DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft SC-200 Practice Questions & Answers 2026 Part3 | Microsoft Security Operations Analyst

Are you preparing for the Microsoft SC-200 certification exam? SPOTO offers the Microsoft SC-200 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have a Microsoft 365 E5 subscription that is linked to a hybrid Microsoft Entra tenant. You need to identify all the changes made to Domain Admins group during the past 30 days. What should you use?
A. the Modifications of sensitive groups report in Microsoft Defender for Identity
B. the identity security posture assessment in Microsoft Defender for Cloud Apps
C. the Microsoft Entra ID Provisioning Analysis workbook
D. the Overview settings of Insider risk management
View answer
Correct Answer: A

View The Updated SC-200 Exam Questions

SPOTO Provides 100% Real SC-200 Exam Questions for You to Pass Your SC-200 Exam!

Question #2
An engineer updates the SCOS version from 6.5.x to 6.6.x on an SC4020 via ISO. Theengineer uses the following credentials: admin / admin. The engineer calls Dell Support forfinal health checks and is informed that a newer SCOS 6.6.x version is available. Theengineer tries to perform another ISO update to the newest SCOS 6.6.x version. Theengineer is unable to log back in to the BMC interface to start the ISO update.What should the engineer do to update the newest SCOS version via ISO?
A. use the login credentials root/ calvin in SCOS 6
B. update Java to version 8 to use the updated BMC interface
C. downgrade Java to version 7 from version 8
D. request Dell Support to reset the expired admin password
View answer
Correct Answer: A
Question #3
Your company uses Microsoft Defender for Endpoint.The company has Microsoft Word documents that contain macros. The documents are used frequently on the devices of the company's accounting team.You need to hide false positive in the Alerts queue, while maintaining the existing security posture.Which three actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. esolve the alert automatically
B. ide the alert
C. reate a suppression rule scoped to any device
D. reate a suppression rule scoped to a device group
E. enerate the alert
View answer
Correct Answer: BDE
Question #4
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You configure Controlled folder access. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #5
Case studyThis is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.To start the case study To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.OverviewAdatum Corporation is a United States-based financial services company that has regional offices in New York, Chicago, and San Francisco.Existing EnvironmentIdentity EnvironmentThe on-premises network contains an Active Directory Domain Services (AD DS) forest named corp.adatum.com that syncs with an Azure AD tenant named adatum.com. All user and group management tasks are performed in corp.adatum.com. The corp.adatum.com domain contains a group named Group1 that syncs with adatum.com.Licensing StatusAll the users at Adatum are assigned a Microsoft 365 ES license and an Azure Active Directory Premium P2 license.Cloud EnvironmentThe cloud environment contains a Microsoft 365 subscription, an Azure subscription linked to the adatum.com tenant, and the resources shown in the following table.On-premises EnvironmentThe on-premises network contains the resources shown in the following table.RequirementsPlanned changesAdatum plans to perform the following changes:Implement a query named rulequery1 that will include the following KQL query.Implement a Microsoft Sentinel scheduled rule that generates incidents based on rulequery1.Microsoft Defender for Cloud RequirementsAdatum identifies the following Microsoft Defender for Cloud requirements:The members of Group1 must be able to enable Defender for Cloud plans and apply regulatory compliance initiatives.Microsoft Defender for Servers Plan 2 must be enabled on all the Azure virtual machines.Server2 must be excluded from agentless scanning.Microsoft Sentinel RequirementsAdatum identifies the following Microsoft Sentinel requirements:Implement an Advanced Security Information Model (ASIM) query that will return a count of DNS requests that results in an NXDOMAIN response from Infoblox1.Ensure that multiple alerts generated by rulequery1 in response to a single user launching Azure Cloud Shell multiple times are consolidated as a single incident.Implement the Windows Security Events via AMA connector for Microsoft Sentinel and configure it to monitor the Security event log of Server1.Ensure that incidents generated by rulequery1 are closed automatically if Azure Cloud Shell is launched by the companys SecOps team.Implement a custom Microsoft Sentinel workbook named Workbook1 that will include a query to dynamically retrieve data from Webapp1.Implement a Microsoft Sentinel near-real-time (NRT) analytics rule that detects sign-ins to a designated break glass account.Ensure that HuntingQuery1 runs automatically when the Hunting page of Microsoft Sentinel in the Azure portal is accessed.Ensure that higher than normal volumes of password resets for corp.adatum.com user accounts are detected.Minimize the overhead associated with queries that use ASIM parsers.Ensure that the Group1 members can create and edit playbooks.Use built-in ASIM parsers whenever possible.Business RequirementsAdatum identifies the following business requirements:Follow the principle of least privilege whenever possible.Minimize administrative effort whenever possible.You need to ensure that the Group1 members can meet the Microsoft Sentinel requirements.Which role should you assign to Group1?
A. icrosoft Sentinel Playbook Operator
B. ogic App Contributor
C. utomation Operator
D. icrosoft Sentinel Automation Contributor
View answer
Correct Answer: B
Question #6
You have a Microsoft 365 E5 subscription that uses Microsoft SharePoint Online. You delete users from the subscription.You need to be notified if the deleted users downloaded numerous documents from SharePoint Online sites during the month before their accounts were deleted.What should you use?
A. a file policy in Microsoft Defender for Cloud Apps
B. an access review policy
C. an alert policy in Microsoft Defender for Office 365
D. an insider risk management policy
View answer
Correct Answer: D
Question #7
You have an Azure subscription that uses Microsoft Defender for Servers Plan 1 and contains a server named Server1.You enable agentless scanning.You need to prevent Server1 from being scanned. The solution must minimize administrative effort. What should you do?
A. Create an exclusion tag
B. Upgrade the subscription to Defender for Servers Plan 2
C. Create a governance rule
D. Create an exclusion group
View answer
Correct Answer: A
Question #8
The SAS chain starts in port 1 controller 1 and ends at controller 2 at port 3.What are the correct connections in a 4-port SAS IO card?
A. ide A port 3: port 3 & : Side B port 3: port 3
B. ide A port 1: port 1 & : Side B port 1: port 1
C. ide A port 1: port 1& : Side B port 3: port 3
D. ide A port 1: port 3 & : Side B port 1: port 3
View answer
Correct Answer: D
Question #9
You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.You have Microsoft SharePoint Online sites that contain sensitive documents. The documents contain customer account numbers that each consists of 32 alphanumeric characters.You need to create a data loss prevention (DLP) policy to protect the sensitive documents. What should you use to detect which documents are sensitive?
A. SharePoint search
B. a hunting query in Microsoft 365 Defender
C. Azure Information Protection
D. RegEx pattern matching
View answer
Correct Answer: D
Question #10
When replacing a defective SC4020 controller with a new controller, the engineer noticesthat the new controller does NOT fully initialize. The system runs SCOS version 6.5.30.Which three actions should the engineer take? (Choose three.)
A. contact Dell Support
B. note the controller LEDsthat are lit or blinking
C. send a PhoneHome/SupportAssist
D. remove the battery from the controller
E. remove power cables from the chassis to drain the BMC
View answer
Correct Answer: ABC
Question #11
You have a Microsoft 365 subscription that uses Microsoft 365 Defender. You need to identify all the entities affected by an incident.Which tab should you use in the Microsoft 365 Defender portal?
A. Investigations
B. Devices
C. Evidence and Response
D. Alerts
View answer
Correct Answer: C
Question #12
You have a Microsoft 365 subscription. The subscription uses Microsoft Purview and has data loss prevention (DLP) policies that have aggregated alerts configured.You need to identify the impacted entities in an aggregated alert.What should you review in the DLP alert management dashboard of the Microsoft Purview compliance portal?
A. the Events tab of the alert
B. the Sensitive Info Types tab of the alert
C. Management log
D. the Details tab of the alert
View answer
Correct Answer: A
Question #13
You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.You have Microsoft SharePoint Online sites that contain sensitive documents. The documents contain customer account numbers that each consists of 32alphanumeric characters.You need to create a data loss prevention (DLP) policy to protect the sensitive documents.What should you use to detect which documents are sensitive?
A. SharePoint search
B. a hunting query in Microsoft 365 Defender
C. Azure Information Protection
D. RegEx pattern matching
View answer
Correct Answer: D
Question #14
You have a Microsoft Sentinel workspace named Workspace1. Workspace1 contains a table named Table1 that stores security events from a custom application. Table1 is used by the analytics rules in Microsoft Sentinel to generate incidents. You discover that the security events in Table1 are inaccurate. You need to ensure that future incidents are NOT generated by the analytics rules until the security events in Table1 are resolved. The solution must minimize effort. What should you do in Microsoft Sentinel?
A. Modify the analytics rules
B. Modify the Workspace settings
C. Select the incidents, and then set the severity of each incident to Informational
D. Select the incidents, and then set the status of each incident to Closed
View answer
Correct Answer: A
Question #15
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You configure Controlled folder access. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #16
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You discover that when Microsoft Defender for Endpoint generates alerts for a commonly used executable file, it causes alert fatigue.You need to tune the alerts.Which two actions can an alert tuning rule perform for the alerts? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. delete
B. hide
C. resolve
D. merge
E. assign
View answer
Correct Answer: BC
Question #17
The issue for which team can be resolved by using Microsoft Defender for Endpoint?
A. executive
B. sales
C. marketing
View answer
Correct Answer: B
Question #18
You create an Azure subscription named sub1. In sub1, you create a Log Analytics workspace named workspace1. You enable Azure Security Center and configure Security Center to use workspace1. You need to ensure that Security Center processes events from the Azure virtual machines that report to workspace1. What should you do?
A. AIn workspace1, install a solution
B. BIn sub1, register a provider
C. CFrom Security Center, create a Workflow automation
D. DIn workspace1, create a workbook
View answer
Correct Answer: A
Question #19
Your company uses Microsoft Defender for Endpoint.The company has Microsoft Word documents that contain macros. The documents are used frequently on the devices of the company’s accounting team.You need to hide false positive in the Alerts queue, while maintaining the existing security posture. Which three actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. Resolve the alert automatically
B. Hide the alert
C. Create a suppression rule scoped to any device
D. Create a suppression rule scoped to a device group
E. Generate the alert
View answer
Correct Answer: BDE
Question #20
You have a Microsoft 365 subscription that contains a user named User1. You need to identify whether User1 signed in to Microsoft 365 and shared a document stored in Microsoft OneDrive during the last 30 days. What should you use?
A. the Azure portal
B. the Microsoft Defender portal
C. the Microsoft Entra admin center
D. the Microsoft Purview portal
View answer
Correct Answer: D
Question #21
You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in.Which Microsoft Defender for Cloud Apps anomaly detection policy should you use?
A. Impossible travel
B. Activity from anonymous IP addresses
C. Activity from infrequent country
D. Malware detection
View answer
Correct Answer: C
Question #22
You are configuring Microsoft Defender for Cloud Apps.You have a custom threat detection policy based on the IP address ranges of your company’s United States- based offices.You receive many alerts related to impossible travel and sign-ins from risky IP addresses. You determine that 99% of the alerts are legitimate sign-ins from your corporate offices. You need to prevent alerts for legitimate sign-ins from known locations.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. Configure automatic data enrichment
B. Add the IP addresses to the corporate address range category
C. Increase the sensitivity level of the impossible travel anomaly detection policy
D. Add the IP addresses to the other address range category and add a tag
E. Create an activity policy that has an exclusion for the IP addresses
View answer
Correct Answer: AB
Question #23
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You configure endpoint detection and response (EDR) in block mode. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #24
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that mightmeet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are configuring Microsoft Defender for Identity integration with Active Directory.From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit.Solution: From Entity tags, you add the accounts as Honeytoken accounts.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #25
Your company uses Microsoft Defender for Cloud. You need to configure the continuous export of Defender for Cloud data. To which two destinations can you export the data? Each correct answer presents a complete solution.
A. an Azure SQL database
B. a Log Analytics workspace
C. a storage account
D. an Azure Synapse Analytics workspace
E. an event hub
View answer
Correct Answer: BE
Question #26
You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.You deploy Azure Sentinel.You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
A. And a new scheduled query rule
B. Add a data connector to Azure Sentinel
C. Configure a custom Threat Intelligence connector in Azure Sentinel
D. Modify the trigger in the logic app
View answer
Correct Answer: D
Question #27
Your company has a single office in Istanbul and a Microsoft 365 subscription.The company plans to use conditional access policies to enforce multi-factor authentication (MFA). You need to enforce MFA for all users who work remotely.What should you include in the solution?
A. a fraud alert
B. a user risk policy
C. a named location
D. a sign-in user policy
View answer
Correct Answer: C
Question #28
You have a Microsoft Sentinel workspace named Workspace1. You need to create and customize a workbook based on an Identity & Access template in Workspace1. What should you do first?
A. Publish the workbook template
B. Edit the workbook template
C. Clone the workbook template
D. Save the workbook template
View answer
Correct Answer: C
Question #29
How are replay scheduling rules applied to a particular volume?
A. Areplay profile may have multiple schedule rules, but a volume belongs to exactly one replay profile
B. A replay profile may have multiple schedule rules, and a volume may belong to multiple replay profiles
C. A replay profile has exactly one schedulerule, but a volume may belong to multiple replay profiles
D. A replay profile has exactly one schedule rule, and a volume belongs to exactly one replay profile
View answer
Correct Answer: A
Question #30
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint.You need to identify any devices that triggered a malware alert and collect evidence related to the alert. The solution must ensure that you can use the results to initiate device isolation for the affected devices.What should you use in the Microsoft 365 Defender portal?
A. incidents
B. Remediation
C. Investigations
D. Advanced hunting
View answer
Correct Answer: D
Question #31
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You need to implement deception rules. The solution must ensure that you can limit the scope of the rules. What should you create first?
A. device groups
B. device tags
C. honeytoken entity tags
D. sensitive entity tags
View answer
Correct Answer: B
Question #32
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You configure Controlled folder access. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #33
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.You need to add threat indicators for all the IP addresses in a range of 171.23.34.32-171.23.34.63. The solution must minimize administrative effort.What should you do in the Microsoft 365 Defender portal?
A. Create an import file that contains the individual IP addresses in the range
B. Create an import file that contains the IP address of 171
C. Select Add indicator and set the IP address to 171
D. Select Add indicator and set the IP address to 171
View answer
Correct Answer: A
Question #34
You have five on-premises Linux servers.You have an Azure subscription that uses Microsoft Defender for Cloud.You need to use Defender for Cloud to protect the Linux servers.What should you install on the servers first?
A. the Dependency agent
B. the Log Analytics agent
C. the Azure Connected Machine agent
D. the Guest Configuration extension
View answer
Correct Answer: B
Question #35
You have a Microsoft 365 subscription that uses Microsoft Purview and Microsoft Teams. You have a team named Team1 that has a project named Project1.You need to identify any Project1 files that were stored on the team site of Team1 between February 1, 2023, and February 10, 2023.Which KQL query should you run?
A. (c:c)(Project1)(date=(2023-02-01)
B. AuditLogs| where Timestamp between (datetime(2023-02-01)
C. Project1(c:c)(date=2023-02-01
D. AuditLogs| where Timestamp > ago(10d)| where FileName contains “Project1”
View answer
Correct Answer: C
Question #36
An engineer has installed a Storage Array with a Tier 1 consisting of SSDs.What should the engineer do to optimize performance for I/O workloads utilizing this Tier?
A. isable write cache on volumes
B. onvert Tier 1 to RAID 0
C. egregate the SSDs to a separate disk folder
D. hange the sector size from 512 to 4K
View answer
Correct Answer: A
Question #37
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are configuring Microsoft Defender for Identity integration with Active Directory.From the Microsoft Defender portal, you need to configure several accounts for attackers to exploit. Solution: From Entity tags, you add the accounts as Honeytoken accounts.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #38
You have a Microsoft 365 E5 subscription. You plan to create a Microsoft Defender XDR hunting query to identify users that have been affected by clicking a suspicious URL. You need to create a detection rule that will mark the user as compromised. Which two properties should you include in the rule? Each answer presents part of the solution. Select all answers that apply.
A. TimeGenerated
B. AlertId
C. ReportId
D. AccountUpn
View answer
Correct Answer: CD
Question #39
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.You need to review new attack techniques discovered by Microsoft and identify vulnerable resources in the subscription. The solution must minimize administrative effort.Which blade should you use in the Microsoft Defender portal?
A. Advanced hunting
B. Threat analytics
C. Incidents & alerts
D. Learning hub
View answer
Correct Answer: B
Question #40
You have the following advanced hunting query in Microsoft 365 Defender.You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. reate a detection rule
B. reate a suppression rule
C. dd | order by Timestamp to the query
D. eplace DeviceProcessEvents with DeviceNetworkEvents
E. dd DeviceId and ReportId to the output of the query
View answer
Correct Answer: AE
Question #41
You have a Microsoft 365 tenant that uses Microsoft Exchange Online and Microsoft Defender for Office 365.What should you use to identify whether zero-hour auto purge (ZAP) moved an email message from the mailbox of a user?
A. the Threat Protection Status report in Microsoft Defender for Office 365
B. the mailbox audit log in Exchange
C. the Safe Attachments file types report in Microsoft Defender for Office 365
D. the mail flow report in Exchange
View answer
Correct Answer: A
Question #42
You have a Microsoft Sentinel workspace. You need to view a visual representation of the data in the workspace. What should you use?
A. a notebook
B. a playbook
C. a workbook
D. Azure Data Factory
View answer
Correct Answer: C
Question #43
You have an Azure subscription that has Azure Defender enabled for all supported resource types.You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution.To which service should you export the alerts?
A. zure Cosmos DB
B. zure Event Grid
C. zure Event Hubs
D. zure Data Lake
View answer
Correct Answer: C
Question #44
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You configure endpoint detection and response (EDR) in block mode. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #45
You have a Microsoft Sentinel workspace named Workspace1 that contains the AzureActivity table.You need to configure the retention period for the AzureActivity table. The solution must meet the following requirements:* Maximize the period during which you can run interactive queries.* Minimize retention costs.To what should you set the retention period? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
A. 0 days
B. 80 days
C. years
D. 0 days
View answer
Correct Answer: A
Question #46
Your company uses Azure Sentinel to manage alerts from more than 10,000 IoT devices.A security manager at the company reports that tracking security threats is increasingly difficult due to the large number of incidents.You need to recommend a solution to provide a custom visualization to simplify the investigation of threats and to infer threats by using machine learning.What should you include in the recommendation?
A. uilt-in queries
B. ookmarks
C. otebooks
D. ivestream
View answer
Correct Answer: B
Question #47
You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices.The devices have Microsoft 365 Apps installed and are onboarded to Microsoft Defender for Endpoint. You need to mitigate the following device threats:Microsoft Excel macros that download scripts from untrusted websites Users that open executable attachments in Microsoft OutlookOutlook rules and forms exploits What should you use?
A. antivirus exclusions of Microsoft Defender for Endpoint
B. attack surface reduction rules in Microsoft Defender for Endpoint
C. Windows Defender Firewall rules
D. adaptive application control in Microsoft Defender for Cloud
View answer
Correct Answer: B
Question #48
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You discover that when Microsoft Defender for Endpoint generates alerts for a commonly used executable file, it causes alert fatigue.You need to tune the alerts.Which two actions can an alert tuning rule perform for the alerts? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. delete
B. hide
C. resolve
D. merge
E. assign
View answer
Correct Answer: BC
Question #49
The issue for which team can be resolved by using Microsoft Defender for Endpoint?
A. executive
B. sales
C. marketing
View answer
Correct Answer: B
Question #50
You have an Azure Sentinel deployment in the East US Azure region.You create a Log Analytics workspace named LogsWest in the West US Azure region.You need to ensure that you can use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to LogsWest.What should you do first?
A. eploy Azure Data Catalog to the West US Azure region
B. odify the workspace settings of the existing Azure Sentinel deployment
C. dd Azure Sentinel to a workspace
D. reate a data connector in Azure Sentinel
View answer
Correct Answer: C
Question #51
An engineer has installed an SC8000 with 15K drives in Tier 1, and 7K drives in Tier 3. Thevolume is created using the recommended storage profile. A replay is taken after the initialdata is imported, which results in On Demand Data Progression running.What is going to happen to the data?
A. Drozen user data is converted to Raid 5/6 from Raid 10 immediately
B. The oldest data moves to the lowest storage tier
C. Data moves from Tier1 storage to Tier 3
D. Data moves to the lowest storage tier allowed by the storage profile
View answer
Correct Answer: C
Question #52
You need to configure Microsoft Defender for Cloud Apps to generate alerts and trigger remediation actions in response to external sharing of confidential files.Which two actions should you perform in the Microsoft Defender portal? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. From Settings, select Information Protection, select Azure Information Protection, and then select Only scan files for Azure Information Protection classification labels and content inspection warnings from this tenant
B. From Cloud apps, select Files, and then filter File Type to Document
C. From Settings, select Information Protection, select Files, and then enable file monitoring
D. From Cloud apps, select Files, and then filter App to Office 365
E. From Cloud apps, select Files, and then select New policy from search
F. From Settings, select Information Protection, select Azure Information Protection, and then select Automatically scan new files for Azure Information Protection classification labels and content inspection warnings
View answer
Correct Answer: BF
Question #53
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You discover that when Microsoft Defender for Endpoint generates alerts for a commonly used executable file, it causes alert fatigue.You need to tune the alerts.Which two actions can an alert tuning rule perform for the alerts? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. delete
B. hide
C. resolve
D. merge
E. assign
View answer
Correct Answer: BC

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us