Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 1–75

1303 questions total · 18pages · All types, answers revealed

Page 1 of 18

Page 2
1
MCQeasy

Your organization uses Microsoft Defender XDR. You receive an alert about a potentially unwanted application (PUA) being installed on a device. The PUA is not blocked by your current policy. You need to prevent future installations of this PUA without affecting other software. What should you do?

A.Enable blocking of all potentially unwanted applications in the antivirus policy.
B.Reset the device to its factory settings.
C.Create a custom indicator of compromise (IoC) to block the specific file's hash.
D.Run a full scan on the device to remove the PUA.
AnswerC

Creating a custom indicator of compromise (IoC) for the specific file hash, with the action set to Block and remediate, is the precise and recommended response. This indicator is propagated to all devices through Microsoft Defender XDR, preventing the file from executing and automatically triggering remediation of existing copies on any onboarded endpoint. Because the block is scoped solely to that file hash, legitimate applications are preserved, avoiding false positives, and the defense persists for future attempts to execute or download the file.

Why this answer

Creating a custom indicator of compromise (IoC) with the specific file hash allows you to block only that exact PUA file without affecting other software. This leverages Microsoft Defender for Endpoint's custom IoC capability to override the default PUA detection policy, targeting the specific file hash rather than enabling a broad block on all PUAs.

Exam trap

The trap here is that candidates may choose Option A, thinking that enabling PUA blocking is the simplest solution, but they overlook the requirement to avoid affecting other software, which makes the broad policy change inappropriate.

How to eliminate wrong answers

Option A is wrong because enabling blocking of all potentially unwanted applications would affect other software that may be legitimate or needed, violating the requirement to not affect other software. Option B is wrong because resetting the device to factory settings is an extreme, disruptive action that does not prevent future installations of the PUA and is not a targeted solution. Option D is wrong because running a full scan removes the existing PUA but does not prevent future installations of the same file.

2
Multi-Selecteasy

Which TWO built-in Microsoft Sentinel hunting queries are useful for detecting signs of compromised credentials?

Select 2 answers
A.Baseline of user behavior
B.Anomalous logon location
C.Brute force attempt against user accounts
D.Deleted user account
E.New user account creation
AnswersB, C

Anomalous logon location is one of the built-in hunting queries in Microsoft Sentinel, found in the Hunting blade. It uses KQL to analyze sign-in logs, detecting attempts from unexpected geographies or IP addresses, which may indicate compromised credentials or impossible travel. This query is part of Sentinel's predefined hunting pack and is a strong indicator of credential misuse.

Why this answer

Option B, 'Anomalous logon location,' is correct because it flags authentication events where a user signs in from an unusual or unexpected geographic location, which is a classic indicator that credentials have been stolen and are being used by an attacker from a different region. Option C, 'Brute force attempt against user accounts,' is correct because it detects repeated failed authentication attempts followed by a success, directly surfacing password-guessing activity that results in compromised credentials. Option A, 'Baseline of user behavior,' is a general behavioral analytics query that establishes normal activity patterns rather than specifically detecting credential compromise.

Option D, 'Deleted user account,' relates to account lifecycle or destructive actions, not credential theft. Option E, 'New user account creation,' indicates persistence or privilege escalation via a newly created account, not the compromise of existing credentials.

Exam trap

SC-200 often tests whether candidates confuse persistence-related queries (new/deleted accounts) with credential compromise indicators (anomalous logon, brute force), so knowing the exact built-in query names and their purpose is essential.

3
MCQeasy

Your SOC team uses Microsoft Sentinel incident investigation. An analyst needs to quickly see all related entities (users, IPs, machines) for an incident. Which feature should the analyst use?

A.Incident timeline
B.Hunting blade
C.Entity behavior analytics page
D.Incident investigation graph
AnswerD

The Incident investigation graph is the correct choice because it presents an interactive, visual map of all entities (e.g., IPs, hosts, accounts, and files) related to the incident, along with the edges representing their relationships. This graph helps you quickly identify potential attack vectors and pivot between connected entities to understand the full scope of the incident, fulfilling the SOC team's requirement to see all related entities in one view.

Why this answer

The Incident investigation graph in Microsoft Sentinel provides a visual, interactive map of all entities (users, IPs, machines) linked to an incident, allowing analysts to quickly see relationships and pivot between entities. This is the dedicated feature for entity-centric incident exploration, unlike other options that serve different purposes.

Exam trap

Microsoft often tests the distinction between a chronological timeline (incident timeline) and a relational graph (investigation graph), leading candidates to confuse the incident timeline's alert sequence with the entity relationship view.

How to eliminate wrong answers

Option A is wrong because the Incident timeline shows a chronological list of alerts and activities within an incident, not a visual graph of related entities. Option B is wrong because the Hunting blade is used for proactive threat hunting with KQL queries, not for viewing entities tied to an existing incident. Option C is wrong because the Entity behavior analytics page provides behavioral insights and anomalies for a single entity over time, not a consolidated view of all entities related to an incident.

4
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to create a hunting query that finds users who have accessed a high number of distinct Azure resources within a short time frame, which may indicate credential theft. Which KQL query would be most effective?

A.AzureActivity | summarize dcount(Resource) by bin(TimeGenerated, 1m), Caller
B.AzureActivity | summarize count() by Caller | where count_ > 20
C.AzureActivity | summarize dcount(OperationName) by Caller, bin(TimeGenerated, 1h) | where dcount_OperationName > 20
D.AzureActivity | where TimeGenerated > ago(1d) | summarize dcount(Resource) by Caller, bin(TimeGenerated, 1h) | where dcount_Resource > 20
AnswerD

This query correctly isolates the last 24 hours of activity, groups events by each caller (user or service principal) and by one-hour time bins, and then computes the distinct count of Resource values—the full Azure resource IDs—for each group. The filter dcount_Resource > 20 surfaces users that accessed an unusually high number of distinct Azure resources within a single hour, a pattern consistent with an attacker rapidly enumerating the environment to find high-value targets. This approach balances sensitivity and performance, and it directly maps to the MITRE ATT&CK technique T1087 (Account Discovery) or T1526 (Cloud Service Discovery) when run as a scheduled Sentinel analytics rule.

Why this answer

It uses the AzureActivity table to count distinct resources per user per hour, filtering for those with more than 20 resources. Option A is wrong because it uses a 1-minute bucket, too granular for meaningful hunting. Option B is wrong because it counts operations, not distinct resources.

Option C is wrong because it counts distinct operation names, not resources.

5
MCQmedium

Refer to the exhibit. You are investigating a user account that shows multiple logons to the Azure Portal from various countries within a short time. The query returns no results despite known logons. What is the most likely issue?

A.The Timestamp filter should be Timestamp > ago(7d) but instead it's written incorrectly.
B.The AccountUpn field is not present in IdentityLogonEvents.
C.The Application filter should be 'Azure Portal' in a different case.
D.IdentityLogonEvents does not contain Azure Portal logon events; use AADSignInEventsBeta instead.
AnswerD

IdentityLogonEvents captures only on-premises Active Directory and AD FS authentication, not cloud sign-ins. Azure Portal logons are recorded in Microsoft Entra ID sign-in logs, surfaced in Microsoft Defender for Cloud Apps through the AADSignInEventsBeta table. Querying the wrong table explains the empty result despite known portal logons.

Why this answer

IdentityLogonEvents in Microsoft Defender for Identity (MDI) captures on-premises Active Directory authentication events, not Azure AD (Entra ID) sign-in events. Azure Portal logons are Azure AD sign-in events, which are stored in the AADSignInEventsBeta table in Microsoft 365 Defender advanced hunting. Therefore, querying IdentityLogonEvents for Azure Portal logons returns no results, and the correct table is AADSignInEventsBeta.

Exam trap

SC-200 often tests the distinction between on-premises identity tables (IdentityLogonEvents) and cloud identity tables (AADSignInEventsBeta), so candidates who assume all logon events are in one table pick the wrong filter or field.

How to eliminate wrong answers

Option A is wrong because the Timestamp filter syntax 'ago(7d)' is valid in Kusto Query Language; the issue is not the time filter but the wrong table. Option B is wrong because AccountUpn is a valid field in IdentityLogonEvents; the field exists, but the table does not contain Azure Portal logon events. Option C is wrong because Kusto string comparisons are case-sensitive by default, but the Application field in IdentityLogonEvents does not capture Azure Portal logons at all, so changing case would not help.

6
MCQeasy

During a security incident response, you need to collect forensic evidence from a Windows 10 device that is suspected to be compromised. The device is not domain-joined and is located in a remote office. You have remote administrative access. Which Microsoft 365 tool should you use to acquire a memory dump of the device?

A.Microsoft Sentinel
B.Microsoft Purview eDiscovery
C.Microsoft Intune
D.Microsoft Defender for Endpoint
AnswerD

Microsoft Defender for Endpoint's live response feature provides a remote shell to the non-domain-joined Windows 10 device, where the memory dump can be captured using its built-in commands. This satisfies the remote acquisition constraint without physical access or domain membership.

Why this answer

Microsoft Defender for Endpoint includes live response and the ability to collect forensic artifacts, including memory dumps, from onboarded devices. It supports remote acquisition from non-domain-joined Windows 10 devices as long as they are onboarded and you have the appropriate permissions. Sentinel, Purview eDiscovery, and Intune do not provide memory dump acquisition.

Exam trap

The trap is confusing forensic acquisition with management or eDiscovery tools—candidates pick Intune or Purview because they sound like they handle devices or data, but only Defender for Endpoint provides live response memory capture.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a SIEM/SOAR platform for detection and investigation, not a forensic acquisition tool for memory dumps. Option B is wrong because Microsoft Purview eDiscovery is for identifying, collecting, and reviewing electronically stored information for legal cases, not for acquiring volatile memory. Option C is wrong because Microsoft Intune is for device management and configuration, not forensic memory capture.

7
MCQmedium

You are responding to a ransomware incident in Microsoft Defender XDR. You have identified that the malware encrypted files on several devices and then deleted the volume shadow copies. Which of the following actions should you take first to contain the incident?

A.Run a remediation action to delete the detected malware
B.Restore encrypted files from backup
C.Run a full antivirus scan on all devices
D.Isolate affected devices using Microsoft Defender for Endpoint
AnswerD

Isolating affected devices using Microsoft Defender for Endpoint is the correct first step because it immediately blocks all incoming and outgoing communication to and from the compromised host, cutting off the ransomware's ability to spread laterally and communicate with command-and-control servers. This action preserves forensic evidence while containing the attack, and it can be initiated remotely from the MDE console without requiring physical access or disrupting the rest of the network. Full isolation still allows the Defender service to communicate, so security teams can continue to investigate and remediate the endpoint.

Why this answer

Isolating affected devices using Microsoft Defender for Endpoint is the correct first action because it immediately cuts off network communication, preventing the ransomware from spreading laterally to other devices and stopping further encryption or deletion of shadow copies. Containment must precede remediation to limit the blast radius, and Defender for Endpoint's device isolation feature achieves this at the network level without requiring physical disconnection.

Exam trap

The trap here is that candidates often confuse containment with remediation, choosing to delete malware or run scans first, but the SC-200 exam emphasizes that immediate isolation is the priority to stop lateral spread before any cleanup or recovery actions.

How to eliminate wrong answers

Option A is wrong because running a remediation action to delete the detected malware does not contain the incident; it attempts to remove the threat after it has already encrypted files and deleted shadow copies, and without isolation the malware could still spread or re-infect. Option B is wrong because restoring encrypted files from backup is a recovery step that should only be performed after containment and eradication are complete; attempting restoration first risks re-encryption if the malware is still active on the network. Option C is wrong because running a full antivirus scan on all devices is a detection and remediation step, not a containment measure; it does not stop the ransomware from continuing to encrypt or spread during the scan.

8
Multi-Selectmedium

Which THREE are valid investigation actions in Microsoft Sentinel? (Select THREE.)

Select 3 answers
A.View related entities such as IP addresses.
B.Run a playbook.
C.View related incidents.
D.Modify an analytics rule.
E.View related alerts.
AnswersA, C, E

Viewing related entities such as IP addresses is a core Sentinel investigation action, letting analysts pivot from an incident to the associated hosts, accounts and addresses on the entity graph. This satisfies the stem's requirement for valid investigation actions, since entity exploration is built into the incident investigation experience.

Why this answer

Viewing related entities such as IP addresses is a fundamental investigation action in Microsoft Sentinel. Option C is correct because viewing related incidents helps in correlating events. Option E is correct because viewing related alerts provides context.

Option B is incorrect because running a playbook is a remediation action, not an investigation action. Option D is incorrect because modifying an analytics rule is a configuration task outside the investigation scope.

9
Multi-Selecteasy

Which THREE actions are recommended when conducting a threat hunt for compromised identities using Microsoft Sentinel UEBA?

Select 3 answers
A.Search for access to applications the user does not normally use
B.Query DNS logs for unusual domain resolutions
C.Look for multiple failed logon attempts followed by a successful one
D.Investigate changes to firewall rules
E.Review UEBA anomalies for unusual logon times or locations
AnswersA, C, E

Checking for access to applications outside a user's historical usage is a high-fidelity indicator of identity compromise because attackers rarely mimic the exact application footprint of the legitimate user. In Microsoft Sentinel, you can use UEBA data or sign-in logs to build a baseline and then alert when a newly logged-on application has no prior events for that user. This type of anomaly is less likely to be a false positive than raw volume-based signals, because it directly reflects the attacker's post-authentication intent.

Why this answer

Option A is correct because Microsoft Sentinel UEBA baselines each user's normal application usage, so access to applications the user does not normally use is a high-signal anomaly indicating possible credential compromise or token theft. Option C is correct because a burst of failed logon attempts followed by a successful one is the classic pattern of a brute-force or password-spray attack that ends in a valid session, and UEBA surfaces this as an anomalous sign-in sequence. Option E is correct because UEBA specifically models per-user behavioral baselines for logon times and locations, so deviations such as impossible travel or off-hours sign-ins are core indicators of a compromised identity.

Option B does not belong because DNS log analysis targets command-and-control or malware beaconing rather than identity compromise, and it is not a UEBA identity-focused action. Option D does not belong because firewall rule changes are a network/infrastructure configuration concern, not an identity behavior anomaly tracked by UEBA.

Exam trap

SC-200 often tests the scope of UEBA — candidates pick network-layer or configuration hunts (DNS logs, firewall rules) that sound like threat hunting but are not identity-focused UEBA actions.

10
MCQeasy

Refer to the exhibit. You are running a PowerShell script to enable the Anomalies setting in Microsoft Sentinel. After running the script, you check the Sentinel settings in the portal and see that Anomalies is still disabled. What is the most likely reason?

A.The cmdlet 'Set-AzSentinelSetting' does not exist in the Az module.
B.The user does not have Contributor permissions on the workspace.
C.The script requires the -PassThru parameter to apply changes.
D.The workspace was not retrieved correctly because the name is misspelled.
AnswerA

The non-existence of 'Set-AzSentinelSetting' in the Az module directly explains why the Anomalies setting remains disabled. PowerShell scripts fail when attempting to invoke cmdlets that are not recognised or do not exist within the loaded modules. This scenario indicates the script encountered an execution error because the specified cmdlet for modifying Sentinel settings was not found, preventing the intended configuration change from being applied.

Why this answer

The cmdlet 'Set-AzSentinelSetting' does not exist in the official Az.SecurityInsights module. Microsoft Sentinel settings, including Anomalies, are managed via the REST API or the 'Update-AzSentinelSetting' cmdlet (part of the Az.SecurityInsights preview module). Running a non-existent cmdlet would produce an error, not apply any changes, leaving Anomalies disabled in the portal.

Exam trap

The trap here is that candidates assume all Azure PowerShell cmdlets follow the 'Set-*' naming convention, but Microsoft Sentinel settings specifically use 'Update-*' in the Az.SecurityInsights module, leading to the mistaken belief that 'Set-AzSentinelSetting' is valid.

How to eliminate wrong answers

Option B is wrong because Contributor permissions on the workspace are sufficient to modify Sentinel settings; the issue is the cmdlet itself, not permissions. Option C is wrong because the -PassThru parameter is used to output the result object but is not required for the change to apply; its absence does not prevent the setting from being saved. Option D is wrong because even if the workspace name were misspelled, the script would fail with a 'workspace not found' error, not silently leave Anomalies disabled; the question states the script ran, implying no retrieval error.

11
Multi-Selecthard

Which THREE actions are part of the threat hunting process in Microsoft Defender XDR?

Select 3 answers
A.Configure automated response actions
B.Investigate entities found in the results
C.Query advanced hunting using KQL
D.Formulate a hypothesis based on threat intelligence
E.Set data retention policies for hunting data
AnswersB, C, D

Investigating entities found in the query results is a defining threat-hunting action because it requires pivoting from raw data to the entity pages for users, devices, files, IPs, or mailboxes, then reviewing timelines, related alerts, and correlated events to decide whether the behavior is genuinely malicious. This validation step is what confirms or refutes the original hypothesis and reveals the scope of the threat. Without entity-level investigation, a hunter cannot distinguish a true positive from a benign anomaly or a false positive.

Why this answer

Threat hunting in Microsoft Defender XDR follows a hypothesis-driven, iterative process, and option D ("Formulate a hypothesis based on threat intelligence") is correct because a hunt begins by defining a specific, testable hypothesis derived from threat intel, known TTPs, or an anomaly to guide the search. Option C ("Query advanced hunting using KQL") is correct because the hypothesis is tested by running KQL queries in Advanced Hunting against tables such as DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents to surface matching telemetry. Option B ("Investigate entities found in the results") is correct because any suspicious processes, devices, IPs, or accounts returned by the query are then pivoted on and investigated (e.g., via the entity page, timeline, and incident correlation) to confirm or refute the hypothesis.

Option A ("Configure automated response actions") is not part of hunting itself; automated response is configured through automated investigation and response (AIR) and custom detection/action settings, which are remediation, not hunting. Option E ("Set data retention policies for hunting data") is not part of the hunting process; retention is governed by tenant/Advanced Hunting data retention settings and is an administrative configuration rather than a hunting step.

Exam trap

SC-200 often tests whether candidates conflate threat hunting with incident response or data governance — the trap is selecting 'configure automated response actions' because it sounds like part of the security workflow.

12
MCQhard

Your organization uses Microsoft Sentinel with UEBA enabled. You need to identify anomalous user behavior that indicates a potential compromise. Which entity behavior analytics feature should you use?

A.Automation rules
B.Hunting queries
C.Entity behavior analytics peer comparison
D.Anomaly rules in analytics
AnswerC

Entity behavior analytics in Microsoft Sentinel uses UEBA to build a historical behavioral profile for each user, host, or other entity, including attributes like sign-in times, accessed apps, and resource usage. It then performs peer comparison by grouping entities with similar roles or attributes and statistically identifies when an individual's current behavior deviates from the group's baseline, such as an unusual location or impossible travel. This automated, baseline-driven peer comparison is precisely how UEBA detects anomalies, making it the correct answer.

Why this answer

Entity behavior analytics peer comparison (option C) is the correct feature because it uses UEBA to compare a user's activities against their historical baseline and peer group behavior to detect anomalies indicative of compromise. This directly addresses the requirement to identify anomalous user behavior, as peer comparison highlights deviations like unusual access patterns or data exfiltration attempts that single-entity baselines might miss.

Exam trap

The trap here is that candidates often confuse anomaly rules in analytics (option D) with UEBA peer comparison, but anomaly rules are generic detection mechanisms that do not inherently use peer-group baselines, whereas peer comparison is a dedicated UEBA capability for entity-specific anomaly detection.

How to eliminate wrong answers

Option A is wrong because automation rules are used to automate incident response actions (e.g., assigning tasks or triggering playbooks) based on alerts, not to analyze entity behavior for anomalies. Option B is wrong because hunting queries are proactive KQL-based searches for threats across log data, not a built-in UEBA feature that continuously compares entity behavior against peers. Option D is wrong because anomaly rules in analytics are scheduled or near-real-time detection rules that flag anomalies based on static thresholds or machine learning models, but they do not specifically leverage peer comparison for entity behavior analytics.

13
MCQeasy

An analyst in your SOC receives a Microsoft Defender for Cloud Apps alert indicating a suspicious Power Automate flow that is forwarding emails to an external domain. The analyst needs to disable the flow immediately. Which action should they take?

A.Block the external domain in Exchange Online mail flow rules
B.Remove the flow from the Microsoft 365 admin center
C.Disable the user account in Microsoft Entra ID
D.Use the governance action in Microsoft Defender for Cloud Apps to disable the flow
AnswerD

Microsoft Defender for Cloud Apps governance actions apply remediation directly to connected apps, letting the analyst disable the offending Power Automate flow from within the alert. This stops the exfiltration immediately without leaving the portal, matching the requirement to disable the flow at once.

Why this answer

Microsoft Defender for Cloud Apps (MDCA) provides governance actions directly on discovered app activities, including the ability to disable a Power Automate flow from within the alert. This is the fastest, most targeted remediation because it acts on the specific flow rather than broader controls.

Exam trap

SC-200 often tests whether candidates choose the most targeted remediation action available in the alerting tool rather than broader, slower controls like blocking domains or disabling accounts.

How to eliminate wrong answers

Option A is wrong because blocking the external domain in Exchange mail flow rules only stops delivery to that domain — the malicious flow remains active and could target other domains or exfiltrate via other channels. Option B is wrong because removing the flow from the Microsoft 365 admin center is a manual, slower process and may not be available or practical during an active incident. Option C is wrong because disabling the user account is overly broad, disrupts legitimate user activity, and does not immediately stop the flow if it runs under a service principal or continues executing.

14
MCQeasy

A SOC analyst is triaging an incident in Microsoft Sentinel and needs to assign it to a senior analyst for further investigation. What is the correct action?

A.Create a new incident and manually add the senior analyst as a comment.
B.Open the incident and change the Owner field to the senior analyst.
C.Close the incident and reopen it under the senior analyst's name.
D.Run a playbook that sends an email to the senior analyst.
AnswerB

In Microsoft Sentinel, incident ownership is controlled by the Owner field in the incident details pane; setting it to the senior analyst formally assigns the incident to them, making it appear in their 'My incidents' view and routing any notifications according to the workspace's settings. Updating the owner preserves the incident's original ID, entity links, evidence, and full audit history, which is critical for accurate incident response documentation. This action is the recommended way to escalate an incident for additional review.

Why this answer

In Microsoft Sentinel, the correct way to assign an incident to a specific analyst is to open the incident and change the Owner field to that analyst. This action formally transfers ownership and responsibility for the incident within the SIEM, ensuring proper tracking and accountability. Other methods, such as adding comments or sending emails, do not update the incident's ownership metadata.

Exam trap

The trap here is that candidates might confuse external notification (email) or informal tagging (comments) with the formal ownership change required by Sentinel's incident management model, leading them to choose options that do not actually reassign the incident.

How to eliminate wrong answers

Option A is wrong because adding a comment does not change the incident's owner; it only adds an annotation, leaving the incident unassigned or assigned to the original owner. Option C is wrong because closing an incident marks it as resolved, and reopening it under a different name does not properly reassign ownership—it creates confusion in the incident lifecycle. Option D is wrong because running a playbook to send an email is an external notification, not a Sentinel-native assignment action; it does not update the Owner field or any other incident property.

15
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that all incidents from Microsoft Defender XDR are synchronized to Microsoft Sentinel with the same status (e.g., 'Active', 'Resolved'). What should you configure?

A.Create a custom playbook to poll Defender XDR API and update Sentinel incidents.
B.Connect Microsoft Defender XDR to Microsoft Sentinel using the official data connector.
C.Manually update status in both systems.
D.Disable the Microsoft Defender XDR connector and use separate connectors for each workload.
AnswerB

Ingesting Microsoft Defender XDR incidents through its official data connector is the supported first-party integration path and the only method that provides bi-directional synchronization natively. After you enable the connector, incidents created in Defender XDR appear in Sentinel and any analyst status update—such as resolved or closed—is written back to Defender XDR, and vice versa, through an automated sync mechanism. This approach preserves the full incident context and correlation across Defender workloads instead of just importing raw alerts.

Why this answer

The official Microsoft Defender XDR data connector in Microsoft Sentinel automatically synchronizes incidents, including their status (e.g., 'Active', 'Resolved'), bidirectionally. This ensures that any status change in either system is reflected in the other without manual intervention or custom scripting. Option B is correct because it leverages the built-in integration that handles the synchronization natively.

Exam trap

The trap here is that candidates may think a custom playbook or API polling is required for synchronization, not realizing that the official connector already handles bidirectional status updates natively.

How to eliminate wrong answers

Option A is wrong because creating a custom playbook to poll the Defender XDR API is unnecessary and introduces complexity, latency, and potential for errors; the official connector already provides real-time bidirectional synchronization. Option C is wrong because manually updating status in both systems is inefficient, error-prone, and defeats the purpose of automated security operations; it does not scale and violates the principle of a single pane of glass. Option D is wrong because disabling the Microsoft Defender XDR connector and using separate connectors for each workload would break the unified incident correlation and status synchronization that the single connector provides, leading to fragmented incident management.

16
MCQeasy

A security analyst in Microsoft Sentinel receives an incident with a high severity alert from Microsoft Defender for Identity. The incident description mentions a suspected lateral movement pass-the-hash attack. What should the analyst do first?

A.Reset the password of the compromised account.
B.Review the Microsoft Defender for Cloud Apps logs.
C.Isolate the affected device from the network.
D.Create a new analytics rule to detect pass-the-hash attacks.
AnswerC

Isolating the affected device from the network breaks the attacker's ability to use the compromised host to authenticate to other systems via pass-the-hash, effectively containing the lateral movement at the source. This is an immediate containment action that limits the blast radius while preserving process memory and network evidence for forensic analysis. In Microsoft Defender for Endpoint, 'Isolate device' blocks all inbound/outbound traffic except to the Defender service.

Why this answer

The immediate priority in a suspected lateral movement pass-the-hash attack is to contain the threat by isolating the affected device from the network. This prevents the attacker from using the compromised account's NTLM hash to authenticate to other systems, stopping the lateral spread while preserving forensic evidence for further investigation.

Exam trap

The trap here is that candidates often choose password reset (Option A) thinking it immediately revokes access, but they overlook that the cached NTLM hash on the compromised device remains usable for lateral movement until the device is isolated or the hash is cleared.

How to eliminate wrong answers

Option A is wrong because resetting the password of the compromised account does not invalidate the cached NTLM hash already present on the affected device; the attacker can still use that hash for lateral movement until the device is isolated. Option B is wrong because Microsoft Defender for Cloud Apps logs focus on cloud application activity, not on-premises lateral movement techniques like pass-the-hash, which occur at the network authentication level. Option D is wrong because creating a new analytics rule is a proactive detection measure that takes time to deploy and does not address the immediate containment need; the analyst must first stop the active attack.

17
MCQhard

Your SOC uses Microsoft Sentinel and Microsoft Defender XDR. An incident is created from a Defender for Endpoint alert about a malware detection on a device. The incident has low priority, but you want to automatically isolate the device from the network if the alert is confirmed as a true positive by the SOC. What is the recommended approach?

A.Create a separate analytics rule that triggers on the same alert and uses a playbook to isolate the device.
B.Use automatic attack disruption in Microsoft Defender XDR to isolate the device automatically.
C.Configure an automated response in Defender for Endpoint to isolate the device immediately when an alert is generated.
D.Create an automation rule in Microsoft Sentinel that triggers a playbook with an approval step before executing device isolation.
AnswerD

An automation rule in Microsoft Sentinel runs when an incident is created or updated and can trigger a playbook that includes an approval action—for example, a Microsoft Teams adaptive card or Outlook email requiring a SOC analyst to click Approve. Only after that approval is received does the Logic App continue to the Defender for Endpoint device-isolation step, ensuring a human has actively confirmed the containment decision. This approach also records every action in the playbook's run history and complies with the SOC's requirement to confirm before isolating.

Why this answer

It aligns with the recommended SOC workflow: an automation rule in Microsoft Sentinel triggers a playbook that includes an approval step, ensuring that device isolation only occurs after the SOC confirms the alert as a true positive. This approach maintains human oversight for low-priority incidents while leveraging automation for the response action.

Exam trap

The trap here is that candidates often confuse automated response capabilities (like immediate isolation in Defender for Endpoint) with the need for human approval in a SOC workflow, leading them to choose Option C without considering the 'confirmed as a true positive' requirement.

How to eliminate wrong answers

Option A is wrong because creating a separate analytics rule that triggers on the same alert would duplicate incident generation and bypass the existing incident's lifecycle, leading to unnecessary noise and potential race conditions. Option B is wrong because automatic attack disruption in Microsoft Defender XDR is designed for high-confidence, automated containment of active attacks, not for low-priority alerts that require SOC confirmation before isolation. Option C is wrong because configuring an automated response in Defender for Endpoint to isolate the device immediately would execute without any SOC validation, which contradicts the requirement to isolate only after confirmation of a true positive.

18
MCQmedium

You are a SOC analyst using Microsoft Defender for Endpoint. A device is flagged as compromised and you need to isolate it from the network while still allowing you to remotely investigate it. Which action should you take?

A.Restrict app execution on the device.
B.Collect an investigation package from the device.
C.Run a full antivirus scan on the device.
D.Isolate the device using the 'Isolate device' action.
AnswerD

The 'Isolate device' action in Microsoft Defender for Endpoint disconnects the device from the network except for the Defender for Endpoint service, allowing you to remotely investigate and remediate. This meets the requirement of isolating the device while maintaining a management channel. It is the correct containment action for a compromised device.

Why this answer

Microsoft Defender for Endpoint's 'Isolate device' action provides network containment by blocking all network traffic except for the Defender for Endpoint cloud service. This allows analysts to remotely connect to the device, run investigations, and remediate threats without the attacker being able to communicate externally or move laterally. It is the standard response for a compromised device.

Exam trap

The trap here is thinking that antivirus scans or app restrictions provide isolation; they do not block network communication.

19
MCQmedium

Your security team receives frequent false positive alerts from Microsoft Defender for Cloud Apps. You need to reduce noise without disabling any threat detection policies. What should you do?

A.Disable the built-in anomaly detection policies that generate false positives.
B.Configure suppression rules based on user, IP, or app to automatically dismiss matching alerts.
C.Adjust the alert severity thresholds in the policy settings.
D.Create custom detection policies to override default rules.
AnswerB

Suppression rules are the correct approach because they operate at the alert-dismissal stage rather than the detection stage. In Microsoft Defender for Cloud Apps, you can define suppression based on entity attributes such as user, IP address, or app, so alerts that match the rule are automatically closed or hidden before they reach the analyst. This directly addresses false positives by removing known-benign patterns (e.g., a service account that legitimately performs anomalous-looking bulk downloads) while keeping the underlying policy active for genuinely suspicious activity. Crucially, this does not weaken detection coverage and is fully auditable, making it the recommended operational response to alert fatigue.

Why this answer

Suppression rules in Microsoft Defender for Cloud Apps allow you to automatically dismiss alerts that match specific criteria (e.g., user, IP address, or app) without disabling the underlying threat detection policy. This reduces false positive noise while keeping the detection engine active for genuine threats. Disabling policies or adjusting severity thresholds would either remove detection entirely or fail to address the root cause of false positives.

Exam trap

The trap here is that candidates often confuse 'suppression' with 'disabling' or 'tuning' policies, assuming that reducing noise requires altering detection logic or severity, rather than using the dedicated suppression feature that automatically dismisses matching alerts without affecting detection.

How to eliminate wrong answers

Option A is wrong because disabling built-in anomaly detection policies would remove threat detection capabilities entirely, contradicting the requirement to not disable any threat detection policies. Option C is wrong because adjusting alert severity thresholds only changes the classification of alerts (e.g., from high to medium) but does not suppress or dismiss them, so false positives would still appear in the console. Option D is wrong because creating custom detection policies adds new rules but does not reduce noise from existing default policies; it would not suppress false positives generated by the built-in policies.

20
MCQhard

A SOC manager wants to implement a new workflow where high-severity Microsoft Defender for Cloud Apps alerts are automatically sent to a Teams channel for immediate action. The solution must not require custom code. What should the manager configure?

A.Use Microsoft Power Automate to monitor the alerts and send a Teams message
B.Configure a rule in Microsoft Defender XDR to send email notifications
C.Create an automation rule in Microsoft Sentinel with a playbook that posts to Teams
D.Configure Microsoft Entra ID to send the alerts to Teams
AnswerC

The recommended approach is to ingest Defender for Cloud Apps alerts into Microsoft Sentinel using the Defender for Cloud Apps data connector, which normalizes the alerts as Sentinel incidents. Once ingested, a Sentinel automation rule can be created to run when an incident is generated, triggering an Azure Logic Apps-based playbook that posts a formatted message to a Microsoft Teams channel. This pipeline is fully integrated, leverages Sentinel's native threat intelligence and incident management, and can include enrichment steps before the Teams notification is sent.

Why this answer

Microsoft Sentinel's automation rules can trigger a playbook (built on Azure Logic Apps) when a high-severity alert is generated, and the playbook can post a message to a Teams channel without requiring custom code. This directly meets the requirement of automatically sending high-severity Microsoft Defender for Cloud Apps alerts to Teams for immediate action, leveraging built-in connectors.

Exam trap

The trap here is that candidates may confuse Microsoft Defender XDR's email notification rules with the ability to send Teams messages, or assume Power Automate is the correct low-code solution, but the question's requirement for no custom code and direct integration with Microsoft Defender for Cloud Apps alerts points specifically to Sentinel's automation rules with playbooks.

How to eliminate wrong answers

Option A is wrong because Microsoft Power Automate does not natively integrate with Microsoft Defender for Cloud Apps alerts to trigger on them directly; it would require custom connectors or workarounds, and the question explicitly states no custom code is allowed. Option B is wrong because configuring a rule in Microsoft Defender XDR to send email notifications only sends emails, not Teams messages, and does not meet the requirement of sending alerts to a Teams channel. Option D is wrong because Microsoft Entra ID (formerly Azure AD) is an identity and access management service and does not have the capability to send alerts from Microsoft Defender for Cloud Apps to Teams.

21
MCQmedium

You are a security analyst using Microsoft Sentinel. You want to proactively search for signs of a specific threat actor known to use PowerShell encoded commands. Which hunting technique is most appropriate?

A.Create an analytics rule to trigger an alert when PowerShell encoded commands are detected.
B.Create a watchlist of known malicious IPs and correlate with PowerShell events.
C.Enable UEBA to detect anomalous PowerShell usage.
D.Use a hunting query in the Microsoft Sentinel hunting blade to search for PowerShell encoded commands.
AnswerD

Hunting queries in the Microsoft Sentinel hunting blade let analysts proactively search logs for indicators such as PowerShell encoded commands, matching the requirement to seek out a known threat actor's techniques rather than wait for an alert.

Why this answer

Hunting queries in Microsoft Sentinel allow proactive searching for suspicious patterns. Option D is correct because it directly aligns with the need to create a custom KQL query to detect encoded PowerShell commands in the hunting blade. Option A is incorrect because analytics rules trigger alerts after detection, not for proactive hunting.

Option B is incorrect because a watchlist is used for correlation with known indicators, not proactive hunting. Option C is incorrect because UEBA identifies anomalies, not specific threat actor techniques.

22
MCQmedium

A Microsoft Defender for Endpoint alert indicates that a device has been communicating with a known command-and-control (C2) server. The device is critical for production. What is the most appropriate response?

A.Disconnect the network cable of the device.
B.Run a full antivirus scan on the device.
C.Block the C2 server URL in the firewall.
D.Isolate the device using Microsoft Defender for Endpoint's device isolation feature.
AnswerD

Isolating the device with Microsoft Defender for Endpoint's device isolation feature is the correct initial response because it severs all inbound and outbound communication except to the Defender service, immediately containing the threat while keeping the device powered on. When forensic preservation mode is enabled, the device remains in a state that preserves volatile evidence and prevents file system changes, allowing security analysts to investigate the compromise, collect artifacts, and remediate without losing critical data—all through a centrally managed, reversible action.

Why this answer

Microsoft Defender for Endpoint's device isolation feature is designed to contain a compromised device while preserving forensic data and minimizing disruption. For a critical production device, full isolation (blocking all network traffic except to the Defender service) stops C2 communication without physically disconnecting the device, allowing the security team to investigate and remediate remotely.

Exam trap

The trap here is that candidates often choose 'Block the C2 server URL in the firewall' (Option C) because it seems like a quick network fix, but they fail to recognize that the device itself is already compromised and must be contained at the endpoint level to prevent lateral movement or data exfiltration.

How to eliminate wrong answers

Option A is wrong because physically disconnecting the network cable is a brute-force containment that may cause abrupt service disruption, loss of remote management, and potential data corruption on a critical production device; it also prevents the security team from performing remote investigation or applying updates. Option B is wrong because running a full antivirus scan is a detection and remediation step, not a containment action; it does not stop active C2 communication and may allow the attacker to exfiltrate data or execute further commands during the scan. Option C is wrong because blocking the C2 server URL in the firewall only prevents future connections to that specific URL, but the device may still be compromised and could communicate with other C2 endpoints or use IP-based fallback; it does not contain the device itself.

23
MCQmedium

An organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident is created when a user is detected as compromised. The incident severity is set to High. The SOC manager wants to ensure that all incidents with severity High or above are automatically assigned to the senior analyst tier. What should the analyst configure?

A.Set a playbook to run when an incident is created.
B.Create an analytics rule with a custom severity.
C.Define an automation rule to assign incidents based on severity.
D.Configure an alert tuning rule.
AnswerC

Automation rules in Microsoft Sentinel trigger on incident creation and can set owner, status or severity. Configuring one with a severity condition of High or above automatically assigns matching incidents to the senior analyst tier, removing manual triage effort.

Why this answer

Microsoft Sentinel automation rules are designed to trigger on incident creation and perform actions such as assigning owners, changing severity, adding tags, or running playbooks. To automatically assign all High-or-above incidents to the senior analyst tier, an automation rule with a severity condition and an 'Assign owner' action is the correct mechanism.

Exam trap

SC-200 often tests the confusion between automation rules (incident-level routing/assignment) and playbooks (action orchestration) — candidates pick playbooks for simple assignment tasks that automation rules handle natively.

How to eliminate wrong answers

Option A is wrong because a playbook (Logic App) can perform many actions but is not the native, lightweight mechanism for owner assignment based on incident severity — automation rules are purpose-built for this and are evaluated before playbooks. Option B is wrong because analytics rules generate incidents and set severity; they do not assign owners or route incidents to tiers. Option D is wrong because alert tuning rules suppress or modify alerts, not route incidents to analysts.

24
MCQeasy

Your organization is planning to deploy Microsoft Sentinel. You need to ensure that security events from on-premises servers are sent to Sentinel. Which connector should you use?

A.Install the Log Analytics agent (MMA) on the servers and connect to Sentinel workspace.
B.Use the Microsoft Defender for Cloud (MDC) connector to stream security events.
C.Enable Azure Arc on the servers and use the Arc agent to forward events.
D.Install the Azure Monitor Agent (AMA) on the servers and configure a Data Collection Rule (DCR) to send events to Sentinel.
AnswerD

The correct approach is to install the Azure Monitor Agent (AMA) on each server, because it is the current, fully supported agent for sending logs to Azure Monitor and Microsoft Sentinel. You then define a Data Collection Rule (DCR) that specifies which security event logs — such as the Windows Security log, Sysmon, or Linux syslog — are collected and routed to the Sentinel workspace. The DCR can also apply filtering to reduce noise and control which event IDs are ingested, giving you precise and scalable collection.

Why this answer

The Azure Monitor Agent (AMA) is the current recommended agent for collecting security events from on-premises servers and forwarding them to Microsoft Sentinel. By installing AMA and configuring a Data Collection Rule (DCR), you can specify which security events (e.g., Windows Security Event logs) to collect and send directly to the Sentinel workspace, ensuring efficient and modern data ingestion.

Exam trap

The trap here is that candidates often confuse the deprecated Log Analytics agent (MMA) with the current Azure Monitor Agent (AMA), or mistakenly believe that Azure Arc alone can forward security events, when in fact it requires an additional agent like AMA for log collection.

How to eliminate wrong answers

Option A is wrong because the Log Analytics agent (MMA) is deprecated and no longer recommended for new deployments; Microsoft has announced its retirement and advises using AMA instead. Option B is wrong because the Microsoft Defender for Cloud (MDC) connector is used to ingest security alerts and findings from Defender for Cloud, not to directly stream raw security events from on-premises servers to Sentinel. Option C is wrong because Azure Arc enables management and governance of on-premises servers but does not natively forward security events to Sentinel; the Arc agent is not designed for log collection and requires additional configuration (e.g., AMA) to send events.

25
MCQhard

Your organization has Microsoft Sentinel and Microsoft Defender for Identity deployed. An incident is created for a user whose account was used to access a sensitive database from an unusual workstation. The user is a member of the 'Database Admins' group. The security team needs to prevent further unauthorized access and preserve evidence. What should you do first?

A.Disable the user's account in Active Directory
B.Reset the user's password
C.Force the user to log off all sessions
D.Remove the user from the Database Admins group
AnswerA

Disabling the account in Active Directory immediately blocks further authentication, stopping the unauthorised access while the account and its activity remain intact for forensic review. Containment first prevents additional damage before broader investigation or remediation.

Why this answer

Disabling the user's account in Active Directory is the fastest and most effective way to immediately prevent further unauthorized access while preserving the account and its associated evidence for forensic investigation. It stops all authentication and access without deleting data or altering group memberships that investigators may need to review. Resetting the password or removing group membership does not immediately terminate existing sessions or prevent access as decisively.

Exam trap

SC-200 often tests the difference between containment actions that immediately stop access (disable account) and those that only partially mitigate (password reset, group removal), so candidates must choose the most decisive first step.

How to eliminate wrong answers

Option B is wrong because resetting the password does not immediately terminate active sessions and the attacker may still have valid tokens or cached credentials; it also changes evidence. Option C is wrong because forcing logoff of all sessions may disrupt business operations and does not prevent the attacker from re-authenticating if the account remains enabled. Option D is wrong because removing the user from the Database Admins group only revokes that specific privilege but leaves the account active and able to access other resources, and it alters group membership evidence.

26
MCQmedium

A SOC analyst is creating a scheduled analytics rule in Microsoft Sentinel to detect brute-force attacks on Microsoft Entra ID. The rule should generate an incident when a single user account fails to authenticate more than 10 times in 5 minutes from the same IP address. Which KQL operator is most appropriate to aggregate the count of failed sign-ins?

A.summarize
B.extend
C.project
D.where
AnswerA

summarize is the KQL aggregation operator that groups rows by specified columns, such as UserPrincipalName or IPAddress, and computes aggregates like count(), sum(), or avg() across each group. In a scheduled analytics rule, this is exactly what enables threshold detection by producing per-entity event counts that can be compared against a threshold, such as more than 5 failed sign-ins for a single user.

Why this answer

The `summarize` operator is the correct choice because it aggregates data into groups based on specified criteria, such as counting the number of failed sign-ins per user and IP address within a time window. In this scenario, you need to count events where `ResultType` indicates failure (e.g., 50053 or 50057), grouped by `UserPrincipalName` and `IPAddress`, and then filter for counts exceeding 10. The `summarize` operator with `count()` directly provides this aggregation, enabling the rule to trigger an incident when the threshold is met.

Exam trap

Microsoft often tests the distinction between row-level operators (`extend`, `project`, `where`) and aggregation operators (`summarize`, `make-series`), and the trap here is that candidates mistakenly choose `where` thinking it can count events by filtering for a threshold, but `where` only filters rows and cannot aggregate across multiple rows to produce a count.

How to eliminate wrong answers

Option B (`extend`) is wrong because it creates new calculated columns or modifies existing ones but does not perform any aggregation; it operates on individual rows, not groups, so it cannot count events across multiple rows. Option C (`project`) is wrong because it selects or reorders columns without any aggregation capability; it is used to shape the output, not to summarize data. Option D (`where`) is wrong because it filters rows based on a condition but does not group or count; it can only reduce the dataset to rows meeting a predicate, such as failed sign-ins, but cannot produce a count per user and IP.

27
MCQeasy

An organization uses Microsoft Sentinel for security operations. A security engineer needs to automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel. Which feature should the engineer use?

A.Analytics rule
B.Workbook
C.Automation rule with a playbook
D.Hunting query
AnswerC

An automation rule triggers on incident creation and launches a playbook, which executes the Logic Apps workflow calling Microsoft Entra ID to disable the compromised account. This satisfies the requirement for automatic response without manual analyst intervention.

Why this answer

To automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel, the engineer should use an automation rule that triggers a playbook. Automation rules in Microsoft Sentinel allow you to define conditions (e.g., incident severity) and then invoke a playbook, which can contain the logic to call Microsoft Graph or Entra ID to disable the user. This is the standard method for automated response.

Exam trap

SC-200 often tests the confusion between analytics rules (detection) and automation rules (response), leading candidates to select analytics rules for automated remediation tasks.

How to eliminate wrong answers

Option A is wrong because analytics rules are used to detect threats and create incidents, not to perform automated remediation actions. Option B is wrong because workbooks are for visualization and reporting, not automation. Option D is wrong because hunting queries are for proactive threat hunting, not for automated response.

28
MCQeasy

You are hunting for signs of credential theft in Microsoft Defender XDR. Which advanced hunting table is most appropriate to investigate suspicious logon events?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.EmailEvents
D.IdentityLogonEvents
AnswerD

IdentityLogonEvents records authentication activity across Microsoft Entra ID and on-premises identity infrastructure, including logon type, application and failure reasons. This makes it the appropriate table for surfacing anomalous or suspicious logon patterns indicative of credential theft.

Why this answer

IdentityLogonEvents contains authentication logs, which are most relevant for investigating suspicious logon events and credential theft. Option A (DeviceNetworkEvents) is for network connections. Option B (DeviceProcessEvents) is for process events.

Option C (EmailEvents) is for email records.

29
MCQmedium

The exhibit shows a Conditional Access policy configuration in Microsoft Entra ID. The policy is intended to require MFA and compliant device for all users accessing all applications from trusted locations. However, users are reporting that they are being prompted for MFA even when accessing from the office (which is a trusted location). What is the most likely issue?

A.The policy should target specific applications instead of 'All applications'.
B.The grant controls should be 'Require MFA' only, not 'Require compliant device'.
C.The policy should exclude the 'All Users' group and instead assign specific users.
D.The location condition should include 'All untrusted locations' and exclude 'All trusted locations'.
AnswerD

The location condition is the root cause of the MFA prompt because it is set to include 'All trusted locations,' causing the policy to force MFA even when users connect from the corporate network. To require MFA only on untrusted connections, the policy should either include 'All untrusted locations' or include 'Any location' and then exclude 'All trusted locations.' Excluding trusted locations from the policy's scope ensures that sign-ins from the office aren't challenged, while still protecting access from unknown or risky networks.

Why this answer

The policy is configured to require MFA and compliant device for 'All users' accessing 'All applications' from 'Trusted locations'. However, users are being prompted for MFA from the office, which is a trusted location. The most likely issue is that the location condition is inverted: the policy should target 'All untrusted locations' (i.e., require MFA when not in a trusted location) and exclude 'All trusted locations' to avoid prompting from trusted IPs.

Option D correctly identifies this misconfiguration.

Exam trap

The trap here is that candidates often confuse 'include' vs. 'exclude' logic for location conditions, thinking that including trusted locations will exempt them, when in fact it applies the policy to those locations.

How to eliminate wrong answers

Option A is wrong because targeting 'All applications' is not the issue; the policy is intended to cover all applications, and the problem is with the location condition, not the application scope. Option B is wrong because requiring both MFA and compliant device is a valid and common requirement for untrusted locations; removing 'Require compliant device' would not fix the location-based prompting issue. Option C is wrong because excluding 'All Users' and assigning specific users would not resolve the location condition misconfiguration; the policy is intended for all users, and the problem is that trusted locations are being treated as untrusted.

30
MCQmedium

You are managing a Microsoft Sentinel environment. You need to ensure that only security analysts with specific roles can modify automation rules. The solution must use least privilege. What should you do?

A.Use Azure Policy to restrict access to automation rules.
B.Assign the 'Microsoft Sentinel Contributor' role to all security analysts.
C.Assign the 'Microsoft Sentinel Reader' role to the analysts and grant them 'Automation' permissions via a separate policy.
D.Create a custom role with 'Microsoft Sentinel Automation Contributor' permission and assign it to the analysts.
AnswerD

Creating a custom role that includes the Microsoft Sentinel Automation Contributor permission is the correct approach because it provides the least-privilege access needed to read, create, edit, and delete automation rules, playbooks, and automation rule actions without granting full control over all Sentinel resources. The Microsoft Sentinel Automation Contributor role (often the built-in role or a custom role based on it) scopes permissions specifically to automation rule management, including the ability to trigger playbooks, while avoiding broader Sentinel management rights. Assigning this custom role only to the security analysts ensures they can perform their required tasks without exposing sensitive configurations or other security operations features. This aligns with Azure RBAC best practices and the principle of least privilege, making it the technically correct solution.

Why this answer

Microsoft Sentinel provides a built-in 'Microsoft Sentinel Automation Contributor' role that grants granular permissions to manage automation rules without granting broader Contributor access. This adheres to the least privilege principle by limiting modifications to only the necessary automation-related actions, such as creating, editing, or deleting automation rules, while preventing changes to other Sentinel resources like analytics rules or data connectors.

Exam trap

The trap here is that candidates often confuse Azure Policy with RBAC, assuming a policy can grant permissions, or they incorrectly think that the 'Contributor' role is the only way to allow modifications, overlooking the existence of purpose-built custom or built-in roles like 'Microsoft Sentinel Automation Contributor'.

How to eliminate wrong answers

Option A is wrong because Azure Policy is used for governance and compliance enforcement (e.g., auditing or denying resource configurations), not for granting granular RBAC permissions to specific users for modifying automation rules. Option B is wrong because the 'Microsoft Sentinel Contributor' role grants full write access to all Sentinel resources, including analytics rules, workbooks, and data connectors, which violates the least privilege principle by providing excessive permissions beyond automation rules. Option C is wrong because the 'Microsoft Sentinel Reader' role only allows read access, and there is no separate 'Automation' policy in Azure RBAC that can grant write permissions to automation rules; RBAC permissions are assigned via roles, not policies.

31
MCQeasy

A company runs SQL Server on Azure Virtual Machines (IaaS). The security team wants to enable Advanced Threat Protection (ATP) to detect threats like SQL injection against these SQL Server instances. Which single action is required to achieve this?

A.Enable Microsoft Defender for SQL on the Azure subscription or at the SQL Server resource level.
B.Install the SQL Server IaaS Agent extension on each virtual machine.
C.Enable just Microsoft Defender for Servers on the subscription.
D.Configure an Azure SQL firewall rule to allow only trusted IP addresses.
AnswerA

Enabling Microsoft Defender for SQL at the subscription or resource level is the action that activates the SQL-specific threat detection engine, which combines Advanced Threat Protection and vulnerability assessment for SQL Server on Azure VMs. This plan analyzes database telemetry and audit logs to raise alerts for SQL injection, brute-force attacks, and unusual access patterns. Subscription-level enablement ensures all existing and newly provisioned SQL resources are protected, while resource-level enablement scopes the same protections to a particular SQL Server instance.

Why this answer

To enable Advanced Threat Protection (ATP) for SQL Server on Azure VMs, you must enable Microsoft Defender for SQL at the Azure subscription or SQL Server resource level. This activates the SQL-specific threat detection capabilities, including alerts for SQL injection, anomalous access patterns, and suspicious activities. Without this, the SQL Server instances lack the dedicated security monitoring that ATP provides.

Exam trap

The trap here is that candidates confuse the prerequisite infrastructure (SQL IaaS Agent extension) with the actual security service (Defender for SQL), or assume that general server protection (Defender for Servers) covers SQL-specific threats, which it does not.

How to eliminate wrong answers

Option B is wrong because the SQL Server IaaS Agent extension is required for managing SQL Server on Azure VMs (e.g., licensing, patching), but it does not enable ATP; ATP is a feature of Microsoft Defender for SQL, not the extension. Option C is wrong because Microsoft Defender for Servers protects the VM's OS and network layer but does not include SQL-specific threat detection like SQL injection alerts; that requires Defender for SQL. Option D is wrong because configuring an Azure SQL firewall rule restricts network access but does not enable ATP; ATP is a security monitoring and alerting service, not a network control.

32
MCQmedium

You have deployed Microsoft Defender for Endpoint and integrated it with Microsoft Sentinel. You notice that alerts from Defender for Endpoint are not appearing in Sentinel. What should you check first?

A.Verify that the Microsoft 365 Defender connector in Sentinel is enabled and configured.
B.Confirm that Defender for Endpoint is licensed for all users.
C.Check that the alert severity is not being filtered out by analytics rules.
D.Ensure that all devices are onboarded to Defender for Endpoint.
AnswerA

The Microsoft 365 Defender connector is the data plane that carries M365 Defender alerts, including those from Defender for Endpoint, into Microsoft Sentinel. If this connector is not enabled in Sentinel's content hub and configured with the correct Microsoft 365 Defender workspace setting, no alerts will be streamed to the workspace. Since the symptoms point to missing alerts, verifying the connector's status and configuration is the primary and most direct troubleshooting step.

Why this answer

The Microsoft 365 Defender connector in Microsoft Sentinel is the specific data connector responsible for ingesting alerts from Microsoft Defender for Endpoint (and other Defender products). If this connector is not enabled or misconfigured, alerts will not flow into Sentinel regardless of licensing, device onboarding, or analytics rules. This is the first and most direct check because the connector acts as the ingestion pipeline.

Exam trap

The trap here is that candidates often jump to troubleshooting device onboarding or licensing, forgetting that the Sentinel connector is the explicit integration point that must be verified first.

How to eliminate wrong answers

Option B is wrong because licensing for Defender for Endpoint is a prerequisite for generating alerts, but it does not control the data ingestion pipeline into Sentinel; even with full licensing, alerts will not appear if the connector is disabled. Option C is wrong because analytics rules in Sentinel process events that have already been ingested; if alerts are not arriving, filtering by severity is irrelevant. Option D is wrong because device onboarding is necessary for Defender for Endpoint to generate alerts, but it does not affect the Sentinel connector's ability to receive those alerts; onboarded devices with alerts still require the connector to be enabled.

33
MCQmedium

Your organization uses Microsoft Sentinel with Microsoft Defender XDR integrated. A critical incident has been raised involving a user account that was used to access a confidential SharePoint site from an unusual location at 2:00 AM. The incident includes alerts from Microsoft Defender for Cloud Apps, Microsoft Defender for Identity, and Microsoft Defender for Office 365. The analyst needs to contain the incident, investigate the scope, and begin remediation. The environment has the following: Microsoft Entra ID with conditional access policies, Microsoft Intune for device management, and Microsoft Defender for Endpoint on all devices. The analyst has identified the user account and the device used. Which course of action should the analyst take first?

A.Create a conditional access policy to block the user.
B.Isolate the user's device using Microsoft Defender for Endpoint.
C.Run a KQL query to find all resources accessed by the user.
D.Disable the user account in Microsoft Entra ID and revoke all sessions.
AnswerD

Disabling the account in Microsoft Entra ID and revoking all sessions immediately cuts off the attacker's access, containing the incident before scope investigation. This neutralises the compromised identity across SharePoint, Defender XDR workloads and conditional access, which is the priority containment step.

Why this answer

Disabling the user account in Microsoft Entra ID and revoking all sessions is the immediate containment step because it stops the compromised account from being used for any further access, including the suspicious SharePoint access and any lateral movement. This action directly addresses the core of the incident—the user account—and is the fastest way to cut off the attacker's current authentication tokens and sessions, preventing further damage while the investigation proceeds.

Exam trap

The trap here is that candidates often prioritize device isolation (Option B) because they think of endpoint compromise first, but the incident is about a user account used from an unusual location, meaning the account itself is the primary vector—disabling the account is the fastest and most effective containment step before any device or investigation actions.

How to eliminate wrong answers

Option A is wrong because creating a conditional access policy to block the user is a slower, more complex approach that requires policy propagation time and may not immediately revoke existing sessions or tokens, leaving the attacker with active access. Option B is wrong because isolating the user's device using Microsoft Defender for Endpoint contains the device but does not prevent the attacker from using the same compromised user account from another device or via web-based access (e.g., SharePoint Online). Option C is wrong because running a KQL query to find all resources accessed by the user is a forensic investigation step that should occur after containment; performing it first delays the critical containment action and allows the attacker more time to exfiltrate data or move laterally.

34
MCQmedium

A company has Azure virtual machines running Windows Server. The security team wants to use Microsoft Defender for Cloud's vulnerability assessment solution to identify missing security updates. Which of the following is required to enable built-in vulnerability assessment for VMs?

A.Enable Defender for Servers plan
B.Install the Log Analytics agent manually
C.Configure a vulnerability assessment solution from Azure Marketplace
D.Enable the regulatory compliance dashboard
AnswerA

Enabling Defender for Servers activates the built-in vulnerability assessment that automatically deploys the Qualys agent extension to supported Windows Server VMs, discovering missing security updates and configuration vulnerabilities without additional licensing. This integration is native to Defender for Cloud, and once the plan is enabled, the assessment runs continuously, surfacing findings in the Security Center recommendations such as "Machines should have vulnerability findings resolved." It does not require manual installation of any separate agent or marketplace product.

Why this answer

The built-in vulnerability assessment solution in Microsoft Defender for Cloud for Azure VMs is powered by Qualys and is automatically provisioned when the Defender for Servers plan is enabled. This integration does not require manual agent installation or third-party solutions; enabling the plan activates the scanner on supported VMs to identify missing security updates and other vulnerabilities.

Exam trap

The trap here is that candidates often assume a separate agent or marketplace solution is required, but Microsoft’s built-in assessment is automatically included with the Defender for Servers plan, making the other options unnecessary.

How to eliminate wrong answers

Option B is wrong because the built-in vulnerability assessment uses a Qualys-based scanner that is automatically deployed by Defender for Cloud, not the Log Analytics agent. Option C is wrong because the built-in solution is native and does not require configuring a separate solution from Azure Marketplace; that would be for third-party integrations. Option D is wrong because the regulatory compliance dashboard is a separate feature for tracking compliance standards, not a prerequisite for enabling vulnerability scanning.

35
Multi-Selecteasy

Which TWO Microsoft Defender XDR entities can be managed during incident response?

Select 2 answers
A.Network interfaces
B.Azure subscriptions
C.Devices
D.Microsoft 365 tenants
E.User accounts
AnswersC, E

Devices are a primary managed entity in Microsoft Defender XDR. In Defender for Endpoint, every onboarded workstation, server, and mobile device is represented in the Device inventory and can be isolated, scanned, excluded from automated investigation, or added to a device group. Because device context drives alert correlation across identity, email, and data protection, the device is a core entity for XDR incident management.

Why this answer

During incident response in Microsoft Defender XDR, you can manage devices (endpoints) and user accounts directly from the incident page. Devices can be isolated, have antivirus scans run, or be added to a blocklist, while user accounts can be disabled, forced to sign out, or have their password reset. These actions are executed via Microsoft Defender for Endpoint and Microsoft Defender for Identity integrations within the unified incident response workflow.

Exam trap

The trap here is that candidates often confuse 'entities that can be managed' with 'entities that provide telemetry'—for example, thinking network interfaces or Azure subscriptions are actionable, when in fact only user accounts and devices have direct remediation actions available in the incident response pane.

36
Multi-Selecteasy

Which TWO actions can a Microsoft Sentinel automation rule perform when an incident is created?

Select 2 answers
A.Create a new analytics rule
B.Query Log Analytics workspaces
C.Run a playbook
D.Change the incident severity
E.Ingest data from a new source
AnswersC, D

Running a playbook is a supported action for an automation rule: the rule can invoke a Microsoft Sentinel playbook, which is a Logic Apps workflow, as its action and pass contextual data such as incident ID, alert ID, or analytics rule ID to the logic app. This enables automatic investigative and remediation steps such as blocking an IP, checking threat intelligence, or creating a support ticket. The playbook must be configured with the correct permissions, either through the automation rule's managed identity or a service principal, and must have the appropriate Microsoft Sentinel role assignments.

Why this answer

Microsoft Sentinel automation rules can trigger actions when an incident is created, including running a playbook (Option C) and changing the incident severity (Option D). Playbooks are automated workflows based on Azure Logic Apps that can perform complex response actions, while severity changes allow dynamic triage based on incident properties.

Exam trap

The trap here is that candidates may confuse automation rule actions with analytics rule capabilities, incorrectly assuming automation rules can create rules or query workspaces directly, when in fact those are separate functions within Sentinel.

37
MCQeasy

A SOC analyst is using Microsoft Sentinel to respond to an incident involving multiple compromised user accounts. The analyst needs to quickly see the timeline of all related events. Which feature should the analyst use?

A.Entity behavior page.
B.Analytics rule page.
C.Workbook.
D.Incident timeline.
AnswerD

The Incident timeline is the correct feature because it provides a chronological, visual view of all alerts, bookmarks, and related activities associated with a specific incident. This timeline lets analysts quickly reconstruct the attack sequence, correlate events, and understand the full scope of the incident in one place. It is the primary view used during incident triage and investigation in Microsoft Sentinel.

Why this answer

The Incident timeline (option D) is the correct feature because it provides a chronological view of all events, alerts, and actions associated with a specific incident in Microsoft Sentinel. This allows the SOC analyst to quickly see the sequence of events related to the compromised user accounts without navigating away from the incident investigation page.

Exam trap

The trap here is that candidates may confuse the Incident timeline with the Entity behavior page, thinking they both show event history, but the Entity behavior page is entity-centric and not designed to show the full incident-scoped chronology across multiple compromised accounts.

How to eliminate wrong answers

Option A is wrong because the Entity behavior page focuses on the historical behavior and anomalies of a single entity (e.g., a user or device), not the aggregated timeline of events for a multi-account incident. Option B is wrong because the Analytics rule page is used to create, edit, and manage detection rules, not to view the timeline of events for an active incident. Option C is wrong because a Workbook is a customizable dashboard for visualizing data from multiple queries, but it does not provide the incident-specific, chronological event timeline that the Incident timeline feature offers.

38
MCQhard

A security engineer is responsible for protecting containerized workloads in Azure Kubernetes Service (AKS) clusters. They want to enable Microsoft Defender for Cloud to detect threats against the Kubernetes control plane and container runtime. Additionally, they want to ensure vulnerability assessments are performed on images stored in Azure Container Registry. Which Defender for Cloud plan should the engineer enable?

A.Enable the Microsoft Defender for Servers plan on the subscription.
B.Enable the Microsoft Defender for Containers plan on the subscription.
C.Enable the Microsoft Defender for App Service plan on the subscription.
D.Enable the Microsoft Defender for Container Registries plan (legacy) on the registry.
AnswerB

Defender for Containers is the Microsoft Defender for Cloud plan specifically built for AKS and can also cover Kubernetes distributions in Azure Arc-enabled environments. It combines control plane threat detection from Kubernetes audit logs, workload runtime protection via a daemon set, and vulnerability assessment for images from any registry, making it the correct choice for protecting containerized workloads. Enabling this plan on the subscription provides consolidated coverage for both the orchestration layer and the containers themselves.

Why this answer

The Microsoft Defender for Containers plan is the only plan that provides integrated threat detection for the AKS control plane and container runtime, as well as vulnerability assessment for images in Azure Container Registry. This plan replaces the legacy Defender for Container Registries and Defender for Kubernetes plans, offering a unified solution for container security.

Exam trap

The trap here is that candidates may confuse the legacy Defender for Container Registries plan (Option D) as sufficient, not realizing it lacks control plane threat detection and has been replaced by the unified Defender for Containers plan.

How to eliminate wrong answers

Option A is wrong because the Microsoft Defender for Servers plan is designed for protecting virtual machines and on-premises servers, not containerized workloads in AKS or container registries. Option C is wrong because the Microsoft Defender for App Service plan focuses on threats against web applications running on Azure App Service, not Kubernetes clusters or container registries. Option D is wrong because the Microsoft Defender for Container Registries plan (legacy) only provides vulnerability scanning for images in the registry and does not include threat detection for the AKS control plane or container runtime; it has been superseded by the Defender for Containers plan.

39
Multi-Selecteasy

Which TWO actions are essential for configuring Microsoft Sentinel to support effective threat hunting?

Select 2 answers
A.Connect Microsoft 365 data sources (e.g., Office 365, Entra ID, Defender for Cloud Apps)
B.Create a Watchlist that maps user names to email addresses
C.Enable User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel
D.Configure custom analytics rules for every MITRE ATT&CK technique
E.Install Sysmon on all domain controllers
AnswersA, C

Connecting Microsoft 365 data sources is essential because Microsoft Sentinel hunting queries must run against ingested telemetry from these connectors. Office 365 and Entra ID provide audit logs, sign-in logs, and email/Teams activity, and Defender for Cloud Apps adds SaaS shadow IT and session data. Without these sources, KeyVault events, IdentityInfo, and other UEBA-dependent tables remain empty, so hunting for malicious user behavior is impossible.

Why this answer

Enabling User and Entity Behavior Analytics (UEBA) provides baselines for hunting anomalies, and connecting Microsoft 365 data sources provides rich data for hunting. Customizing analytics rules is for detection, not hunting; Sysmon is not required; Watchlists are helpful but not essential for basic hunting setup.

40
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. You notice that a large number of log entries from Defender for Cloud Apps are being dropped at ingestion due to 'malformed data' errors. The data connector shows a healthy status. What is the most likely cause?

A.The log type is not supported by Sentinel.
B.The Log Analytics workspace key has expired.
C.The data volume exceeds the workspace's ingestion capacity, causing data truncation.
D.The Defender for Cloud Apps connector is blocked by a firewall.
AnswerC

Log Analytics workspaces enforce ingestion rate limits (for example, 500 MB per minute or a 100 GB per-day cap depending on the pricing tier). When the combined volume from all sources exceeds these thresholds, the platform throttles ingestion and drops or truncates the excess data, which can result in partially written JSON records that appear as malformed logs. This specifically explains why a high data volume scenario would produce parsing or truncation errors without any authentication or connectivity issues.

Why this answer

When the data volume exceeds the Log Analytics workspace's ingestion capacity, Defender for Cloud Apps log entries can be truncated mid-record, causing them to be malformed and dropped. The connector status remains healthy because the connector itself is still connected and receiving data, but the workspace's ingestion rate limit (typically 500 MB/min per workspace or 2 GB/min per workspace depending on pricing tier) causes truncation, not a connectivity or authentication failure.

Exam trap

The trap here is that candidates see a 'healthy' connector status and assume the issue must be with the log format or connectivity, but Microsoft deliberately tests the nuance that ingestion rate limits can cause data truncation without breaking the connector's health status.

How to eliminate wrong answers

Option A is wrong because Defender for Cloud Apps sends supported log types (e.g., CloudAppEvents, McasShadowItReporting) that are natively ingested by Sentinel; unsupported log types would not appear as 'malformed data' but would simply not be available in the connector schema. Option B is wrong because an expired Log Analytics workspace key would cause the connector to show a 'disconnected' or 'error' status, not a healthy status, and would result in no data ingestion rather than malformed data. Option D is wrong because a firewall blocking the connector would prevent any data from reaching Sentinel, resulting in a 'disconnected' or 'failed' connector status, not a healthy status with partial data drops.

41
MCQeasy

Your organization uses Microsoft Defender for Cloud to manage security posture. You need to assign a custom initiative to a specific management group to track compliance. Which two components must you create?

A.An Azure Blueprint and a role assignment.
B.A policy definition and an initiative definition.
C.An Azure RBAC role and a Log Analytics workspace.
D.An Azure Monitor workbook and an alert rule.
AnswerB

A custom policy initiative requires at least one policy definition and an initiative definition that references those policies. The initiative definition is a JSON document containing metadata, parameters, and an array of policy definition IDs, all grouped for a shared compliance goal. Without both elements, there is no logical grouping to assign or evaluate in Azure Policy. Therefore, this pair is the minimal and correct set of components needed to create a custom initiative.

Why this answer

To track compliance for a custom initiative in Microsoft Defender for Cloud, you must first create a custom policy definition that specifies the rules or effects to enforce. Then, you must create an initiative definition (a group of policy definitions) that can be assigned to a management group. This assignment enables Defender for Cloud to evaluate resources against the custom initiative and report compliance.

Exam trap

The trap here is that candidates confuse Azure Blueprints (which also group resources) with policy initiatives, or they think a Log Analytics workspace is required to store compliance data, when in fact compliance data is stored and reported by Defender for Cloud itself without needing a separate workspace.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used for deploying repeatable environments and templates, not for creating custom compliance initiatives in Defender for Cloud; role assignments control permissions, not policy definitions. Option C is wrong because Azure RBAC roles manage access control, and Log Analytics workspaces store monitoring data, but neither component defines the compliance rules required for a custom initiative. Option D is wrong because Azure Monitor workbooks and alert rules are for visualizing and responding to telemetry, not for defining or assigning compliance policies.

42
Multi-Selectmedium

Which THREE of the following are valid sources of data that a threat hunter can use in Microsoft Sentinel for hunting? (Choose three.)

Select 3 answers
A.Microsoft Entra ID audit logs
B.Azure Cost Management data
C.Azure DevOps pipelines
D.Microsoft 365 audit logs
E.AWS CloudTrail logs
AnswersA, D, E

Microsoft Entra ID audit logs record sign-in and directory change activity, and Microsoft Sentinel ingests them through the Entra ID data connector. They surface authentication anomalies and privilege changes, giving threat hunters a native identity-based data source for correlating suspicious account behaviour across the environment.

Why this answer

Microsoft Sentinel ingests Microsoft Entra ID audit logs through the Azure Active Directory (now Entra ID) data connector, which records sign-in and directory activity and is a legitimate hunting source, so option A is correct. Microsoft 365 audit logs are collected via the Office 365 data connector (using the Management Activity API) and provide Exchange, SharePoint, Teams, and general audit events usable for hunting, making option D correct. AWS CloudTrail logs are supported through the Amazon Web Services S3/CloudTrail connector, which pulls API activity into Sentinel for cross-cloud hunting, so option E is correct.

Azure Cost Management data (option B) is billing and cost-analysis telemetry, not security event data ingested as a hunting table in Sentinel, and Azure DevOps pipelines (option C) are CI/CD build/release processes rather than a native Sentinel hunting data source, so neither belongs.

43
MCQmedium

A security administrator wants to assess their Azure environment against the Azure Security Benchmark and also include custom security controls defined by their organization. They need a single, reusable policy initiative that can be assigned across multiple subscriptions and management groups. What should the administrator create in Microsoft Defender for Cloud?

A.A new regulatory compliance standard
B.A custom Azure Policy initiative
C.A custom Azure Policy definition
D.A Secure Score recommendation override
AnswerB

A custom Azure Policy initiative is the correct mechanism because an initiative bundles multiple policy definitions, including built-in Azure Security Benchmark definitions and your own custom definitions, into a single assignable unit. When assigned at the subscription or management group scope, it evaluates resources against both the benchmark's built-in controls and your additional custom rules. This satisfies the requirement to assess the environment against two combined sets of controls simultaneously.

Why this answer

The administrator needs a single, reusable policy initiative that includes both Azure Security Benchmark controls and custom organizational controls. A custom Azure Policy initiative (also known as a policy set) allows combining multiple policy definitions, including built-in benchmark controls and custom definitions, into one assignable package across subscriptions and management groups. This is the correct approach because initiatives are designed for grouping related policies and can be assigned at scale in Microsoft Defender for Cloud.

Exam trap

The trap here is that candidates confuse a single custom policy definition (Option C) with a policy initiative, not realizing that an initiative is the only way to group multiple controls into a single assignable package for compliance assessment.

How to eliminate wrong answers

Option A is wrong because a new regulatory compliance standard in Defender for Cloud is a built-in framework (like Azure Security Benchmark, ISO 27001) that cannot be customized to include arbitrary custom controls; it only maps to predefined compliance assessments. Option C is wrong because a custom Azure Policy definition is a single policy rule, not a collection of multiple controls; it cannot bundle the Azure Security Benchmark with custom controls into one reusable package. Option D is wrong because a Secure Score recommendation override only changes the scoring impact or status of an existing recommendation, not the underlying policy set or compliance standard.

44
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. You receive an alert indicating that a user from the finance department accessed a sensitive SharePoint file from an IP address associated with a known malicious Tor exit node. The file contains payment information. The user's account has not been disabled. What should you do first to contain the incident?

A.Delete the SharePoint file from the site
B.Notify the user of the suspicious activity
C.Block the IP address in Microsoft Defender for Cloud Apps
D.Suspend the user's account in Microsoft Entra ID
AnswerD

Suspending the account prevents further access immediately.

Why this answer

The first step to contain the incident is to suspend the user's account in Microsoft Entra ID (Option D). This immediately revokes access to all resources, preventing further data exfiltration while preserving the current state for investigation. Option A is incorrect because deleting the SharePoint file may destroy evidence.

Option B is incorrect because blocking the IP address in Defender for Cloud Apps is less effective; the attacker can easily switch to a different IP address. Option C is incorrect because notifying the user could alert a potential attacker who might have compromised the account, leading to further malicious actions.

45
MCQmedium

Your security operations team receives an alert from Microsoft Sentinel about a suspicious sign-in from an unfamiliar IP address. You need to investigate the alert by correlating it with user activity and device information. Which data sources should you query first?

A.Microsoft Purview audit logs and Microsoft Intune device compliance
B.Microsoft 365 Defender alerts and Microsoft Sentinel incidents
C.Microsoft Entra ID sign-in logs and Microsoft Defender for Endpoint device events
D.Azure Activity Logs and Azure Firewall logs
AnswerC

Microsoft Entra ID sign-in logs are the authoritative source for user authentication events, containing details such as sign-in time, IP address, location, conditional access policies, MFA result, and risk detection—all essential for analyzing a sign-in anomaly. Microsoft Defender for Endpoint device events provide host-level telemetry like process execution, network connections, and attack behavior, allowing the analyst to correlate the sign-in activity with what is happening on the device used to authenticate. Together, these sources let you establish whether the sign-in is truly abnormal and whether the device itself is compromised, enabling a data-driven investigation.

Why this answer

Investigating a suspicious sign-in requires correlating the sign-in event with user activity and device context. Microsoft Entra ID sign-in logs provide the authentication details (IP address, timestamp, user), while Microsoft Defender for Endpoint device events supply device-level telemetry (processes, network connections, logged-on users). This combination directly enables the correlation needed to validate whether the sign-in was legitimate or malicious.

Exam trap

The trap here is that candidates often confuse aggregated alert sources (like Microsoft 365 Defender alerts) with raw telemetry sources (like sign-in logs and device events), leading them to pick Option B instead of the correct raw data sources needed for correlation.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview audit logs focus on data governance and compliance events (e.g., file access, eDiscovery), not real-time sign-in or device activity; Intune device compliance checks device policy adherence but lacks the granular sign-in and process-level events needed for alert correlation. Option B is wrong because Microsoft 365 Defender alerts and Sentinel incidents are aggregated alert outputs, not raw data sources; querying them first would only re-consume the same alert without underlying telemetry for correlation. Option D is wrong because Azure Activity Logs track control-plane operations (e.g., resource creation) and Azure Firewall logs capture network traffic, neither of which provides user sign-in details or device process-level events required for this investigation.

46
Multi-Selecteasy

Which TWO of the following are valid data connectors in Microsoft Sentinel? (Select two.)

Select 2 answers
A.Windows Defender Firewall
B.Office 365
C.Microsoft Forms
D.Azure DevOps
E.Azure Activity
AnswersB, E

The Office 365 connector is a first-party, built-in data connector in Microsoft Sentinel. It ingests audit logs from Exchange Online, SharePoint Online, Microsoft Teams, and other Microsoft 365 workloads through the Microsoft 365 Management Activity API, and you enable it by simply connecting an Office 365 tenant on the connectors page. This is one of the standard, valid connectors.

Why this answer

Office 365 is a valid Microsoft Sentinel data connector because it ingests audit logs from Exchange Online, SharePoint Online, Teams, and other Office 365 services via the Office 365 Management Activity API. This connector enables security monitoring of user and admin activities across the Microsoft 365 tenant, making it a core data source for insider threat detection and compliance scenarios.

Exam trap

The trap here is that candidates often confuse 'Windows Defender Firewall' with the 'Windows Firewall' logs that can be collected via the Windows Security Events connector, but there is no dedicated Sentinel data connector named 'Windows Defender Firewall'.

47
MCQhard

Your organization uses Microsoft Defender for Cloud Apps to monitor SaaS applications. You discover that a user is downloading a large number of files from SharePoint Online to an unmanaged device. You need to automatically block the download and require the user to acknowledge a policy violation. Which action should you configure in a session policy?

A.Set the action to 'Monitor only'.
B.Set the action to 'Redirect to Microsoft Entra ID conditional access'.
C.Set the action to 'Block' and enable 'Notify user' with a customized message.
D.Set the action to 'Block' and enable 'Custom block message'.
AnswerC

Setting the action to 'Block' instructs Defender for Cloud Apps to deny the request at the reverse proxy when the download is attempted, effectively preventing the file from being transferred. Enabling 'Notify user' with a customized message displays an interactive notification that the user must read and acknowledge, which warns the user and leaves an audit record of the acknowledgment. This combination of a hard block and an acknowledged, personalized message meets both the download-prevention and user-notification requirements.

Why this answer

A session policy in Microsoft Defender for Cloud Apps can enforce real-time controls on SaaS app traffic. Setting the action to 'Block' stops the download immediately, and enabling 'Notify user' with a customized message both blocks the action and requires the user to acknowledge the policy violation, satisfying the requirement to automatically block and obtain acknowledgment.

Exam trap

The trap here is that candidates confuse 'Custom block message' (a static notification) with 'Notify user' (which includes an interactive acknowledgment), leading them to select Option D instead of the correct Option C.

How to eliminate wrong answers

Option A is wrong because 'Monitor only' only logs the activity without blocking it, failing to meet the requirement to automatically block the download. Option B is wrong because 'Redirect to Microsoft Entra ID conditional access' redirects the session for additional authentication or device compliance checks but does not block the download or require acknowledgment of a policy violation. Option D is wrong because 'Block' with 'Custom block message' blocks the download but does not require the user to acknowledge the violation; it simply displays a message without an interactive acknowledgment step.

48
Multi-Selecthard

Which THREE actions are part of the containment phase in the Microsoft Incident Response process?

Select 3 answers
A.Notify senior management of the incident.
B.Block known malicious IP addresses at the firewall.
C.Disable compromised user accounts.
D.Isolate affected systems from the network.
E.Collect forensic data from affected systems.
AnswersB, C, D

Blocking known malicious IP addresses at the firewall is a direct and immediate containment action that severs the network communication path between the compromised environment and the attacker's command-and-control (C2) infrastructure. By applying egress and ingress rules to deny traffic to these IPs, you cut off remote commands, data exfiltration, and potential malware downloads, thereby limiting the adversary's operational control without disrupting normal business traffic.

Why this answer

Blocking known malicious IP addresses at the firewall is a containment action because it immediately stops inbound or outbound communication with threat actors, preventing further data exfiltration or command-and-control traffic. In the Microsoft Incident Response (IR) process, containment focuses on limiting the blast radius and stopping the spread of an attack, and firewall rules are a primary technical control for achieving this at the network perimeter.

Exam trap

The SC-200 exam often tests the distinction between containment and investigation phases, where candidates mistakenly choose forensic data collection (Option E) as containment, but in the IR process, containment must happen first to stop the bleeding before any evidence gathering that could alter system state.

49
MCQhard

Refer to the exhibit. You are configuring an automation rule in Microsoft Sentinel. The rule is enabled but never runs. The playbook exists and is in the same resource group. What is the most likely cause?

A.The condition uses 'Contains' operator, but 'AlertProvider' requires 'Equals'.
B.The automation rule is in a 'Disabled' state.
C.The trigger type is incorrect; it should be 'Microsoft.SecurityInsights/Alert'.
D.The playbookId is missing the subscription ID.
AnswerC

Sentinel automation rules must specify a valid trigger type: 'Microsoft.SecurityInsights/Alert' for alert-triggered rules or 'Microsoft.SecurityInsights/Incident' for incident-triggered rules. The exhibit shows 'Microsoft.SecurityInsights/AlertRule', which is not a recognized trigger type in the automation rule schema, so the rule will not fire as intended. This invalid trigger type is the actual defect preventing the rule from working.

Why this answer

The exhibit shows the trigger type set to 'Microsoft.SecurityInsights/Incident', but the playbook is designed to run on alerts, not incidents. Automation rules in Microsoft Sentinel require the trigger type to match the data type the playbook expects; for alert-triggered playbooks, the trigger must be 'Microsoft.SecurityInsights/Alert'. Since the rule is enabled and the playbook exists in the same resource group, the mismatch in trigger type is the most likely reason the rule never runs.

Exam trap

The trap here is that candidates assume any enabled automation rule with a valid playbook will run, overlooking the critical requirement that the trigger type must exactly match the playbook's intended data source (alert vs. incident).

How to eliminate wrong answers

Option A is wrong because the 'Contains' operator is valid for string conditions in automation rules; 'AlertProvider' does not require 'Equals' exclusively. Option B is wrong because the question explicitly states the rule is enabled, so a 'Disabled' state cannot be the cause. Option D is wrong because the playbookId in an automation rule does not require the subscription ID to be included; the resource ID format is sufficient as long as the playbook is in the same resource group.

50
MCQmedium

Your organization uses Microsoft Sentinel with a workspace in the East US region. You need to respond to an incident involving data exfiltration from a virtual machine in West Europe. The incident was created from a custom analytics rule that queries the AzureActivity table. What should you do to ensure the incident contains all relevant evidence from the West Europe region?

A.Create the analytics rule in a separate workspace in West Europe
B.Ensure that Azure activity logs from West Europe are streamed to the same Sentinel workspace in East US
C.Configure the analytics rule to query the West Europe workspace
D.Use the incident merge feature to combine incidents from multiple workspaces
AnswerB

AzureActivity data is regional; the West Europe VM's activity logs are only written to a workspace in that region unless explicitly streamed. Routing them into the East US workspace ensures the analytics rule can correlate all evidence for the incident.

Why this answer

To have the analytics rule in the East US workspace evaluate AzureActivity logs from West Europe, those logs must be collected into the same workspace. Streaming activity logs from West Europe to the East US workspace ensures all relevant data is available for the rule to query. Option A is incorrect because creating a separate workspace in West Europe would isolate the data, and the incident is in the East US workspace; cross-workspace queries would be required.

Option C is incorrect because the analytics rule runs only in the workspace where it is defined; to query data from another workspace, you would need a cross-workspace query, but the rule is already defined in East US and cannot directly query the West Europe workspace without additional configuration. Option D is incorrect because incident merge is used to combine duplicate incidents within the same workspace, not across different workspaces.

51
MCQhard

Your company uses Microsoft Sentinel and Microsoft Defender for Cloud Apps (MCAS). A security analyst detects that a user is accessing a sanctioned cloud app from an unusual location. The analyst creates an incident in Sentinel. You need to automatically apply a session policy in MCAS to block downloads from that user for the next hour. You have an existing playbook that can apply session policies. What is the most efficient way to automate this response?

A.Create an automation rule in Sentinel that triggers when an incident is created with the relevant conditions and runs the playbook.
B.Instruct the analyst to run the playbook manually from the incident page each time.
C.Configure the incident creation rule in MCAS to automatically run the playbook.
D.Modify the analytics rule that detected the anomaly to run the playbook as an automated response.
AnswerA

An automation rule in Microsoft Sentinel is the correct mechanism for incident-driven response: it evaluates incidents the moment they are created, matches configured conditions (e.g., severity, entity, tactic), and immediately executes a playbook. This is event-driven, consistent, and removes the need for analyst intervention, aligning with the scenario's requirement to automate incident-created actions.

Why this answer

An automation rule in Microsoft Sentinel is triggered by incident creation and can run a playbook automatically when specified conditions are met. This is the most efficient way to automate the response because it eliminates manual intervention and ensures the session policy is applied immediately upon incident creation. The automation rule can be scoped to incidents with specific analytics rules, severities, or entities, matching the requirement.

Exam trap

SC-200 often tests the distinction between analytics rules (detection), automation rules (orchestration), and playbooks (action); candidates may incorrectly think analytics rules can directly run playbooks or that MCAS rules can trigger Sentinel playbooks.

How to eliminate wrong answers

Option B is wrong because instructing the analyst to run the playbook manually each time does not automate the response and is inefficient, contrary to the requirement for automation. Option C is wrong because MCAS incident creation rules create incidents in MCAS but do not natively trigger Sentinel playbooks; integration is done via Sentinel automation rules. Option D is wrong because analytics rules detect and create incidents but do not directly run playbooks as automated responses; automation rules are the correct mechanism for triggering playbooks based on incident creation.

52
MCQhard

Your organization uses Microsoft Defender for Cloud to assess security posture. You need to ensure that any new Azure subscription automatically has Microsoft Defender for Cloud enabled with the 'Defender for Cloud (CSPM)' plan active. What should you do?

A.Create an automation account that runs a PowerShell script daily to check and enable Defender for Cloud.
B.Configure Azure Arc to enforce the plan on new subscriptions.
C.Assign a built-in Azure Policy initiative that deploys Microsoft Defender for Cloud configuration to subscriptions.
D.Use Microsoft Sentinel's 'Subscription Migration' playbook.
AnswerC

The correct answer is to assign the built-in Azure Policy initiative that deploys Microsoft Defender for Cloud configuration, such as the 'Microsoft Defender for Cloud' initiative, to the root management group or subscription scope. This initiative uses DeployIfNotExists and Modify effects to automatically enable the Defender plans, configure data collection, and remediate any drift. Because policy inheritance flows to all child scopes, every new subscription is continuously assessed and brought into compliance without manual or scheduled intervention, providing a fully governed, auditable enforcement mechanism.

Why this answer

Azure Policy can enforce compliance at scale by assigning the built-in initiative 'Deploy Microsoft Defender for Cloud configuration' to a management group or subscription. This initiative includes policies that automatically enable Microsoft Defender for Cloud and activate the 'Defender for Cloud (CSPM)' plan on new subscriptions, ensuring consistent security posture without manual intervention.

Exam trap

The trap here is that candidates may confuse Azure Arc (which extends Azure management to non-Azure environments) with Azure Policy (which enforces configurations on Azure subscriptions), leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because using an automation account with a PowerShell script that runs daily introduces a delay (up to 24 hours) and is not a native, real-time enforcement mechanism; Azure Policy provides immediate, idempotent enforcement at resource creation. Option B is wrong because Azure Arc is designed to manage hybrid and multi-cloud servers, not to enforce Azure subscription-level plans like Defender for Cloud CSPM; it does not have a policy or capability to enable Defender plans on new subscriptions. Option D is wrong because Microsoft Sentinel's 'Subscription Migration' playbook is intended for migrating Sentinel resources between subscriptions, not for enabling Defender for Cloud plans; it does not address the requirement of automatically enabling CSPM on new subscriptions.

53
MCQhard

You are conducting a threat hunt in Microsoft Defender XDR and want to identify devices that have recently communicated with a known C2 server IP address. Which advanced hunting table should you query?

A.DeviceNetworkEvents
B.DeviceFileEvents
C.DeviceLogonEvents
D.DeviceProcessEvents
AnswerA

DeviceNetworkEvents is the correct table for C2 hunting because it specifically records network connection attempts, including source and destination IP addresses, ports, protocols, and remote URLs. Unlike file or process events, this table lets you directly search for outbound connections to known malicious or suspicious infrastructure, which is the core signature of command-and-control communications. Without this telemetry, you cannot definitively identify the network egress point to a C2 server.

Why this answer

EviceNetworkEvents (Option A) because this table contains network connection events including destination IP addresses, ports, and protocols. It is used to identify network communications with suspicious IPs such as C2 servers. DeviceProcessEvents (Option D) is for process creation events, DeviceLogonEvents (Option C) is for authentication events, and DeviceFileEvents (Option B) is for file system events.

Only DeviceNetworkEvents provides the necessary network traffic information for threat hunting in Microsoft Defender XDR.

54
MCQhard

A threat hunter is using Microsoft Sentinel and wants to leverage machine learning to detect anomalous behavior in Azure subscription activity. Which analytics rule template should the hunter use?

A.Anomalous Sign-In Locations
B.Anomalous Azure Operations
C.Anomalous User Behavior
D.Lateral Movement Detection
AnswerB

The Anomalous Azure Operations rule is a built-in Microsoft Sentinel analytics rule that uses machine learning to analyze AzureActivity logs and flag unusual operations within an Azure subscription, such as atypical role assignments, resource deployments, or modification of critical settings. Unlike other anomaly rules, it specifically targets the Azure control plane and is driven by the AzureActivity data connector. This rule is the correct choice for a threat hunter seeking to uncover abnormal Azure subscription operations.

Why this answer

The 'Anomalous Azure Operations' analytics rule template in Microsoft Sentinel uses machine learning to baseline Azure subscription activity and flag unusual operations, which directly matches the hunter's goal of detecting anomalous Azure activity. It is purpose-built for Azure control-plane events.

Exam trap

The trap is confusing sign-in anomaly detection (identity layer) with Azure operations anomaly detection (control-plane layer) — both are ML rules but target different telemetry.

How to eliminate wrong answers

Option A is wrong because 'Anomalous Sign-In Locations' targets Azure AD/Entra ID sign-in geography, not Azure subscription operations. Option C is wrong because 'Anomalous User Behavior' is a UEBA concept rather than a specific Sentinel analytics rule template for Azure operations. Option D is wrong because 'Lateral Movement Detection' is a Fusion/behavioral detection scenario, not an ML anomaly template for Azure subscription activity.

55
Multi-Selecthard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. During a security incident involving a compromised Azure VM, which THREE actions are appropriate to contain and investigate the incident?

Select 3 answers
A.Use Microsoft Defender for Cloud's Just-in-Time VM access to isolate the VM.
B.Create a Microsoft Sentinel automation rule to trigger a playbook that runs investigation actions.
C.Enable network security group flow logs to capture network traffic.
D.Delete the compromised VM to prevent further damage.
E.Update the VM's operating system to the latest patch.
AnswersA, B, C

Just-in-Time VM access in Microsoft Defender for Cloud allows you to control inbound traffic to management ports (RDP/SSH) by enforcing approved source IPs and time windows. When an incident occurs, you can configure JIT to deny all inbound traffic to the VM, effectively isolating it from the network while the VM remains powered on for forensic collection. This non-destructive containment preserves the VM's memory, disk, and logs for investigation, unlike deletion or shutdown.

Why this answer

Microsoft Defender for Cloud's Just-in-Time VM access can be used to lock down inbound traffic to the VM, effectively isolating it from the network while preserving the VM for forensic analysis. This action reduces the attack surface and prevents lateral movement without destroying evidence, which is critical during incident response.

Exam trap

The trap here is that candidates may confuse containment with remediation, choosing to delete or patch the VM immediately, but Microsoft tests the principle of preserving forensic evidence during the containment phase of incident response.

56
Multi-Selecthard

Which THREE indicators are commonly associated with ransomware activity in Microsoft Sentinel threat hunting?

Select 3 answers
A.Network connections to known C2 infrastructure
B.Unusual DNS queries to known safe domains
C.Excessive failed logon attempts from a single IP
D.Mass file rename or extension changes
E.Scheduled task creation on multiple endpoints
AnswersA, D, E

Ransomware communicates with C2 servers for key exchange.

Why this answer

Ransomware activity commonly involves three indicators: network connections to known C2 infrastructure (command and control communication), mass file rename or extension changes (file encryption), and scheduled task creation on multiple endpoints (persistence mechanism). Option A (unusual DNS queries to known safe domains) is not typical for ransomware, and option C (excessive failed logon attempts) is more indicative of brute-force attacks. Therefore, the correct options are A, D, and E.

57
MCQhard

You are configuring an automated investigation and response (AIR) playbook in Microsoft Sentinel. The playbook should automatically block a user in Microsoft Entra ID when a high-severity incident is created. Which action should you include in the playbook?

A.Use the 'Block user' action from the Microsoft Entra ID connector in Azure Logic Apps.
B.Call the Microsoft Graph API to update the user's accountEnabled property to false.
C.Add a 'Block IP' action from the Azure Firewall connector.
D.Add a 'Change incident status' action to close the incident.
AnswerB

Calling the Microsoft Graph API to set the user's accountEnabled property to false is the correct method because this property controls whether the user can authenticate. A PATCH request to /users/{id} with body {"accountEnabled": false} immediately disables the account across Microsoft 365 services, effectively blocking the user's access. This approach is also what documented playbooks for automated response recommend.

Why this answer

The 'Block user' action is not available in the Microsoft Entra ID connector for Azure Logic Apps; instead, you must call the Microsoft Graph API to update the user's `accountEnabled` property to `false`. This directly disables the user account in Microsoft Entra ID, effectively blocking their access. The playbook in Microsoft Sentinel uses Azure Logic Apps, and the Graph API is the appropriate method to perform this action programmatically.

Exam trap

The trap here is that candidates assume a 'Block user' action exists in the Microsoft Entra ID connector, but Microsoft Sentinel playbooks rely on Logic Apps connectors, which lack that specific action, forcing the use of the Graph API instead.

How to eliminate wrong answers

Option A is wrong because the Microsoft Entra ID connector in Azure Logic Apps does not include a 'Block user' action; it only supports actions like 'Get user' or 'Update user', and blocking requires a Graph API call. Option C is wrong because a 'Block IP' action from the Azure Firewall connector blocks network traffic from an IP address, not a user account in Microsoft Entra ID, which is irrelevant for blocking a user identity. Option D is wrong because changing the incident status to closed does not perform any blocking action; it only updates the incident's lifecycle in Microsoft Sentinel, leaving the user unblocked.

58
MCQmedium

An organization has enabled enhanced security features for a hybrid infrastructure including SQL servers on-premises and in Azure. Which Microsoft Defender for Cloud plan provides threat detection for both SQL Server on-premises and Azure SQL Database?

A.Defender for Servers
B.Defender for SQL
C.Defender for Databases
D.Defender for Storage
AnswerB

Defender for SQL is the correct cloud security plan for protecting SQL Server workloads, whether they run as Azure SQL Database, Azure SQL Managed Instance, or SQL Server on an Azure VM or on-premises server connected via Azure Arc. It includes vulnerability assessment, data discovery and classification, and advanced threat protection that generates alerts for SQL injection and unusual access patterns. Because the question asks about enhanced security features for a hybrid infrastructure involving SQL, this plan directly covers both cloud and on-premises database layers.

Why this answer

Defender for SQL is the correct plan because it is specifically designed to protect both on-premises SQL Server instances (via Azure Arc-enabled SQL Server) and Azure SQL Database. It provides threat detection, vulnerability assessment, and advanced threat protection across the hybrid SQL estate, unlike other Defender plans that focus on different resource types.

Exam trap

The trap here is that candidates confuse 'Defender for Databases' (a broader, non-existent plan in the current Microsoft Defender for Cloud portfolio) with 'Defender for SQL,' which is the actual plan that covers both on-premises and Azure SQL databases.

How to eliminate wrong answers

Option A is wrong because Defender for Servers protects virtual machines and servers (including SQL Server hosts) but does not provide SQL-specific threat detection for the database engine itself. Option C is wrong because Defender for Databases is not a standalone plan; it is a legacy term or a grouping that has been replaced by Defender for SQL, which is the actual plan covering SQL databases. Option D is wrong because Defender for Storage protects Azure Blob Storage, Azure Files, and Azure Data Lake Storage from storage-specific threats, not SQL databases.

59
Multi-Selecthard

Which TWO permissions are required to create and manage automation rules in Microsoft Sentinel?

Select 2 answers
A.Microsoft Sentinel Reader
B.Microsoft Sentinel Automation Contributor
C.Microsoft Sentinel Responder
D.Log Analytics Contributor
E.Microsoft Sentinel Contributor
AnswersC, E

Cannot manage automation rules.

Why this answer

Microsoft Sentinel Contributor (E) is correct because it grants full management of Microsoft Sentinel resources, including creating, editing, and deleting automation rules. Microsoft Sentinel Responder (C) is also correct because it can manage incidents, run playbooks, and create and edit automation rules. Microsoft Sentinel Automation Contributor (B) is not sufficient for a user to create or manage automation rules; it is used to allow the Microsoft Sentinel service to run playbooks triggered by automation rules.

Microsoft Sentinel Reader (A) only allows viewing data and incidents, so it cannot create or modify automation rules. Log Analytics Contributor (D) manages the underlying Log Analytics workspace but does not grant the Sentinel-specific permissions needed for automation rules.

Exam trap

The trap is confusing the Microsoft Sentinel Automation Contributor role with the ability to author automation rules. Automation Contributor is for allowing the Microsoft Sentinel service to run playbooks, not for creating or managing automation rules. The roles that allow a user to create and manage automation rules are Microsoft Sentinel Contributor and Microsoft Sentinel Responder.

60
Multi-Selectmedium

Which THREE components are part of the Microsoft Sentinel SOAR capabilities? (Select THREE.)

Select 3 answers
A.Connectors
B.Workbooks
C.Playbooks
D.Analytics rules
E.Automation rules
AnswersA, C, E

Connectors are the integration layer that enables Sentinel to ingest threat intelligence, alerts, and other data from external sources, and also to take outbound actions across connected systems like ServiceNow, Teams, or Azure Active Directory. In the SOAR context, connectors provide the input triggers and output actions that playbooks rely on to orchestrate response workflows beyond Sentinel's native data. Without connectors, automated response would be limited to internal Sentinel data, making them an essential component of the SOAR architecture.

Why this answer

Connectors are part of Microsoft Sentinel's SOAR capabilities because they enable the ingestion of security alerts and events from various sources, which is the foundational step for triggering automated responses. Without connectors, Sentinel cannot receive the data needed to initiate playbooks or automation rules, making them an essential component of the SOAR workflow.

Exam trap

The trap here is that candidates often confuse Workbooks (visualization) or Analytics rules (detection) with SOAR components, because they are all part of Sentinel's core features, but only connectors, playbooks, and automation rules directly enable orchestration and automated response.

61
MCQmedium

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You receive an alert in MDE about a suspicious PowerShell command executed on a device. You create an incident in Sentinel from this alert. You need to automatically collect a memory dump from the affected device for further analysis. You have a playbook that can initiate a memory dump collection via the MDE API. What is the best way to automate this?

A.Configure the alert details enrichment in Sentinel to automatically add the memory dump to the incident.
B.Create an automation rule that triggers when an incident is created from a MDE alert and runs the playbook to collect the memory dump.
C.Use entity behavior analytics in Sentinel to trigger the playbook when suspicious behavior is detected.
D.Have the analyst manually run the playbook from the incident page.
AnswerB

Automation rules in Microsoft Sentinel respond to incident creation events, and can filter on the alert's product source being Microsoft Defender for Endpoint. Triggering the playbook this way runs the MDE API memory dump collection automatically, satisfying the requirement without manual intervention.

Why this answer

Automation rules in Microsoft Sentinel can trigger playbooks when an incident is created. Option B is correct because it creates an automation rule that triggers on incident creation from a Microsoft Defender for Endpoint alert and runs the playbook to collect the memory dump automatically. Option A is incorrect because alert details enrichment only adds enrichment details, it does not run playbooks.

Option C is incorrect because entity behavior analytics does not directly trigger playbooks on incident creation. Option D is incorrect because the requirement is automation, not manual action.

62
MCQeasy

You are a security analyst at a company that uses Microsoft 365 Defender. You receive an automated email indicating that a user has been flagged for possible credential theft. The email includes a link to investigate the alert in the Microsoft 365 Defender portal. Which role is responsible for sending this email?

A.A mail flow rule in Exchange Online configured to forward alerts.
B.Microsoft 365 Defender email notification settings.
C.Microsoft Defender for Cloud Apps notification settings.
D.A Microsoft Sentinel analytics rule configured to send email notifications.
AnswerB

Microsoft 365 Defender (formerly Microsoft Defender for Endpoint) provides built-in email notification settings under Incidents & alerts, allowing you to configure email alerts for new incidents or updated severity levels. These notifications are sent directly by the Defender platform itself, using its internal alert engine to trigger the email—no external workflow or additional licensing is required. This option correctly explains the source of the email in question because Defender has native, out-of-the-box alert notification capabilities that deliver standardized incident updates to specified recipients.

Why this answer

The automated email alerting a user about possible credential theft is sent by Microsoft 365 Defender's built-in email notification settings. These settings allow security teams to configure notifications for specific alert severities or categories, such as credential theft, directly from the Microsoft 365 Defender portal. The email includes a link to investigate the alert, which aligns with the notification functionality within Microsoft 365 Defender.

Exam trap

The trap here is that candidates may confuse the source of the alert (Microsoft 365 Defender) with other Microsoft security tools like Microsoft Defender for Cloud Apps or Microsoft Sentinel, which have their own notification settings but are not responsible for this specific credential theft alert.

How to eliminate wrong answers

Option A is wrong because a mail flow rule in Exchange Online is used to route, filter, or modify email messages based on conditions like sender or content, not to generate security alerts from Microsoft 365 Defender. Option C is wrong because Microsoft Defender for Cloud Apps notification settings are specific to cloud app security alerts, such as anomalous activity in SaaS apps, not credential theft alerts from Microsoft 365 Defender. Option D is wrong because a Microsoft Sentinel analytics rule can send email notifications, but Sentinel is a separate SIEM tool; the question explicitly states the alert originates from Microsoft 365 Defender, not Sentinel.

63
MCQmedium

Your organization is using Microsoft Sentinel and has deployed the Microsoft Entra ID (Azure AD) connector. You need to create an analytics rule that triggers an incident when a user from a specific IP address is assigned the Global Administrator role. The IP address is not in your trusted IP list. Which KQL query should you use as the rule logic?

A.AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress == '10.0.0.1'
B.AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress !in (dynamic(['10.0.0.1', '10.0.0.2']))
C.AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress !has '10.0.'
D.AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress !in ('trusted IP list')
AnswerB

This is correct because it uses the !in operator with a dynamic array literal containing the trusted IP addresses, which properly excludes any events initiated from either 10.0.0.1 or 10.0.0.2 while still capturing all other IPs performing Global Administrator role assignments. The dynamic array syntax is the proper KQL way to represent a list of values for membership testing.

Why this answer

It uses the `!in` operator to filter out specific IP addresses from the `InitiatedBy.app.ipAddress` field, ensuring that only events from IP addresses not in the trusted list trigger an incident. The query correctly targets `AuditLogs` with `ActivityDisplayName == 'Add member to role'` and checks that the role assigned is `Global Administrator` via `TargetResources[0].displayName`. This logic matches the requirement to alert when a user from a specific IP address (10.0.0.1) that is not in the trusted list is assigned the Global Administrator role.

Exam trap

The trap here is that candidates often confuse the `!has` operator (which checks for substring containment) with the `!in` operator (which checks for exact membership in a list), leading them to select Option C which would incorrectly exclude entire IP subnets rather than specific trusted IPs.

How to eliminate wrong answers

Option A is wrong because it uses `== '10.0.0.1'` which would only trigger when the IP address exactly matches that single IP, not when the IP is not in the trusted list; the requirement is to trigger for any IP not in the trusted list, not just a specific one. Option C is wrong because `!has '10.0.'` is a string containment operator that would incorrectly exclude any IP starting with '10.0.' (e.g., 10.0.0.1, 10.0.1.5), which is too broad and does not match the specific trusted IP list requirement. Option D is wrong because `!in ('trusted IP list')` treats the string literal 'trusted IP list' as a single value, not as a dynamic array of IPs, and would not evaluate against actual IP addresses; KQL requires a dynamic array or a list of values for the `in` operator.

64
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. During an incident investigation, you find that a device is exfiltrating data to an external IP. You need to isolate the device from the network using automated response. Which action should you configure in an automation rule?

A.Trigger a Microsoft Purview data loss prevention policy.
B.Run a Microsoft Entra ID playbook to disable the device.
C.Run a playbook that triggers a Microsoft Defender for Endpoint 'Isolate device' action.
D.Create an automation rule in Microsoft Intune to wipe the device.
AnswerC

Running a playbook that invokes the Microsoft Defender for Endpoint 'Isolate device' action is the correct containment response because it actively disconnects the endpoint from the corporate network while preserving a connection to the MDE cloud service for management and forensics. This action terminates all network traffic to and from the device (except low-level MDE communication), immediately stopping data exfiltration and command-and-control traffic. In Sentinel, this playbook can be triggered automatically or manually and is the only listed option that provides a network-level isolation layer.

Why this answer

The scenario requires network isolation of a device that is actively exfiltrating data. Microsoft Defender for Endpoint provides a built-in 'Isolate device' action that can be triggered via a playbook from a Microsoft Sentinel automation rule. This action immediately blocks all inbound and outbound network traffic to and from the device, except for communication with the Defender for Endpoint service, effectively containing the threat.

Exam trap

The trap here is that candidates may confuse 'disabling a device' in Entra ID (which only revokes authentication) with true network isolation, or they may think a DLP policy can stop active network-level exfiltration, when in fact only a Defender for Endpoint isolation action blocks all network traffic at the host level.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview data loss prevention (DLP) policies are designed to inspect and prevent data exfiltration at the application or content level (e.g., email, SharePoint), not to perform network-level isolation of a device. Option B is wrong because Microsoft Entra ID (formerly Azure AD) playbooks can disable a device's identity or access tokens, but they do not isolate the device from the network; the device remains connected and can still communicate with external IPs. Option D is wrong because Microsoft Intune's wipe action is a device management operation that resets or removes corporate data, but it does not provide immediate network isolation and is not designed for automated incident response to an active exfiltration event.

65
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. During an incident, you discover that a user is downloading large amounts of data from SharePoint to an unmanaged device. You need to automatically block further downloads from that device. What should you configure?

A.Create a session policy in Microsoft Defender for Cloud Apps to block download.
B.Create a Conditional Access policy to require a compliant device.
C.Configure Microsoft Intune device compliance policy.
D.Create a DLP policy in Microsoft Purview.
AnswerA

A session policy in Microsoft Defender for Cloud Apps operates via reverse-proxy conditional access app control, giving you real-time, action-level visibility and enforcement. By setting the 'block download' action alongside other file-related controls, the policy inspects every HTTP transaction and can block a download request while still allowing viewing or other cloud-app activities. This is the only option here that directly targets downloads as a discrete action rather than toggling all-or-nothing access to the application.

Why this answer

A session policy in Microsoft Defender for Cloud Apps uses reverse proxy capabilities to monitor and control user activities in real time. By configuring a session policy with the 'block download' action, you can immediately stop further downloads from SharePoint to the unmanaged device during the incident, without affecting managed devices.

Exam trap

The trap here is that candidates often confuse session policies with Conditional Access or DLP policies, not realizing that only session policies provide real-time, granular control over specific actions like downloads within a cloud app session.

How to eliminate wrong answers

Option B is wrong because a Conditional Access policy to require a compliant device would block access entirely for non-compliant devices, but it does not provide granular, real-time control to block only downloads while allowing other activities like viewing. Option C is wrong because Intune device compliance policy is used to define compliance requirements for managed devices, but it cannot enforce real-time blocking of downloads from an unmanaged device that is not enrolled in Intune. Option D is wrong because a DLP policy in Microsoft Purview is designed to detect and prevent data loss by inspecting content at rest or in transit, but it does not provide session-level, real-time blocking of downloads based on device trust or risk.

66
MCQeasy

You need to create a custom detection rule in Microsoft Sentinel that alerts when an anomalous number of failed logons occur from a single IP address within 5 minutes. Which KQL operator should you use to count failed logons per IP?

A.summarize
B.project
C.where
D.extend
AnswerA

The summarize operator aggregates log data, allowing you to count failed logons grouped by IP address within a five-minute bin. This produces the per-IP threshold needed to trigger the anomalous failed-logon alert in Microsoft Sentinel.

Why this answer

'summarize' is used to aggregate counts per key (IP). Option B (project) only selects columns. Option C (where) filters rows.

Option D (extend) adds calculated columns.

67
Multi-Selectmedium

Which TWO of the following are valid methods to perform threat hunting in Microsoft Sentinel? (Choose TWO.)

Select 2 answers
A.Create and save custom KQL queries in the Hunting blade
B.Use the built-in hunting queries in the Microsoft Sentinel Hunting blade
C.Configure automated response rules to detect threats
D.Use Workbooks to visualize data and identify anomalies
E.Create a Playbook to automatically run queries on a schedule
AnswersA, B

Saved custom KQL queries in the Hunting blade let analysts run reusable, scheduled or ad hoc searches across Sentinel's Log Analytics workspace, directly satisfying the requirement for a valid threat-hunting method rather than relying solely on automated analytics rules.

Why this answer

Option A is correct because the Hunting blade in Microsoft Sentinel lets analysts create, save, and run custom KQL (Kusto Query Language) queries against the Log Analytics workspace, which is a core proactive threat-hunting technique. Option B is correct because Microsoft Sentinel ships with built-in hunting queries (based on MITRE ATT&CK tactics) that can be run directly from the Hunting blade to surface suspicious activity. Option C is not a hunting method; automation rules are used to trigger responses (such as running playbooks or changing incident properties) after an alert or incident is created, not to proactively search for threats.

Option D is incorrect because Workbooks are for visualization and reporting of data, not for the query-driven, hypothesis-based exploration that defines threat hunting. Option E is incorrect because Playbooks are Logic Apps-based automation workflows that respond to incidents or alerts, not a mechanism for scheduling ad-hoc hunting queries.

Exam trap

SC-200 often tests whether candidates confuse threat hunting (interactive, query-driven investigation in the Hunting blade) with automated detection and response (Analytics Rules, Automation Rules, and Playbooks).

68
MCQmedium

You are investigating a detection in Microsoft Defender for Endpoint. The PowerShell output shows a threat with ID 2147723152. Which type of threat does this ID represent?

A.Ransomware
B.HackTool
C.Worm
D.Trojan
AnswerB

HackTool is the correct classification because detection ID 2147723152 corresponds to a known hacking utility, which Defender categorizes under the HackTool threat type. These tools are commonly used for privilege escalation, credential dumping, or lateral movement, and their detection is based on file signatures and behavior analytics. The alert's ID directly maps to this family, confirming the verdict.

Why this answer

Threat ID 2147723152 corresponds to a hacktool (specifically, a tool used for penetration testing), often detected as 'HackTool:MSIL/Mimikatz!dha'.

69
MCQmedium

A company uses Microsoft Defender XDR and has enabled automatic attack disruption for human-operated ransomware. During an incident, the system automatically contains a compromised account. However, the SOC team wants to ensure that the containment action is reversible and that the account can be restored after investigation. What should the team do before restoring the account?

A.Change the account's password and enable multi-factor authentication.
B.Verify that no other accounts were compromised.
C.Remove the account from all administrative roles.
D.Run a full antivirus scan on the account's devices.
AnswerA

Resetting the account's password invalidates the compromised credentials that an attacker may be using, and enabling MFA adds a second authentication layer that blocks unauthorized re-entry. This is the required remediation step before restoring the account because it directly addresses the known compromise of the identity itself. Without this step, any restoration action would leave the account vulnerable to immediate re-compromise, as existing tokens or cached credentials could still be leveraged.

Why this answer

After automatic containment disables a compromised account, the SOC team must change its password and enable multi-factor authentication before restoring it. This ensures the attacker cannot regain access with stolen credentials. Option B is a good practice but not a prerequisite for restoring this specific account.

Option C is unnecessary if the account was not an administrator. Option D is irrelevant because containment applies to the account, not devices.

70
MCQeasy

Your organization uses Microsoft Sentinel. A security incident is created, and the assigned analyst needs to perform initial triage. What is the first step the analyst should take according to Microsoft best practices for incident response?

A.Contain the affected resources immediately to prevent further damage.
B.Run a full investigation using Microsoft 365 Defender hunting queries.
C.Review the incident details and verify the alert is a true positive.
D.Escalate the incident to the senior security team.
AnswerC

The correct first step is to open the incident in Microsoft Sentinel and review its details to verify the alert is a true positive. This means checking the incident's severity, status, entities, MITRE ATT&CK tactics, and the raw data or logs that triggered the analytics rule, then correlating it with other alerts on the same resource to confirm the activity is genuinely malicious. Only after this validation should you decide whether to contain, investigate, or escalate, because taking response actions on an unverified false positive can cause unnecessary damage.

Why this answer

The first step in the Microsoft incident response process is to verify the alert and determine its validity. Option A is wrong because containment should follow after verification. Option B is wrong because escalating before verification bypasses triage.

Option D is wrong because detailed investigation comes after initial triage.

71
Multi-Selecteasy

Which TWO data sources are natively supported by Microsoft Sentinel for ingesting security events? (Choose two.)

Select 2 answers
A.Salesforce audit logs
B.GitHub audit logs
C.Google Cloud Platform (GCP) logs
D.Windows Security Events
E.Azure Activity Logs
AnswersD, E

Windows Security Events are natively supported through the 'Windows Security Events via AMA' or legacy 'Windows Security Events' connector, which uses the Log Analytics agent (or Azure Monitor Agent) to collect security event logs from Windows machines. This built-in, first-party connector requires no custom development and is a standard source for detecting threats, making it one of the two correct answers.

Why this answer

Windows Security Events are natively supported by Microsoft Sentinel via the Windows Security Events via AMA connector or the legacy Log Analytics agent. This connector ingests security event logs (e.g., Event ID 4625 for failed logons) directly into Sentinel without requiring a third-party parser or custom data connector. Azure Activity Logs are also natively supported through the Azure Activity connector, which streams subscription-level operational events (e.g., resource creation, policy changes) into Sentinel at no additional cost.

Exam trap

The trap here is that candidates often confuse 'natively supported' with 'available via a connector in the content hub,' but Microsoft Sentinel defines native support as built-in data connectors that require no additional custom code or third-party services, excluding connectors that rely on Azure Functions or partner solutions.

72
MCQhard

Your organization uses Microsoft Sentinel. You need to implement a custom incident response process that requires approval before taking action on an incident. What should you use?

A.Automation rules with conditions
B.Watchlist for approval status
C.Playbook with Microsoft Teams connector for approval
D.Analytics rule with custom details
AnswerC

A playbook is an Azure Logic Apps workflow and can include the Microsoft Teams connector, which enables sending an adaptive card to a designated Teams channel and using the approval action to wait for a Yes/No response from a user. This directly delivers a human-in-the-loop checkpoint that blocks subsequent steps until the approver decides, satisfying the need for approval in the incident response process. Once the response is collected, the playbook can branch to different actions based on the outcome, making it the correct mechanism for this requirement.

Why this answer

A playbook with a Microsoft Teams connector is the correct choice because it enables an interactive approval workflow directly within Teams. When an incident is triggered, the playbook can send an adaptive card to a Teams channel or user, pause execution until an approval decision is made, and then continue with the next steps based on that decision. This satisfies the requirement for a custom approval process before taking action on an incident.

Exam trap

The trap here is that candidates often confuse automation rules (which can run playbooks automatically) with the playbook itself, failing to recognize that only a playbook with an interactive connector like Teams can implement a human-in-the-loop approval step.

How to eliminate wrong answers

Option A is wrong because automation rules with conditions can trigger actions based on incident properties but cannot pause for human approval; they execute actions automatically without any interactive approval step. Option B is wrong because a watchlist for approval status is a static reference table used for correlation or enrichment, not a mechanism to request, track, or enforce an approval workflow. Option D is wrong because an analytics rule with custom details is used to generate alerts and incidents from log data, not to implement an approval process after an incident is created.

73
Multi-Selecteasy

Your organization uses Microsoft Sentinel. You are investigating an incident and need to gather additional context about a suspicious IP address. Which TWO Microsoft Sentinel features can you use to enrich the investigation?

Select 2 answers
A.Threat intelligence
B.Watchlist
C.Hunting
D.Entity behavior analytics
E.User and Entity Behavior Analytics (UEBA)
AnswersA, D

Threat intelligence can indicate if the IP is known malicious.

Why this answer

Threat intelligence is correct because it allows you to cross-reference the suspicious IP address against known threat intelligence feeds (e.g., Tor exit nodes, known C2 servers) directly within Microsoft Sentinel. This enriches the investigation by providing context such as reputation scores, associated malware families, and geographic origin, helping you assess the IP's maliciousness.

Exam trap

The trap here is that candidates often confuse UEBA (Option E) with entity behavior analytics (Option D), but UEBA is a broader analytics framework that does not directly enrich a specific IP address with external threat context, whereas entity behavior analytics is the correct feature for enriching investigation by providing entity-specific behavioral insights.

74
MCQeasy

A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request. What is the first step the analyst should take?

A.Disable the user account
B.Reset the user's password
C.Run a full antivirus scan on the user's device
D.Validate the alert by checking the user's recent activity
AnswerD

Validating the alert by checking the user's recent activity is the correct first step because it confirms whether the alert corresponds to a genuine security event, such as anomalous sign-ins, impossible travel, or suspicious mailbox activity in Microsoft Defender. By reviewing the user's sign-in logs and other evidence, you can determine the alert's true positive or false positive status, which guides all subsequent containment and remediation decisions. This triage approach aligns with incident response best practices, ensuring you act based on evidence rather than assumptions and avoiding unnecessary disruption to the user.

Why this answer

When Microsoft Defender for Identity alerts on a suspicious Kerberos ticket request, the first step is to validate the alert by checking the user's recent activity. This ensures the alert is not a false positive caused by legitimate behavior (e.g., scheduled tasks or application service tickets) before taking any disruptive action. Defender for Identity uses network traffic and event logs to detect anomalies like overpass-the-hash or Kerberoasting, but initial validation prevents unnecessary account lockouts or password resets.

Exam trap

The trap here is that candidates often jump to containment (disable account) or remediation (reset password) without first validating the alert, confusing the 'respond' phase with the initial 'validate' step required by incident response best practices.

How to eliminate wrong answers

Option A is wrong because disabling the user account is a containment step that should only occur after the alert is validated as a true positive, as premature disabling can disrupt legitimate access and generate false incident response overhead. Option B is wrong because resetting the user's password is a remediation step that assumes the account is compromised, but without validation, it may be unnecessary and could alert an actual attacker prematurely. Option C is wrong because running a full antivirus scan on the user's device addresses endpoint malware, but the alert originates from network-level Kerberos authentication anomalies, not from a local infection; the scan would not validate the specific ticket request.

75
MCQmedium

Your team uses Microsoft Sentinel to investigate incidents. You need to create a custom analytic rule that triggers an incident when a user signs in from an unfamiliar location. What is the most efficient way to achieve this?

A.Create a playbook triggered by Microsoft Entra ID alerts.
B.Write a custom KQL query using SigninLogs.
C.Configure a Microsoft Purview insider risk policy.
D.Use a built-in Anomalous Sign-in Location rule template.
AnswerD

The built-in Anomalous Sign-in Location rule template in Microsoft Sentinel is the most direct solution. It uses Microsoft Sentinel's UEBA (User and Entity Behavior Analytics) to baseline user behavior and flag sign-ins from unusual geographic locations or IP addresses. This template is ready to enable, requires no custom KQL, and automatically maps entities and generates alerts that feed into incidents—exactly what is needed for investigating sign-in anomalies.

Why this answer

Microsoft Sentinel provides a built-in 'Anomalous Sign-in Location' rule template that leverages Microsoft Entra ID Identity Protection data to detect sign-ins from unfamiliar locations. This template is pre-configured with the necessary KQL logic and alerting, making it the most efficient method without requiring custom development or additional data sources.

Exam trap

The trap here is that candidates may assume a custom KQL query (Option B) is the most flexible and efficient approach, overlooking that Sentinel's built-in templates are pre-optimized and require no manual logic for defining 'unfamiliar' locations.

How to eliminate wrong answers

Option A is wrong because playbooks are automated response actions (e.g., sending emails or blocking users) triggered by alerts, not the mechanism to create detection rules for unfamiliar location sign-ins. Option B is wrong because while a custom KQL query using SigninLogs could detect unfamiliar locations, it requires manual logic to define 'unfamiliar' (e.g., comparing against historical geolocation data) and is less efficient than using the built-in template. Option C is wrong because Microsoft Purview insider risk policies focus on detecting risky user activities like data exfiltration or policy violations, not sign-in location anomalies.

Page 1 of 18

Page 2