exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 2 question 12 discussion

Actual exam question from Microsoft's SC-100
Question #: 12
Topic #: 2
[All SC-100 Questions]

DRAG DROP -
You have a Microsoft 365 subscription.
You need to recommend a security solution to monitor the following activities:
✑ User accounts that were potentially compromised
✑ Users performing bulk file downloads from Microsoft SharePoint Online
What should you include in the recommendation for each activity? To answer, drag the appropriate components to the correct activities. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Azure Active Directory (Azure AD) Identity Protection
Risk detections in Azure AD Identity Protection include any identified suspicious actions related to user accounts in the directory. Risk detections (both user and sign-in linked) contribute to the overall user risk score that is found in the Risky Users report.
Identity Protection provides organizations access to powerful resources to see and respond quickly to these suspicious actions.
Note:
Premium sign-in risk detections include:
* Token Issuer Anomaly - This risk detection indicates the SAML token issuer for the associated SAML token is potentially compromised. The claims included in the token are unusual or match known attacker patterns.
* Suspicious inbox manipulation rules - This detection is discovered by Microsoft Defender for Cloud Apps. This detection profiles your environment and triggers alerts when suspicious rules that delete or move messages or folders are set on a user's inbox. This detection may indicate that the user's account is compromised, that messages are being intentionally hidden, and that the mailbox is being used to distribute spam or malware in your organization.
* Etc.
Incorrect:
Not: Microsoft 365 Defender for Cloud
Part of your incident investigation can include user accounts. You can see the details of user accounts identified in the alerts of an incident in the Microsoft 365
Defender portal from Incidents & alerts > incident > Users.
Box 2: Microsoft 365 Defender for App
Defender for Cloud apps detect mass download (data exfiltration) policy
Detect when a certain user accesses or downloads a massive number of files in a short period of time.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks https://docs.microsoft.com/en-us/defender-cloud-apps/policies-threat-protection#detect-mass-download-data-exfiltration https://docs.microsoft.com/en-us/microsoft-365/security/defender/investigate-users

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheMCT
Highly Voted 2 years, 10 months ago
The given answer is correct.
upvoted 25 times
...
zellck
Highly Voted 2 years, 2 months ago
1. Azure AD Identity Protection 2. Microsoft Defender for Cloud Apps https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks#nonpremium-user-risk-detections https://learn.microsoft.com/en-us/defender-cloud-apps/policies-threat-protection#detect-mass-download-data-exfiltration Detect when a certain user accesses or downloads a massive number of files in a short period of time.
upvoted 13 times
...
rekaro
Most Recent 1 year ago
Correct
upvoted 3 times
...
besoaus
1 year ago
Answer is true
upvoted 1 times
...
calotta1
1 year, 10 months ago
Has anyone considered DLP as the better solution here since the question is about reporting? REF: https://www.microsoft.com/en-gb/security/business/security-101/what-is-data-loss-prevention-dlp?ef_id=_k_Cj0KCQjw_5unBhCMARIsACZyzS11Eh7eQSTGLIRjq5TP3xT2cbyWnDkJaHSav13rcKytz0ZwytyaBugaAqq4EALw_wcB_k_&OCID=AIDcmmao55x8o7_SEM__k_Cj0KCQjw_5unBhCMARIsACZyzS11Eh7eQSTGLIRjq5TP3xT2cbyWnDkJaHSav13rcKytz0ZwytyaBugaAqq4EALw_wcB_k_&gclid=Cj0KCQjw_5unBhCMARIsACZyzS11Eh7eQSTGLIRjq5TP3xT2cbyWnDkJaHSav13rcKytz0ZwytyaBugaAqq4EALw_wcB
upvoted 4 times
Ramye
1 year, 6 months ago
DLP is for data loss prevention in terms of sensitive data, i.e., credit card, health info, social security card etc.,
upvoted 1 times
...
...
TJ001
2 years, 6 months ago
The given answers are correct as it is for monitoring purpose
upvoted 2 times
...
examtopics_100
2 years, 6 months ago
Correct
upvoted 3 times
...
JCkD4Ni3L
2 years, 9 months ago
Answers are correct !
upvoted 2 times
...
tester18128075
2 years, 10 months ago
identity protection and cloud
upvoted 2 times
...
JMuller
2 years, 10 months ago
Correct
upvoted 3 times
...
prabhjot
2 years, 10 months ago
yes correct ans
upvoted 4 times
...
Alex_Burlachenko
2 years, 10 months ago
right, correct answer
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...