SC-200 Respond to security incidents • Set 11
SC-200 Respond to security incidents Practice Test 11 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Sentinel with UEBA (User and Entity Behavior Analytics). An alert indicates a user's sign-in from an unusual location, followed by a mass download of sensitive files from SharePoint. The user is a low-privilege employee. What is the most likely conclusion?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.