最新的Microsoft Security Operations Analyst (SC-200日本語版) - SC-200日本語免費考試真題

お客様は、Microsoft Defender for Cloudを使用するAzureサブスクリプションをお持ちです。
以下のリスクを軽減するために、Defender for Cloudを設定する必要があります。
* アプリケーションのソースコード内の脆弱性
* 宣言型テンプレートにおけるエクスプロイトツールキット
* 悪意のあるIPアドレスからの操作
暴露された秘密
Defender for Cloudのサービスのうち、どれを2つ使用すべきでしょうか?それぞれの正解は、解決策の一部を示しています。
注:正解ごとに1ポイントが加算されます。

正確答案: B,E
說明:(僅 Fast2test 成員可見)
あなたはMicrosoft 365 E5のサブスクリプションをお持ちです。
Windowsデバイス上でPowerShellを使用して、Microsoft Purviewの監査ログを検索する必要があります。
まず最初に何をすべきでしょうか?

正確答案: A
說明:(僅 Fast2test 成員可見)
注: この質問は、同じシナリオを示す一連の質問の一部です。このシリーズの各質問には、指定された目標を達成できる可能性のある独自の解決策が含まれています。一部の質問セットには複数の正しい解決策が含まれる場合がありますが、他の質問セットには正しい解決策がない場合があります。
このセクションの質問に回答すると、その質問に戻ることはできません。そのため、これらの質問はレビュー画面には表示されません。
Active Directory との ID 統合のために Microsoft Defender を構成しています。
Microsoft Defender for ID ポータルから、攻撃者が悪用できるようにいくつかのアカウントを構成する必要があります。
解決策: Azure Identity Protection から、サインイン リスク ポリシーを構成します。
これは目標を達成していますか?

正確答案: A
說明:(僅 Fast2test 成員可見)
オンプレミスのデータセンターに、Appl という名前のカスタム Web アプリケーションがあります。App1 は Active Directory ドメイン サービス (AD DS) 認証を使用し、Microsoft Entra アプリケーション プロキシを使用してアクセスできます。
お客様は、Microsoft Defender XDRを使用するMicrosoft 365 E5サブスクリプションをご利用されています。
ユーザーが極秘文書をダウンロードしたというアラートを受け取ります。
ユーザーがApp1を使用して「極秘」ラベルが付与されたドキュメントのダウンロードを開始する際に、多要素認証(MFA)を必須とすることで、アラートに関連するリスクを軽減する必要があります。
どうすればよいですか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。
正確答案:

Explanation:

In this scenario, App1 is a custom web app published through Microsoft Entra Application Proxy and authenticated using Active Directory Domain Services (AD DS) . Because it's integrated with Microsoft Entra ID (formerly Azure AD) for access control, the most appropriate and supported way to require MFA for users accessing the application is through Conditional Access .
Microsoft Entra Conditional Access policies evaluate user sign-in conditions such as risk level, device compliance, location, and sensitivity of data before granting access. Specifically, Microsoft's documentation states:
"Conditional Access policies allow administrators to require multi-factor authentication, block access, or enforce specific controls such as app protection or session policies for cloud and on-premises applications integrated with Microsoft Entra ID." Therefore, to make MFA mandatory for users accessing App1, a Conditional Access policy must be created targeting that application.
For the second part, to implement a session policy that controls or monitors user behavior (such as downloading highly confidential documents), the correct choice is Microsoft Defender for Cloud Apps (MDA) . Microsoft's official guidance says:
"Session policies in Microsoft Defender for Cloud Apps provide real-time session controls that enable administrators to monitor and restrict user activity in cloud apps, including download, cut/copy, and upload actions based on sensitivity labels or user risk." These session policies integrate seamlessly with Conditional Access via the "Use Conditional Access App Control" setting to apply continuous access evaluation during a user's session.
Hence, the correct verified configuration is:
* Require MFA: Conditional Access
* Implement session policy: Microsoft Defender for Cloud Apps
SW1という名前のMicrosoft Sentinelワークスペースがあります。
SW1では、ユーザーおよびエンティティ行動分析(UEBA)を有効にします。
以下のタスクを実行するには、KQLを使用する必要があります。
* 各エンティティタイプに対応するフィールドを持つエンティティデータを表示します。
ルールがどれだけ効果的に機能するかを分析することで、ルールの品質を評価する。
各タスクにおいて、KQLではどのテーブルを使用すべきでしょうか?回答するには、適切なテーブルを正しいタスクにドラッグしてください。
各表は、1回だけ使用することも、複数回使用することも、全く使用しないことも可能です。コンテンツを表示するには、ペイン間の分割バーをドラッグするか、スクロールする必要がある場合があります。
注:正解ごとに1ポイントが加算されます。
正確答案:

Explanation:

When User and Entity Behavior Analytics (UEBA) is enabled in Microsoft Sentinel , it creates several dedicated tables within the Log Analytics workspace to store processed data for behavioral analytics and anomaly detection. Each table serves a specific purpose according to Microsoft documentation.
* BehaviorAnalytics Table - for viewing entity data The BehaviorAnalytics table stores enriched information about entities (such as users, hosts, IP addresses, and applications) and their observed behaviors. Each record includes multiple fields that describe user or entity activities, risk scores, and behavioral baselines. Microsoft Sentinel documentation states:
"Use the BehaviorAnalytics table to view the entity data collected and analyzed by UEBA. This table contains fields for each type of entity, including account, host, and IP data." Therefore, to view the entity data with detailed attributes for each type, you query the BehaviorAnalytics table in KQL.
* Anomalies Table - for assessing rule quality The Anomalies table is used to analyze the results of anomaly detection rules and evaluate their effectiveness. Each record represents an anomaly event generated by UEBA's machine learning or statistical models. Microsoft's UEBA and Sentinel analytics documentation explains:
"Use the Anomalies table to assess the performance and quality of your anomaly detection rules. The table helps you identify how well each rule detects unusual activities and whether it produces false positives." Thus, when you need to measure how well your rules perform (i.e., their quality, hit rate, or alert effectiveness), you use the Anomalies table.
Summary Mapping:
* View entity data # BehaviorAnalytics
* Assess rule quality # Anomalies
This mapping aligns directly with the functionality of UEBA-related tables in Microsoft Sentinel and follows official documentation for analyzing entity behaviors and anomaly rule performance.
Azure Active Directory (Azure AD) テナントにリンクされた Azure サブスクリプションがあります。このテナントには、User1 と User2 という名前の 2 人のユーザーがいます。
Azure Defender をデプロイする予定です。
以下の表に示すように、User1とUser2がサブスクリプションレベルでタスクを実行できるようにする必要があります。

解決策は、最小権限の原則に基づかなければならない。
各ユーザーにどの役割を割り当てますか?回答するには、適切な役割を正しいユーザーにドラッグしてください。各役割は、1回、複数回、またはまったく使用しない場合があります。コンテンツを表示するには、ペイン間の分割バーをドラッグするか、スクロールする必要がある場合があります。
正確答案:

Explanation:
Box 1: Owner
Only the Owner can assign initiatives.
Box 2: Contributor
Only the Contributor or the Owner can apply security recommendations.
Reference:
https://docs.microsoft.com/en-us/azure/defender -for-cloud/permissions
Sub1という名前のAzureサブスクリプションがあり、そこではMicrosoft Defender for Cloudが使用されています。
PCI DSS 4.0イニシアチブをSub1に割り当て、Defender for Cloudの規制遵守ダッシュボードにそのイニシアチブが表示されるようにする必要があります。
環境設定のセキュリティポリシーを確認すると、業界標準や規制基準を追加するオプションが利用できないことがわかります。
まず最初に何をすべきでしょうか?

正確答案: B
說明:(僅 Fast2test 成員可見)
注: この質問は、同じシナリオを示す一連の質問の一部です。このシリーズの各質問には、指定された目標を達成できる可能性のある独自の解決策が含まれています。一部の質問セットには複数の正しい解決策が含まれる場合がありますが、他の質問セットには正しい解決策がない場合があります。
このセクションの質問に回答すると、その質問に戻ることはできません。そのため、これらの質問はレビュー画面には表示されません。
アマゾン ウェブ サービス (AWS) 上に Linux 仮想マシンがあります。
Azure Defender をデプロイし、自動プロビジョニングを有効にします。
Azure Defender を使用して仮想マシンを監視する必要があります。
解決策: Azure Arc を有効にし、仮想マシンを Azure Arc にオンボードします。
これは目標を達成していますか?

正確答案: B
說明:(僅 Fast2test 成員可見)
カスタムワークブックを含むMicrosoft Sentinelワークスペースがあります。
セキュリティイベントの概要を照会する必要があります。ソリューションは以下の要件を満たす必要があります。
* 過去1週間に取り込まれたセキュリティイベントの数を特定します。
* 日ごとのイベント数をグラフで表示する。
質問にはどのように回答すればよいですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。
正確答案:

Explanation:

To summarize security events over the last week and chart them by day , use KQL time binning on the event timestamp. In Sentinel/Log Analytics, bin() groups records into fixed time buckets on a datetime column- here, TimeGenerated . Pair that with a time filter for the past 7 days and render as a timechart. The key pattern is:
SecurityEvent
| where TimeGenerated > = ago(7d)
| summarize Count = count() by bin(TimeGenerated, 1d)
| render timechart
* bin is the correct aggregator for time-based bucketing.
* TimeGenerated is the standard timestamp column used across Sentinel tables for ingestion time.
* Using a 1-day bin shows the daily counts; the where TimeGenerated > = ago(7d) limits results to the past week .
* render timechart visualizes the grouped counts over time.
In the answer area shown, you select bin and TimeGenerated ; (the full query would also include the where line and a 1d bin size to meet the "by day" requirement).
Microsoft Sentinelワークスペースをお持ちです。
Microsoft Defenderコネクタによって生成されたインシデントを一時的に抑制するには、Fusion Analyticsルールを構成する必要があります。このソリューションは、以下の要件を満たす必要があります。
多段階攻撃の検出能力への影響を最小限に抑える。
管理業務の手間を最小限に抑える。
ルールはどのように設定すればよいですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。
正確答案:

Explanation:

The Fusion analytics rule in Microsoft Sentinel automatically correlates alerts from multiple sources (including Microsoft Defender connectors) to detect multistage attacks . Because Fusion runs continuously and cannot be disabled without losing multi-stage detection, the best practice for temporarily suppressing incidents from a specific connector (like Microsoft Defender) is to use automation rules , not by disabling the Fusion rule itself.
An automation rule can be configured to trigger on specific conditions (such as "When incident is updated" or "When incident is created") and then perform an action like running a playbook that applies suppression logic.
Here's the reasoning:
* Trigger:
* Setting the trigger to "When incident is updated" ensures that the rule evaluates changes to existing incidents-such as enrichment or tagging from Fusion-and provides finer control over suppression, minimizing impact on the Fusion detection pipeline.
* Using "When incident is created" could interfere with Fusion's initial detection process.
* Action:
* The appropriate action is "Run playbook" , which allows automated handling (for example, tagging or closing certain incidents from a specific connector). This requires minimal administrative effort and avoids turning off the Fusion rule.
This configuration ensures that Fusion continues to detect multistage attacks (so detection isn't impacted) while automation handles temporary suppression for specific connectors efficiently.
報告された問題を解決するには、異常検出ポリシーの設定を変更して、Microsoft Defender for Cloud Apps の要件を満たす必要があります。
どのポリシーを変更すべきでしょうか?

正確答案: A
說明:(僅 Fast2test 成員可見)
お客様は、Microsoft Defender XDRを使用するMicrosoft 365サブスクリプションをご利用されています。
Microsoft Graphのアクティビティログを使用して、サブスクリプションにおける不審なアクティビティを調査する予定です。
サブスクリプションからリソースを削除するリクエストを検索し、そのリクエストを開始したユーザーを特定する必要があります。
KQLクエリはどのように入力すればよいですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。
正確答案:

Explanation:
Microsoft Defender XDR を使用し、Device1 という名前の Windows デバイスが含まれる Microsoft 365 サブスクリプションがあります。
Device1 のタイムラインには、File1.ps1、File2.exe、File3.dll という名前の 3 つのファイルが含まれています。
Microsoft Defender XDR で詳細な分析を行うには、ファイルを送信する必要があります。
どのファイルを送信できますか?

正確答案: B
說明:(僅 Fast2test 成員可見)

聯系我們

如果您有任何問題,請留下您的電子郵件地址,我們將在12小時內回复電子郵件給您。

我們的工作時間:( GMT 0:00-15:00 )
週一至週六

技術支持: 立即聯繫 

English 日本語 Deutsch 한국어