SC-200 Manage a security operations environment • Set 20
SC-200 Manage a security operations environment Practice Test 20 — 15 questions with explanations. Free, no signup.
Your SOC uses Microsoft Sentinel and Microsoft Defender XDR. An incident is generated from a Microsoft Defender for Identity alert about a suspicious Kerberos ticket request. The incident is assigned the 'Medium' severity. You want to automatically increase the severity to 'High' if the user is in a privileged role, based on data from Microsoft Entra ID. What is the most efficient way to achieve this?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.