NEW
Font size
WorksheetsSC-200 Quiz
Total questions: 25
Worksheet time: 13mins
There are various components in DLP. Which among the following classifies as a document, and which component can protect content in locations like SharePoint Online?
Sensitive info types and Access Policy
Access Policy and DLP Policy
Sensitivity label and DLP Policy
DLP Policy and Retention Policy
Your organization uses Microsoft defender for cloud. In Microsoft defender for cloud, you want to see the topology of your workloads. Which feature of Defender enables you to see it:
Secure Score
Inventory
Network map
Biometric analytics
Your organization has Microsoft 365 Defender, Microsoft Defender for Endpoint. Your organization need you to do an in-depth investigation and take immediate response action on identified threats in real-time? What should you use:
Hunt for emerging threats
Live device investigation manager
Live response
Security operations
Which live response basic command is used to Initiates a live response session to the device?
connect
processes
connections
Init
You have Microsoft Defender for Endpoint. In Indicators, which file type and type is used to upload and accepted type?
CSV and Certificates
CSV and Code data
XML and Certificates
JSON and Email subject line
What types of risks are there in Azure AD?
User and sign-in risks
Credentials and identity risks
Sign-in and identity risk
User and identity risks
Your organization has Microsoft Defender for Cloud. You need to protect against identity risk. Your organization’s specialist expertise is in retail and not a security specialist. What can you use to protect against identity risk?
Security Center
Security manager
Identity manager
Azure AD Identity Protection
Your organization have Microsoft Defender and Microsoft Cloud App Security. You have sensitive data which contain users details such as card numbers, etc. You plan to create a policy that can help to protect sensitive information. You plan to use a data loss prevention (DLP) policy to protect.
What will you use to detect sensitive information/data, and in which document is it?
SharePoint search
Document Scanner
Hunting query in Microsoft Defender
Microsoft Purview
Your organization has Microsoft defender for cloud. You need to investigate potential cyberattack, and the sooner you identify better off your organization will be. You are receiving alerts. What will you use to investigate automatically and respond with a set of security playbooks when an alert triggered?
Threat mitigation
Automated investigation and response (AIR)
Remediate
Automated alert and response (AAR)
Your organization has a Microsoft 365 subscription that uses Microsoft Defender for Office 365. You have configured Cloud App Security, and you have sensitive information, so you have used DLP to protect. Which type of policy is used?
Access Policy
Session Policy
Anomaly detection policy
File Policy
You have an Azure subscription that has Microsoft Defender for Cloud. You want to safeguards encryption secrets and key. Ex: Passwords. Which service will use for secrets?
Advanced Threat Protection
Microsoft Defender for Key Vault
Microsoft Defender for Secret storage
Microsoft Defender for servers
Your company has an Azure subscription that uses Microsoft Defender for Cloud. You want to ensure that Microsoft Defender for Cloud covers all resources in Azure subscription by Enabling the Automatic provisioning option. What if you started a new Azure Windows VM without using auto-provisioning? What should you install in the new VM?
Auto Log generator
Sysmon
Windows firewall
Log Analytics Agent
You are planning to automate remediation in your subscription. Which Azure technology will be used?
Azure Batch
Azure Functions
Log Analytics Agent
Azure Logic Apps
Which render operator is used to creating a visualization of time series in the KQL query?
timechart
areachart
datetimechart
Piechart
Your company has an Azure subscription. You have Microsoft Sentinel. Security operations could be included when you use Microsoft Sentinel. Which of the following is not included in Security operations?
Anomaly detection
Security patch detection
Visualization of log data
Threat hunting
Your organization has an Azure subscription, and you want to collect event data from various sources and perform security operations on that data to identify suspicious activity. What service will you plan to use to identify suspicious activity?
Security Center
Microsoft Sentinel
Security Manager
None of above
You have a Microsoft Sentinel. You can create a query using Kusto Query Language(KQL). Which table will you query to view your indicators?
Indicator
ThreatIntelligenceIndicator
Watchlist
IT Indicator
You have Microsoft Sentinel. Next, you must configure a Linux machine to forward the logs from your security solution to your Microsoft Sentinel workspace. You want to connect an external solution. You plan to use the CEF connector. What needs to be installed in the Linux machine?
Log collector for Linux
Azure monitor agent for Linux
Ext-connector for Linux
CEF connector agent for Linux
Your organization uses Microsoft Sentinel, and you have a Sentinel workspace. Where can you test in Microsoft Sentinel from, as you want to try a playbook manually in the Azure portal?
Incidents
Threat intelligence
Analytics
Playbooks
When a user attempts to sign in from a location that was never used by the other users in your organization to sign in, you need to receive a security alert when user attempts to sign in from unused location by users in organization. Which anomaly detection policy should you use?
Malware detection
Impossible travel
Activity from infrequent country
Activity from anonymous IP addresses.
You have an Azure subscription that has Microsoft Defender for cloud enabled for all supported resource types. You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution such as Splunk or Qradar.
To which service should you export the alerts?
Azure Cosmos DB
Azure Event Grid
Azure Event Hubs
Azure Data Lake
You have a playbook in Microsoft Sentinel. When you trigger the playbook, it sends an email to a distribution group. You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
What should you do?
Add a parameter and modify the trigger.
Add a custom data connector and modify the trigger.
Add a condition and modify the action.
Add a parameter and modify the action.
You recently deployed Microsoft Sentinel. You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled. You need to ensure that the Fusion rule can generate alerts.
What should you do?
Disable, and then enable the rule.
Add data connectors
Create a new machine learning analytics rule.
Add a hunting bookmark.
Your company uses Microsoft Sentinel. A new security analyst reports that she cannot assign and dismiss incidents in Microsoft Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privileges.
Which role should you assign to the analyst?
Microsoft Sentinel Responder
Logic App Contributor
Microsoft Sentinel Contributor
Microsoft Sentinel Reader
You need to create the test rule to meet the requirements for Investigate an incident.
What should you add when you create the rule?
From Set rule logic, turn off suppression.
From Analytics rule details, configure the tactics.
From Set rule logic, map the entities.
From Analytics rule details, configure the severity.
