomaly detection policy should you use?

a)

Malware detection

b)

Impossible travel

c)

Activity from infrequent country

d)

Activity from anonymous IP addresses.

21.

You have an Azure subscription that has Microsoft Defender for cloud enabled for all supported resource types. You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution such as Splunk or Qradar.

To which service should you export the alerts?

a)

Azure Cosmos DB

b)

Azure Event Grid

c)

Azure Event Hubs

d)

Azure Data Lake

22.

You have a playbook in Microsoft Sentinel. When you trigger the playbook, it sends an email to a distribution group. You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.

What should you do?

a)

Add a parameter and modify the trigger.

b)

 Add a custom data connector and modify the trigger.

c)

Add a condition and modify the action.

d)

Add a parameter and modify the action.

23.

You recently deployed Microsoft Sentinel. You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled. You need to ensure that the Fusion rule can generate alerts.

What should you do?

a)

Disable, and then enable the rule.

b)

Add data connectors

c)

Create a new machine learning analytics rule.

d)

Add a hunting bookmark.

24.

Your company uses Microsoft Sentinel. A new security analyst reports that she cannot assign and dismiss incidents in Microsoft Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privileges.

Which role should you assign to the analyst?

a)

Microsoft Sentinel Responder

b)

Logic App Contributor

c)

Microsoft Sentinel Contributor

d)

Microsoft Sentinel Reader

25.

You need to create the test rule to meet the requirements for Investigate an incident.

What should you add when you create the rule?

a)

From Set rule logic, turn off suppression.

b)

From Analytics rule details, configure the tactics.

c)

From Set rule logic, map the entities.

d)

From Analytics rule details, configure the severity.