Microsoft · Free Practice Questions · Last reviewed May 2026
18real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
41% of exam · 6 sample questions below
Your SOC team needs to ensure that all high-severity Microsoft Sentinel incidents are automatically assigned to the senior analyst on call. The team uses Microsoft Teams for communication. Which configuration should you implement?
Configure an analytics rule to set the incident owner to the senior analyst and enable Teams integration in Sentinel settings.
Create a playbook that reassigns incidents and posts to Teams, and attach it to an automation rule triggered by high-severity incidents.
Create a workbook that filters high-severity incidents and configure a Teams webhook in the workbook settings.
Create an automation rule that runs when an incident is created with severity High, sets the owner to the senior analyst, and then runs a playbook to post a message to Teams.
An automation rule can be configured to trigger 'When incident is created' and apply a condition for Severity equals High, then perform actions such as setting the owner to the senior analyst and running a playbook. The playbook, typically an Azure Logic App with a Microsoft Teams connector, can post an adaptive card message to a Teams channel. This combined approach correctly satisfies both requirements: automated ownership assignment and proactive notification, making it the right solution.
Your organization uses Microsoft Defender for Cloud Apps to monitor SaaS application usage. You need to generate an alert when a user performs more than 50 failed login attempts in 10 minutes, and the alert must be based on a built-in anomaly detection policy. What should you do?
Create a data loss prevention (DLP) policy in Microsoft Purview that triggers on failed logins.
Deploy a session policy in Defender for Cloud Apps that blocks after 50 failed logins.
Configure an app connector for each SaaS app and then create a custom activity policy.
Enable the 'Multiple failed login attempts' anomaly detection policy in Defender for Cloud Apps.
The 'Multiple failed login attempts' policy is a built-in anomaly detection policy in Defender for Cloud Apps that uses machine learning/UEBA to establish a per-user or per-tenant baseline and then flags abnormal spikes in failed sign-ins. Enabling this template automatically generates alerts when the anomaly is detected, and you can tune sensitivity and notification recipients. This is the correct, native way to meet the requirement without building custom activity rules or DLP policies.
You are a security analyst at a company that uses Microsoft 365 Defender. You receive an automated email indicating that a user has been flagged for possible credential theft. The email includes a link to investigate the alert in the Microsoft 365 Defender portal. Which role is responsible for sending this email?
A mail flow rule in Exchange Online configured to forward alerts.
Microsoft 365 Defender email notification settings.
Microsoft 365 Defender (formerly Microsoft Defender for Endpoint) provides built-in email notification settings under Incidents & alerts, allowing you to configure email alerts for new incidents or updated severity levels. These notifications are sent directly by the Defender platform itself, using its internal alert engine to trigger the email—no external workflow or additional licensing is required. This option correctly explains the source of the email in question because Defender has native, out-of-the-box alert notification capabilities that deliver standardized incident updates to specified recipients.
Microsoft Defender for Cloud Apps notification settings.
A Microsoft Sentinel analytics rule configured to send email notifications.
Your organization uses Microsoft Sentinel and Microsoft Defender for Office 365. You have configured incident creation from Microsoft Defender for Office 365 alerts in Microsoft Sentinel. However, you notice that some alerts are not creating incidents. Which step should you take to troubleshoot this issue?
Examine the analytics rule that creates incidents from Microsoft Defender for Office 365 alerts and verify the severity threshold.
The correct action is to examine the analytics rule that creates incidents from Microsoft Defender for Office 365 alerts, because Microsoft Sentinel does not automatically create incidents from every raw alert. Analytics rules use KQL queries to match incoming alerts and apply conditions, and if the rule's severity threshold (e.g., only Medium and higher) is too high, alerts with lower severity won't trigger an incident. Verifying the rule's query, alert grouping, and severity filter directly addresses the symptom of users receiving Microsoft 365 Defender alerts while Sentinel incidents are missing.
Check the Microsoft 365 Defender portal to confirm that the alerts are being generated.
Review the Microsoft Sentinel workbooks for any visualization errors.
Verify that the Microsoft Defender for Office 365 data connector in Microsoft Sentinel is connected and data is ingested.
Your SOC uses Microsoft Sentinel and Microsoft Defender for Identity (MDI). You have configured MDI to send alerts to Microsoft 365 Defender. From there, Microsoft Sentinel ingests the alerts via the Microsoft 365 Defender connector. You want to ensure that when MDI detects a suspicious activity, the incident in Microsoft Sentinel is created within 5 minutes. Which factors should you consider?
The latency is determined solely by the MDI sensor health and network speed.
The incident creation time is controlled by the Microsoft Defender for Cloud Apps connector.
The incident will be created within 5 minutes because MDI writes directly to Microsoft Sentinel.
The latency depends on the Microsoft 365 Defender connector's polling interval and the analytics rule's frequency.
The end-to-end latency for MDI incident creation in Microsoft Sentinel depends on two sequential factors: the Microsoft 365 Defender connector's polling interval, which determines how frequently alerts are fetched from the unified API, and the frequency of the analytics rule that converts those alerts into incidents. The connector typically polls every few minutes, but that interval is not instant, and the scheduled rule runs on its own cadence (e.g., every 5-15 minutes) based on the configured frequency. Therefore, the total delay is the sum of these intervals, not a fixed duration, and is the primary driver of when the incident appears.
Your organization is implementing Microsoft Sentinel. You need to design a solution to automatically disable a user account in Microsoft Entra ID when a high-severity incident is triggered in Microsoft Sentinel related to that user. Which component should you use?
A playbook that uses the Microsoft Graph API to disable the user.
A playbook triggered by the incident calls the Microsoft Graph API to disable the user account in Microsoft Entra ID. Graph exposes the account management operation, and Logic Apps provides the automation, satisfying the requirement to disable the user automatically on high-severity incidents.
An analytics rule that includes a query to disable the user.
An automation rule that runs a PowerShell script on a hybrid worker.
A workbook that triggers a webhook to disable the user.
Want more Manage a security operations environment practice?
Practice this domain37% of exam · 6 sample questions below
You are investigating a security incident in Microsoft Sentinel where a user received a phishing email containing a link to a malicious domain. The link was clicked, but no further actions were observed. Which playbook action should you take immediately to prevent potential lateral movement?
Disable the user's account
Revoke the user's active sessions
Reset the user's password
Block the malicious domain on the firewall
Blocking the malicious domain at the firewall is a network-based containment action that stops all clients from resolving or connecting to the malicious site, effectively breaking the delivery chain for phishing or malware. It is a reversible, low-impact measure that addresses the root cause regardless of which user or device attempts access, and it aligns with security operations best practice to contain the threat at the earliest opportunity.
During a ransomware incident, Microsoft Defender for Cloud Apps alerts indicate that a user is uploading large volumes of data to an external cloud storage provider not approved by your organization. Which two actions should you take first? (Choose two.)
Block the unapproved cloud storage app
Blocking the unapproved cloud storage app in Microsoft Defender for Cloud Apps immediately enforces a block policy that prevents any session or upload to that app, cutting off the attacker's exfiltration channel. This is a direct containment action that stops ransomware from spreading via file uploads to shadow IT services. By applying a session policy or app governance control, you terminate the active data movement without waiting for user awareness.
Suspend the user's account
Suspending the user's account (disabling it in Microsoft Entra ID) instantly revokes the user's tokens and access rights, preventing the compromised identity from using any Microsoft 365 or Defender-for-Cloud-Apps resources. This neutralizes the attacker's foothold and stops lateral movement or further file encryption. Account suspension is a core containment procedure that limits the blast radius before deeper investigation.
Notify the user about the policy violation
Initiate a legal hold on the user's data
Your security team uses Microsoft Sentinel analytics rules to detect brute-force attacks. A rule triggers when more than 10 failed logins occur within 5 minutes from a single IP. An incident is generated. Which first step should the analyst take?
Block the source IP address on the firewall
Investigate the incident details
Investigating the incident details is the correct first step because it provides the necessary context to determine the scope and severity of the threat. In Microsoft Sentinel, you open the incident to review the full timeline, related alerts, entities (accounts, hosts, IPs), and raw evidence gathered by the analytics rule. This investigation enables triage—confirming whether the failed logins indicate a brute-force attack, a password spray, or a false positive—and guides all subsequent containment and remediation decisions with data rather than assumptions.
Notify the users of the failed login attempts
Reset passwords for all affected accounts
An incident in Microsoft Defender XDR involves a device that is suspected to be infected with ransomware. The device is online and actively encrypting files. Which action should you take to contain the threat?
Isolate the device from the network
Device isolation in Microsoft Defender for Endpoint severs all external network connections while maintaining a secure channel to the MDE cloud so the security team can continue monitoring and issuing commands. This containment action immediately stops the attacker from using the compromised host to propagate over SMB, PsExec, or other protocols, and prevents ransomware from encrypting remote file shares. Isolation is reversible once forensic collection is complete, making it the correct first step in the incident response workflow.
Disable the user's account
Run a full antivirus scan on the device
Collect a memory dump from the device
Your organization uses Microsoft Sentinel with UEBA (User and Entity Behavior Analytics). An alert indicates a user's sign-in from an unusual location, followed by a mass download of sensitive files from SharePoint. The user is a low-privilege employee. What is the most likely conclusion?
The user's account is compromised
In Sentinel UEBA, this alert likely combines an impossible-travel event (source IP geolocation far from the user's normal base) with a mass-download anomaly such as copying hundreds of sensitive files from SharePoint Online or OneDrive within minutes. Because the location shift coincides with a sudden spike in data access that does not match the user's established behavioral baseline, the most probable scenario is an attacker using stolen credentials. UEBA also assigns a high risk score when the anomalous activity targets sensitive data categories, and the combination of geographic and volumetric deviations strongly indicates account compromise rather than benign behavior.
The alert is a false positive due to user travel
The user is an insider threat
The user is conducting a ransomware attack
In Microsoft Sentinel, an incident is created from a Fusion rule that correlates multiple alerts. The incident has a high severity. What should the analyst do first?
Run an automated playbook to contain the threat
Close the incident as false positive
Triage the incident by reviewing the evidence
Triage by reviewing the evidence is the mandatory first action for any Fusion-generated incident in Microsoft Sentinel, as it confirms whether the correlated alerts represent a genuine security threat and establishes the appropriate severity and priority. Analysts examine the incident's alerts, entities, and timeline to understand the attack chain and decide on next steps. This initial assessment ensures that subsequent actions—whether investigation, containment, or escalation—are based on accurate and complete information.
Escalate the incident to senior management
Want more Respond to security incidents practice?
Practice this domain22% of exam · 6 sample questions below
A security analyst is using KQL in Microsoft Sentinel to hunt for potential data exfiltration by a user who has been sending unusually large amounts of data to an external IP address. Which KQL operator should the analyst use to identify the top source IP addresses and total bytes sent over the last 7 days?
... | where SentBytes > 1000000 | project SourceIP, SentBytes
... | extend TotalBytes=SentBytes | summarize count() by SourceIP
... | project SourceIP, SentBytes | sort by SentBytes desc
... | summarize TotalBytes=sum(SentBytes) by SourceIP | top 10 by TotalBytes desc
This is the correct approach because the summarize operator groups all events by SourceIP and calculates TotalBytes as the sum of SentBytes for each group, converting row-level byte counts into a single aggregate metric per unique IP address. The subsequent top 10 by TotalBytes desc operator then sorts those aggregated results in descending order and returns only the first ten rows, which are the ten source IPs with the highest total outbound byte volume. Using 'top' after 'summarize' is also more efficient than 'sort' followed by 'take' because Kusto can discard non-top records during execution. This pipeline precisely satisfies the goal of identifying the top source IPs by total bytes sent and is the only option that combines both grouping and aggregation with a limiting operation.
A threat hunter is using Microsoft Defender for Endpoint advanced hunting to investigate a suspicious process that was observed launching from a temporary folder. The hunter wants to find all devices that have executed this specific process (with the same SHA256 hash) in the last 24 hours. Which table and column should be used in the query?
DeviceNetworkEvents table, SHA256 column
DeviceEvents table, SHA256 column
DeviceProcessEvents table, SHA256 column
DeviceProcessEvents records process creation events and exposes the SHA256 column, letting the hunter filter executions by the exact file hash observed. This satisfies the 24-hour scope via Timestamp filtering, returning every device that ran that specific binary regardless of filename or path.
DeviceFileEvents table, SHA256 column
A security team uses Microsoft Sentinel to hunt for signs of credential theft. They want to detect when a user account has been used to log in from an unusual location and then immediately performs a password reset for another user. Which hunting approach is most effective for this scenario?
Use a Microsoft Sentinel playbook to automatically flag any password reset
Write a KQL query that joins SigninLogs with AuditLogs on user principal name and times within a short window
Joining SigninLogs and AuditLogs on user principal name, constrained to a short time window, correlates an anomalous sign-in with a subsequent password reset. This temporal correlation across both tables surfaces the credential-theft sequence, which neither log alone reveals.
Search the SigninLogs table for logins from unusual locations
Create a watchlist of known unusual locations and use it in a query against AuditLogs
A threat hunter is investigating a potential malware outbreak in Microsoft Defender for Cloud Apps. The hunter notices that multiple users have installed a new app with high permissions that accesses their email. The app was not requested by IT. What is the most effective way to hunt for all instances of this app across the organization?
Review Conditional Access app control policies for any block rules
Check Microsoft 365 Defender alerts for malicious OAuth apps
Query the Microsoft 365 Defender advanced hunting table 'CloudAppEvents' for app installation events and then use 'AppGovernance' to list all apps
Use the Cloud App Security activity log to search for 'Install app' events and then review the 'App governance' dashboard for all instances
In Microsoft Defender for Cloud Apps, the activity log is the authoritative source for operational events, and filtering for the activity type 'Install app' directly surfaces when an OAuth app was introduced to the tenant. After identifying these installation events, the App governance dashboard provides a unified inventory of all app instances, including permissions, publisher, and usage, enabling the hunter to scope the outbreak. This sequence—find the installation event, then pivot to the governance inventory—matches the intended workflow for OAuth app threat hunting.
A threat hunter is using Microsoft Sentinel and Microsoft Defender XDR to hunt for a potential cross-domain attack where an attacker compromised an on-premises server and then used a privileged account to sign into Microsoft 365 from a new IP. The hunter wants to identify the server using a query that combines Windows Event Logs from the server with Microsoft 365 sign-in logs. Which approach should the hunter take to correlate the data?
Create a Sentinel watchlist of known attacker IPs and compare with server logs
Enable Sysmon on the server and use its Event ID 3 (network connection) to find the IP
Ingest Windows Security Event logs (Event ID 4624) from the server into a Log Analytics workspace, and join with SigninLogs on account name and timestamp
Ingesting Windows Security Event ID 4624 into a Log Analytics workspace lets the hunter join those sign-in events with SigninLogs on account name and timestamp, correlating the on-premises server compromise with the Microsoft 365 sign-in from the new IP.
Use the DeviceLogonEvents table in Microsoft Defender XDR advanced hunting
A threat hunter wants to proactively search for signs of ransomware activity in the environment using Microsoft Sentinel. Which data source is most likely to provide early indicators of ransomware, such as mass file renaming or encryption?
Microsoft Entra ID sign-in logs
Microsoft Defender for Endpoint advanced hunting tables like DeviceFileEvents and DeviceProcessEvents
DeviceFileEvents records file creation, renaming and modification, exposing the mass rename and encryption patterns ransomware produces. DeviceProcessEvents supplies the spawning processes behind that activity, giving hunters early endpoint-level indicators rather than relying on network or email telemetry.
Azure Activity Log
Office 365 audit logs (UnifiedAuditLog)
Want more Perform threat hunting practice?
Practice this domainThe SC-200 exam has 50 questions and must be completed in 120 minutes. The passing score is 700/1000.
Security operations scenario questions covering Microsoft Sentinel, Defender XDR, Defender for Cloud, and incident investigation and response.
The exam covers 3 domains: Manage a security operations environment, Respond to security incidents, Perform threat hunting. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Microsoft SC-200 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.