Exam Name: | Microsoft Security Operations Analyst | ||
Exam Code: | SC-200 Dumps | ||
Vendor: | Microsoft | Certification: | Microsoft Certified: Security Operations Analyst Associate |
Questions: | 370 Q&A's | Shared By: | iqra |
You recently deployed Azure Sentinel.
You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled.
You need to ensure that the Fusion rule can generate alerts.
What should you do?
You have an Azure subscription that uses Microsoft Defender for Cloud.
You have a GitHub account named Account1 that contains 10 repositories.
You need to ensure that Defender for Cloud can assess the repositories in Account1.
What should you do first in the Microsoft Defender for Cloud portal?
You have a Microsoft 365 E5 subscription and a Microsoft Sentinel workspace. You need to create a KQL query that will combine data from the following sources:
• Microsoft Graph
• Risky users detected by using Microsoft Entra ID Protection
The solution must minimize the volume of data returned. How should the query start?
You plan to create a custom Azure Sentinel query that will provide a visual representation of the security alerts generated by Azure Security Center.
You need to create a query that will be used to display a bar graph. What should you include in the query?