SC-200 Manage a security operations environment • Set 4
SC-200 Manage a security operations environment Practice Test 4 — 15 questions with explanations. Free, no signup.
Your security operations center uses Microsoft Sentinel and Microsoft Defender XDR. A new type of attack involves a user receiving a malicious email that triggers a macro, which then executes PowerShell to download a payload. You need to create a detection that correlates email, process creation, and network connection events from multiple Microsoft 365 Defender sources. What should you use?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.