Microsoft Security Operations Analyst (SC-200日本語版) - SC-200日本語 Exam Practice Test
Azure Active Directory (Azure AD) ユーザーをブロックするために使用される既存の Azure ロジック アプリがあります。ロジック アプリは手動でトリガーされます。
Azure Sentinel をデプロイします。
既存のロジック アプリを Azure Sentinel のプレイブックとして使用する必要があります。まず何をすべきでしょうか?
Azure Sentinel をデプロイします。
既存のロジック アプリを Azure Sentinel のプレイブックとして使用する必要があります。まず何をすべきでしょうか?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
あなたはAzureサブスクリプションをお持ちです。
Microsoft Graphのアクティビティログをサードパーティ製のセキュリティ情報およびイベント管理(SIEM)ツールにストリーミングする必要があります。このソリューションは、管理作業を最小限に抑えるものでなければなりません。
ログはどこにストリーミングすべきですか?
Microsoft Graphのアクティビティログをサードパーティ製のセキュリティ情報およびイベント管理(SIEM)ツールにストリーミングする必要があります。このソリューションは、管理作業を最小限に抑えるものでなければなりません。
ログはどこにストリーミングすべきですか?
Correct Answer: A
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
VM1 という名前の仮想マシンを含む Azure サブスクリプションがあり、Microsoft Defender for Cloud を使用しています。Microsoft Defender for Cloud では、Azure Monitor Agent を使用するように自動プロビジョニングが構成されています。
VM1 上で疑わしい PowerShell の使用に関する誤検知アラートを抑制するアラート抑制ルール。最初に何をすべきでしょうか?
VM1 上で疑わしい PowerShell の使用に関する誤検知アラートを抑制するアラート抑制ルール。最初に何をすべきでしょうか?
Correct Answer: D
Vote an answer
貴社では、各プロジェクトのデータをそれぞれ異なるAzureサブスクリプションに保存しています。すべてのサブスクリプションは同じMicrosoft Entraテナントを使用しています。
各プロジェクトは、Windows Serverを実行する複数のAzure仮想マシンで構成されています。仮想マシンのWindowsイベントは、各マシンのそれぞれのサブスクリプション内のLog Analyticsワークスペースに保存されます。
Microsoft Sentinel を新しい Azure サブスクリプションにデプロイします。
すべてのサブスクリプションのすべての Log Analytics ワークスペースを横断的に検索するには、Microsoft Sentinel でハンティングクエリを実行する必要があります。
どの2つの行動をとるべきでしょうか?それぞれの正解は、解決策の一部を示しています。
注:正解ごとに1ポイントが加算されます。
各プロジェクトは、Windows Serverを実行する複数のAzure仮想マシンで構成されています。仮想マシンのWindowsイベントは、各マシンのそれぞれのサブスクリプション内のLog Analyticsワークスペースに保存されます。
Microsoft Sentinel を新しい Azure サブスクリプションにデプロイします。
すべてのサブスクリプションのすべての Log Analytics ワークスペースを横断的に検索するには、Microsoft Sentinel でハンティングクエリを実行する必要があります。
どの2つの行動をとるべきでしょうか?それぞれの正解は、解決策の一部を示しています。
注:正解ごとに1ポイントが加算されます。
Correct Answer: A,E
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Microsoft Defender for Cloud による強化されたセキュリティ機能が有効になっている Azure サブスクリプションが 100 件あります。これらのサブスクリプションはすべて、単一の Azure AD テナントにリンクされています。
Defender for Cloudのログをsyslogサーバーにストリーミングする必要があります。
解決策は管理上の労力を最小限に抑えるものでなければなりません。では、どうすればよいのでしょうか?
回答するには、回答欄で適切な選択肢を選んでください。注:正解ごとに1ポイントが加算されます。
Defender for Cloudのログをsyslogサーバーにストリーミングする必要があります。
解決策は管理上の労力を最小限に抑えるものでなければなりません。では、どうすればよいのでしょうか?
回答するには、回答欄で適切な選択肢を選んでください。注:正解ごとに1ポイントが加算されます。
Correct Answer:
Export logs to: # Azure event hub
Configure streaming by: # Configuring continuous export in Defender for Cloud for each subscription In Microsoft Defender for Cloud, if you need to stream security alerts and recommendations to an external SIEM or syslog server, the supported approach is to export data to an Azure Event Hub, which acts as a streaming pipeline. The syslog server or SIEM solution can then pull data from the Event Hub in real time using connectors or custom listeners.
The configuration method for sending Defender for Cloud data to an Event Hub is known as continuous export. According to Microsoft's official Defender for Cloud documentation, continuous export lets you automatically stream alerts and security recommendations to Event Hubs or Log Analytics workspaces.
However, when your target is a syslog server, Event Hub is required because it supports continuous streaming outside Azure.
To minimize administrative effort across multiple subscriptions (100 in this case), you can use Azure Policy or a script to apply continuous export settings per subscription, but the feature must still be enabled individually for each subscription - hence the correct configuration step is:
"Configuring continuous export in Defender for Cloud for each subscription." Why not other options:
Log Analytics workspace: used for querying within Azure, not for streaming to external syslog servers.
Azure Storage account: suitable for archival, not streaming.
Modifying diagnostic settings of the tenant: applies only to Azure AD logs, not Defender for Cloud data.
Configure streaming by: # Configuring continuous export in Defender for Cloud for each subscription In Microsoft Defender for Cloud, if you need to stream security alerts and recommendations to an external SIEM or syslog server, the supported approach is to export data to an Azure Event Hub, which acts as a streaming pipeline. The syslog server or SIEM solution can then pull data from the Event Hub in real time using connectors or custom listeners.
The configuration method for sending Defender for Cloud data to an Event Hub is known as continuous export. According to Microsoft's official Defender for Cloud documentation, continuous export lets you automatically stream alerts and security recommendations to Event Hubs or Log Analytics workspaces.
However, when your target is a syslog server, Event Hub is required because it supports continuous streaming outside Azure.
To minimize administrative effort across multiple subscriptions (100 in this case), you can use Azure Policy or a script to apply continuous export settings per subscription, but the feature must still be enabled individually for each subscription - hence the correct configuration step is:
"Configuring continuous export in Defender for Cloud for each subscription." Why not other options:
Log Analytics workspace: used for querying within Azure, not for streaming to external syslog servers.
Azure Storage account: suitable for archival, not streaming.
Modifying diagnostic settings of the tenant: applies only to Azure AD logs, not Defender for Cloud data.
お客様は、WS1 という名前の Microsoft Sentinel ワークスペースを含む Azure サブスクリプションをお持ちです。WS1 には、Azure Activity コネクタと Microsoft Entra ID コネクタが構成されています。
どのアカウントに最も多くの警告が発生しているか、また各警告に対応するインシデント情報を調査する必要があります。解決策は管理作業を最小限に抑えるものでなければなりません。WS1 で最初に行うべきことは何ですか?
どのアカウントに最も多くの警告が発生しているか、また各警告に対応するインシデント情報を調査する必要があります。解決策は管理作業を最小限に抑えるものでなければなりません。WS1 で最初に行うべきことは何ですか?
Correct Answer: A
Vote an answer
あなたはMicrosoft 365のサブスクリプションをお持ちです。
グループの変更または削除を要求したすべてのセキュリティプリンシパルを特定する必要があります。KQLクエリはどのように作成すればよいでしょうか?回答するには、回答領域で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

グループの変更または削除を要求したすべてのセキュリティプリンシパルを特定する必要があります。KQLクエリはどのように作成すればよいでしょうか?回答するには、回答領域で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

Correct Answer:

Explanation:

To find all security principals (users or service principals/apps) that changed or deleted groups, you should query MicrosoftGraphActivityLogs and filter for requests targeting the groups endpoint, then exclude read- only operations. The RequestUri field contains the full Graph URL that the principal called (e.g., /v1.0/groups/{id}), so filtering where RequestUri contains " /group " (or " /groups " ) isolates group-related operations.
Changes and deletions are non-read HTTP verbs such as POST, PATCH, PUT, and DELETE. The simplest way to capture all of them is to exclude reads: where RequestMethod != " GET " . Finally, projecting AppId, UserId, and ServicePrincipalId returns the identities (user or app) behind each request, which are the "security principals" you need to report.
So the completed KQL is:
MicrosoftGraphActivityLogs
| where RequestUri contains " /group "
| where RequestMethod != " GET "
| project AppId, UserId, ServicePrincipalId
あなたの会社では Azure Sentinel を使用しています。
新しいセキュリティ アナリストは、Azure Sentinel でインシデントを割り当てたり削除したりできないと報告しています。アナリストのために問題を解決する必要があります。ソリューションでは、最小特権の原則を使用する必要があります。アナリストにはどの役割を割り当てるべきですか?
新しいセキュリティ アナリストは、Azure Sentinel でインシデントを割り当てたり削除したりできないと報告しています。アナリストのために問題を解決する必要があります。ソリューションでは、最小特権の原則を使用する必要があります。アナリストにはどの役割を割り当てるべきですか?
Correct Answer: D
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
カスタム Kusto クエリを含む workspace1 という名前の Microsoft Sentinel ワークスペースがあります。
ビジュアルを作成する Python ベースの Jupyter ノートブックを作成する必要があります。ビジュアルにはクエリの結果が表示され、ダッシュボードに固定されます。ソリューションでは、開発労力を最小限に抑える必要があります。
ビジュアルを作成するには何を使用する必要がありますか?
ビジュアルを作成する Python ベースの Jupyter ノートブックを作成する必要があります。ビジュアルにはクエリの結果が表示され、ダッシュボードに固定されます。ソリューションでは、開発労力を最小限に抑える必要があります。
ビジュアルを作成するには何を使用する必要がありますか?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
お客様は、Microsoft Sentinelを使用するAzureサブスクリプションをお持ちです。
セキュリティインシデントを解決するのにかかる平均時間を計算するカスタムワークブックを作成する必要があります。
解決策は、管理上の負担を最小限に抑えるものでなければならない。
Microsoft Sentinelに組み込まれているワークブックテンプレートのうち、どれを選択すべきでしょうか?
セキュリティインシデントを解決するのにかかる平均時間を計算するカスタムワークブックを作成する必要があります。
解決策は、管理上の負担を最小限に抑えるものでなければならない。
Microsoft Sentinelに組み込まれているワークブックテンプレートのうち、どれを選択すべきでしょうか?
Correct Answer: D
Vote an answer
Azure Sentinelの要件を満たすように、Azure Sentinelとの統合を構成する必要があります。
どうすればよいですか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。

どうすればよいですか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。

Correct Answer:

Explanation:

To integrate Microsoft Defender for Cloud Apps (MCAS) with Microsoft Sentinel, Microsoft's official SecOps and Sentinel documentation specifies a two-step configuration process.
In the Defender for Cloud Apps portal - You add a security extension to enable integration with external SIEM platforms. This action allows MCAS to forward its alerts, activities, and discovered app telemetry to other Microsoft or third-party security platforms. By adding the security extension, Defender for Cloud Apps is authorized to send data streams and alerts to Microsoft Sentinel through a supported API connection.
In Microsoft Sentinel (Azure portal) - You then add a data connector. Data connectors in Sentinel are predefined integration pipelines that bring in telemetry from Microsoft or external security solutions. The Microsoft Defender for Cloud Apps connector specifically ingests MCAS alerts and audit logs into Sentinel, where they can be correlated with other Microsoft Defender XDR signals, enabling unified detection and investigation across identity, endpoint, and cloud layers.
This integration approach adheres to Microsoft's principle of minimizing administrative effort by using native connectors rather than custom ingestion or log collector configurations. Once connected, Sentinel automatically normalizes MCAS alerts into its SecurityAlert and CloudAppEvents tables for rule creation, playbook automation, and incident correlation.
Therefore, the verified correct configuration is:
Defender for Cloud Apps: Add a security extension
Sentinel: Add a data connector
Microsoft Sentinelワークスペースを含むAzureサブスクリプションをお持ちです。
Microsoft Entra ID監査ログ用のワークブックを作成し、カスタマイズする必要があります。
どの3つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。

Microsoft Entra ID監査ログ用のワークブックを作成し、カスタマイズする必要があります。
どの3つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。

Correct Answer:

Explanation:

あなたはMicrosoft 365 E5のサブスクリプションをお持ちです。
サードパーティ製のウイルス対策ソフトがインストールされ、Microsoft Defenderウイルス対策ソフトがパッシブモードで動作しているWindowsデバイスが1,000台あります。
すべてのWindowsデバイスは、Microsoft Defender for Endpointに登録されています。
サードパーティ製のウイルス対策製品では検出されなかった悪意のあるファイルからデバイスが保護されていることを確認する必要があります。
解決策:ライブレスポンスを有効にします。
これは目標を達成していると言えるでしょうか?
サードパーティ製のウイルス対策ソフトがインストールされ、Microsoft Defenderウイルス対策ソフトがパッシブモードで動作しているWindowsデバイスが1,000台あります。
すべてのWindowsデバイスは、Microsoft Defender for Endpointに登録されています。
サードパーティ製のウイルス対策製品では検出されなかった悪意のあるファイルからデバイスが保護されていることを確認する必要があります。
解決策:ライブレスポンスを有効にします。
これは目標を達成していると言えるでしょうか?
Correct Answer: B
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
次の図に示すように、クラウドアプリセキュリティポータルを開きます。

Launchpadアプリのリスクを軽減する必要があります。
どの4つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。


Launchpadアプリのリスクを軽減する必要があります。
どの4つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。

Correct Answer:

Explanation:

According to Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) documentation, when an application discovered by Cloud Discovery is deemed risky or non-compliant, the recommended remediation process is to unsanction it and enforce blocking through your network security devices or firewalls.
The process follows these four exact steps:
Select the app - In the Discovered apps tab, security analysts must first locate and select the risky application (in this case, Launchpad).Microsoft documentation states: "Select the discovered app that you want to remediate to open available actions." Tag the app as Unsanctioned - Marking an app as Unsanctioned flags it as not allowed for organizational use.
This designation helps track and automatically block or monitor it through connected security controls.
Reference guidance: "Unsanction apps that you want to block across your network to prevent user access." Generate a block script - Once an app is tagged as Unsanctioned, you can generate a block script compatible with your firewall or proxy device (such as Palo Alto, Cisco ASA, or Zscaler).Microsoft documentation explains: "From the unsanctioned app menu, select Generate block script to create a script for your appliance type." Run the script on the source appliance - Finally, to enforce blocking, the generated script must be executed on the network appliance or proxy device that is integrated with Cloud Discovery.Official description: "Run the generated script on your network appliance to block unsanctioned apps." This sequence ensures compliance and reduces data exposure by automatically restricting high-risk apps, aligning with Microsoft SecOps best practices of proactive risk mitigation and least privilege.
# Final Correct Order:
1. Select the app # 2. Tag the app as Unsanctioned # 3. Generate a block script # 4. Run the script on the source appliance