Microsoft Security Operations Analyst Associate SC-200 Practice Question

Your organization has several Windows Server 2019 file servers that run in an on-premises datacenter behind a strict firewall. You need to build a Microsoft Sentinel playbook that automatically executes a PowerShell remediation script on those servers each time an incident with the tag "High-severity ransomware" is generated. The solution must avoid opening any inbound ports on the firewall while still allowing the script to run locally on every affected server. Which playbook action should you use to meet these requirements?

  • Add an Azure Function "HTTP trigger" action that calls a REST API exposed by each on-premises server.

  • Add an Azure Automation "Create job" action that starts a PowerShell runbook configured to run on a Hybrid Runbook Worker installed on the file servers.

  • Add an Azure Arc "Run command" action that executes the PowerShell script on each server.

  • Add an On-premises data gateway "Execute script" action to run the script on the servers.

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot