exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 12 question 1 discussion

Actual exam question from Microsoft's SC-300
Question #: 1
Topic #: 12
[All SC-300 Questions]

You need to configure the detection of multi-staged attacks to meet the monitoring requirements.
What should you do?

  • A. Customize the Microsoft Sentinel rule logic.
  • B. Create a workbook.
  • C. Add Microsoft Sentinel data connectors.
  • D. Add an Microsoft Sentinel playbook.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DeepMoon
Highly Voted 2 years, 2 months ago
Given Answer A is correct. Because it is the most specific thing you can do from the given choices (A, C & D). https://learn.microsoft.com/en-us/azure/sentinel/configure-fusion-rules#configure-fusion-rules
upvoted 7 times
...
Roliani
Most Recent 8 months, 2 weeks ago
Selected Answer: A
Fusion is enabled by default in Microsoft Sentinel, as an analytics rule called Advanced multistage attack detection. You can view and change the status of the rule, configure source signals to be included in the Fusion ML model, or exclude specific detection patterns that may not be applicable to your environment from Fusion detection. Learn how to configure the Fusion rule. Rules ) Option A
upvoted 3 times
...
dule27
1 year, 5 months ago
Selected Answer: A
A. Customize the Microsoft Sentinel rule logic.
upvoted 1 times
...
ACSC
2 years ago
Selected Answer: A
https://learn.microsoft.com/en-us/azure/sentinel/configure-fusion-rules#configure-fusion-rules
upvoted 2 times
...
zman_83
2 years, 2 months ago
Hmm, why not C. Add Microsoft Sentinel data connectors.?
upvoted 3 times
LHADUK
2 years ago
connectors are already added, it's listed in existing environment: "The subscription contains an Azure Sentinel instance that uses the AAD connector and the Office 365 connector."
upvoted 7 times
Doinitza
9 months, 4 weeks ago
"suspicious Azure AD sign-ins" => MS Entra ID Protection connector needed. The answer is C.
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...