exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 2 question 34 discussion

Actual exam question from Microsoft's SC-200
Question #: 34
Topic #: 2
[All SC-200 Questions]

You have an Azure subscription that uses Microsoft Defender for Cloud and contains a storage account named storage1.

You receive an alert that there was an unusually high volume of delete operations on the blobs in storage1.

You need to identify which blobs were deleted.

What should you review?

  • A. the activity logs of storage1
  • B. the Azure Storage Analytics logs
  • C. the alert details
  • D. the related entities of the alert
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RodrigoLima
Highly Voted 1 year, 10 months ago
Selected Answer: B
Seems like the answer is actually correct. "Azure Storage Analytics performs logging and provides metrics data for a storage account. You can use this data to trace requests, analyze usage trends, and diagnose issues with your storage account."
upvoted 12 times
...
imhere4you
Highly Voted 1 year, 6 months ago
On exam - 19 June 2023
upvoted 7 times
...
HAjouz
Most Recent 4 days ago
Selected Answer: A
Activity logs offer a more precise and reliable way to identify the deleted blobs because they capture detailed information about each operation performed on the storage account. By analyzing these logs, you can pinpoint the exact blobs that were deleted, the time of deletion, and potentially the user or process responsible.
upvoted 1 times
...
talosDevbot
2 months, 2 weeks ago
Selected Answer: D
D) "Related entities" of the alert Question is saying you need to identify the blob involved in the alert you just received. Each alert in Defender for Cloud has a "Related entities" section. 'Entities' can be users, IP addresses, Resource ID, Hostname, File, Process. In this case, the Related entities section will have the resource ID of the blob related to the alert
upvoted 2 times
...
user636
3 months, 3 weeks ago
Selected Answer: D
The answer is D.
upvoted 1 times
...
user636
3 months, 3 weeks ago
The answer is D. Related entities will have the details of the blobs that were deleted. The alert details does not give the name of the blobs, but will only list the "Operations" that was performed. In this scenario, the operation name is "Storage.Blob_DeletionAnomaly". (Ref: https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-azure-storage#unusual-deletion-in-a-storage-account) The question expects you to use the tool "Microsoft Defender for Cloud", so try to stick with the options/features provided by the tool & not the complete Azure platform.
upvoted 1 times
...
Sekpluz
6 months ago
Selected Answer: D
https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts#respond-to-security-alerts
upvoted 2 times
...
Sneekygeek
8 months, 1 week ago
Selected Answer: D
Under the alert details there is a related entities field which will tell you to which resources are related to the alert. I would definitely start here before I dove blindly into the logs. https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts#respond-to-security-alerts
upvoted 1 times
...
ostralo
9 months ago
The answer is D. When you open an Alert(Delete operations on the blobs in storage 1) When you open the alert by clicking "View full details", it shows you the Alert details tab. If you scroll down, you will find the "Related entities" section. It shows Azure Resource (Resource ID, Subscription ID), Blob container (Name, Storage resource) etc.. It doesn't make sense the alert doesn't provide blob container name.
upvoted 2 times
...
Gurulee
11 months, 2 weeks ago
To identify deleted blobs in Azure Blob Storage, you can enable Storage Analytical logs. These logs contain details of each and every operation, including the ones that delete blobs.
upvoted 1 times
...
chepeerick
1 year, 1 month ago
Correct
upvoted 1 times
...
NICKTON81
1 year, 3 months ago
Selected Answer: D
D - Related Entities https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts#respond-to-security-alerts
upvoted 3 times
...
mali1969
1 year, 3 months ago
Selected Answer: D
The activity logs of storage1 and the Azure Storage Analytics logs are not sufficient to identify the deleted blobs, as they only provide general information about the operations performed on the storage account. The alert details provide more specific and contextual information about the activity and the related entities
upvoted 3 times
mali1969
1 year, 3 months ago
The related entities are the objects that are involved in or affected by the activity, such as blobs, containers, files, shares, directories, etc. You can use the related entities to identify which blobs were deleted in your storage account
upvoted 2 times
...
...
donathon
1 year, 3 months ago
Selected Answer: B
https://learn.microsoft.com/en-us/rest/api/storageservices/storage-analytics-logged-operations-and-status-messages#logged-operations
upvoted 1 times
...
[Removed]
1 year, 3 months ago
Selected Answer: B
Azure Storage Analytics logs provide detailed insights into the activities performed on your storage account, including information about blob operations like delete operations. These logs capture information about operations, including their types, targets, timestamps, and authentication details. By analyzing the Storage Analytics logs, you can determine which blobs were deleted and gather other relevant details about the delete operations. The other options are not as directly related to identifying which specific blobs were deleted: A. the activity logs of storage1: While the activity logs provide information about management activities and data plane operations on Azure resources, they might not contain the detailed information needed to identify individual deleted blobs.
upvoted 1 times
...
therealletsgo
1 year, 7 months ago
Tough one, but B seems to be for "Storage Analytics logs detailed information about successful and failed requests to a storage service." I suppose I will go with A and be the black sheep based on these: https://learn.microsoft.com/en-us/azure/storage/blobs/monitor-blob-storage?tabs=azure-portal https://learn.microsoft.com/en-us/azure/storage/blobs/monitor-blob-storage-reference
upvoted 1 times
therealletsgo
1 year, 7 months ago
nvm on this....
upvoted 2 times
...
...
haskelatchi
1 year, 8 months ago
Selected Answer: C
You are all incorrect. Answer is C When Microsoft Defender for Cloud generates an alert, it includes detailed information about the event that triggered the alert, including information about the specific resources that were affected. In this case, since the alert was triggered by an unusually high volume of delete operations on the blobs in storage1, the alert details would provide information about which specific blobs were deleted. Azure Storage Analytics logs provide detailed information about successful and failed requests to a storage service, including delete operations. However, in this specific scenario where you have received an alert from Microsoft Defender for Cloud about an unusually high volume of delete operations on the blobs in storage1, the alert details would be the best place to look for information about which blobs were deleted.
upvoted 3 times
Holii
1 year, 8 months ago
Security alert -> View Full Details -> Alert details does NOT contain a list of affected blob resources. In order to see affected blob containers affected by a deletion event, the answer would be D Expand the Related Entities -> Blob container -> Provides a list of all blob entities affected by the alert. Since this is specifically talking about an alert, and the entities affected by the deletion of the alert, I think it would honestly be best to do it from inside the 'Related Entities -> blob containers' page rather than generating a view of deleted blob incidents. You don't know whether a blob container was deleted that was not part of that alert if you're searching the analytics logs or storage account logs. For the fact that it is specifically targeting blobs touching this alert, im choosing D.
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago