Microsoft Security Operations Analyst Associate SC-200 Practice Question

Your organization is adopting Microsoft Security Copilot to streamline incident investigations. You are asked to ingest threat intelligence files that reside in a secured Azure Storage blob and make them available to Security Copilot prompts. You must meet the following requirements:

  • The integration must not require developers to write any custom code.
  • The ingestion process must support scheduled, incremental imports as new files are dropped in the blob.

Which action should you perform first to satisfy the requirements?

  • Grant Security Copilot the Storage Blob Data Reader role on the container that holds the threat intelligence files.

  • Create an Azure Event Grid subscription on the storage account that triggers the Logic Apps Security Copilot data connector when a new blob is created.

  • Upload the threat intelligence files to the built-in Files workspace in Security Copilot.

  • Enable the Generic Threat Intelligence IMPORT data connector in Microsoft Sentinel and point it to the storage account.

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot