exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 41 discussion

Actual exam question from Microsoft's SC-200
Question #: 41
Topic #: 3
[All SC-200 Questions]

You have a Microsoft Sentinel workspace that contains the following incident.
Brute force attack against Azure Portal analytics rule has been triggered.
You need to identify the geolocation information that corresponds to the incident.
What should you do?

  • A. From Overview, review the Potential malicious events map.
  • B. From Incidents, review the details of the IPCustomEntity entity associated with the incident.
  • C. From Incidents, review the details of the AccountCustomEntity entity associated with the incident.
  • D. From Investigation, review insights on the incident entity.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Harryd82
7 months, 1 week ago
B is the correct answer
upvoted 1 times
...
fiksarion
10 months, 2 weeks ago
Selected Answer: B
To identify the geolocation information corresponding to the incident "Brute force attack against Azure Portal analytics rule has been triggered" in Microsoft Sentinel, you should review the details of the IPCustomEntity entity associated with the incident. The IPCustomEntity typically contains information related to IP addresses, including geolocation data such as country or region. By examining the details of the IPCustomEntity entity, you can retrieve the geolocation information associated with the IP addresses involved in the brute force attack. Therefore, option B is the correct choice for identifying the geolocation information corresponding to the incident
upvoted 3 times
...
chepeerick
1 year, 1 month ago
Option B
upvoted 1 times
...
mali1969
1 year, 3 months ago
Selected Answer: B
B. From Incidents, review the details of the IPCustomEntity entity associated with the incident. According to this article, Microsoft Defender for Cloud detects brute force attacks and triggers alerts that contain the attacking IP address in the ‘entities’ field. You can use this IP address to find the geolocation information by reviewing the details of the IPCustomEntity entity associated with the incident.
upvoted 3 times
...
7c0a
1 year, 5 months ago
Selected Answer: B
B - IPCustomEntity, you can even create a custom playbook to get one from the maxmind, which is more precise than microsoft. A is outdated and even in the past was not an efficient choice if you had a multiple incidents and various attack sources... You need to identify the geolocation information that corresponds to the incident.
upvoted 3 times
...
[Removed]
1 year, 9 months ago
Selected Answer: B
B. From Incidents, review the details of the IPCustomEntity entity associated with the incident. The IPCustomEntity entity associated with the incident should provide the IP address that triggered the brute force attack. You can then use a geolocation lookup tool to determine the country or region associated with that IP address
upvoted 3 times
...
RodrigoLima
1 year, 10 months ago
Selected Answer: B
In the details of an incident, if you click on the IP entity it shows you the information under Geolocation information
upvoted 2 times
...
saurabh123sml
1 year, 10 months ago
Selected Answer: B
Verified. Answer is B
upvoted 2 times
...
eddz25
1 year, 10 months ago
Selected Answer: A
A. From Overview, review the Potential malicious events map. The Potential malicious events map in the Overview section of Microsoft Sentinel can display geolocation information for incidents, such as a brute force attack against an Azure Portal analytics rule. By reviewing this map, you can identify the location from where the attack is originating.
upvoted 1 times
...
Ouma
1 year, 11 months ago
Selected Answer: B
Its B, confirmed
upvoted 3 times
...
ACSC
2 years ago
Selected Answer: B
Once an incident is created, you can view more details of the incident by clicking on the View full details button, then navigate to the investigation page. You can investigate all entities for this alert such as IP addresses, accounts, and so on. https://charbelnemnom.com/detect-a-brute-force-attack-with-azure-sentinel/
upvoted 3 times
...
kiketxu
2 years ago
Currently, this question is outdated. It can't be in the Overview (A) because the Map was removed from there. Additionally, the question is asking to identify the geolocation information that corresponds to the incident. So, I opt for B, inside Investigation and selecting the IP, in entities you can find Geolocation info.
upvoted 3 times
kiketxu
2 years ago
Btw, the provided link in the answer seems quite out of date too. That overview map was removed in the "New" Overview version which is in public preview.
upvoted 1 times
...
...
ACSC
2 years ago
Selected Answer: A
https://docs.microsoft.com/en-us/azure/sentinel/get-visibility#get-visualization
upvoted 1 times
ACSC
2 years ago
I was wrong. Correct answer is B.
upvoted 1 times
...
...
AMZ
2 years, 1 month ago
Correct answer is A - once you click on the red or orange circle within the map it forwards you to logs analytics where the query is shown, this has the malicious IPs, country, confidence and other columns.
upvoted 1 times
...
Nickname01
2 years, 1 month ago
You need to identify the geolocation information that corresponds to the incident. How will you do this from the overview, i think it must be answer B. You go the the incident you click in de IP under Entities in the Details page and you will see the geolocation information related to the incident.
upvoted 2 times
...
fred99
2 years, 2 months ago
I vote for d- From Investigation, review insights on the incident entity.
upvoted 1 times
fred99
2 years, 2 months ago
after second though, A seems the better option even if it does not display the geolocation for one particular incident but for all
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...