SC-200 Respond to security incidents • Set 12
SC-200 Respond to security incidents Practice Test 12 — 15 questions with explanations. Free, no signup.
A SOC analyst is investigating an incident where a user's credentials were compromised. The analyst uses Microsoft Sentinel to find all activities performed by the user in the last 24 hours. Which data source should the analyst query FIRST to get the most comprehensive view of the user's actions across Microsoft 365?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.