Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SC-200

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in.Which anomaly detection policy should you use?

a)

Activity from infrequent country

b)

Impossible travel

c)

Activity from anonymous IP addresses

d)

Malware detection

2.

This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are configuring Microsoft Defender for Identity integration with Active Directory.From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit.Solution: From Entity tags, you add the accounts as Honeytoken accounts.Does this meet the goal?

a)

Yes

b)

No

3.

What does the search operator do?

a)

Searches across tables and isn't column-specific.

b)

Searches only data in the last hour.

c)

Searches in columns specified.

4.

What are project operators?

a)

Project operators filter a table to the subset of rows that satisfy a predicate.

b)

Project operators create summarized columns and append them to the result set.

c)

Project operators add, remove, or rename columns in a result set.

5.

You can classify an Incident as which of the following?

a)

True alert

b)

High alert

c)

Test alert

6.

What describes Safe Attachments from Microsoft Defender for Office 365?

a)

Messages and attachments are routed to a special environment where Microsoft Defender for Office 365 uses a variety of machine learning and analysis techniques to detect malicious intent.

b)

Protects your users from malicious URLs in a message or in an Office document.

c)

A powerful report that enables your Security Operations team to investigate and respond to threats effectively and efficiently.

7.

How can you ensure that a file is sent into quarantine for review by an administrator?

a)

When creating a file policy, select Quarantine for admin

b)

When creating a file policy, select Put in admin quarantine

c)

When creating a file policy, select Put in review for admin

8.

Your company has a single office in Istanbul and a Microsoft 365 subscription.The company plans to use conditional access policies to enforce multi-factor authentication (MFA).You need to enforce MFA for all users who work remotely.What should you include in the solution?

a)

a fraud alert

b)

a user risk policy

c)

a named location

d)

a sign-in user policy

9.

You create an Azure subscription named sub1.In sub1, you create a Log Analytics workspace named workspace1.You enable Azure Security Center and configure Security Center to use workspace1.You need to collect security event logs from the Azure virtual machines that report to workspace1.What should you do?

a)

From Security Center, enable data collection

b)

In sub1, register a provider.

c)

From Security Center, create a Workflow automation.

d)

In workspace1, create a workbook.

10.

You create an Azure subscription. You enable Azure Defender for the subscription. You need to use Azure Defender to protect on-premises computers. What should you do on the on-premises computers?

a)

A Install the Log Analytics agent.

b)

nstall the Dependency agent.

c)

Configure the Hybrid Runbook Worker role.

d)

Install the Connected Machine agent.