Go Back on SC-200 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

SC-200 Practice Test


Page 5 out of 32 Pages

Topic 3: Misc. Questions

You have a custom analytics rule to detect threats in Azure Sentinel.
You discover that the analytics rule stopped running. The rule was disabled, and the rule
name has a prefix of AUTO DISABLED.
What is a possible cause of the issue?


A.

There are connectivity issues between the data sources and Log Analytics.


B.

The number of alerts exceeded 10,000 within two minutes.


C.

The rule query takes too long to run and times out.


D.

Permissions to one of the data sources of the rule query were modified





D.
  

Permissions to one of the data sources of the rule query were modified



You have an Azure subscription that uses Microsoft Defender for Cloud and contains a
storage account named storage1. You receive an alert that there was an unusually high
volume of delete operations on the blobs in storage1.
You need to identify which blobs were deleted.
What should you review?


A.

the Azure Storage Analytics logs


B.

the activity logs of storage1


C.

the alert details


D.

the related entities of the alert





B.
  

the activity logs of storage1



You have an Azure subscription that uses Microsoft Sentinel.
You need to create a custom report that will visualise sign-in information over time.
What should you create first?


A.

a workbook


B.

a hunting query


C.

a notebook


D.

a playbook





A.
  

a workbook



Explanation:
A workbook is a data-driven interactive report in Microsoft Sentinel. You can use
workbooks to create custom reports based on data from your Azure subscription.
Reference: https://docs.microsoft.com/en-us/azure/sentinel/workbooks-overview

You recently deployed Azure Sentinel.
You discover that the default Fusion rule does not generate any alerts. You verify that the
rule is enabled.
You need to ensure that the Fusion rule can generate alerts.
What should you do?


A.

Disable, and then enable the rule.


B.

Add data connectors


C.

Create a new machine learning analytics rule


D.

Add a hunting bookmark.





B.
  

Add data connectors



Your company stores the data for every project in a different Azure subscription. All the
subscriptions use the same Azure Active Directory (Azure AD) tenant.
Every project consists of multiple Azure virtual machines that run Windows Server. The
Windows events of the virtual machines are stored in a Log Analytics workspace in each
machine’s respective subscription.
You deploy Azure Sentinel to a new Azure subscription.
You need to perform hunting queries in Azure Sentinel to search across all the Log
Analytics workspaces of all the subscriptions.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.


A.

Add the Security Events connector to the Azure Sentinel workspace.


B.

Create a query that uses the workspace expression and the union operator.


C.

Use the alias statement.


D.

Create a query that uses the resource expression and the alias operator.


E.

Add the Azure Sentinel solution to each workspace.





B.
  

Create a query that uses the workspace expression and the union operator.



E.
  

Add the Azure Sentinel solution to each workspace.




Page 5 out of 32 Pages
Previous