SC-200 試験問題を無料オンラインアクセス
| 試験コード: | SC-200 |
| 試験名称: | Microsoft Security Operations Analyst |
| 認定資格: | Microsoft |
| 無料問題数: | 415 |
| 更新日: | 2026-08-30 |
You have a Microsoft Sentinel workspace that contains the following incident.
Brute force attack against Azure Portal analytics rule has been triggered.
You need to identify the geolocation information that corresponds to the incident.
What should you do?
You have a Microsoft Sentinel workspace that contains the following incident Brute force attack against Azure Portal analytics rule has been triggered. You need to identify the geolocation information that corresponds to the incident. What should you do?
You have a Microsoft Sentinel workspace named Workspaces1.
The AzureActivity table in Workspace! has the following retention periods:
* Interactive: 180 days
* Total:180days
You need to modify the retention periods to meet the following requirements:
* Minimize the costs associated with storing data in the table.
* Maximize the period during which the table data remains available.
How should you configure each retention period? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
You have a playbook in Azure Sentinel.
When you trigger the playbook, it sends an email to a distribution group.
You need to modify the playbook to send the email to the owner of the resource instead of the distribution group.
What should you do?
You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices.
The devices have Microsoft 365 Apps installed and are onboarded to Microsoft Defender for Endpoint.
You need to mitigate the following device threats:
* Microsoft Excel macros that download scripts from untrusted websites
* Users that open executable attachments in Microsoft Outlook
* Outlook rules and forms exploits
What should you use?


最近のコメント (最新のコメントはトップにあります。)
Do My Best!