最新的Microsoft Security Operations Analyst (SC-200日本語版) - SC-200日本語免費考試真題
お客様は、WS1 という名前の Microsoft Sentinel ワークスペースを含む Azure サブスクリプションをお持ちです。WS1 には、Azure Activity コネクタと Microsoft Entra ID コネクタが構成されています。
どのアカウントに最も多くの警告が発生しているか、また各警告に対応するインシデント情報を調査する必要があります。解決策は管理作業を最小限に抑えるものでなければなりません。WS1 で最初に行うべきことは何ですか?
どのアカウントに最も多くの警告が発生しているか、また各警告に対応するインシデント情報を調査する必要があります。解決策は管理作業を最小限に抑えるものでなければなりません。WS1 で最初に行うべきことは何ですか?
正確答案: D
Azure Sentinel から、次の図に示すように、重大度の高いインシデントの調査ペインを開きます。

図に示された情報に基づいて、各記述を完成させる選択肢をドロップダウンメニューを使用して選択してください。
注:正解ごとに1ポイントが加算されます。


図に示された情報に基づいて、各記述を完成させる選択肢をドロップダウンメニューを使用して選択してください。
注:正解ごとに1ポイントが加算されます。

正確答案:

Explanation:
If you hover over the virtual machine named vm1, you can view the running processes.
If you select Info, you can navigate to the bookmarks related to the incident.
お客様は、Microsoft Defender XDRを使用するMicrosoft 365 E5サブスクリプションをご利用されています。
自動攻撃阻止機能を有効にします。
最近発生したランサムウェア攻撃の際、Defender for Endpointは自動的に対応しました。
インシデントに対するDefender for Endpointの自動応答を確認する必要があります。
Microsoft Defenderポータルでは何を使用すべきですか?
自動攻撃阻止機能を有効にします。
最近発生したランサムウェア攻撃の際、Defender for Endpointは自動的に対応しました。
インシデントに対するDefender for Endpointの自動応答を確認する必要があります。
Microsoft Defenderポータルでは何を使用すべきですか?
正確答案: C
Azure サブスクリプションには、Workspace1 という名前の Microsoft Sentinel ワークスペースと User1 という名前のユーザーが含まれています。
User1がWorkspace1を使用してインシデントを調査できるようにする必要があります。このソリューションは、最小権限の原則に従う必要があります。
User1にはどの役割を割り当てるべきですか?
User1がWorkspace1を使用してインシデントを調査できるようにする必要があります。このソリューションは、最小権限の原則に従う必要があります。
User1にはどの役割を割り当てるべきですか?
正確答案: D
說明:(僅 Fast2test 成員可見)
Azure Sentinelの要件を満たすには、分析ルールを作成する必要があります。
どうすればよいですか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。

どうすればよいですか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。

正確答案:

According to Microsoft Security Operations (SecOps) and Azure Sentinel documentation, when you need to create an analytics rule that executes a custom KQL query and automatically initiates a playbook, the correct configuration is to create a Scheduled rule and ensure the playbook includes a trigger.
Here's why:
A Scheduled analytics rule in Microsoft Sentinel (Microsoft Defender XDR portal) is designed for running custom KQL queries at defined intervals (for example, every hour or every few minutes) to detect specific patterns of suspicious activity. When the rule's conditions are met, Sentinel generates alerts that can automatically trigger a playbook for response and automation.
A playbook in Sentinel is an Azure Logic App that automates responses to incidents or alerts. To connect a playbook to an analytics rule, it must include a trigger-specifically, the "Microsoft Sentinel Alert" or
"Incident trigger." This allows the rule to start the playbook automatically when the defined condition is met.
The other options are incorrect because:
Fusion rules are built-in and use Microsoft's machine learning to correlate signals automatically; they can't be used for custom queries.
Microsoft incident creation rules are also built-in and handle alert-to-incident grouping logic, not custom query execution.
A service principal would be needed for permissions (e.g., admin1 configuring playbooks), but not inside the playbook itself.
Diagnostics settings apply to log collection and retention, not rule automation.
Therefore, based on Microsoft Sentinel best practices and documentation:
# Create the rule of type: Scheduled
# Configure the playbook to include: A trigger
お客様は、Microsoft Defender XDRを使用するMicrosoft 365サブスクリプションをご利用されています。
お客様は、Microsoft Security Copilot を使用する Azure サブスクリプションをお持ちです。
Security Copilotで、インシデントIDに関する以下の情報を収集するカスタムプロンプトブックを作成する必要があります。
* インシデントの概要
* 特定された脅威アクターに関する脅威インテリジェンス
* 当該事件の影響を受けたユーザーに関する詳細な分析。
* 事件の影響を受けた機器の詳細な分析
どの4つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。

お客様は、Microsoft Security Copilot を使用する Azure サブスクリプションをお持ちです。
Security Copilotで、インシデントIDに関する以下の情報を収集するカスタムプロンプトブックを作成する必要があります。
* インシデントの概要
* 特定された脅威アクターに関する脅威インテリジェンス
* 当該事件の影響を受けたユーザーに関する詳細な分析。
* 事件の影響を受けた機器の詳細な分析
どの4つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。

正確答案:

Explanation:

Sub1 という名前の Azure サブスクリプションがあります。Sub1 には、SW1 という名前の Microsoft Sentinel ワークスペースと、Windows Server を実行する VM1 という名前の仮想マシンが含まれています。SW1 は、AMA コネクタを介して Windows セキュリティ イベントを使用して、VM1 からセキュリティ ログを収集します。
VM1から収集するイベントの範囲を制限する必要があります。ソリューションは、監査失敗イベントのみが収集されるようにする必要があります。
コネクタのフィルタ式はどのように完成させるべきですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

VM1から収集するイベントの範囲を制限する必要があります。ソリューションは、監査失敗イベントのみが収集されるようにする必要があります。
コネクタのフィルタ式はどのように完成させるべきですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

正確答案:

Explanation:

In Microsoft Sentinel, when using the Windows Security Events via AMA (Azure Monitor Agent) connector, you can configure an XPath filter expression to control which Windows security events are collected from a connected virtual machine.
Microsoft's documentation specifies that event filtering is based on the EventLog XML schema, and filtering by Keywords allows you to target specific audit categories. In Windows Security logs, events are categorized as follows by their Keywords bitmask:
0x8020000000000000 # Audit Success events
0x8010000000000000 # Audit Failure events
Since the requirement is to collect only audit failure events, the XPath filter must include only the System node (which contains the event header metadata) and filter by the Keywords attribute equal to
0x8010000000000000.
The correct XPath syntax for the filter in this case is:
Security!*[System[Keywords= ' 0x8010000000000000 ' ]]
Explanation of components:
Security!* - Targets the Windows Security event log.
System[...] - Refers to the event's header metadata section (where Keywords, EventID, and Level are stored).
Keywords= ' 0x8010000000000000 ' - Matches only events that have the Audit Failure bit set.
Therefore, only events with Audit Failure outcomes will be collected from VM1, satisfying the requirement to minimize event ingestion and reduce unnecessary log noise.
# Final Answer: Security!*[System[Keywords= ' 0x8010000000000000 ' ]]
Microsoft Defender for Endpointに登録され、改ざん防止機能が有効になっている、Device1という名前のWindows 11デバイスがあります。
あるユーザーから、Microsoft Defender Antivirusが基幹業務(LOB)アプリケーションのインストールをブロックしているという報告があった。
デバイス1でトラブルシューティングモードを有効にします。
Device1がトラブルシューティングモードになっているときに、Defender for Endpointによって収集されたログと設定スナップショットを取得する必要があります。このソリューションは、管理作業を最小限に抑える必要があります。
あなたはどうすべきですか?
あるユーザーから、Microsoft Defender Antivirusが基幹業務(LOB)アプリケーションのインストールをブロックしているという報告があった。
デバイス1でトラブルシューティングモードを有効にします。
Device1がトラブルシューティングモードになっているときに、Defender for Endpointによって収集されたログと設定スナップショットを取得する必要があります。このソリューションは、管理作業を最小限に抑える必要があります。
あなたはどうすべきですか?
正確答案: B
Microsoft Defender for Identityの誤検知アラートの調査に必要な労力を最小限に抑える必要があります。何を確認すべきでしょうか?
正確答案: B
說明:(僅 Fast2test 成員可見)
以下の表に示すリソースが利用可能です。

お客様は、Microsoft Defender for Cloudを使用するAzureサブスクリプションをお持ちです。
VM1とServer1を保護するには、Defender for Cloudを使用する必要があります。ソリューションは以下の要件を満たす必要があります。
* 高度な脅威対策と脆弱性評価をサポートする
* 各 SQL Server 2022 インスタンスを SQL 仮想マシンとして登録します。
導入と管理の手間を最小限に抑える
各サーバーには何をデプロイすべきですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。


お客様は、Microsoft Defender for Cloudを使用するAzureサブスクリプションをお持ちです。
VM1とServer1を保護するには、Defender for Cloudを使用する必要があります。ソリューションは以下の要件を満たす必要があります。
* 高度な脅威対策と脆弱性評価をサポートする
* 各 SQL Server 2022 インスタンスを SQL 仮想マシンとして登録します。
導入と管理の手間を最小限に抑える
各サーバーには何をデプロイすべきですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

正確答案:

Explanation:

For SQL Server on Azure VMs (VM1), Defender for Cloud's Advanced Threat Protection and Vulnerability Assessment for SQL "on machines" are enabled by registering the instance as a SQL virtual machine using the SQL IaaS Agent extension. This single Azure VM extension onboards the SQL workload, exposes SQL VM resource management, and lights up Defender for SQL (ATP + VA) with minimal admin effort-no separate agents are required on Azure VMs beyond this extension for these features.
For on-premises/Arc servers (Server1), the machine is already Arc-enabled. To protect SQL instances with Defender for Cloud and to surface vulnerability assessment and threat protection signals, you deploy the Azure Arc SQL Server extension (delivered as an Arc "virtual machine extension") to register the instance with Azure. In addition, Arc scenarios use the Azure Monitor Agent (AMA) for data collection and security signal ingestion in Defender for Cloud (the legacy Log Analytics agent is not recommended). This combination satisfies ATP/VA requirements while keeping operations simple and consistent with current agent guidance.
Therefore:
VM1: only the Azure VM extension (SQL IaaS Agent extension).
Server1: AMA + an Azure (Arc) extension (Arc SQL Server extension).
お客様は、Microsoft Defenderを使用するMicrosoft 365 E5サブスクリプションと、Azure Sentinelを使用するAzureサブスクリプションをお持ちです。
既知の悪意のあるメール送信者から送信されたメールに含まれるファイルを持つすべてのデバイスを特定する必要があります。クエリはSHA256ハッシュの一致に基づいて実行されます。
質問にはどのように回答すればよいですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

既知の悪意のあるメール送信者から送信されたメールに含まれるファイルを持つすべてのデバイスを特定する必要があります。クエリはSHA256ハッシュの一致に基づいて実行されます。
質問にはどのように回答すればよいですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

正確答案:

Explanation:

To correlate malicious email attachments with endpoints, Microsoft Defender data schemas expose attachment metadata in EmailAttachmentInfo (including the SHA256 hash) and endpoint file activity in DeviceFileEvents (which also records SHA256 for observed files). The recommended investigation pattern is:
(1) filter email telemetry to the suspected sender and keep only attachments with a populated hash; (2) join that result with endpoint file events on the SHA256 hash to find devices where an identical file (by cryptographic hash) was seen. In KQL, isnotempty(SHA256) ensures you only pass attachments with a valid hash to the join, and join ... on SHA256 performs an exact-match correlation across datasets. This method aligns with Defender's guidance to use hash-based correlation as the most reliable way to match artifacts across different security workloads (email vs. endpoint), since filenames and paths can change, but a cryptographic hash uniquely identifies file content. The final project selects operational fields for response- timestamps, file name and hash, device identifiers/names, message IDs, and sender/recipient-so the SOC can quickly pivot to the impacted devices and the original email that delivered the file.
1,000 台の Windows 10 デバイスを含む Microsoft 365 サブスクリプションがあります。デバイスには Microsoft Office 365 がインストールされています。
次のデバイスの脅威を軽減する必要があります。
信頼できない Web サイトからスクリプトをダウンロードする Microsoft Excel マクロ
Microsoft Outlook で実行可能な添付ファイルを開くユーザー
Outlook のルールとフォームの悪用
何を使えばいいのでしょうか?
次のデバイスの脅威を軽減する必要があります。
信頼できない Web サイトからスクリプトをダウンロードする Microsoft Excel マクロ
Microsoft Outlook で実行可能な添付ファイルを開くユーザー
Outlook のルールとフォームの悪用
何を使えばいいのでしょうか?
正確答案: C
說明:(僅 Fast2test 成員可見)