無料SC-200日本語サンプル問題で100%カバー率のリアル試験問題(更新された390問あります) [Q35-Q55]

Share

無料SC-200日本語サンプル問題で100%カバー率のリアル試験問題(更新された390問あります)

今すぐダウンロード!リアルMicrosoft SC-200日本語試験問題集テストエンジン試験問題

質問 # 35
Workbook1 という名前のカスタム ブックを含む Microsoft Sentine1 ワークスペースがあります。
Workbook1 に、ログオン イベント ID が 4624 および 4634 であるアカウントのログオン数を表示するビジュアルを作成する必要があります。
クエリをどのように完了すればよいですか? 回答するには、回答領域で適切なオプションを選択します。
注意: 正しい選択ごとに 1 ポイントが付与されます。

正解:

解説:

Explanation:


質問 # 36
Microsoft 365 Defender を使用してインシデントを調査しています。
CFOLaptop という名前の 3 つのデバイスで失敗したサインイン認証をカウントするには、高度な検索クエリを作成する必要があります。 CEOラップトップとCOOLラップトップ。
クエリをどのように完了すればよいでしょうか?回答するには、回答領域で適切なオプションを選択してください。
注意 正しい選択はそれぞれ 1 ポイントの価値があります

正解:

解説:

Explanation:


質問 # 37
Azure Sentinel の要件を満たすには、イベントにメモを追加する必要があります。
どの 3 つのアクションを順番に実行する必要がありますか?回答するには、アクションのリストから適切なアクションを回答領域に移動し、正しい順序で並べます。

正解:

解説:

1 - From the Azure Sentinel workspace, run a Log Analytics query.
2 - Select a query result.
3 - Add a bookmark and map an entity.
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/bookmarks


質問 # 38
指定されたブレークグラス アカウントを監視するには、Microsoft Sentinel NRT ルールを実装する必要があります。ソリューションは Microsoft Sentinel の要件を満たしている必要があります。
クエリをどのように完了すればよいでしょうか?回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:

Explanation:


質問 # 39
Microsoft Defender XDR を使用する Microsoft 365 サブスクリプションをお持ちです。
過去 24 時間以内に 5 回を超えるウイルス検出があったデバイスを識別するカスタム検出ルールを作成する必要があります。
クエリをどのように完了すればよいですか? 回答するには、回答領域で適切なオプションを選択します。
注意: 正しい選択ごとに 1 ポイントが付与されます。

正解:

解説:

Explanation:


質問 # 40
XYZ社で複数の誤検知アラートが発生しています。XYZ社のセキュリティ運用アナリストは、アラートを減らすために実行可能ファイル(c:\myxyzapp\myxyzwinapp.exe)を除外する必要があります。どの除外タイプを使用すればよいでしょうか?

  • A. レジストリ
  • B. ファイル
  • C. 拡張機能
  • D. フォルダ

正解:B

解説:
File will exclude only this specific file, whereas extension would exclude all files with the extensions, and folder would exclude all files in a folder. Registry exclusion doesn't happen.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-extension- file-exclusions-microsoft-defender-antivirus?view=o365-worldwide


質問 # 41
Defender for Cloud の要件を実装する必要があります。
どのサブスクリプション レベルのロールを Group1 に割り当てる必要がありますか?

  • A. 寄稿者
  • B. 所有者
  • C. セキュリティ管理者
  • D. セキュリティ評価の貢献者

正解:D

解説:
The Defender for Cloud requirement states:
"The members of Group1 must be able to enable Defender for Cloud plans and apply regulatory compliance initiatives." According to Microsoft Defender for Cloud's RBAC documentation, the Security Assessment Contributor role provides permissions to:
* Enable and configure Defender plans,
* Manage security policies and initiatives,
* View and edit recommendations and compliance results.
This role gives enough permissions to perform Defender configuration tasks but follows the principle of least privilege, unlike broader roles like Owner or Contributor, which grant excessive rights.
# Answer for Question 9: C. Security Assessment Contributor


質問 # 42
注:このセクションには、同じシナリオと問題に関する複数の質問セットが含まれています。各質問には、問題に対する固有の解決策が提示されています。提示された解決策が、提示された目標を満たしているかどうかを判断する必要があります。セット内の複数の解決策が問題を解決できる場合もあります。また、セット内のどの解決策も問題を解決できない場合もあります。
このセクションの質問に回答すると、前のセクションに戻ることはできません。そのため、これらの質問は復習画面には表示されません。
あなたはMicrosoft 365のサブスクリプションをお持ちです。
サードパーティ製のウイルス対策ソフトがインストールされ、Microsoft Defenderウイルス対策ソフトがパッシブモードで動作しているWindowsデバイスが1,000台あります。
すべてのWindowsデバイスは、Microsoft Defender for Endpointにオンボーディングされています。
サードパーティ製のウイルス対策製品では検出されなかった悪意のあるファイルからデバイスが保護されていることを確認する必要があります。
解決策:ライブレスポンスを有効にします。
これは目標を達成していると言えるでしょうか?

  • A. いいえ
  • B. はい

正解:A


質問 # 43
Workbook1 と Webapp1 のクエリを実装する必要があります。ソリューションは Microsoft Sentinel の要件を満たしている必要があります。クエリをどのように設定すればよいでしょうか?回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:

Explanation:


質問 # 44
Microsoft Sentinel を使用し、User1 という名前のユーザーを含む Azure サブスクリプションがあります。
User1 が Microsoft Entra テナント内のエンティティ動作に対してユーザーおよびエンティティ動作分析 (UEBA) を有効にできることを確認する必要があります。ソリューションでは、最小権限の原則を使用する必要があります。
User1 にどのロールを割り当てる必要がありますか? 回答するには、回答領域で適切なオプションを選択します。
注意: 正しい選択ごとに 1 ポイントが付与されます。

正解:

解説:

Explanation:

Enabling User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel requires specific permissions in both Microsoft Entra ID (Azure AD) and the Azure Sentinel workspace. The goal is to grant the least privilege necessary for the user (User1) to enable UEBA and manage entity behavior analytics.
Microsoft's documentation for UEBA setup specifies that to enable UEBA for an Entra tenant, the user must have access to identity-related signals and security settings within the Microsoft Entra environment.
Specifically:
"To enable UEBA and connect Microsoft Entra ID data, the user must be assigned the Security Administrator role in Microsoft Entra ID. This role allows management of security-related features without granting full directory or global admin privileges." The Security Administrator role provides just enough access to security configurations, alerts, and risk data, aligning with the principle of least privilege.
Other roles:
* Global Administrator is overly privileged.
* Security Operator can only view alerts, not configure settings.
* Identity Governance Administrator focuses on access reviews and entitlement management, not UEBA setup.
Hence, the correct Entra role is Security Administrator.
For the Azure side, Microsoft's official Sentinel RBAC guidance states:
"To enable or configure UEBA in a Sentinel workspace, the user must have the Microsoft Sentinel Contributor role. This role allows enabling and configuring UEBA, managing analytics, and viewing data within Sentinel." The Sentinel Contributor role grants permissions to configure data connectors, UEBA settings, and entity analytics features but not workspace-wide administrative rights.
Other options:
* Microsoft Sentinel Automation Contributor is limited to playbook and automation configurations.
* Security Admin and Security Assessment Contributor roles apply to Microsoft Defender for Cloud and general Azure security posture, not UEBA configuration.
# Final Correct Roles:
* Microsoft Entra role: Security Administrator
* Azure role: Microsoft Sentinel Contributor


質問 # 45
Microsoft Defender for Cloud の要件とビジネス要件を満たすには、Microsoft Defender for Cloud を実装する必要があります。ソリューションには何を含めるべきでしょうか?回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:

Explanation:


質問 # 46
Microsoft 365 Defender データ コネクタを使用する Microsoft Sentinel ワークスペースがあります。
Microsoft Sentinel から Microsoft 365 インシデントを調査します。
Microsoft Defender for Cloud Apps によって生成されたアラートを含めるようにインシデントを更新する必要があります。
何を使えばいいのでしょうか?

  • A. Microsoft Sentinel の [インシデント] ページの [タイムライン] タブ
  • B. Microsoft 365 Defender ポータルの [アラート] ページ
  • C. Microsoft Sentinel のタイムライン カードのエンティティ サイド パネル
  • D. Microsoft Sentinel のインシデント ページの調査グラフ

正解:C


質問 # 47
ホットスポットに関する質問
デフォルトのデータ保持期間が30日間に設定されているMicrosoft Sentinelワークスペースがあります。このワークスペースには、次の表に示す2つのカスタムテーブルが含まれています。

過去365日間、各テーブルは1日あたり2件のレコードを取り込んだ。
分析ルールで使用するKQLステートメントは、次の表に示すように作成します。

以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。

正解:

解説:


質問 # 48
あなたはMicrosoft 365テナントをお持ちです。
File1.docxという名前の既知の脅威ファイルが見つかりました。
ユーザーがFile1.docxをダウンロードできないようにする必要があります。
あなたはどうすべきでしょうか?

  • A. Microsoft Purview ポータルから、機密ラベルを作成します。
  • B. Microsoft Defender ポータルからインジケーターを追加します。
  • C. Microsoft Purview ポータルから、データ損失防止 (DLP) ポリシーを作成します。
  • D. Microsoft Defender ポータルから自動調査を設定します。

正解:B

解説:
Implement Endpoint Indicators
If you have Microsoft Defender for Endpoint, you can create a custom indicator to block the file from being executed on managed devices.
Navigate to: Settings > Endpoints > Indicators > File hashes.
Action: Add the SHA256 hash and set the response action to Block and Remediate. This will stop the file from running and attempt to remove it if found on a device.
Reference:
https://learn.microsoft.com/en-us/defender-endpoint/indicator-file


質問 # 49
お客様は、Microsoft Defender 365を使用するMicrosoft 365 E5サブスクリプションをご利用中です。
Microsoft Defender for Cloud Apps の統合監査ログのデータを使用して脅威を調査できることを確認する必要があります。
最初に何を設定すべきですか?

  • A. ユーザーエンリッチメント設定
  • B. Azureコネクタ
  • C. Office 365 コネクタ
  • D. 自動ログアップロード設定

正解:C

解説:
https://learn.microsoft.com/en-us/defender-cloud-apps/connect-office-365


質問 # 50
あなたはMicrosoft 365 E5のサブスクリプションをお持ちです。
統合監査ログを照会するPowerShellスクリプトがあります。
サーバー側のページング処理のため、クエリは最初のページの結果しか返さないことが分かります。
すべての結果を確実に得る必要があります。
結果の中でどのプロパティを照会すべきですか?

  • A. @odata.deltaLink
  • B. @odata.nextLink
  • C. @odata.count
  • D. @odata.context

正解:B


質問 # 51
セキュリティ管理者は、ストレージ アカウントにアップロードされた潜在的なマルウェアやブルート フォース攻撃の成功などのアクティビティに関する電子メール アラートを Azure Defender から受け取ります。
セキュリティ管理者は、マルウェア対策アクションの失敗や不審なネットワーク アクティビティなどのアクティビティに関する電子メール アラートを受信しません。アラートは Azure Security Center に表示されます。
セキュリティ管理者がすべてのアクティビティに関する電子メール アラートを受信するようにする必要があります。
セキュリティ センターの設定で何を構成する必要がありますか?

  • A. 脅威検出の統合設定
  • B. クラウド コネクタ
  • C. 電子メール通知の重大度レベル
  • D. Azure Defender プラン

正解:C

解説:
Reference:
https://techcommunity.microsoft.com/t5/microsoft-365-defender/get-email-notifications-on-new-incidents-from-microsoft-365/ba-p/2012518


質問 # 52
次の Advanced Security Information Model (ASIM) パーサーを含む Microsoft Sentinel ワークスペースがあります。
* _Im_プロセス作成
* 作成中
vimProcessCreate という名前の新しいソース固有のパーサーを作成します。
次の要件を満たすようにパーサーを変更する必要があります。
* すべての ProcessCreate パーサーを呼び出します。
* フィールドをプロセス スキーマに標準化します。
各要件を満たすには、どのパーサーを変更する必要がありますか? 回答するには、適切なパーサーを正しい要件にドラッグします。各パーサーは、1 回、複数回、またはまったく使用されない場合があります。コンテンツを表示するには、ペイン間の分割バーをドラッグするか、スクロールする必要がある場合があります。
注意: 正しい選択ごとに 1 ポイントが付与されます。

正解:

解説:


質問 # 53
カスタムワークブックを含むMicrosoft Sentinelワークスペースがあります。
セキュリティイベントの概要を照会する必要があります。ソリューションは以下の要件を満たす必要があります。
* 過去1週間に取り込まれたセキュリティイベントの数を特定します。
* 日ごとのイベント数をグラフで表示する。
質問にはどのように回答すればよいですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

正解:

解説:

Explanation:

To summarize security events over the last week and chart them by day , use KQL time binning on the event timestamp. In Sentinel/Log Analytics, bin() groups records into fixed time buckets on a datetime column- here, TimeGenerated . Pair that with a time filter for the past 7 days and render as a timechart. The key pattern is:
SecurityEvent
| where TimeGenerated > = ago(7d)
| summarize Count = count() by bin(TimeGenerated, 1d)
| render timechart
* bin is the correct aggregator for time-based bucketing.
* TimeGenerated is the standard timestamp column used across Sentinel tables for ingestion time.
* Using a 1-day bin shows the daily counts; the where TimeGenerated > = ago(7d) limits results to the past week .
* render timechart visualizes the grouped counts over time.
In the answer area shown, you select bin and TimeGenerated ; (the full query would also include the where line and a 1d bin size to meet the "by day" requirement).


質問 # 54
Microsoft Defender for Endpoint を使用する Microsoft 365 E5 サブスクリプションを持っている。マルウェア アラートをトリガーしたデバイスを特定し、アラートに関連する証拠を収集する必要があります。ソリューションでは、その結果を使用して、影響を受けるデバイスのデバイス分離を開始できることを保証する必要があります。
Microsoft 365 Defender ポータルでは何を使用する必要がありますか?

  • A. 調査
  • B. 高度なハンティング
  • C. インシデント
  • D. 修復

正解:B


質問 # 55
......

最新SC-200日本語テスト問題集を試そう!更新されたMicrosoft試験が合格できます:https://jp.fast2test.com/SC-200J-premium-file.html


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어