Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

SC-200 Exam Dumps - Microsoft Certified: Security Operations Analyst Associate Questions and Answers

Question # 44

You need to deploy the native cloud connector to Account! to meet the Microsoft Defender for Cloud requirements. What should you do in Account! first?

Options:

A.

Create an AWS user for Defender for Cloud.

B.

Create an Access control (1AM) role for Defender for Cloud.

C.

Configure AWS Security Hub.

D.

Deploy the AWS Systems Manager (SSM) agent

Buy Now
Question # 45

You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in.

Which anomaly detection policy should you use?

Options:

A.

Impossible travel

B.

Activity from anonymous IP addresses

C.

Activity from infrequent country

D.

Malware detection

Buy Now
Question # 46

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 1 and contains a macOS device named Device1.

You need to investigate a Defender for Endpoint agent alert on Device1. The solution must meet the following requirements:

• Identify all the active network connections on Device1.

• Identify all the running processes on Device1.

• Retrieve the login history of Device1.

• Minimize administrative effort.

What should you do first from the Microsoft Defender portal?

Options:

A.

From Advanced features in Endpoints, disable Authenticated telemetry.

B.

From Advanced features in Endpoints, enable Live Response unsigned script execution.

C.

From Devices, click Collect investigation package for Device 1.

D.

From Devices, initiate a live response session on Device1.

Buy Now
Question # 47

You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud.

You need to assign the PCI DSS 4.0 initiative to Sub1 and have the initiative displayed in the Defender for Cloud Regulatory compliance dashboard.

From Security policies in the Environment settings, you discover that the option to add more industry and regulatory standards is unavailable.

What should you do first?

Options:

A.

Enable the Cloud Security Posture Management (CSPM) plan for the subscription.

B.

Disable the Microsoft Cloud Security Benchmark (MCSB) assignment.

C.

Configure the Continuous export settings for Azure Event Hubs.

D.

Configure the Continuous export settings for Log Analytics.

Buy Now
Question # 48

You have a Microsoft 365 E5 subscription that contains a device named Device1. From the Microsoft Defender portal, you discover that an alert was triggered for Device1. From the Device inventory page, you isolate Device1. You need to collect a list of installed programs on Device1. What should you do?

Options:

A.

Run an advanced hunting query against the DeviceTvmlnfoGathering table.

B.

Initiate a live response session and run the processes command.

C.

Run an advanced hunting query against the DeviceTvmSoftwarelnventory table.

D.

Run an advanced hunting query against the DeviceProcessEvents table.

Buy Now
Question # 49

You have 50 Microsoft Sentinel workspaces.

You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort.

Which page should you use in the Azure portal?

Options:

A.

Microsoft Sentinel - Incidents

B.

Microsoft Sentinel - Workbooks

C.

Microsoft Sentinel

D.

Log Analytics workspaces

Buy Now
Question # 50

You need to create the test rule to meet the Azure Sentinel requirements. What should you do when you create the rule?

Options:

A.

From Set rule logic, turn off suppression.

B.

From Analytics rule details, configure the tactics.

C.

From Set rule logic, map the entities.

D.

From Analytics rule details, configure the severity.

Buy Now
Question # 51

You need to configure DC1 to meet the business requirements.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Buy Now
Question # 52

Which rule setting should you configure to meet the Microsoft Sentinel requirements?

Options:

A.

From Set rule logic, turn off suppression.

B.

From Analytic rule details, configure the tactics.

C.

From Set rule logic, map the entities.

D.

From Analytic rule details, configure the severity.

Buy Now
Question # 53

You need to restrict cloud apps running on CLIENT1 to meet the Microsoft Defender for Endpoint requirements.

Which two configurations should you modify? Each correct answer present part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

the Onboarding settings from Device management in Microsoft Defender Security Center

B.

Cloud App Security anomaly detection policies

C.

Advanced features from Settings in Microsoft Defender Security Center

D.

the Cloud Discovery settings in Cloud App Security

Buy Now
Exam Code: SC-200
Exam Name: Microsoft Security Operations Analyst
Last Update: Aug 16, 2025
Questions: 370
SC-200 pdf

SC-200 PDF

$28.5  $94.99
SC-200 Engine

SC-200 Testing Engine

$33  $109.99
SC-200 PDF + Engine

SC-200 PDF + Testing Engine

$43.5  $144.99