Microsoft Security Operations Analyst (SC-200日本語版) - SC-200日本語무료 덤프문제 풀어보기

お客様のオンプレミスネットワークには、contoso という名前の Active Directory ドメインサービス (AD DS) ドメインが 2 つ存在します。
Contoso.com と fabrikam.com には Group1 という名前のグループがあります。Fabrikam.com には Group2 という名前のグループがあります。
WS1 という名前の Microsoft Sentinel ワークスペースがあり、その中に Rule1 という名前のスケジュール済みクエリ ルールが含まれています。
ルール1は、異常なAD DSセキュリティイベントに対応してアラートを生成します。各アラートはインシデントを作成します。
以下の要件を満たすインシデントトリアージソリューションを導入する必要があります。
contoso.com からのセキュリティインシデントは、グループ1に割り当てる必要があります。
fabrikam.comからのセキュリティインシデントは、グループ2に割り当てる必要があります。
事務的な負担は最小限に抑えなければならない。
解決策には何を含めるべきでしょうか?

정답: C
설명: (Fast2test 회원만 볼 수 있음)
お客様は、WS1 という名前の Microsoft Sentinel ワークスペースを含む Azure サブスクリプションをお持ちです。
WS1のインシデントには、実行すべきアクションのリストが含まれていることを確認する必要があります。ソリューションは以下の要件を満たす必要があります。
* それぞれのインシデントの種類に応じて、個別の対応策リストを作成できることを確認してください。
管理業務の手間を最小限に抑える。
どうすればよいですか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。
정답:
注: この質問は、同じシナリオを示す一連の質問の一部です。このシリーズの各質問には、指定された目標を達成できる可能性のある独自の解決策が含まれています。一部の質問セットには複数の正しい解決策が含まれる場合がありますが、他の質問セットには正しい解決策がない場合があります。
このセクションの質問に回答すると、その質問に戻ることはできません。そのため、これらの質問はレビュー画面には表示されません。
Active Directory との ID 統合のために Microsoft Defender を構成しています。
Microsoft Defender for ID ポータルから、攻撃者が悪用できるようにいくつかのアカウントを構成する必要があります。
解決策: 各アカウントを機密アカウントとして追加します。
これは目標を達成していますか?

정답: B
설명: (Fast2test 회원만 볼 수 있음)
Workspace1という名前のMicrosoft Sentinelワークスペースがあります。
組み込みの統合型ASIMパーサーから、ソース固有の組み込み型Advanced Security Information Model(ASIM)パーサーを除外する必要があります。
Workspace1には何を作成すべきですか?

정답: C
설명: (Fast2test 회원만 볼 수 있음)
お客様のネットワークには、Azure ADテナントと同期するオンプレミスのActive Directoryドメインサービス(AD DS)ドメインが含まれています。
Sentinel1という名前のMicrosoft Sentinelワークスペースがあります。
Sentinel1 でユーザーおよびエンティティ行動分析 (UEBA) を有効にし、AD DS ドメインからセキュリティ イベントを収集する必要があります。
どの3つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。
정답:

Explanation:

To enable User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel and collect Active Directory Domain Services (AD DS) security events, the integration relies on Microsoft Defender for Identity (MDI).
Defender for Identity monitors on-premises domain controllers and provides deep identity-based telemetry that Sentinel consumes for behavioral analytics and threat detection.
Here's the correct sequence explained step-by-step:
Deploy Microsoft Defender for Identity on the AD DS domain
Defender for Identity sensors must be installed on each domain controller (or dedicated server) in your on- premises AD DS environment.
This step enables continuous monitoring of AD activities like logons, Kerberos authentications, and LDAP queries.
Microsoft documentation states:
"To collect and analyze AD DS activities for UEBA, deploy Microsoft Defender for Identity sensors in your domain controllers." Configure the Microsoft Defender for Identity connector in Microsoft Sentinel In the Sentinel workspace (Sentinel1), go to Data connectors # Microsoft Defender for Identity # Connect.
This connector ingests identity-related alerts and telemetry from Defender for Identity into Sentinel's Log Analytics workspace.
It allows Sentinel to correlate identity-based security data with other sources for threat detection and investigation.
Enable UEBA in Microsoft Sentinel
After integrating MDI, enable UEBA in Sentinel's configuration settings.
UEBA uses identity data (from MDI and Azure AD) and other logs to build behavioral baselines and detect anomalies such as lateral movement or privilege escalation.
Microsoft documentation notes:
"To start analyzing user and entity behaviors, enable UEBA after connecting identity data sources such as Defender for Identity." Other actions listed (such as using legacy connectors or Windows Event Forwarding) are outdated or unnecessary when using MDI and Sentinel's built-in connectors.
Tenant1とTenant2という名前の2つのMicrosoft Entraテナントがあります。各テナントはAzureサブスクリプションにリンクされています。Tenant1にはGroup1という名前のグループが含まれています。Tenant2にはGroup2という名前のグループが含まれています。
各テナントに対してMicrosoft Sentinelを実装する必要があります。ソリューションは以下の要件を満たす必要があります。
* グループ1がテナント1とテナント2のセキュリティインシデントを単一のワークスペースで管理できるようにします。
* Group2がテナント2に関するセキュリティインシデントのみを管理できるようにします。
ゲストアカウントの使用を最小限に抑える。
管理業務の手間を最小限に抑える。
コストを最小限に抑える。
解決策には何を含めるべきでしょうか?

정답: B
ある企業は Azure Sentinel を使用しています。
自動化された脅威への対応を作成する必要があります。
何を使えばいいのでしょうか?

정답: D
설명: (Fast2test 회원만 볼 수 있음)
技術要件を満たすためには、ContosoとFabrikam向けにAzure Sentinelクエリを実装する必要があります。
解答には何を含めるべきでしょうか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。
정답:

Explanation:

In Microsoft Sentinel (built on Azure Monitor Logs), analytics and hunting queries are executed within a Log Analytics workspace. To run Sentinel queries for Fabrikam, the tenant must have at least one workspace (with Sentinel enabled) in its subscription to host rules, incidents, hunting queries, and workbooks. Sentinel's cross- workspace/tenant capability is provided by cross-resource queries in Kusto Query Language (KQL). The key construct for reaching outside the current workspace is the workspace() function, which lets you reference another Log Analytics workspace by name or resource ID-even across subscriptions or tenants when proper permissions (often via Azure Lighthouse or guest access) are in place.
Typical correlation looks like:
union workspace( ' Fabrikam-WS ' ).SecurityEvent, workspace( ' Contoso-WS ' ).SecurityEvent | ...
Here, workspace() is the required element to bring together data sets from multiple tenants; operators like extend and project only shape columns and do not establish cross-tenant scope. Therefore, to meet the requirements with minimal overhead: Fabrikam needs one workspace to host its Sentinel content, and you use workspace() in your KQL to correlate Contoso and Fabrikam data.
サインインログに対してユーザーおよびエンティティ行動分析(UEBA)が有効になっているMicrosoft Sentinelワークスペースをお持ちです。
対話型サインインの失敗を確実に検出する必要があります。
解決策は、管理上の負担を最小限に抑えるものでなければならない。
何を使うべきでしょうか?

정답: A
설명: (Fast2test 회원만 볼 수 있음)
あなたはMicrosoft 365のサブスクリプションをお持ちです。
サードパーティ製のウイルス対策ソフトがインストールされ、Microsoft Defenderウイルス対策ソフトがパッシブモードで動作しているWindowsデバイスが1,000台あります。サードパーティ製のウイルス対策ソフトでは検出されなかった悪意のあるアーティファクトからデバイスを保護する必要があります。解決策:フォルダーアクセス制御を設定します。
これは目標を達成していると言えるでしょうか?

정답: A
설명: (Fast2test 회원만 볼 수 있음)

우리와 연락하기

문의할 점이 있으시면 메일을 보내오세요. 12시간이내에 답장드리도록 하고 있습니다.

근무시간: ( UTC+9 ) 9:00-24:00
월요일~토요일

서포트: 바로 연락하기 

English Deutsch 繁体中文 日本語