SC-900日本語試験無料問題集「Microsoft Security, Compliance, and Identity Fundamentals (SC-900日本語版) 認定」

ホットスポットに関する質問
以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。
正解:

Explanation:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview
Microsoft Entra IDガバナンスには、どの機能が含まれていますか?

解説: (GoShiken メンバーにのみ表示されます)
ホットスポットに関する質問
以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。
正解:

Explanation:
Box 1: Yes
System updates reduces security vulnerabilities, and provide a more stable environment for end users. Not applying updates leaves unpatched vulnerabilities and results in environments that are susceptible to attacks.
Box 2: Yes
Box 3: Yes
If you only use a password to authenticate a user, it leaves an attack vector open. With MFA enabled, your accounts are more secure.
Reference:
https://docs.microsoft.com/en-us/azure/security-center/secure-score-security-controls
ホットスポットに関する質問
以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。
正解:
複数のリソースを含むAzureサブスクリプションをお持ちです。
既存のリソースについて、コンプライアンスを評価し、基準を遵守させる必要があります。
何を使うべきでしょうか?

解説: (GoShiken メンバーにのみ表示されます)
あなたはリソースをクラウドに移行する計画を立てています。
あなたは、IaaS(Infrastructure as a Service)、PaaS(Platform as a Service)、SaaS(Software as a Service)といったクラウドモデルの利用について評価を行っています。
あなたは、クラウドベースのアプリのデータ、ユーザーアカウント、およびユーザーデバイスのみを管理することを計画しています。
どのクラウドモデルを使用しますか?

ドラッグアンドドロップ問題
コンプライアンスマネージャーでコンプライアンススコアを評価しています。
コンプライアンススコアのアクションサブカテゴリを、適切なアクションと照合してください。
回答するには、左側の列から適切なアクションサブカテゴリを右側のアクションにドラッグしてください。各アクションサブカテゴリは、1回、複数回、またはまったく使用しないことができます。
注:正解1つにつき1ポイントが加算されます。
正解:

Explanation:
Box 1: Preventative
Preventative actions address specific risks. For example, protecting information at rest using encryption is a preventative action against attacks and breaches.
Separation of duties is a preventative action to manage conflict of interest and guard against fraud.
Box 2: Detective
Detective actions actively monitor systems to identify irregular conditions or behaviors that represent risk, or that can be used to detect intrusions or breaches.
Examples include system access auditing and privileged administrative actions. Regulatory compliance audits are a type of detective action used to find process issues.
Box 3: Corrective
Corrective actions try to keep the adverse effects of a security incident to a minimum, take corrective action to reduce the immediate effect, and reverse the damage if possible. Privacy incident response is a corrective action to limit damage and restore systems to an operational state after a breach.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-score-calculation
マイクロソフトがプライバシー、コンプライアンス、およびセキュリティを管理する方法に関する情報を提供するマイクロソフトポータルはどれですか。

解説: (GoShiken メンバーにのみ表示されます)
ホットスポットに関する質問
文を正しく完成させる選択肢を選びなさい。
正解:

Explanation:
Box:
In Microsoft Sentinel, ______________ can perform analytics by using Python machine learning.
To perform analytics using Python and machine learning in Microsoft Sentinel, you primarily need to use Jupyter Notebooks integrated with an Azure Machine Learning (AML) workspace.
Core Requirements
Azure Machine Learning Workspace: Required to execute notebooks within the Sentinel portal. It provides the managed compute environment for running Python code.
Compute Instance: A managed virtual machine (VM) in your AML workspace that acts as the
"kernel" to parse and execute your machine learning models.
Python Libraries:
MSTICPy: A critical cybersecurity library designed by Microsoft for data retrieval, analysis, and visualization in Sentinel.
Kqlmagic: Enables you to run Kusto Query Language (KQL) queries directly within your Python code to pull data from Sentinel.
Standard ML Libraries: Tools like pandas, numpy, scikit-learn, matplotlib, and TensorFlow are often pre-installed in the AML environment for data processing and model building.
Reference:
https://www.ais.com/enhancing-security-an-introduction-to-machine-learning-notebooks-in-microsoft-sentinel/
ホットスポットに関する質問
以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。
正解:

Explanation:
Box 1: No
Security defaults in Microsoft Entra ID are available in the free tier and do not require a Premium P1/P2 license.
Box 2: No
Security defaults are configured at the tenant level, not per user.
Box 3: Yes
Security defaults enforce MFA registration and usage for privileged/admin accounts.
ホットスポットに関する質問
以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。
正解:

Explanation:
Each item that supports sensitivity labels can have a single sensitivity label applied to it.
https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide