Practice Free SC-200 Exam Online Questions
You have a Microsoft Sentinel workspace.
You need to prevent a built-in Advance Security information Model (ASIM) parse from being updated automatically.
What are two ways to achieve this goal? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- A . Redeploy the built-in parse and specify a CallerContext parameter of any and a SourceSpecificParse parameter of any.
- B . Create a hunting query that references the built-in parse.
- C . Redeploy the built-in parse and specify a CallerContext parameter of built-in.
- D . Build a custom unify parse and include the build- parse version
- E . Create an analytics rule that includes the built-in parse
You have an Azure subscription that uses Microsoft Defender for Cloud and contains a resource group named RG1. RG1. You need to configure just in time (JIT) VM access for the virtual machines in RG1.
The solution must meet the following:
• Limit the maximum request time to two hours.
• Limit protocol access to Remote Desktop Protocol (RDP) only.
• Minimize administrative effort.
What should you use?
- A . Azure AD Privileged Identity Management (PIM)
- B . Azure Policy
- C . Azure Front Door
- D . Azure Bastion
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 1 and contains a macOS device named Device1.
You need to investigate a Defender for Endpoint agent alert on Device1.
The solution must meet the following requirements:
• Identify all the active network connections on Device1.
• Identify all the running processes on Device1.
• Retrieve the login history of Device1.
• Minimize administrative effort.
What should you do first from the Microsoft Defender portal?
- A . From Advanced features in Endpoints, disable Authenticated telemetry.
- B . From Advanced features in Endpoints, enable Live Response unsigned script execution.
- C . From Devices, click Collect investigation package for Device 1.
- D . From Devices, initiate a live response session on Device1.
You need to implement the scheduled rule for incident generation based on rulequery1.
What should you configure first?
- A . entity mapping
- B . custom details
- C . event grouping
- D . alert details
You have an Azure subscription that contains a user named User1 and a Microsoft Sentinel workspace named WS1. WS1 uses Microsoft Defender for Cloud.
You have the Microsoft security analytics rules shown in the following table.

User1 performs an action that matches Rule1, Rule2, Rule3, and Rule4.
How many incidents will be created in WS1?
- A . 1
- B . 2
- C . 3
- D . 4
HOTSPOT
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You have a Microsoft Sentinel workspace.
Microsoft Sentinel connectors are configured as shown in the following table.

You use Microsoft Sentinel to investigate suspicious Microsoft Graph API activity related to Conditional Access policies.
You need to search for the following activities:
• Downloads of the Conditional Access policies by using PowerShell
• Updates to the Conditional Access policies by using the Microsoft Entra admin center
Which tables should you query for each activity? lo answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to modify the anomaly detection policy settings to meet the Cloud App Security requirements.
Which policy should you modify?
- A . Activity from suspicious IP addresses
- B . Activity from anonymous IP addresses
- C . Impossible travel
- D . Risky sign-in
You need to modify the anomaly detection policy settings to meet the Cloud App Security requirements.
Which policy should you modify?
- A . Activity from suspicious IP addresses
- B . Activity from anonymous IP addresses
- C . Impossible travel
- D . Risky sign-in
HOTSPOT
You need to monitor the password resets. The solution must meet the Microsoft Sentinel requirements.
What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have an Azure subscription.
You need to stream the Microsoft Graph activity logs to a third-party security information and event management (SIEM) tool. The solution must minimize administrative effort.
To where should you stream the logs?
- A . an Azure Event Hubs namespace
- B . an Azure Event Grid namespace
- C . an Azure Storage account
- D . a Log Analytics workspace
