Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 751–825

1303 questions total · 18pages · All types, answers revealed

Page 10

Page 11 of 18

Page 12
751
MCQhard

Your company uses Microsoft Defender for Endpoint. A device shows signs of compromise with suspicious PowerShell execution. You need to collect forensic evidence before performing remediation. Which action should you use?

A.Isolate the device from the network.
B.Run a full antivirus scan.
C.Collect investigation package.
D.Initiate a live response session.
AnswerC

Collecting the investigation package gathers volatile forensic artefacts — running processes, scheduled tasks, network connections and autorun entries — from the compromised device before remediation alters them. This satisfies the stem's requirement to preserve evidence first, whereas isolating or remediating the device would destroy the volatile data needed for later analysis.

Why this answer

In Microsoft Defender for Endpoint, the 'Collect investigation package' action gathers a forensic snapshot of the device — including running processes, network connections, autoruns, scheduled tasks, and recent files — without altering the system state. This is the correct first step when you need to preserve evidence before remediation, because it captures volatile data that would be lost if you isolated or remediated the device. Isolation and live response are separate actions that serve different purposes.

Exam trap

SC-200 often tests the order of incident response actions — candidates pick 'Isolate the device' because it sounds like the most urgent step, but the question specifically asks for evidence collection before remediation, making 'Collect investigation package' the correct choice.

How to eliminate wrong answers

Option A is wrong because isolating the device from the network stops the attack but does not collect forensic evidence — it actually prevents further live data collection from the network and is a containment action, not an evidence-gathering one. Option B is wrong because running a full antivirus scan may quarantine or delete malicious files, destroying evidence, and it does not produce a forensic package. Option D is wrong because a live response session gives you a remote shell to run commands on the device, but it is an interactive tool — it does not automatically collect and package forensic artifacts the way 'Collect investigation package' does.

752
MCQeasy

You are configuring Microsoft Defender for Cloud Apps session controls for a SharePoint site containing sensitive data. Which condition must be met to apply real-time monitoring?

A.The SharePoint site must be added as a custom app in Defender for Cloud Apps.
B.Users must access the site through Microsoft Entra ID application proxy.
C.A browser extension must be installed on all client devices.
D.Users must be configured with Conditional Access policies from Microsoft Entra ID.
AnswerD

Session controls in Microsoft Defender for Cloud Apps are implemented through the Conditional Access session control pipeline in Microsoft Entra ID. When a user is subject to a Conditional Access policy that includes 'Use Conditional Access App Control' as a session control, the user's session is redirected through the Defender for Cloud Apps reverse proxy. Without this policy, the proxy never intercepts the request, so session-level monitoring and restrictions (e.g., download blocking) will not be enforced for SharePoint Online.

Why this answer

Microsoft Defender for Cloud Apps session controls for SharePoint require users to be routed through the Cloud App Security proxy, which is invoked by Conditional Access policies in Microsoft Entra ID. Conditional Access app controls apply session policies to traffic when users access SharePoint, enabling real-time monitoring. The Microsoft Entra ID application proxy is designed for on-premises apps, not for SaaS apps like SharePoint Online.

Therefore, the correct prerequisite is having Conditional Access policies configured.

Exam trap

Candidates often confuse the Microsoft Entra ID application proxy with the Cloud App Security proxy. For SharePoint Online session controls, Conditional Access policies trigger the Cloud App Security proxy, not the application proxy.

How to eliminate wrong answers

Option A is wrong because SharePoint is already a recognized app in Defender for Cloud Apps; adding it as a custom app is unnecessary and does not enable session controls. Option B is correct as explained. Option C is wrong because session controls for SharePoint do not require a client-side browser extension; the proxy handles interception server-side.

Option D is wrong because while Conditional Access policies are used to route traffic to the session control, they are not the condition that enables real-time monitoring—the proxy is the prerequisite.

753
MCQhard

In a threat hunt, you discover that a non-admin user account created a scheduled task that executes a PowerShell script to connect to an external IP on port 4444. Which of the following is the most likely interpretation of this activity?

A.The user is performing legitimate remote administration
B.The PowerShell script is a remote assistance tool
C.The scheduled task is part of a software update mechanism
D.The scheduled task is likely a reverse shell for persistence and remote access
AnswerD

A scheduled task that invokes PowerShell to establish an outbound connection to an external IP on port 4444 is a textbook reverse shell persistence mechanism. The attacker creates the scheduled task to execute at logon or on a recurring interval, ensuring reliable command-and-control access even after system reboots. PowerShell is frequently abused for this purpose because it enables 'living off the land' fileless attacks, often using System.Net.Sockets.TcpClient to send shell output without writing scripts to disk. Port 4444 is also a common default listener for Metasploit, and the non-admin context suggests the attacker is operating with limited privileges, possibly after phishing or lateral movement, maintaining access while working to elevate privileges.

Why this answer

A non-admin user creating a scheduled task that runs PowerShell to connect to an external IP on port 4444 is a textbook reverse shell pattern. Port 4444 is the default listener port for Metasploit's meterpreter payload, and scheduled tasks provide persistence across reboots. The combination of non-admin context, external IP, unusual port, and scheduled execution strongly indicates attacker persistence and command-and-control.

Exam trap

SC-200 often tests whether candidates can distinguish benign admin activity from attacker tradecraft — the trap is assuming 'scheduled task' or 'PowerShell' is inherently benign and missing the reverse-shell indicators (non-admin, external IP, port 4444).

How to eliminate wrong answers

Option A is wrong because legitimate remote administration is typically performed by admin accounts using sanctioned tools (RDP, WinRM, SSH) with documented change control, not by non-admin users via scheduled PowerShell to arbitrary external IPs. Option B is wrong because remote assistance tools (Quick Assist, TeamViewer) use vendor-specific signed binaries and known ports, not raw PowerShell connecting to port 4444. Option C is wrong because software update mechanisms use signed installers, WSUS/SCCM, or vendor endpoints over HTTPS (443), not PowerShell reverse connections to arbitrary IPs on port 4444.

754
MCQmedium

You are reviewing a threat hunting KQL query in Microsoft Sentinel. The query references an external CSV containing malicious IPs. The query returns no results despite known malicious activity. What is the most likely issue?

A.The externaldata function is not supported in Microsoft Sentinel.
B.The HuntingTimeRange variable is not being used correctly.
C.The project clause removes the RemoteIP column.
D.The external CSV file is not accessible or the URL is malformed.
AnswerD

When a KQL query uses `externaldata` to load a CSV file and then performs a `join` against that data, the join depends entirely on the availability and format of the external file. If the URL is malformed (e.g., missing scheme, incorrect path, invalid SAS token) or the endpoint is inaccessible (e.g., network restrictions, expired token, or file deleted), `externaldata` returns an empty table. The subsequent `join` then finds no matching rows, silently producing an empty result set, which matches the symptom described in the question.

Why this answer

The query uses the externaldata operator to load an external CSV file. If the file URL is malformed or inaccessible, the query will not load any IPs, resulting in no matches. Option A is incorrect because externaldata is supported in Microsoft Sentinel.

Option B is incorrect because the HuntingTimeRange variable is likely used correctly to filter by time, but time filtering is not the cause of zero results. Option C is incorrect because the project clause selects the RemoteIP column; it does not remove it.

755
Drag & Dropmedium

Order the steps to configure a Microsoft Sentinel analytics rule using a scheduled query.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Scheduled query rules run on a schedule and generate alerts based on query results meeting a threshold.

756
MCQmedium

Your company uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the default policy. The email contains an external link to a credential harvesting site. You need to block similar emails in the future. What should you do?

A.Create an anti-spam policy to block the sender's domain.
B.Create a Safe Links policy and add the malicious domain to the blocked URLs list.
C.Create an anti-malware policy to block the attachment type.
D.Add the sender's domain to the Tenant Allow/Block List.
AnswerB

Safe Links policies are specifically designed to protect users from malicious hyperlinks by rewriting URLs and checking them against Microsoft's threat intelligence plus your custom block list. Adding the malicious domain to the blocked URLs list causes any link containing that domain to be blocked or to trigger a warning when clicked, even if the email's sender appears benign. This directly addresses the attack vector—the embedded URL—rather than the email's origin, making it the correct control.

Why this answer

The phishing email contains a link to a credential harvesting site, so the most direct way to block similar emails in the future is to use a Safe Links policy. Safe Links proactively scans and blocks URLs at time of click, and you can add the malicious domain to the blocked URLs list to prevent users from accessing that site. This addresses the specific threat vector (malicious URL) rather than the sender's domain or attachment type.

Exam trap

The trap here is that candidates confuse the Tenant Allow/Block List (which is for sender/domain/IP blocking) with the Safe Links blocked URLs list (which is for URL-level blocking), leading them to choose option D instead of B.

How to eliminate wrong answers

Option A is wrong because an anti-spam policy blocks emails based on sender or domain reputation, but the email already bypassed the default policy, and blocking the sender's domain is reactive and easily circumvented by attackers using new domains. Option C is wrong because an anti-malware policy blocks attachments, but the threat here is a URL link, not an attachment, so it would not prevent the phishing email. Option D is wrong because the Tenant Allow/Block List is used to override filtering decisions for specific senders or domains, but adding the sender's domain would block all emails from that domain, which is too broad and does not address the URL-based threat; also, the email already bypassed the default policy, so a block list entry might not be effective if the email is already being delivered.

757
MCQhard

A company uses Microsoft Sentinel with Microsoft Defender for Cloud Apps. An incident is created when a user downloads 500 GB from SharePoint in one hour. The analyst wants to create a playbook that automatically suspends the user in Microsoft Entra ID when such activity is detected. Which connector and action should the analyst use in the playbook?

A.Microsoft Teams connector with 'Post message' action to notify admin.
B.Microsoft Entra ID connector with 'Update user' action to set accountEnabled to false.
C.Microsoft 365 Defender connector with 'Run advanced hunting' action.
D.Exchange Online connector with 'Set mailbox' action.
AnswerB

The Microsoft Entra ID connector's 'Update user' action writes directly to the directory object, letting the playbook set accountEnabled to false and immediately block sign-in. This satisfies the requirement to suspend the user automatically upon the Defender for Cloud Apps incident trigger.

Why this answer

The Microsoft Entra ID connector provides the 'Update user' action, which can set the 'accountEnabled' property to false, effectively suspending the user in Microsoft Entra ID. This directly addresses the requirement to automatically disable a user account when a high-volume SharePoint download incident is detected in Microsoft Sentinel. The playbook can be triggered by the incident and use this action to perform the suspension without manual intervention.

Exam trap

The SC-200 exam often tests the distinction between notification actions (like Teams posts) and remediation actions (like disabling a user account), and the trap here is that candidates may choose a notification option (A) because it seems proactive, but the question explicitly requires automatic suspension, not just alerting.

How to eliminate wrong answers

Option A is wrong because the Microsoft Teams connector with 'Post message' action only sends a notification to an admin; it does not suspend the user or perform any account modification, so it fails to meet the requirement of automatically suspending the user. Option C is wrong because the Microsoft 365 Defender connector with 'Run advanced hunting' action is used to query threat data for investigation, not to modify user account status; it cannot suspend a user in Microsoft Entra ID. Option D is wrong because the Exchange Online connector with 'Set mailbox' action modifies mailbox settings (e.g., forwarding, quotas) but does not disable the user account in Microsoft Entra ID; suspending a user requires disabling the identity, not just the mailbox.

758
MCQmedium

A security analyst is using Microsoft 365 Defender advanced hunting to investigate a phishing campaign. The analyst wants to find emails that were delivered to users (DeliveryAction != 'Blocked') and contained a specific malicious URL (e.g., 'https://malicious.com'). The EmailEvents table contains delivery information, and the EmailUrlInfo table contains URL details. Which KQL query correctly joins these two tables to find the desired emails?

A.EmailEvents | where DeliveryAction != 'Blocked' | join kind=inner EmailUrlInfo on NetworkMessageId | where Url == 'https://malicious.com'
B.EmailEvents | where DeliveryAction != 'Blocked' | join kind=leftouter EmailUrlInfo on NetworkMessageId | where Url == 'https://malicious.com'
C.EmailEvents | where DeliveryAction != 'Blocked' | join kind=inner EmailUrlInfo on Name | where Url == 'https://malicious.com'
D.EmailEvents | where DeliveryAction != 'Blocked' | join kind=inner EmailUrlInfo on SenderFromDomain | where Url == 'https://malicious.com'
AnswerA

This query is correct because it uses an inner join on NetworkMessageId, the unique identifier for a single email message in both EmailEvents and EmailUrlInfo. Filtering DeliveryAction != 'Blocked' first limits the result set to messages that were delivered or otherwise not prevented, then the inner join ensures only events with a matching URL record in EmailUrlInfo survive. Finally, the where clause on Url after the join safely filters for the exact malicious URL without risking null values that would appear with an outer join.

Why this answer

Option A is correct because it uses an inner join on NetworkMessageId, which is the proper key. However, Option B also produces the desired result: the leftouter join retains all delivered emails, but the `where Url == 'https://malicious.com'` predicate excludes rows where no matching URL was found (since null Url does not equal the target). Thus B's result set is identical to A's.

Options C and D join on incorrect keys. In practice, inner join is more efficient, but B is not logically wrong.

Exam trap

The trap should not claim that leftouter join includes all delivered emails after a Url filter; the filter removes them. The real trap is selecting an incorrect join key (Name or SenderFromDomain) from options C/D.

How to eliminate wrong answers

Option B is wrong because a `leftouter` join would include all delivered emails even if they have no matching URL in `EmailUrlInfo`, and the subsequent `where Url == 'https://malicious.com'` would filter those nulls out, but it is less efficient and conceptually incorrect for this requirement (inner join is appropriate since we only want emails with the URL). Option C is wrong because it joins on `Name`, which is not a common key between `EmailEvents` and `EmailUrlInfo`; the correct join key is `NetworkMessageId`. Option D is wrong because it joins on `SenderFromDomain`, which is not a unique identifier for individual emails and would produce incorrect matches across different emails from the same domain.

759
MCQhard

Your Microsoft Defender XDR environment is experiencing high false positive rates for a specific type of alert. You need to reduce the noise without completely disabling the alert. What is the most effective method?

A.Create a custom detection rule to tune the detection logic.
B.Create a suppression rule for the alert.
C.Use an automation rule to automatically close the false positive incidents.
D.Disable the built-in detection rule.
AnswerA

Creating a custom detection rule in Microsoft 365 Defender lets you modify the underlying KQL query, schedule, and thresholds that govern when an alert triggers. This fine-grained approach directly addresses the detection logic responsible for false positives while preserving the rule’s intended coverage. Unlike suppression or automation, this reduces alert noise at the source, ensuring only relevant events generate incidents, and it keeps the original built-in rule available for baseline comparison.

Why this answer

Creating a custom detection rule allows you to refine the detection logic by adding specific conditions, such as excluding known benign processes or IP addresses, thereby reducing false positives while retaining the alert's core detection capability. This approach directly tunes the detection mechanism rather than masking or disabling it, aligning with the goal of reducing noise without completely disabling the alert.

Exam trap

The trap here is that candidates often confuse suppression rules (which hide alerts) with tuning the detection logic itself, leading them to choose Option B because they think hiding the alert is equivalent to reducing noise, but it does not reduce the underlying detection rate or resource consumption.

How to eliminate wrong answers

Option B is wrong because a suppression rule hides the alert from the console but does not prevent the underlying detection logic from firing, meaning the false positive alert is still generated and consumes resources, just not displayed. Option C is wrong because an automation rule that automatically closes false positive incidents only addresses the aftermath (incident lifecycle) without reducing the underlying detection rate, so the alert still fires and creates unnecessary workload. Option D is wrong because disabling the built-in detection rule completely eliminates the alert, which contradicts the requirement to reduce noise without completely disabling the alert.

760
Multi-Selecthard

Which THREE actions can you take in Microsoft Sentinel to respond to an incident?

Select 3 answers
A.Assign the incident to a user
B.Create an automation rule
C.Run a playbook
D.Modify a KQL query in an analytics rule
E.Export logs to Azure Storage
AnswersA, B, C

Assigning an incident to a user is a valid incident management action that designates an owner responsible for investigation and resolution. It establishes accountability, enables tracking of workload, and allows metrics to be based on individual or team performance, all within the Microsoft Sentinel incident workspace.

Why this answer

Assigning an incident to a user is a core incident response action in Microsoft Sentinel. It establishes ownership, ensuring a specific analyst is responsible for investigation and remediation. This action is performed directly from the incident details pane and is a fundamental step in managing the incident lifecycle.

Exam trap

The trap here is that candidates confuse actions that configure detection (like modifying analytics rules) or manage data (like exporting logs) with direct incident response actions, which are limited to triage, investigation, and remediation steps within the incident interface.

761
MCQmedium

You are a SOC analyst using Microsoft Defender XDR. An incident named 'Suspicious PowerShell download' is assigned to you. You need to quickly determine the initial entry point and the scope of affected devices. Which action should you perform first within the incident?

A.Export the incident details to a CSV file for offline analysis.
B.Initiate an automated investigation to remediate the threat.
C.Run an advanced hunting query to list all devices with PowerShell events.
D.Review the incident timeline to identify the first alert and related entities.
AnswerD

The incident timeline in Microsoft Defender XDR aggregates alerts and activities chronologically, helping you pinpoint the initial alert and affected entities. This provides the entry point and scope, enabling efficient triage. Other options may be useful later but do not directly answer the immediate need.

Why this answer

The incident timeline in Microsoft Defender XDR provides a chronological view of alerts and activities, allowing analysts to quickly identify the initial alert and affected entities. This is critical for understanding the entry point and scope before taking further action. Other options, while valid later, do not directly address the immediate need for triage.

Exam trap

The trap here is assuming that advanced hunting or automated investigation should be the first step, when in fact the timeline provides the quickest contextual overview.

762
MCQmedium

Your company uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You need to ensure that when a device is determined to be compromised, the device is automatically isolated from the network and a Sentinel incident is updated with the isolation status. What is the most efficient way to achieve this?

A.Have the SOC analyst manually isolate the device from the MDE console and update the incident in Sentinel
B.Configure Microsoft Intune to automatically isolate the device when a compliance policy is violated
C.Use Microsoft Defender XDR conditional access to block the device
D.Create a Microsoft Sentinel automation rule with a playbook that isolates the device and updates the incident
AnswerD

A Sentinel automation rule can be configured to trigger on incident creation or update, and an associated playbook—an Azure Logic Apps workflow—calls the Microsoft Defender for Endpoint connector to perform a device isolation action while simultaneously updating the Sentinel incident with the isolation status and any analyst notes. This replaces manual steps with orchestration, enabling a consistent and auditable response that eliminates the delay separating detection from containment. The rule can be scoped by severity, entity type, or other conditions, and the playbook can also add a comment to the incident so the SOC can track that the isolation was executed automatically.

Why this answer

It leverages Microsoft Sentinel's automation capabilities to respond to security incidents without manual intervention. By creating an automation rule that triggers a playbook (an Azure Logic Apps workflow), you can automatically isolate a compromised device via Microsoft Defender for Endpoint APIs and simultaneously update the Sentinel incident with the isolation status. This provides the most efficient, end-to-end automated response directly within the security operations workflow.

Exam trap

The trap here is that candidates may confuse Microsoft Intune compliance policies or conditional access with automated incident response actions, not realizing that only a Sentinel automation rule with a playbook can directly orchestrate both device isolation and incident update in a single, efficient workflow.

How to eliminate wrong answers

Option A is wrong because manual isolation and incident update are inefficient, error-prone, and do not meet the requirement for an automated response. Option B is wrong because Microsoft Intune compliance policies are designed for device configuration and health checks, not for real-time incident response to a compromise detected by Defender for Endpoint; Intune cannot trigger isolation based on a Defender alert. Option C is wrong because Microsoft Defender XDR conditional access controls access to cloud apps based on risk, but it does not perform network isolation of a device or update a Sentinel incident; it is a conditional access policy, not an automated response action.

763
MCQhard

A security administrator receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request from a domain controller. The alert suggests a possible Golden Ticket attack. Which action should the administrator take to validate the alert?

A.Review Microsoft Defender for Identity alerts for brute force attempts.
B.Check the domain controller's Security event log for Event ID 4769 with suspicious attributes.
C.Reset the krbtgt account password twice.
D.Verify if the user account associated with the ticket is disabled.
AnswerB

Checking the domain controller's Security event log for Event ID 4769 is the correct validation step because this event records every Kerberos service ticket request. In a Golden Ticket attack, the attacker uses a forged TGT to request service tickets, so Event ID 4769 entries will show anomalies such as unusual encryption types (e.g., RC4 when AES is expected), unexpected service names, or client IP addresses that don't align with normal behavior. These anomalies confirm that a forged ticket is being presented.

Why this answer

Event ID 4769 (Kerberos Service Ticket Request) on a domain controller is the authoritative source for validating suspicious ticket requests. In a Golden Ticket attack, the forged ticket often exhibits anomalous attributes such as an unusually long lifetime, a non-existent or disabled user account, or encryption type mismatches (e.g., RC4 when AES is expected). Reviewing this log directly confirms whether the ticket characteristics deviate from normal Kerberos behavior, providing definitive evidence for the alert.

Exam trap

The trap here is that candidates confuse validation steps with remediation actions, specifically choosing to reset the krbtgt password (Option C) before confirming the attack through log analysis, which would destroy forensic evidence and fail to validate the alert.

How to eliminate wrong answers

Option A is wrong because brute force attempts relate to password guessing or credential stuffing, not the validation of a forged Kerberos ticket; Golden Ticket attacks involve forged TGTs, not repeated authentication failures. Option C is wrong because resetting the krbtgt account password twice is a remediation step to invalidate existing Golden Tickets after an attack is confirmed, not a validation action to determine if the alert is legitimate. Option D is wrong because while a disabled user account might be a clue, it is not a definitive validation step; the ticket could be forged for an enabled account, and the primary validation requires examining the Kerberos service ticket request details in Event ID 4769.

764
MCQeasy

An organization has connected a Palo Alto Networks firewall to Microsoft Sentinel using the Common Event Format (CEF) connector via a Linux log forwarder. The analyst notices that some expected firewall logs are missing in Sentinel. Which troubleshooting step should be performed first to check if the logs are reaching the Sentinel workspace?

A.Run a KQL query in the Sentinel Logs workspace: CommonSecurityLog | where TimeGenerated > ago(1h) | take 10
B.Check the firewall configuration to ensure syslog forwarding is enabled and pointing to the correct Linux forwarder
C.Verify network connectivity between the firewall and the Linux forwarder on port 514 (or the configured port)
D.Restart the Log Analytics agent on the Linux forwarder
AnswerA

Querying CommonSecurityLog with a simple KQL filter for the last hour directly verifies whether Palo Alto CEF messages have been parsed and ingested into the Log Analytics workspace that backs Sentinel. Because CommonSecurityLog is the target schema for third-party syslog/CEF sources, seeing any rows proves the full pipeline (firewall, forwarder, agent, workspace) is functionally delivering data, making this the correct confirmatory test.

Why this answer

The first step in troubleshooting missing logs in Microsoft Sentinel is to verify whether the logs are actually reaching the workspace. Running a KQL query against the CommonSecurityLog table (which stores CEF data) with a recent time filter confirms if any CEF logs have been ingested. If the query returns results, the issue lies elsewhere (e.g., parsing or missing events); if it returns no results, the problem is upstream (connector, forwarder, or source).

This step isolates the problem to the Sentinel ingestion pipeline before investigating network or configuration issues.

Exam trap

The trap here is that candidates often jump to checking the source (firewall) or network connectivity first, but Microsoft Sentinel expects you to start by verifying data ingestion at the workspace level using KQL, as this immediately confirms whether the entire pipeline is working or broken.

How to eliminate wrong answers

Option B is wrong because checking the firewall’s syslog forwarding configuration is a downstream step that should only be taken after confirming logs are not reaching the workspace; it assumes the issue is at the source, but the first diagnostic step must be at the destination (Sentinel). Option C is wrong because verifying network connectivity between the firewall and the Linux forwarder on port 514 is also a downstream step; if logs are reaching the forwarder but not Sentinel, the network between forwarder and Sentinel (or the agent) is the real issue. Option D is wrong because restarting the Log Analytics agent is a reactive, brute-force action that does not provide diagnostic information; it may temporarily mask the problem but does not help identify whether logs are reaching the workspace.

765
MCQeasy

A security analyst in your SOC receives an alert from Microsoft Defender for Cloud Apps indicating that a user downloaded a large number of files from SharePoint in a short time. What is the most likely classification of this activity?

A.Ransomware
B.Lateral movement
C.Data exfiltration
D.Privilege escalation
AnswerC

Bulk downloading many files from a host, especially under a security alert, strongly indicates that an attacker is collecting and removing sensitive data. This aligns with the MITRE ATT&CK exfiltration technique (TA0010), where data is transferred out of the environment via HTTP/S, cloud storage, email, or removable media. The volume and pattern of file downloads make data exfiltration the most reasonable and supported conclusion.

Why this answer

A sudden, large-volume download of files from SharePoint within a short time window is a classic indicator of data exfiltration. Microsoft Defender for Cloud Apps uses anomaly detection policies to flag such activity based on user baseline behavior, download velocity, and the total number of files accessed, which aligns with the exfiltration phase of the cyber kill chain.

Exam trap

The trap here is that candidates may confuse bulk file downloads with ransomware activity (Option A) because both involve unusual file operations, but ransomware focuses on encryption/modification, not exfiltration, and Defender for Cloud Apps has separate detections for each behavior.

How to eliminate wrong answers

Option A is wrong because ransomware typically manifests as file encryption, renaming, or mass deletion, not simply bulk downloads; Defender for Cloud Apps would detect ransomware via file modification patterns or encryption alerts. Option B is wrong because lateral movement involves an attacker moving between hosts or accounts within the network (e.g., using RDP, SMB, or pass-the-hash), not downloading files from a cloud app. Option D is wrong because privilege escalation refers to gaining higher-level permissions (e.g., from user to admin), whereas the described activity is a data access pattern that does not inherently involve permission changes.

766
MCQeasy

A large organization manages multiple Azure subscriptions under a single management group. The security team wants to ensure that when new subscriptions are added to the management group, the Microsoft Defender for Cloud plans (e.g., Defender for Servers) are automatically enabled. What is the most efficient way to achieve this?

A.Assign the Azure Policy initiative 'Configure Azure Defender to be enabled on subscriptions' to the management group with appropriate policy parameters.
B.Enable all Microsoft Defender plans at the management group level in the Microsoft Defender for Cloud portal.
C.Manually enable the Defender plans on each new subscription as they are created.
D.Use an Azure Blueprint to assign the Defender plans to the subscription.
AnswerA

This built-in policy initiative uses DeployIfNotExists effects to enable Microsoft Defender for Cloud plans across all subscriptions within the management group's hierarchy. Because Azure Policy assignments are inherited and continuously evaluated, any subscription added later automatically receives the Defender plans without manual intervention. Assigning parameters lets you control which plans (e.g., SQL, Storage, Key Vault) are enabled, while the policy's remediation task ensures existing non-compliant subscriptions are brought into compliance.

Why this answer

Assigning the built-in Azure Policy initiative 'Configure Azure Defender to be enabled on subscriptions' to the management group ensures that any new subscription added under that management group automatically inherits the policy. This initiative uses DeployIfNotExists effect to enable the specified Defender plans (e.g., Defender for Servers) on subscriptions that do not already have them enabled, providing a fully automated, scalable solution without manual intervention.

Exam trap

The trap here is that candidates often confuse the 'Enable at management group level' portal setting (which only applies to existing subscriptions) with the automatic inheritance behavior of Azure Policy, leading them to choose Option B.

How to eliminate wrong answers

Option B is wrong because enabling Defender plans at the management group level in the Microsoft Defender for Cloud portal only applies to existing subscriptions under that management group; it does not automatically enable plans on newly added subscriptions. Option C is wrong because manually enabling Defender plans on each new subscription is inefficient, error-prone, and does not scale for a large organization with frequent subscription creation. Option D is wrong because Azure Blueprints are used to define and deploy a repeatable set of Azure resources and policies, but they require explicit assignment to each subscription and do not automatically propagate to new subscriptions added to the management group; Azure Policy is the native, more efficient mechanism for automatic inheritance.

767
MCQmedium

A security administrator needs to ensure that only approved applications can run on a set of Windows Server virtual machines. The administrator has already enabled Microsoft Defender for Cloud's enhanced security features. Which Defender for Cloud feature should the administrator configure to define a list of allowed applications and get alerts when unapproved applications are executed?

A.Adaptive Application Controls
B.File Integrity Monitoring (FIM)
C.Just-in-Time VM Access (JIT)
D.Vulnerability Assessment
AnswerA

Correct: Adaptive Application Controls, part of Microsoft Defender for Cloud, leverages machine learning to establish a baseline of normal application usage on each VM. It then creates an allowlist of known-good executables based on file provenance, path, and publisher, and triggers security alerts when an application outside that baseline attempts to run. Administrators can optionally enforce a deny rule to block such executions.

Why this answer

Adaptive Application Controls (AAC) is the correct feature because it uses machine learning to establish a baseline of known-safe processes on your Windows Server VMs, then enforces an allowlist so that only those approved applications can run. When an unapproved application is executed, AAC generates a security alert in Microsoft Defender for Cloud, meeting the requirement to both define allowed applications and receive alerts on violations.

Exam trap

The trap here is that candidates confuse 'application control' with 'file integrity monitoring' because both deal with files, but FIM only alerts on changes to existing files, not on execution of new unapproved applications.

How to eliminate wrong answers

Option B (File Integrity Monitoring) is wrong because FIM monitors changes to critical files, registry keys, and software installations, but it does not enforce an application allowlist or alert on unapproved application execution; it focuses on integrity changes. Option C (Just-in-Time VM Access) is wrong because JIT controls network access to management ports (like RDP or SSH) by reducing exposure, not by controlling which applications can run on the VM. Option D (Vulnerability Assessment) is wrong because VA scans for known vulnerabilities and misconfigurations in the OS and applications, but it does not define or enforce an allowlist of approved applications.

768
MCQmedium

A security operations center (SOC) team uses Microsoft Defender XDR and Microsoft Sentinel. An incident is created in Defender XDR that involves a malicious email and a compromised device. The team wants the incident to automatically sync to Sentinel. What is the minimum configuration required?

A.Configure the Microsoft Defender for Office 365 connector in Sentinel
B.Configure the Azure AD Identity Protection connector in Sentinel
C.Configure the Microsoft Defender XDR connector in Sentinel
D.Configure the Microsoft 365 Defender connector in Sentinel
AnswerC

The Microsoft Defender XDR connector streams incidents and alerts from Defender XDR into Microsoft Sentinel, automatically creating matching incidents. Enabling it is the minimum configuration; analytics rules or playbooks are unnecessary for the sync itself.

Why this answer

The Microsoft Defender XDR connector in Microsoft Sentinel is the dedicated connector that ingests incidents and advanced hunting events from all Defender XDR workloads (Defender for Endpoint, Office 365, Identity, Cloud Apps) and syncs them into Sentinel. Because the incident spans email and device, only the unified Defender XDR connector provides the cross-workload incident stream required for automatic synchronization.

Exam trap

SC-200 often tests the distinction between individual workload connectors and the unified Microsoft Defender XDR connector, tricking candidates into choosing a workload-specific connector for a cross-domain incident.

How to eliminate wrong answers

Option A is wrong because the Defender for Office 365 connector only brings email-related signals and does not sync the full cross-domain incident. Option B is wrong because Azure AD Identity Protection only covers identity risk detections, not email or device incidents. Option D is wrong because 'Microsoft 365 Defender' is the former name of the suite; the current connector in Sentinel is named 'Microsoft Defender XDR', and selecting the legacy name does not provide the unified incident sync.

769
MCQeasy

Your company uses Microsoft Sentinel with the Microsoft Defender for Cloud Apps connector. An incident is created when a user performs an unusual mass download from SharePoint Online. The playbook assigned to the incident automatically suspends the user account in Microsoft Entra ID. However, after investigation, the user's activity is determined to be legitimate (they were backing up data for a migration). You need to restore the user's account and ensure that the user can access all resources immediately. You also need to update the incident to reflect the findings. What should you do?

A.Send a new invitation to the user via Microsoft Entra ID and close the incident as resolved.
B.Reset the user's password in Microsoft Entra ID and force a password change at next sign-in.
C.Edit the playbook to remove the suspend action and re-run it for the incident.
D.Re-enable the user account in Microsoft Entra ID and set the incident status to Closed with classification 'False positive'.
AnswerD

Once the analyst determines the alert is a false positive, the correct remediation is to re-enable the user account by setting accountEnabled back to true in Microsoft Entra ID, restoring the user's access to Entra ID-protected resources. After making that change, the incident should be closed with classification 'False positive' and a comment documenting that the suspension was erroneous. These two steps together restore service and provide accurate reporting for tuning the analytics rule that caused the false trigger.

Why this answer

The user account was suspended by the playbook, so you must manually re-enable it in Microsoft Entra ID to restore access immediately. Setting the incident status to 'Closed' with classification 'False positive' accurately reflects that the alert was triggered by legitimate activity, which is the proper way to close a false positive in Microsoft Sentinel.

Exam trap

The trap here is that candidates may think re-running the playbook (Option C) will undo the suspension, but playbooks are not idempotent for reversing actions; they only execute the defined steps at trigger time and cannot retroactively modify past state.

How to eliminate wrong answers

Option A is wrong because sending a new invitation is used for inviting external users or resetting B2B collaboration, not for re-enabling a suspended internal user account. Option B is wrong because resetting the password does not re-enable a suspended account; the account remains disabled until explicitly enabled, and forcing a password change does not restore access. Option C is wrong because editing the playbook and re-running it for the incident would not retroactively unsuspend the user; playbooks execute actions at the time of incident creation and cannot reverse past actions on the same incident.

770
MCQmedium

You are a threat hunter in a Microsoft Sentinel environment that ingests both Microsoft Defender XDR and third-party network logs. You want to build a reusable hunting query that surfaces failed authentication attempts from IP addresses that have never before been associated with successful sign-ins in your tenant. Which KQL operator should you use to correlate the two datasets and return only the novel source IPs?

A.union of SigninLogs and the successful sign-in set
B.summarize count() by IPAddress on SigninLogs only
C.leftanti join between SigninLogs and the successful sign-in set
D.inner join between SigninLogs and the successful sign-in set
AnswerC

A leftanti join returns rows from the left table that have no match in the right table. By joining failed sign-in records against the historical successful sign-in IP set, you get exactly the source IPs with failures but no prior success, which is the novel-IP condition the hunt requires.

Why this answer

The hunt hypothesis depends on identifying source IPs that generate failures but have no history of successful authentication. A leftanti join preserves the left-side failed sign-in rows and drops any whose IP key appears in the right-side success set, yielding the novel addresses the analyst wants to investigate further.

Exam trap

The trap here is assuming an inner join is needed to correlate datasets, when the requirement is to exclude known-good IPs and only a leftanti join preserves unmatched left-side rows.

771
MCQmedium

Your security team receives alerts from Microsoft Defender for Cloud. You need to configure automated response to remediate a specific alert type. What should you create in Microsoft Sentinel?

A.An analytics rule
B.A workbook
C.A watchlist
D.An automation rule
AnswerD

An automation rule is the correct answer because it is specifically designed to centralize incident-handling automation in Microsoft Sentinel. When a Defender alert triggers incident creation, an automation rule can evaluate conditions and execute actions such as running an Azure Logic Apps playbook, assigning ownership, sending tags, or changing severity. Unlike analytics rules—which only detect—automation rules are incident-based triggers that orchestrate the response workflow. This directly satisfies the goal of automating responses to alerts.

Why this answer

In Microsoft Sentinel, automation rules are the correct mechanism to define automated responses triggered by alerts, including those from Microsoft Defender for Cloud. They allow you to run playbooks, change incident severity, assign ownership, or add comments when a specific alert type fires, enabling remediation without manual intervention.

Exam trap

The trap here is that candidates often confuse 'automation rule' with 'analytics rule', mistakenly thinking the rule that generates the alert can also handle the response, but Sentinel separates detection (analytics rules) from response (automation rules).

How to eliminate wrong answers

Option A is wrong because analytics rules are used to generate alerts or incidents from raw data (e.g., querying Log Analytics), not to automate responses to existing alerts. Option B is wrong because workbooks are interactive dashboards for visualizing data, not for triggering automated remediation actions. Option C is wrong because watchlists are collections of data (e.g., IP addresses or hostnames) used for correlation or filtering in queries, not for executing response actions.

772
MCQmedium

Refer to the exhibit. You are creating a scheduled analytics rule in Microsoft Sentinel using the ARM template snippet. The rule runs every 5 minutes and queries the last 5 minutes of data. The rule is not generating alerts even though malware detections are occurring. What is the most likely issue?

A.The queryPeriod and queryFrequency are the same, causing overlapping windows.
B.The triggerThreshold is set to 0, which should always trigger.
C.The ARM template is missing the required 'kind' property.
D.The table DeviceEvents is not ingested into the Log Analytics workspace.
AnswerD

The rule queries DeviceEvents, so if that table is never ingested into the Log Analytics workspace, the query returns no rows and no alerts fire despite real malware activity. Missing ingestion is the constraint that silently breaks detection.

Why this answer

DeviceEvents is a table from Microsoft Defender for Endpoint, but it is not automatically available in Microsoft Sentinel's Log Analytics workspace. The data connector for Microsoft Defender for Endpoint must be configured and the table must be mapped to Sentinel's workspace. Without this, the query runs against an empty table, returning no results, so the rule never triggers (even with triggerThreshold of 0).

Option A is incorrect: having queryPeriod and queryFrequency both set to 5 minutes is standard for a rule that runs every 5 minutes looking at the last 5 minutes; it does not cause overlapping windows. Option B is incorrect: triggerThreshold of 0 means any result should trigger an alert, but if there are no results due to missing data, the rule won't fire. Option C is incorrect: the ARM template snippet would include the required 'kind' property for a scheduled rule; its absence is not the issue here.

Exam trap

Candidates may assume that any table referenced in a query is automatically available in the Log Analytics workspace, but custom or advanced hunting tables from Microsoft Defender require explicit data connectors to be enabled.

773
MCQmedium

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You have configured the Microsoft Defender for Endpoint connector in Sentinel to ingest alerts and incidents. The security team wants to automatically create a Sentinel incident when an MDE alert of severity 'High' or 'Critical' is generated. Additionally, they want to assign the incident to a specific SOC tier based on the alert title. For example, if the alert title contains 'Ransomware', assign to Tier 3; otherwise assign to Tier 2. You need to implement this automation efficiently. You have already enabled the connector and verified that MDE alerts are flowing into Sentinel. What is the best approach?

A.Create an automation rule that triggers when an incident is created with a condition on alert severity, and set the owner to the appropriate group. Then create another automation rule for 'Ransomware' alerts.
B.Configure an automation rule with a condition on the alert title using KQL, then set the owner.
C.Create an automation rule that triggers on incident creation for High and Critical severity. The rule runs a playbook that uses Logic Apps to parse the alert title and assign the incident to the appropriate tier using the Microsoft Sentinel connector 'Update incident' action.
D.Modify the Microsoft Defender for Endpoint analytics rule to include a custom mapping that assigns the incident to a specific owner based on the alert title.
AnswerC

An automation rule fires on incident creation filtered to High and Critical severity, then invokes a playbook whose Logic Apps condition parses the alert title and assigns the tier via the Update incident action, meeting both routing requirements.

Why this answer

The requirement is conditional logic based on alert title ('Ransomware' → Tier 3, otherwise Tier 2), which cannot be expressed with simple automation-rule conditions alone. An automation rule can trigger on incident creation and filter by severity, then invoke a playbook; the playbook (Logic Apps) can parse the alert title and use the Microsoft Sentinel 'Update incident' action to set the owner to the correct tier. This combines Sentinel's native automation rule engine with Logic Apps' flexible conditional branching.

Exam trap

SC-200 often tests the boundary between automation rules and playbooks — candidates assume automation rules can do conditional string parsing or run KQL, but only playbooks (Logic Apps) can execute that kind of branching logic.

How to eliminate wrong answers

Option A is wrong because automation rules cannot natively branch on substring matching of the alert title to assign different owners — you would need two rules and even then the 'otherwise' fallback logic is awkward and error-prone. Option B is wrong because automation rule conditions do not support KQL queries against alert properties; conditions are limited to simple property comparisons (severity, title contains, etc.), and 'contains' alone cannot implement the if/else tier assignment. Option D is wrong because MDE analytics rules in Sentinel do not support custom owner mapping based on alert title — entity mapping and incident creation settings do not include dynamic owner assignment logic.

774
MCQeasy

A security analyst is reviewing an incident in Microsoft 365 Defender where malware was detected on multiple endpoints. The analyst wants to see a visual representation of the attack progression, including the initial entry point and all affected devices. Which feature in the Microsoft 365 Defender portal should the analyst use?

A.Incident graph
B.Advanced hunting
C.Threat analytics
D.Action center
AnswerA

The Incident graph is correct because Microsoft 365 Defender automatically assembles a visual map of the entire attack chain for the selected incident. It displays related alerts, affected users, devices, and suspicious entities as connected nodes, with edges representing the sequence of events and relationships. This pre-built, interactive graph gives analysts an immediate high-level attack narrative without requiring custom queries.

Why this answer

The incident graph in Microsoft 365 Defender provides a visual, interactive map of the entire attack progression, showing the initial entry point, lateral movement, and all affected devices and users. It correlates alerts and evidence into a single timeline, enabling the analyst to understand the full scope of the incident at a glance. This directly meets the requirement for a visual representation of the attack progression.

Exam trap

The trap here is that candidates confuse the incident graph (visual attack path) with Advanced hunting (raw data querying) because both are used for investigation, but only the graph provides a pre-built visual map of the attack progression.

How to eliminate wrong answers

Option B (Advanced hunting) is wrong because it is a query-based tool for searching raw data using Kusto Query Language (KQL), not a visual representation of an attack progression. Option C (Threat analytics) is wrong because it provides reports on active threats, vulnerabilities, and mitigations, but does not show the specific attack path for a given incident. Option D (Action center) is wrong because it lists pending and completed remediation actions (e.g., isolating devices, running antivirus scans), not a visual attack timeline or device map.

775
MCQeasy

A SOC analyst needs to create a custom scheduled analytics rule in Microsoft Sentinel that detects when a user attempts to sign in from an IP address not in the organization's allowlist. The rule should run every 5 minutes. Which table should the analyst query?

A.SigninLogs
B.AADNonInteractiveUserSignInLogs
C.AuditLogs
D.AzureActivity
AnswerA

In Microsoft Sentinel, the SigninLogs table stores every interactive user sign-in event in Azure AD, including the user principal name, IP address utilized, application accessed, and result type (success/failure). Because the source IP is a first-class field in each event, a custom scheduled analytics rule can simply filter SigninLogs by the address in question and alert on any matches. This makes it the definitive data source for detecting sign-in attempts from specific IP addresses, whether they succeeded or were blocked.

Why this answer

The SigninLogs table in Microsoft Sentinel captures interactive user sign-in events, including the source IP address. Since the rule needs to detect user sign-in attempts from non-allowlisted IPs, SigninLogs is the correct table to query. It provides the necessary fields like UserPrincipalName, IPAddress, and ResultType to build the detection logic.

Exam trap

The trap here is that candidates may confuse AuditLogs or AzureActivity with sign-in logs, but only SigninLogs contains the interactive user sign-in data with source IP addresses needed for this detection.

How to eliminate wrong answers

Option B is wrong because AADNonInteractiveUserSignInLogs captures non-interactive sign-ins (e.g., service-to-service authentication), not the interactive user sign-in attempts the rule targets. Option C is wrong because AuditLogs records administrative actions and changes in Azure AD (e.g., user creation, role changes), not sign-in events. Option D is wrong because AzureActivity logs Azure resource management operations (e.g., VM creation, resource group changes), not user authentication events.

776
Multi-Selectmedium

Which TWO are recommended first steps when responding to a confirmed ransomware incident in Microsoft Defender XDR?

Select 2 answers
A.Assess the financial impact of the incident
B.Disable all user accounts
C.Run a full antivirus scan on all devices
D.Isolate affected devices using Microsoft Defender for Endpoint
E.Revoke user sessions and require reauthentication
AnswersD, E

Isolation severs the endpoint's network connectivity while preserving its volatile memory and forensic artefacts, immediately halting lateral spread and encryption across the estate. This containment step directly satisfies the stem's requirement for a recommended first response action in Microsoft Defender XDR before eradication or recovery begins.

Why this answer

The correct answers are D and E. Isolating affected devices using Microsoft Defender for Endpoint (D) and revoking user sessions to require reauthentication (E) are immediate containment steps to prevent further spread. Assessing financial impact (A) is part of investigation, not first response.

Disabling all user accounts (B) is too disruptive and not recommended as a first step. Running a full antivirus scan (C) may alert the attacker and is not a containment measure.

777
MCQhard

You are the security operations lead for a multinational company using Microsoft Sentinel. You have deployed a custom analytics rule that uses a KQL query to detect anomalous outbound network traffic. The rule runs every hour and looks back 24 hours. Recently, the rule has been generating a high number of false positives. You need to tune the rule to reduce false positives without missing genuine threats. The rule currently triggers when the count of outbound connections to a single IP exceeds 100 in an hour. You analyze the data and find that legitimate cloud services often trigger the rule. What should you do?

A.Disable the rule and create a new one with a different query.
B.Increase the threshold to 200 connections per hour.
C.Configure a suppression rule to automatically close incidents from those IPs.
D.Modify the KQL query to exclude traffic to known benign IP ranges.
AnswerD

Excluding known benign IP ranges directly addresses the false positives caused by legitimate cloud services, since those destinations are the recurring trigger. Filtering them within the KQL query preserves detection of genuine anomalous outbound traffic to other IPs, satisfying the requirement to reduce noise without missing real threats.

Why this answer

The most effective way to reduce false positives without missing genuine threats is to refine the KQL query to exclude traffic to known benign IP ranges, such as those belonging to legitimate cloud services. This preserves the detection logic for suspicious IPs while eliminating noise from trusted sources. It is a targeted tuning approach that maintains threat coverage.

Exam trap

SC-200 often tests the difference between tuning (refining the query) and suppressing (hiding alerts) — candidates must recognize that suppression can create blind spots, while query refinement is the preferred method.

How to eliminate wrong answers

Option A is wrong because disabling the rule and creating a new one with a different query is disruptive and may lose detection capability; tuning is preferred over replacement. Option B is wrong because simply increasing the threshold to 200 connections per hour is a blunt adjustment that could allow genuine threats with 150 connections to slip through, and it does not address the root cause of benign cloud service traffic. Option C is wrong because configuring a suppression rule to automatically close incidents from those IPs would suppress alerts even if those IPs later become malicious, creating a blind spot.

778
MCQhard

Your organization uses Microsoft Defender for Cloud with enhanced security features enabled. You need to ensure that all Azure subscriptions are covered by a single Defender for Cloud policy that enforces specific security standards. The policy must be automatically applied to new subscriptions. What should you do?

A.Enable the default Defender for Cloud policy from the Azure portal.
B.Manually assign the policy to each subscription using PowerShell.
C.Create a custom policy initiative and assign it to the root management group.
D.Configure the security contact email for each subscription.
AnswerC

Create a custom policy initiative—a group of custom policy definitions that expresses your organization's security requirements—and assign it at the root management group scope. Management-group assignments are inherited by every descendant management group and subscription, including subscriptions created later, giving tenant-wide enforcement from a single assignment. Defender for Cloud's regulatory compliance feature recognizes this custom initiative as a compliance standard and displays its results in the dashboard.

Why this answer

Assigning a custom policy initiative to the root management group ensures that the policy is inherited by all subscriptions under that management group, including new subscriptions as they are added. This approach enforces consistent security standards across the entire Azure environment without requiring manual intervention for each subscription.

Exam trap

The trap here is that candidates may think enabling the default Defender for Cloud policy (Option A) is sufficient for all subscriptions, but that only applies to the current subscription and does not enforce a custom standard or automatically cover new subscriptions.

How to eliminate wrong answers

Option A is wrong because enabling the default Defender for Cloud policy from the Azure portal only applies the built-in security policy to the current subscription, not to all subscriptions automatically, and does not enforce a single custom standard across multiple subscriptions. Option B is wrong because manually assigning the policy to each subscription using PowerShell does not automatically cover new subscriptions; each new subscription would require a separate manual assignment, defeating the requirement for automatic application. Option D is wrong because configuring the security contact email for each subscription only sets notification recipients for security alerts, not the enforcement of security standards or policies.

779
MCQeasy

Your organization uses Microsoft Sentinel. You need to provide a SOC analyst with the ability to create and modify incident comments but not delete incidents. Which role should you assign?

A.Global Administrator
B.Microsoft Sentinel Contributor
C.Microsoft Sentinel Reader
D.Microsoft Sentinel Responder
AnswerD

Microsoft Sentinel Responder grants full incident management — assigning, changing status, and creating or editing comments — but cannot delete incidents, which only the Contributor role permits. This matches the analyst's required permissions exactly while enforcing least privilege.

Why this answer

The Microsoft Sentinel Responder role is designed for SOC analysts who need to manage incidents, including adding and modifying comments, but not delete incidents. Microsoft Sentinel Contributor can delete incidents, so it is too permissive. Microsoft Sentinel Reader is read-only and cannot create or modify comments.

Global Administrator has full access to all resources, including the ability to delete incidents, which is excessive for this requirement.

780
MCQeasy

A security administrator needs to ensure that all newly provisioned Azure virtual machines automatically install the Microsoft Defender for Cloud agent (Log Analytics agent) to enable security monitoring. Which configuration should be enabled in Defender for Cloud?

A.Auto-provisioning of the Log Analytics agent
B.Enable the Defender for Servers plan
C.Configure a vulnerability assessment solution
D.Enable just-in-time (JIT) VM access
AnswerA

Auto-provisioning of the Log Analytics agent is the correct mechanism that Microsoft Defender for Cloud uses to automatically deploy the agent to Azure VMs. When this setting is enabled, Defender for Cloud installs the Log Analytics agent (or now Azure Monitor Agent) as a VM extension on both existing machines and every newly provisioned VM, and connects it to the selected Log Analytics workspace. This guarantees that security data is collected from all VMs without manual intervention, which is exactly what the requirement asks for.

Why this answer

Auto-provisioning of the Log Analytics agent in Microsoft Defender for Cloud automatically installs the Log Analytics agent (Microsoft Monitoring Agent) on all new Azure VMs. This ensures that security monitoring data, such as security events and syslog, is collected and sent to the Log Analytics workspace without manual intervention. The setting is found under 'Environment settings' > 'Auto provisioning' and must be toggled to 'On' for the agent to be deployed on newly provisioned VMs.

Exam trap

The trap here is that candidates confuse 'enabling the Defender for Servers plan' with automatic agent deployment, but the plan only enables threat detection capabilities and does not handle the agent installation process.

How to eliminate wrong answers

Option B is wrong because enabling the Defender for Servers plan activates advanced threat protection features (e.g., fileless attack detection, network-based detection) but does not automatically install the Log Analytics agent; the agent must be deployed separately or via auto-provisioning. Option C is wrong because configuring a vulnerability assessment solution (e.g., Qualys or Microsoft Defender Vulnerability Management) scans for software vulnerabilities but does not handle agent deployment for general security event collection. Option D is wrong because enabling just-in-time (JIT) VM access controls network access to management ports (e.g., RDP/SSH) and has no role in installing the Log Analytics agent for monitoring.

781
MCQeasy

Your organization uses Microsoft Defender for Cloud to protect hybrid cloud workloads. An alert indicates that a container in Azure Kubernetes Service (AKS) is running a privileged container. Which response action should you take first?

A.Investigate the alert details in Microsoft Defender for Cloud
B.Disable the container immediately
C.Restart the AKS cluster
D.Delete the container and its image
AnswerA

Investigation is the mandatory first step because Microsoft Defender for Cloud enriches AKS container alerts with the full attack story, affected pod and container identities, MITRE ATT&CK tactics, and associated entities. Opening the alert details lets you confirm whether the activity is a true positive, determine its severity and blast radius, and identify which subsequent containment or remediation action is safe. Proceeding before reviewing these details risks an incorrect response, which is why all other options are premature.

Why this answer

When a Microsoft Defender for Cloud alert indicates a privileged container in AKS, the first response action should be to investigate the alert details within Defender for Cloud. This allows you to assess the scope, impact, and context of the alert—such as which container, namespace, and pod is involved, and whether it is a false positive—before taking any disruptive remediation steps. Prematurely disabling, deleting, or restarting resources could destroy forensic evidence and escalate the incident unnecessarily.

Exam trap

The trap here is that candidates may think immediate containment (disabling or deleting) is always the correct first step, but Microsoft's incident response guidance emphasizes 'investigate first' to avoid destroying evidence and to ensure the response is proportional to the threat.

How to eliminate wrong answers

Option B is wrong because disabling the container immediately without investigation may remove critical forensic data and could disrupt legitimate workloads if the alert is a false positive. Option C is wrong because restarting the entire AKS cluster is an overly aggressive and disruptive action that does not address the specific privileged container and could cause widespread service downtime. Option D is wrong because deleting the container and its image prematurely destroys evidence needed for root cause analysis and may violate incident response procedures that require preservation of artifacts.

782
MCQeasy

You are a threat hunter in Microsoft Sentinel. You want to identify all devices that have communicated with a known malicious IP address (e.g., 203.0.113.5) over the past week. Which data source should you query to find network connection events?

A.DeviceNetworkEvents
B.AzureNetworkAnalytics_CL
C.CommonSecurityLog
D.Syslog
AnswerA

DeviceNetworkEvents in Microsoft Defender XDR (ingested into Microsoft Sentinel via the Defender XDR connector) provides detailed network connection events from endpoints, including remote IP addresses. Querying this table for the malicious IP will identify all devices that connected to it, directly fulfilling the hunting requirement.

Why this answer

DeviceNetworkEvents is the correct data source because it captures endpoint network connections, including remote IP addresses, and is available in Microsoft Sentinel through the Microsoft Defender XDR connector. Querying it for the malicious IP will reveal all devices that communicated with it. Other sources like CommonSecurityLog or Syslog may have some network data but are not as comprehensive or endpoint-focused.

Exam trap

The trap here is assuming that any network log source, such as CommonSecurityLog or AzureNetworkAnalytics_CL, will provide complete endpoint connection data, when only DeviceNetworkEvents offers the necessary endpoint-centric network telemetry.

783
MCQhard

While threat hunting, you find a suspicious scheduled task that runs a PowerShell script from a temp directory. You want to check if this task exists on other devices in the environment. Which Microsoft Defender for Endpoint advanced hunting table would you query?

A.DeviceProcessEvents
B.DeviceNetworkEvents
C.DeviceEvents
D.DeviceRegistryEvents
AnswerC

DeviceEvents records scheduled task creation and related process activity, including the task's action and initiating command line. Querying it surfaces matching PowerShell-from-temp-directory tasks across enrolled devices, letting you determine whether the suspicious task exists elsewhere in the estate.

Why this answer

The `DeviceEvents` table includes scheduled task creation events (ActionType: ScheduledTaskCreated). Option A is wrong because `DeviceProcessEvents` focuses on process execution, not task creation. Option B is wrong because `DeviceNetworkEvents` is for network connections.

Option D is wrong because `DeviceRegistryEvents` is for registry changes.

784
MCQeasy

Your organization is implementing Microsoft Sentinel. You need to ensure that security events from AWS CloudTrail are collected. What should you configure?

A.Azure Policy to audit AWS resources.
B.AWS S3 connector in Sentinel.
C.Microsoft Defender for Cloud to monitor AWS.
D.A REST API connector to call CloudTrail API.
AnswerB

The AWS S3 connector in Microsoft Sentinel is the native, documented data connector specifically built to ingest AWS CloudTrail logs. It works by configuring an Amazon S3 bucket to receive CloudTrail logs, with Simple Queue Service (SQS) providing real-time notifications that Sentinel's connector consumes to pull log data. This connector automatically maps CloudTrail records to the AWSCloudTrail table, enabling standard KQL queries, analytics rules, and incident handling. Because it is purpose-built for this exact use case, it is the correct and recommended solution.

Why this answer

The AWS S3 connector in Microsoft Sentinel is the correct solution because AWS CloudTrail logs are stored in an S3 bucket. Sentinel's native AWS S3 connector ingests these logs by polling the S3 bucket for new CloudTrail events, parsing them into the Sentinel workspace for security monitoring. This is the designated method for collecting CloudTrail data into Sentinel, as documented by Microsoft.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Cloud's AWS monitoring capabilities (which focus on security posture and alerts) with the log ingestion needed for Sentinel, leading them to choose Option C instead of the dedicated S3 connector.

How to eliminate wrong answers

Option A is wrong because Azure Policy is used to enforce compliance rules on Azure resources, not to ingest logs from external cloud providers like AWS. Option C is wrong because Microsoft Defender for Cloud can monitor AWS resources via AWS Security Hub integration, but it does not directly collect CloudTrail logs into Sentinel; Sentinel requires the S3 connector for that purpose. Option D is wrong because while CloudTrail has a REST API, Sentinel does not have a generic REST API connector for CloudTrail; the specific S3 connector is designed to handle the batch log delivery from S3, not real-time API calls.

785
MCQmedium

You are investigating a security incident in Microsoft Sentinel where a user reported receiving a phishing email with a malicious attachment. You need to identify all users who received the same email within the last 24 hours. Which KQL query should you use?

A.EmailEvents | where RecipientEmailAddress == 'user@contoso.com' and Timestamp > ago(24h) | project SenderFromAddress, Subject
B.EmailUrlInfo | where Url == 'http://malicious.com' | project RecipientEmailAddress
C.EmailAttachmentInfo | where FileName == 'malicious.doc' | project RecipientEmailAddress
D.EmailEvents | where SenderFromAddress == 'attacker@example.com' and Subject == 'Invoice' and Timestamp > ago(24h) | project RecipientEmailAddress
AnswerD

This retrieves all recipients who received the same email from the same sender and subject.

Why this answer

To find all users who received the same phishing email, you must pivot on the email's identifying attributes — sender and subject — rather than the reported recipient. Querying EmailEvents filtered by SenderFromAddress, Subject, and a 24-hour window, then projecting RecipientEmailAddress, returns every recipient of that campaign.

Exam trap

The trap is anchoring on the reported victim's email address — the exam tests whether you pivot on campaign identifiers (sender/subject) to find all recipients, not just query the one user who reported it.

How to eliminate wrong answers

Option A is wrong because filtering on the single reported recipient's address only returns that user's emails and cannot identify other recipients. Option B is wrong because EmailUrlInfo contains URL click/URL data and does not reliably enumerate all recipients of the email; it is keyed to URLs, not the campaign. Option C is wrong because EmailAttachmentInfo focuses on attachment metadata and, while it has recipient fields, it does not filter by sender/subject/time to scope the campaign and may miss recipients if the attachment name varies.

786
MCQeasy

An incident in Microsoft Sentinel was assigned to you. After investigation, you determine it is a false positive. What should you do to resolve the incident?

A.Add a comment and leave it open
B.Close the incident with classification 'FalsePositive'
C.Delete the incident
D.Reassign to another analyst
E.Change the status to 'Active'
AnswerB

Closing the incident with the classification 'FalsePositive' is the correct remediation because it formally resolves the incident, records that the detected activity was not malicious, and preserves the audit trail. In Microsoft Sentinel, this action updates the incident status to 'Resolved', stores the classification and closing reason in the incident record, and can trigger automation or analytics rule tuning to reduce future false positives.

Why this answer

In Microsoft Sentinel, when an incident is determined to be a false positive, the correct resolution is to close it with the classification 'FalsePositive'. This action properly documents the outcome, updates the incident status to 'Closed', and ensures the incident is tracked for reporting and analytics. Leaving it open or changing status to 'Active' does not resolve it, while deleting is not supported and reassignment does not address the determination.

Exam trap

The trap here is that candidates may think they can delete an incident to remove it from the queue, but Microsoft Sentinel does not allow deletion—only closure with a proper classification is supported.

How to eliminate wrong answers

Option A is wrong because adding a comment and leaving the incident open does not resolve it; incidents must be closed to indicate completion. Option C is wrong because Microsoft Sentinel does not support deleting incidents; they can only be closed or archived. Option D is wrong because reassigning to another analyst does not resolve the incident; it merely changes ownership without addressing the false positive determination.

Option E is wrong because changing the status to 'Active' would indicate the incident is still under investigation, which contradicts the conclusion that it is a false positive.

787
MCQeasy

As a security operations analyst, you receive an alert from Microsoft Defender for Identity about a suspicious Kerberos activity. You need to investigate the alert and determine if it is a true positive. What should you use to pivot from the alert to the related user and device timeline?

A.Search for the user in Azure AD audit logs.
B.Open the alert in Microsoft Sentinel and use the investigation graph.
C.From the Microsoft 365 Defender portal, open the alert and click on the user or device name to view their timeline.
D.Use the Microsoft 365 compliance portal to run an eDiscovery search.
AnswerC

The Microsoft 365 Defender portal is the native home for Defender for Identity alerts, and the alert page includes a direct link to the affected user's or device's entity page. Clicking that name opens a comprehensive timeline of that entity's activities, including LDAP queries, Kerberos ticket requests, remote logons, directory object modifications, and any other related security alerts. This timeline lets you quickly trace the attack chain, determine the full blast radius, and pivot to associated resources without having to manually query other logs or export data.

Why this answer

In the Microsoft 365 Defender portal, when you open a Microsoft Defender for Identity alert, you can directly click on the user or device name to pivot to their timeline. This timeline provides a consolidated view of activities, including Kerberos events, authentication attempts, and other related signals, enabling you to quickly assess whether the suspicious Kerberos activity is a true positive without leaving the portal.

Exam trap

The trap here is that candidates may assume they need to use a separate tool like Microsoft Sentinel or Azure AD audit logs for deeper investigation, but the exam tests the knowledge that the Microsoft 365 Defender portal provides a built-in, integrated timeline for direct pivoting from Defender for Identity alerts.

How to eliminate wrong answers

Option A is wrong because Azure AD audit logs focus on directory-level administrative actions (e.g., user creation, password changes) and do not include detailed Kerberos authentication events or device timelines needed for this investigation. Option B is wrong because while Microsoft Sentinel has an investigation graph, the question specifically asks about pivoting from a Defender for Identity alert; the native integration within the Microsoft 365 Defender portal provides the most direct and efficient path to the user and device timeline without requiring a separate SIEM. Option D is wrong because the Microsoft 365 compliance portal and eDiscovery are designed for legal and compliance searches (e.g., mailbox, SharePoint content), not for real-time security event investigation of Kerberos activity.

788
MCQmedium

You are a security analyst for a multinational company with Microsoft Sentinel deployed in a central workspace. You need to grant a team of analysts in the European branch the ability to view incidents and run queries, but they should not be able to modify analytics rules or data connectors. The team already has Microsoft Sentinel Reader role assigned. However, they report that they cannot run KQL queries in the Logs blade. You need to provide the minimum additional permissions. What should you do?

A.Assign the Log Analytics Contributor role to the team on the Sentinel workspace.
B.Assign the Microsoft Sentinel Contributor role to the team on the Sentinel workspace.
C.Assign the Log Analytics Reader role to the team on the Sentinel workspace.
D.Assign the Reader role to the team on the Sentinel workspace.
AnswerC

The Log Analytics Reader role grants the ability to read all data in the Log Analytics workspace and, crucially, to execute KQL queries against that data. Because Microsoft Sentinel stores its security logs in a Log Analytics workspace, this role provides exactly the query capability the hunting team needs. It is a read-only role that does not allow modifications to the workspace or its settings, making it the least-privileged assignment that satisfies the requirement.

Why this answer

The Microsoft Sentinel Reader role grants read access to Sentinel data, including incidents, but does not include the ability to run KQL queries in the Logs blade because that requires read permissions on the underlying Log Analytics workspace. The Log Analytics Reader role provides the necessary read access to log data and the ability to execute queries without granting write permissions to analytics rules or data connectors, fulfilling the requirement with minimal privileges.

Exam trap

The trap here is that candidates assume the Microsoft Sentinel Reader role is sufficient for all read operations, but they overlook that running KQL queries in the Logs blade requires separate Log Analytics read permissions, which is a common cross-service dependency tested in SC-200.

How to eliminate wrong answers

Option A is wrong because Log Analytics Contributor role includes write permissions to the Log Analytics workspace, which would allow modifying data connectors and other settings, exceeding the required minimal permissions. Option B is wrong because Microsoft Sentinel Contributor role grants full write access to Sentinel resources, including analytics rules and data connectors, which violates the requirement that the team should not be able to modify these components. Option D is wrong because the Reader role at the Sentinel workspace level does not include the Log Analytics Reader permissions needed to run KQL queries in the Logs blade; it only provides read access to Sentinel-specific resources like incidents and workbooks.

789
MCQeasy

As a threat hunter, you want to use MITRE ATT&CK techniques to categorize detected behaviors. In Microsoft Sentinel, which feature allows you to map alerts to MITRE techniques automatically?

A.Analytics rules
B.Playbooks
C.Watchlists
D.Workbooks
AnswerA

Analytics rules in Microsoft Sentinel include a MITRE ATT&CK mapping section where each rule's tactics and techniques are configured. When the rule fires, generated incidents and alerts inherit those technique tags automatically, satisfying the requirement to categorise detected behaviours without manual enrichment.

Why this answer

Analytics rules in Microsoft Sentinel allow you to map alerts to MITRE ATT&CK techniques automatically. When creating or editing an analytics rule, you can select the relevant MITRE ATT&CK tactic and technique, which enriches the alert with threat intelligence context. Workbooks (Option D) are for visualization, not mapping.

Playbooks (Option B) are for automated response. Watchlists (Option C) are for reference data. Therefore, Option A is correct.

790
MCQeasy

A security analyst needs to create a custom watchlist in Microsoft Sentinel to correlate IP addresses known to be used by a threat actor. The watchlist will be uploaded from a CSV file. Which data type should the analyst specify for the watchlist alias?

A.String
B.Integer
C.DateTime
D.Boolean
AnswerA

IP addresses are represented as strings because they are sequences of characters using dotted-decimal notation for IPv4 or hexadecimal and colons for IPv6. In Microsoft Sentinel watchlists, the String data type supports exact match, pattern matching, and CIDR range comparisons when used with KQL functions like ipv4_is_in_range. Unlike numeric types, String preserves the original formatting, including leading zeros and subnet masks, which is essential for accurate network security matching.

Why this answer

The watchlist alias in Microsoft Sentinel is a string identifier used to reference the watchlist in KQL queries. Since IP addresses are stored as text values in CSV files and are not numeric integers, dates, or boolean flags, the correct data type for the alias is String. This ensures the alias can be used in join or lookup operations without type mismatch errors.

Exam trap

The trap here is that candidates may confuse the data type of the alias with the data type of the IP address values in the CSV, assuming IPs should be integers, but the alias is purely a metadata label and must be a string.

How to eliminate wrong answers

Option B is wrong because Integer is a numeric data type, but IP addresses are not integers and cannot be meaningfully represented as such without conversion. Option C is wrong because DateTime is used for date/time values, not for IP addresses which are textual identifiers. Option D is wrong because Boolean is a true/false data type, which cannot represent an IP address or serve as a watchlist alias.

791
MCQeasy

You are managing a Microsoft Sentinel environment. An analyst reports that a scheduled analytics rule is not generating alerts. The rule has been enabled for a week. What is the most likely cause?

A.The rule is disabled due to a cost threshold.
B.The rule has a short lookback period that misses data.
C.The rule's query does not match any events in the workspace.
D.The rule is configured as a real-time rule instead of scheduled.
AnswerC

A scheduled analytics rule only raises an alert when its KQL query returns one or more rows. If the query's conditions, such as event type, severity, or threshold, do not match any ingested data, the rule runs successfully but remains silent. Since it has been running for a week, the most probable reason for zero alerts is that no events satisfy the query. Test the query manually in Log Analytics over the same lookback period to confirm.

Why this answer

The most likely cause is that the rule's query does not match any events in the workspace. Since the rule has been enabled for a week, if the query logic is correct and data exists, alerts should have been generated. The absence of alerts strongly indicates that the query returns zero results, which is a common issue when the KQL query references tables, columns, or conditions that do not exist in the ingested data.

Exam trap

The trap here is that candidates may assume a rule is disabled or misconfigured due to cost or timing, but the core issue is almost always that the query itself does not match any data, which is the most straightforward and common cause for a rule not generating alerts.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel does not disable scheduled analytics rules due to a cost threshold; cost management is handled through data ingestion retention and pricing tiers, not by disabling rules. Option B is wrong because a short lookback period would only affect how far back the rule looks for data, but if the rule has been enabled for a week, it would still evaluate recent data within that lookback window; the issue is not about missing data but about the query not matching any events. Option D is wrong because there is no 'real-time rule' type in Microsoft Sentinel; all analytics rules are either scheduled or Microsoft Security incident creation rules, and a scheduled rule cannot be misconfigured as a real-time rule.

792
MCQhard

A SOC analyst is configuring a Microsoft Sentinel scheduled analytics rule to detect rare operations on Azure Key Vaults. The rule uses the AzureActivity table. The analyst wants to use a machine learning algorithm to identify anomalies based on historical activity patterns. Which analytics rule type should the analyst choose?

A.Scheduled
B.Microsoft Security Incident (for using existing alert triggers)
C.Anomaly detection
D.NRT (Near-Real-Time)
AnswerC

Anomaly detection rules in Microsoft Sentinel apply trained machine-learning models to establish a baseline of normal behavior for entities, users, or hosts and then flag events that deviate significantly from that baseline. These rules use built-in anomaly templates (such as unusual sign-in or anomalous privilege use) or custom ML models, making them specifically designed to detect rare, unusual operations that would never meet a static threshold. This matches the requirement for detecting rare operations without writing a fixed query.

Why this answer

The Anomaly Detection rule type in Microsoft Sentinel is specifically designed to use machine learning algorithms to identify unusual patterns in historical data. For detecting rare operations on Azure Key Vaults based on historical activity patterns in the AzureActivity table, this rule type automatically applies time series analysis and ML models to baseline normal behavior and flag deviations, making it the correct choice.

Exam trap

The trap here is that candidates often confuse Scheduled rules with Anomaly Detection rules because both can run on a schedule, but only Anomaly Detection rules incorporate built-in machine learning algorithms for dynamic baseline analysis.

How to eliminate wrong answers

Option A is wrong because a Scheduled analytics rule runs a query at defined intervals but does not inherently use machine learning algorithms; it relies on static threshold-based detection. Option B is wrong because Microsoft Security Incident rules are used to import alerts from other Microsoft security products (like Microsoft Defender for Cloud) and do not perform ML-based anomaly detection on AzureActivity data. Option D is wrong because NRT (Near-Real-Time) rules are designed for low-latency detection using simple queries and do not support machine learning-based anomaly detection.

793
MCQeasy

You are investigating a phishing incident in Microsoft Defender XDR. The incident involves a user who clicked a malicious link in an email. Which data source would you use to trace the email's origin?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Office 365 is the correct tool because it natively monitors email flow and protects Exchange Online through threat policies, URL detonation, and attachment sandboxing. It exposes rich hunting telemetry in Threat Explorer, such as email delivery outcomes, URL click verdicts, and user-reported phishing submissions, along with the ability to trace a message's complete path. This direct visibility into the phishing email's origin, targeting, and verdicts makes it the proper investigative surface for a phishing incident. It may later inform pivots to other Defender workloads, but initial triage belongs here.

Why this answer

Microsoft Defender for Office 365 (MDO) is the correct data source because it provides email-specific telemetry, including SMTP headers, sender IP addresses, and authentication results (SPF, DKIM, DMARC). This data is essential for tracing the origin of a phishing email that a user clicked. MDO's Threat Explorer and Email Entity page allow you to reconstruct the email's path from the sending server to the recipient's inbox.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Endpoint's network-level visibility (e.g., URL click events) with the email-specific origin data that only Microsoft Defender for Office 365 can provide.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint focuses on endpoint-level threats (processes, files, network connections) and does not store email headers or SMTP transaction logs needed to trace an email's origin. Option C is wrong because Microsoft Defender for Cloud Apps is designed for cloud application usage and shadow IT discovery, not for email transport analysis or header inspection. Option D is wrong because Microsoft Defender for Identity monitors on-premises Active Directory signals (Kerberos, NTLM, LDAP) for identity-based attacks, not email routing or SMTP metadata.

794
MCQmedium

You are a Microsoft Sentinel administrator for a company that ingests Microsoft Defender XDR incidents into Microsoft Sentinel. You create an automation rule to automatically assign incidents to a specific analyst. The rule uses the condition 'Analytics rule name contains 'Suspicious'' and the action 'Assign owner'. After deployment, you notice that incidents from Microsoft Defender XDR are not being assigned. What is the most likely cause?

A.Automation rules in Microsoft Sentinel can only be triggered by incidents created by analytics rules, not by incidents ingested from Microsoft Defender XDR.
B.The automation rule must be enabled for each Microsoft Defender XDR connector separately.
C.Automation rules require a playbook to be attached to perform the assignment action.
D.The condition 'Analytics rule name' is not populated for incidents that originate from Microsoft Defender XDR, so the rule condition never matches.
AnswerD

Incidents created by Microsoft Defender XDR integration do not have an associated analytics rule name because they are not generated by a Sentinel analytics rule. The 'Analytics rule name' property is only populated for incidents created by scheduled or near-real-time analytics rules. Therefore, the condition fails to match, and the assignment action never executes. Using a condition like 'Product name' or 'Title' would be appropriate instead.

Why this answer

The automation rule failed because incidents from Microsoft Defender XDR do not have an 'Analytics rule name' property. That property is only set for incidents created by Sentinel analytics rules. To assign these incidents, the condition should be based on a property that exists, such as 'Product name' or 'Title'.

This is a common pitfall when mixing incidents from different sources.

Exam trap

The trap here is assuming that all incidents have the same properties, when in fact incidents from different sources may lack certain fields like 'Analytics rule name'.

795
MCQeasy

A threat hunter wants to identify all devices that have communicated with a known malicious IP address in the last 7 days. Which table in Microsoft Defender for Endpoint advanced hunting should be queried?

A.DeviceFileEvents
B.DeviceNetworkEvents
C.DeviceProcessEvents
D.DeviceRegistryEvents
AnswerB

DeviceNetworkEvents is the Advanced Hunting table that stores network connection activity initiated by processes, including source and destination IP addresses, remote ports, protocols, and connection metadata. A threat hunter can query this table with a known-bad IP or domain to list every device that established such communication. This makes it the direct and authoritative source for identifying compromised or suspicious endpoints.

Why this answer

The DeviceNetworkEvents table in Microsoft Defender for Endpoint advanced hunting contains information about network connections, including remote IP addresses and ports. To identify devices that communicated with a specific malicious IP, querying this table for the RemoteIP field is the correct approach. It captures both inbound and outbound network traffic events.

Exam trap

SC-200 often tests knowledge of the advanced hunting schema, and candidates may confuse network events with process or file events, leading to incorrect table selection.

How to eliminate wrong answers

Option A is wrong because DeviceFileEvents records file creation, modification, and other file system activities, not network communications. Option C is wrong because DeviceProcessEvents logs process creation and related events, not network connections. Option D is wrong because DeviceRegistryEvents tracks registry key modifications, which are unrelated to network traffic.

796
Multi-Selectmedium

Which TWO of the following are effective techniques for identifying lateral movement in Microsoft Defender for Endpoint advanced hunting? (Choose two.)

Select 2 answers
A.Check for successful logons from public IP addresses
B.Look for large file uploads to cloud storage
C.Search for remote desktop connections from non-administrative workstations
D.Monitor for phishing emails
E.Analyze NTLM authentication events for pass-the-hash
AnswersC, E

Unexpected remote desktop connections from non-administrative workstations are a strong lateral movement indicator because attackers frequently use RDP to hop to other systems once they compromise an endpoint. By searching for RDP sessions initiated from a standard user's workstation, a defender can spot activity that does not match the user's baseline behavior, especially when the destination is a server or privileged host. This technique corresponds to MITRE ATT&CK T1021.001, since legitimate users rarely initiate such connections from non-admin workstations.

Why this answer

Option C is correct because in Microsoft Defender for Endpoint advanced hunting, RDP logons (e.g., LogonType 10 in DeviceLogonEvents) originating from non-administrative workstations are a classic lateral-movement indicator, since attackers pivot from a compromised user endpoint to other hosts rather than from trusted admin jump boxes. Option E is correct because NTLM authentication events (e.g., in DeviceLogonEvents or DeviceEvents with NTLM-related fields) can reveal pass-the-hash activity, where stolen NTLM hashes are reused to authenticate to remote systems without knowing the plaintext password, a hallmark of lateral movement. Option A is not the best fit because successful logons from public IP addresses typically indicate initial access or external exposure rather than internal lateral movement.

Option B is unrelated because large uploads to cloud storage suggest exfiltration, not lateral movement. Option D is unrelated because phishing emails are an initial-access vector, not a lateral-movement detection technique in advanced hunting.

Exam trap

SC-200 often tests whether candidates can distinguish lateral movement from initial access and exfiltration — options about phishing or cloud uploads are distractors that describe other attack stages.

797
MCQmedium

You are analyzing a firewall policy in Azure Firewall deployed via Azure Policy. What is the effect of this rule?

A.Allows outbound traffic from any source to IP 10.0.0.5.
B.Allows inbound traffic from IP 10.0.0.5 to any destination.
C.Denies inbound traffic from IP 10.0.0.5 to any destination.
D.Denies outbound traffic from any source to IP 10.0.0.5.
AnswerC

This option is correct because it exactly matches the rule's configuration: Access is Deny, Direction is Inbound, Source is 10.0.0.5, and Destination is Any. When the Azure Firewall processes inbound packets, any traffic with a source IP of 10.0.0.5 will be dropped before reaching any internal resource. The 'Any' destination ensures the denial applies to all internal IP addresses, ports, and protocols, making this the accurate interpretation of the rule's intent.

Why this answer

The rule in Azure Firewall deployed via Azure Policy uses a default deny approach for inbound traffic. Since the rule explicitly denies inbound traffic from IP 10.0.0.5 to any destination, option C is correct. Azure Firewall processes rules in a priority order, and a deny rule for inbound traffic from a specific source IP overrides any allow rules that might match the same traffic.

Exam trap

The trap here is that candidates often confuse the direction of traffic (inbound vs outbound) and the action (allow vs deny), leading them to select options that reverse the source/destination or misinterpret the rule's effect.

How to eliminate wrong answers

Option A is wrong because the rule specifies 'Deny' action, not 'Allow', and it targets inbound traffic from a specific source IP, not outbound traffic to any source. Option B is wrong because the rule denies inbound traffic from IP 10.0.0.5, not allows inbound traffic from that IP. Option D is wrong because the rule is for inbound traffic (source IP 10.0.0.5 to destination), not outbound traffic from any source to that IP.

798
Multi-Selecteasy

You are investigating a security incident involving a compromised user account. The attacker used the account to access sensitive data in SharePoint Online. Which TWO actions should you take to remediate the incident? (Choose two.)

Select 2 answers
A.Reset the user's password.
B.Revoke all refresh tokens for the user.
C.Disable the user account in Microsoft Entra ID.
D.Review the sign-in logs to determine the extent of the breach.
E.Create a Conditional Access policy to require MFA for the user.
AnswersB, C

Revoking refresh tokens immediately invalidates the attacker's existing sessions, preventing token renewal and further access to SharePoint Online. This satisfies the containment constraint by cutting off persistent access tied to the compromised account, since access tokens alone expire quickly but refresh tokens sustain the intrusion.

Why this answer

Option B is correct because revoking all refresh tokens for the compromised user immediately invalidates the OAuth 2.0 refresh tokens that the attacker could use to silently obtain new access tokens for SharePoint Online and other Microsoft 365 resources, cutting off their persistent access. Option C is correct because disabling the user account in Microsoft Entra ID blocks any further authentication attempts with that identity, preventing the attacker from signing in again while the incident is contained. Option A is not the best remediation action here because resetting the password alone does not invalidate existing refresh tokens, so the attacker could retain access until those tokens expire.

Option D is a detection/investigation step rather than a remediation action, and Option E is a preventive control that does not immediately stop an active compromise.

Exam trap

Distinguish between investigative actions (reviewing logs) and remediation actions (revoking tokens, disabling account). Immediate remediation stops the breach; investigation follows.

799
MCQmedium

You are investigating a security incident in Microsoft Sentinel. You need to preserve a snapshot of the investigation including comments, bookmarks, and entities for future reference. What should you do?

A.Create an automation rule to tag the incident
B.Create a bookmark with the relevant data
C.Add the entities to a watchlist
D.Close the incident as a false positive
AnswerB

Creating a bookmark in Microsoft Sentinel captures a snapshot of a hunting query result, including the selected rows, entities, and any comments you add, and links it to the incident. Bookmarks persist the evidence as a standalone artifact that can be re-opened, shared, and investigated, making them the correct choice for preserving the incident data at a specific time. Unlike other options, a bookmark maintains the contextual provenance of how you found the evidence.

Why this answer

Bookmarks in Microsoft Sentinel allow you to preserve a snapshot of an investigation, including comments, bookmarks, and entities, for future reference. Bookmarks capture the state of an investigation at a specific point in time, enabling you to revisit and share the context later.

Exam trap

The trap here is that candidates often confuse bookmarks with watchlists or automation rules, thinking that static data storage or automated actions can preserve an investigation snapshot, but only bookmarks capture the full interactive context including comments and entities.

How to eliminate wrong answers

Option A is wrong because automation rules are used to automate incident response actions (e.g., assigning, changing severity, or triggering playbooks) and do not preserve a snapshot of investigation data like comments and entities. Option C is wrong because watchlists are used to store static data for correlation and matching against events, not to capture a dynamic investigation snapshot with comments and bookmarks. Option D is wrong because closing an incident as a false positive dismisses it without preserving the investigation context; it does not create a persistent record of comments, bookmarks, or entities.

800
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to ensure that when a user reports a phishing email, the email is automatically analyzed and remediated. What should you configure?

A.Configure User Reported Message settings to use the built-in reporting tool and automated investigation.
B.Configure Anti-Phish policy to move messages to quarantine.
C.Enable Safe Attachments policy.
D.Enable Safe Links policy.
AnswerA

User Reported Message settings route user-reported phishing into the built-in reporting tool, which feeds automated investigation and response so the message is analysed and remediated without manual triage, meeting the automatic analysis and remediation requirement.

Why this answer

Configuring User Reported Message settings in Microsoft 365 Defender to use the built-in reporting tool and enable automated investigation ensures that when a user reports a phishing email, it is routed to Microsoft, analyzed, and remediated automatically (e.g., moved to quarantine, soft-deleted, or blocked for other recipients). This is the purpose-built feature for the scenario. It ties the user report directly into the automated investigation and response (AIR) pipeline.

Exam trap

The trap is selecting Safe Links or Safe Attachments because they are phishing-related controls — but the question is about user-reported messages triggering automated analysis and remediation, which is the User Reported Message settings feature.

How to eliminate wrong answers

Option B is wrong because an anti-phish policy moves messages to quarantine based on filter verdicts — it does not act on user-reported messages and does not provide the automated analysis/remediation workflow described. Option C is wrong because Safe Attachments detonates attachments in a sandbox at delivery time; it is a preventive control, not a user-report-driven remediation mechanism. Option D is wrong because Safe Links rewrites and checks URLs at click time; like Safe Attachments, it is preventive and does not process user-reported emails for automated investigation.

801
MCQhard

You are responsible for Microsoft Sentinel pricing. You notice that data ingestion costs are high due to verbose logs from Windows security events. You need to reduce costs while still collecting critical security events. What should you do?

A.Use Common Event Format (CEF) connector instead of Windows Events
B.Change the table plan to Basic Logs
C.Increase the workspace retention period to archive warm data
D.Configure Windows Security Events via AMA connector with event filtering
AnswerD

Configuring Windows Security Events via the Azure Monitor Agent (AMA) connector with a data collection rule is the correct approach because it filters event IDs and event levels at the source before the data is transmitted to the workspace. You can select only high-signal security events such as 4624/4625 (logon) and 4688 (process creation) and suppress verbose or unneeded event categories, reducing billable ingestion volume. This directly lowers the Log Analytics/Sentinel ingestion cost while still keeping the security telemetry your analytics rules require.

Why this answer

The Azure Monitor Agent (AMA) connector for Windows Security Events allows granular filtering of event IDs and levels, enabling you to collect only critical security events (e.g., 4624, 4625) while excluding verbose logs like Event ID 5156 (Windows Filtering Platform permit connections). This reduces ingestion volume and cost without losing essential security visibility.

Exam trap

The trap here is that candidates confuse 'reducing costs' with 'changing retention' (Option C) or 'using a different connector' (Option A), when the real solution is to filter data at the source using the AMA's event filtering capability, which directly addresses ingestion volume.

How to eliminate wrong answers

Option A is wrong because the Common Event Format (CEF) connector is used for syslog-based appliances (e.g., firewalls, network devices), not for Windows Security Events; it does not reduce costs from Windows event logs. Option B is wrong because changing the table plan to Basic Logs reduces the log retention and query capabilities (no KQL full-text search, limited analytics), which is unsuitable for security events that require advanced hunting and detection rules. Option C is wrong because increasing the workspace retention period to archive warm data actually increases storage costs (warm data is interactive, not archived) and does not reduce ingestion costs; archiving cold data would reduce costs but is not relevant to ingestion volume.

802
MCQhard

You are reviewing a custom hunting query in Microsoft Sentinel. The query above returns results, but you suspect it misses low-frequency beaconing. Which modification improves detection while reducing false positives?

A.Use a sliding window to count distinct connection times per IP per device
B.Group by DeviceName only
C.Decrease the count threshold to 10
D.Add RemotePort to the summarize clause
AnswerA

Grouping connections into a sliding window and counting distinct connection times per IP and device surfaces periodic low-and-slow beaconing that single-event thresholds miss, while the distinct-count aggregation suppresses noisy repeated hits from the same host, cutting false positives.

Why this answer

Low-frequency beaconing is characterized by a small number of connections spread over long, regular intervals — a simple count threshold misses it because the total count is low. Using a sliding window (e.g., bin() or make-series with a time window) to count distinct connection times per remote IP per device surfaces the periodicity and regularity that distinguishes beaconing from normal traffic, while grouping by both IP and device reduces false positives from benign recurring connections.

Exam trap

SC-200 often tests the misconception that lowering a count threshold improves beaconing detection — candidates confuse 'more sensitive' with 'more accurate' and ignore that beaconing is defined by timing regularity, not volume.

How to eliminate wrong answers

Option B is wrong because grouping by DeviceName only collapses all remote IPs into one bucket, hiding the per-IP beaconing pattern and increasing false positives from unrelated traffic. Option C is wrong because decreasing the count threshold to 10 makes the query more sensitive to any low-volume traffic, dramatically increasing false positives without addressing the periodicity that defines beaconing. Option D is wrong because adding RemotePort to the summarize clause fragments the data further and does not help detect regularity — beaconing is identified by timing patterns, not port diversity.

803
MCQmedium

In Microsoft 365 Defender, a security analyst reviews an automated investigation that found a potentially unwanted application on multiple devices. The analyst wants to manually approve the suggested remediation action of uninstalling the application. Where should the analyst go?

A.The Action center
B.The Incidents page
C.The Alerts queue
D.The Device inventory
AnswerA

The Action center is the centralized console in Microsoft 365 Defender where all pending and completed remediation actions — such as file quarantine, device isolation, and email deletion — are listed, regardless of their originating automated investigation or manual response. Analysts must use this hub to review and either approve or reject each pending action before it is executed, and the center also preserves a full history for audit and investigation purposes. Because it is specifically designed to aggregate these actionable tasks from across Microsoft Defender for Endpoint, Office 365, and Identity, it is the only place that meets the analyst's need to review remediation actions.

Why this answer

The Action center in Microsoft 365 Defender is the centralized location where security analysts can view and manually approve or reject remediation actions that were suggested by automated investigations, such as uninstalling a potentially unwanted application. This is the correct place because the Action center consolidates all pending and completed actions across devices, allowing the analyst to take direct manual intervention on the recommended remediation.

Exam trap

The trap here is that candidates often confuse the Incidents page or Alerts queue as the place to approve remediation actions, not realizing that the Action center is the sole interface for managing pending remediation actions from automated investigations.

How to eliminate wrong answers

Option B is wrong because the Incidents page is used to view and manage the full scope of an incident, including alerts, devices, and evidence, but it does not provide the interface to manually approve or reject specific remediation actions like uninstalling an application. Option C is wrong because the Alerts queue lists individual security alerts, but it does not show the suggested remediation actions from automated investigations; those actions are only visible and actionable in the Action center. Option D is wrong because the Device inventory shows the list of devices and their details, but it does not contain the pending remediation actions or the ability to approve them; it is purely an inventory view.

804
MCQeasy

Your organization uses Microsoft Sentinel to manage security incidents. The security team wants to automatically close low-severity incidents after 24 hours if no activity has occurred. Which feature should you use?

A.Playbooks
B.Automation rules
C.Watchlists
D.Analytics rules
AnswerA

Playbooks automate response actions triggered by alerts, but they lack a native scheduling mechanism to evaluate elapsed inactivity time and close incidents after a fixed 24-hour window. This scenario requires a time-based automation rule, which is provided by Microsoft Sentinel’s automation rules with expiry conditions. Playbooks are tempting because they can close incidents on-demand when invoked, and would be correct for orchestrating complex, multi-step responses to a specific alert type.

Why this answer

A playbook (Azure Logic App) built on a Recurrence trigger — not an incident trigger — is the correct mechanism. Automation rules only fire in response to a Sentinel incident event (created/updated) and have no built-in condition to detect elapsed inactivity time; they cannot poll on a schedule. A recurrence-triggered playbook, by contrast, can run periodically (e.g., hourly), query the Sentinel incidents REST API for Low-severity incidents that have had no updates in the last 24 hours, and close them automatically — this is Microsoft's documented pattern for automated stale-incident closure.

Exam trap

Candidates often confuse automation rules with playbooks, assuming automation rules can handle time delays. However, automation rules only perform immediate actions based on incident triggers; time-based scenarios require playbooks.

How to eliminate wrong answers

Option A is wrong because playbooks are automated workflows that run in response to alerts or incidents, but they require a trigger from an automation rule or analytics rule and do not natively support time-based conditions like 'after 24 hours of no activity' without custom logic. Option C is wrong because watchlists are collections of data (e.g., IP addresses, hostnames) used for correlation or enrichment in analytics rules, not for automating incident closure based on time or activity. Option D is wrong because analytics rules generate alerts or incidents based on query results from log data; they do not manage the lifecycle of existing incidents or apply time-based closure actions.

805
MCQhard

Your SOC uses Microsoft Sentinel and Microsoft Defender for Identity (MDI). You have configured MDI to send alerts to Microsoft 365 Defender. From there, Microsoft Sentinel ingests the alerts via the Microsoft 365 Defender connector. You want to ensure that when MDI detects a suspicious activity, the incident in Microsoft Sentinel is created within 5 minutes. Which factors should you consider?

A.The latency is determined solely by the MDI sensor health and network speed.
B.The incident creation time is controlled by the Microsoft Defender for Cloud Apps connector.
C.The incident will be created within 5 minutes because MDI writes directly to Microsoft Sentinel.
D.The latency depends on the Microsoft 365 Defender connector's polling interval and the analytics rule's frequency.
AnswerD

The end-to-end latency for MDI incident creation in Microsoft Sentinel depends on two sequential factors: the Microsoft 365 Defender connector's polling interval, which determines how frequently alerts are fetched from the unified API, and the frequency of the analytics rule that converts those alerts into incidents. The connector typically polls every few minutes, but that interval is not instant, and the scheduled rule runs on its own cadence (e.g., every 5-15 minutes) based on the configured frequency. Therefore, the total delay is the sum of these intervals, not a fixed duration, and is the primary driver of when the incident appears.

Why this answer

The incident creation latency in this architecture depends on two factors: the Microsoft 365 Defender connector's polling interval (which retrieves alerts from Microsoft 365 Defender) and the frequency of the Microsoft Sentinel analytics rule that creates incidents from those ingested alerts. Even if MDI sends alerts quickly to Microsoft 365 Defender, the connector polls at a configurable interval (default every 5 minutes), and the analytics rule runs on its own schedule (typically every 5 minutes). Thus, the total time to incident creation is the sum of these intervals, not a fixed 5 minutes.

Exam trap

The trap here is that candidates assume MDI alerts flow directly into Microsoft Sentinel with minimal delay, overlooking the polling-based Microsoft 365 Defender connector and the scheduled analytics rule that together introduce cumulative latency.

How to eliminate wrong answers

Option A is wrong because latency is not solely determined by MDI sensor health and network speed; the Microsoft 365 Defender connector's polling interval and analytics rule frequency are the primary bottlenecks. Option B is wrong because the Microsoft Defender for Cloud Apps connector is not involved in this alert flow; MDI alerts go to Microsoft 365 Defender, not directly to Defender for Cloud Apps. Option C is wrong because MDI does not write directly to Microsoft Sentinel; alerts flow through Microsoft 365 Defender and the Microsoft 365 Defender connector, which introduces polling and rule processing delays.

806
MCQhard

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector. You have a critical incident that involves multiple alerts across different services. The incident is being updated with new alerts. You need to ensure that a specific playbook runs only when the incident severity is updated to High. How should you configure the automation rule?

A.Set the trigger to 'When an alert is created' and filter for alerts with High severity.
B.Set the trigger to 'When incident is updated' and add a condition on severity equals High.
C.Set the trigger to 'When incident is created' and add a condition on severity equals High.
D.Configure the condition inside the playbook to check severity and exit if not High.
AnswerB

The 'When incident is updated' trigger is the correct lifecycle hook because it fires on any change to an incident's properties, including a severity change. Adding a condition that severity equals High ensures the playbook only proceeds for incidents that are or have been set to High, satisfying the requirement. This is the recommended pattern: keep the condition in the automation rule so the playbook is only invoked when the condition is true.

Why this answer

The requirement is to run the playbook only when the incident severity is updated to High, so the automation rule must trigger on 'When incident is updated' and include a condition that severity equals High. This ensures the playbook fires on the severity change event rather than on creation or alert events.

Exam trap

SC-200 often tests whether candidates confuse incident-level triggers with alert-level triggers, and whether they place conditions in the automation rule versus inside the playbook, leading to unnecessary executions or missed events.

How to eliminate wrong answers

Option A is wrong because triggering on alert creation and filtering for High severity would fire on new alerts, not on an incident severity update, and would not reflect the incident-level change. Option C is wrong because triggering on incident creation only fires once at creation and would miss later severity updates. Option D is wrong because putting the severity check inside the playbook means the playbook still runs (and consumes resources) on every trigger, and it does not address the trigger condition itself; the requirement is to run only when severity is updated to High.

807
MCQmedium

A company uses Microsoft Defender for Cloud to protect an Azure Kubernetes Service (AKS) cluster. The security team wants to receive security alerts about suspicious activities within the cluster, such as a container running with root privileges or attempts to read sensitive host paths. Which Defender for Cloud plan must be enabled to generate these alerts?

A.Defender for Servers
B.Defender for Containers
C.Defender for Cloud Apps
D.Defender for SQL
AnswerB

Defender for Containers is the dedicated Microsoft Defender for Cloud plan for securing containerized environments, including Azure Kubernetes Service (AKS), Amazon EKS, Google GKE, and Arc-enabled Kubernetes. It provides runtime threat detection by analyzing Kubernetes audit logs, container host telemetry, and cluster activities, detecting threats such as privilege escalation, suspicious network flows, and attempts to execute high-risk binaries in containers. This is the plan that should be enabled to protect the AKS cluster.

Why this answer

Defender for Containers is the specific plan that provides threat detection for Azure Kubernetes Service (AKS) clusters, including alerts for suspicious activities such as containers running with root privileges or attempts to read sensitive host paths. This plan monitors the Kubernetes control plane and container runtime to generate security alerts based on Kubernetes audit logs and container-specific signals.

Exam trap

The trap here is that candidates often confuse Defender for Servers with container protection because they think containers run on servers, but Defender for Servers does not monitor Kubernetes audit logs or container runtime activities, which are essential for detecting the described alerts.

How to eliminate wrong answers

Option A is wrong because Defender for Servers is designed to protect virtual machines and on-premises servers, not container orchestration platforms like AKS; it does not ingest Kubernetes audit logs or container runtime events. Option C is wrong because Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on SaaS application usage and shadow IT, not on container or Kubernetes-level threats. Option D is wrong because Defender for SQL is dedicated to protecting Azure SQL databases and SQL servers, providing alerts for SQL injection and database anomalies, not for container or Kubernetes security events.

808
MCQhard

A Microsoft Defender XDR incident shows that a user's device has been communicating with a known malicious C2 server. The device is online and the user is actively working. You need to contain the threat with minimal business disruption. What should you do?

A.Remove the device from the network by disabling the switch port
B.Shut down the device remotely
C.Run a full antivirus scan on the device
D.Initiate device isolation from Microsoft Defender XDR
AnswerD

Initiating device isolation from Microsoft Defender XDR contains the threat while the device stays online, satisfying the minimal-disruption constraint. Network isolation blocks all traffic except Defender XDR communication, so the user's session persists and the C2 channel is severed without wiping or powering off the endpoint.

Why this answer

Initiating device isolation in Microsoft Defender XDR stops all network communication to and from the device while allowing the user to continue working locally, thus containing the threat with minimal business disruption. Option A is incorrect because disabling the switch port would require physical access to the network infrastructure and may not be feasible remotely. Option B is incorrect because shutting down the device remotely causes immediate disruption and loss of user productivity.

Option C is incorrect because a full antivirus scan does not stop ongoing C2 communication and may allow the threat to continue spreading.

809
MCQeasy

You are responding to an incident where a user's device may be compromised. You need to collect forensic data from the device using Microsoft Defender for Endpoint. Which action should you take?

A.Isolate device
B.Initiate Live Response
C.Collect investigation package
D.Run antivirus scan
AnswerC

The 'Collect investigation package' action in Microsoft Defender for Endpoint is the correct choice because it automatically assembles a ZIP file containing forensic data from the device, including registry entries, event logs, loaded modules, network connections, and running processes. This artifact is specifically designed for deep investigation and can be downloaded by the analyst for offline analysis. It is a built-in response action that captures the full evidentiary picture needed to determine the scope and origin of the incident.

Why this answer

The 'Collect investigation package' action in Microsoft Defender for Endpoint is specifically designed to gather forensic data—such as registry hives, event logs, memory dumps, and disk images—from a device for offline analysis. This is the correct choice because the question explicitly asks to collect forensic data, and this action packages all relevant artifacts into a single .zip file for detailed examination.

Exam trap

The trap here is that candidates often confuse 'Initiate Live Response' with forensic data collection because it offers interactive access, but the question specifically asks for a method to 'collect forensic data' in a packaged format, which only 'Collect investigation package' provides.

How to eliminate wrong answers

Option A is wrong because 'Isolate device' disconnects the device from the network to contain a threat but does not collect forensic data; it prevents further spread but provides no artifacts for analysis. Option B is wrong because 'Initiate Live Response' provides a real-time remote shell for interactive investigation and remediation, but it is not a one-click collection of a comprehensive forensic package; it requires manual commands to gather data. Option D is wrong because 'Run antivirus scan' only performs a malware scan and removal, which does not capture the full forensic evidence needed for incident response, such as memory or registry artifacts.

810
MCQmedium

You are a security operations analyst at a company that uses Microsoft Sentinel. You have enabled User and Entity Behavior Analytics (UEBA) to detect anomalies. A new alert fires indicating a user is logging in from an unusual location. However, the user is a known traveler. How can you reduce false positives without disabling the UEBA rule?

A.Add the user to the entity behavior analytics exclusion list.
B.Disable the UEBA anomaly rule for unusual locations.
C.Change the alert severity to Informational.
D.Increase the lookback period for the anomaly detection.
AnswerA

Adding the user to the entity behavior analytics exclusion list in Microsoft 365 Defender suppresses UEBA anomaly alerts for that specific entity only, leaving the 'unusual location' detection rule active for all other users. This is the targeted, least-privilege response for a legitimate traveler because it preserves the rule's ability to catch genuine account-compromise anomalies while preventing false positives tied to the known user's expected foreign sign-ins.

Why this answer

Microsoft Sentinel's UEBA allows you to add specific users to an entity behavior analytics exclusion list. This prevents the UEBA engine from generating alerts for that user's anomalous activities, such as logins from unusual locations, without disabling the underlying detection rule. This approach maintains detection coverage for other users while suppressing false positives for known travelers.

Exam trap

The trap here is that candidates may think disabling the rule or changing severity is the correct approach, but Microsoft specifically tests the ability to use entity-level exclusions to handle known exceptions without compromising overall detection coverage.

How to eliminate wrong answers

Option B is wrong because disabling the UEBA anomaly rule for unusual locations would stop all alerts for that anomaly type across all users, not just the known traveler, which is an overly broad and disruptive solution. Option C is wrong because changing the alert severity to Informational does not prevent the alert from being generated; it only changes its classification, so false positives would still clutter the security operations queue. Option D is wrong because increasing the lookback period for anomaly detection would make the UEBA model consider older baseline data, potentially making the detection less sensitive to recent changes and not specifically addressing the false positive for a single known traveler.

811
MCQhard

You are investigating a ransomware incident in Microsoft Sentinel. The incident contains multiple alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. You need to correlate the alerts and identify the initial entry point. Which KQL function should you use to combine the alerts?

A.materialize()
B.union
C.mv-expand
D.make_set()
AnswerD

make_set() is a KQL aggregation function that constructs an array of unique values from a specified column, grouped by one or more key columns. When correlating alerts in a ransomware investigation, you can use make_set(AlertTitle) with a summarize by Account or Hostname to gather all distinct alert names that fired for that entity. This creates a concise, ordered set of alert titles that reveals the sequence or combination of malicious activities, such as initial access and data encryption. It is therefore the correct choice for aggregating alert titles to support correlation analysis.

Why this answer

D is correct because `make_set()` is used with `summarize` to create a distinct list of values from a column across multiple rows, which is essential for correlating alerts from different data sources (e.g., DeviceEvents, EmailEvents, IdentityLogonEvents) by a common identifier like `DeviceName` or `AccountUpn`. This allows you to group alerts from Defender for Endpoint, Office 365, and Identity into a single row per entity, making it easier to trace the initial entry point by analyzing the timeline of distinct alert types.

Exam trap

The trap here is that candidates confuse `union` (which simply appends rows) with the need to correlate alerts by a common entity, leading them to overlook `make_set()` as the correct aggregation function for grouping distinct alert data from multiple sources.

How to eliminate wrong answers

Option A is wrong because `materialize()` is used to cache the result of a subquery for performance optimization in complex queries, not to combine or correlate alerts from different tables. Option B is wrong because `union` merges rows from multiple tables into a single result set but does not aggregate or correlate alerts by a common entity; it simply appends rows, which would not help identify the initial entry point without further summarization. Option C is wrong because `mv-expand` is used to expand multi-value arrays or dynamic fields into multiple rows, not to combine alerts from different sources; it would break apart existing data rather than correlate it.

812
MCQmedium

A security analyst is investigating a suspicious email that was reported by a user. The email contains an attachment with a known malicious macro. The analyst wants to find all instances of this same email being delivered to other users in the organization. Which Advanced Hunting table should the analyst query to find the delivery events?

A.EmailAttachmentInfo
B.EmailEvents
C.EmailUrlInfo
D.DeviceFileEvents
AnswerB

EmailEvents records delivery, block and post-delivery events for messages, including sender, recipient, subject and verdict. Querying it for the malicious attachment's sender or subject hash reveals every mailbox that received the same email, which is exactly the delivery evidence required.

Why this answer

The EmailEvents table in Microsoft Defender XDR Advanced Hunting contains records of email delivery events, including sender, recipient, subject, and delivery status. Since the analyst needs to find all instances where the same email (with the malicious macro attachment) was delivered to other users, querying EmailEvents with the email's unique identifier (e.g., NetworkMessageId) will return all delivery events across the organization.

Exam trap

The trap here is that candidates confuse EmailAttachmentInfo (which contains attachment hashes) with EmailEvents, assuming attachment data alone can identify all recipients, but only EmailEvents holds the delivery event records needed to find every user who received the email.

How to eliminate wrong answers

Option A is wrong because EmailAttachmentInfo stores metadata about attachments (e.g., filename, SHA256 hash) but does not include delivery event details like recipient or delivery status; it is used to correlate attachments with emails, not to find delivery instances. Option C is wrong because EmailUrlInfo contains information about URLs in the email body or attachments, not delivery events; it is used for phishing URL investigations, not for locating all recipients of a specific email. Option D is wrong because DeviceFileEvents tracks file creation, modification, and deletion events on endpoints, not email delivery events; it is irrelevant for finding email recipients.

813
MCQmedium

Your organization, Fabrikam, has a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You are using Microsoft Sentinel and Microsoft Defender XDR. You have enabled Microsoft Defender for Identity (MDI) to protect on-premises Active Directory. Recently, you received an incident in Microsoft Sentinel indicating a potential DCSync attack from a domain controller. The incident was generated from an MDI alert. You need to investigate the incident and determine if the attack was successful. You have the following options: A) Use the Microsoft Sentinel incident investigation graph to view entities and relationships. Then query the IdentityDirectoryEvents table for the domain controller to see if any directory replication requests were made. B) Use the Microsoft Defender XDR advanced hunting to query the IdentityLogonEvents table for the domain controller. C) Use the Microsoft Sentinel workbook for MDI to visualize the attack timeline. D) Use the Microsoft Defender for Cloud Apps activity log to review the domain controller's activities. Which option should you choose?

A.Use the Microsoft Sentinel workbook for MDI to visualize the attack timeline.
B.Use the Microsoft Defender XDR advanced hunting to query the IdentityLogonEvents table for the domain controller.
C.Use the Microsoft Sentinel incident investigation graph to view entities and relationships. Then query the IdentityDirectoryEvents table for the domain controller to see if any directory replication requests were made.
D.Use the Microsoft Defender for Cloud Apps activity log to review the domain controller's activities.
AnswerC

To confirm the DCSync attack, first open the incident investigation graph to see how the compromised entity relates to the domain controller and other machines. Then query the IdentityDirectoryEvents table for the domain controller, filtering on action types that correspond to directory replication, such as the GetNCChanges operation. This table, sourced from Microsoft Defender for Identity, records replication requests and is exactly the data required to prove that an account attempted to replicate credentials from the domain controller. The investigation graph guides you to the right entity (the DC) and shows the attack path, while the IdentityDirectoryEvents query provides the forensic evidence.

Why this answer

A DCSync attack involves an attacker impersonating a domain controller to request directory replication via the MS-DRSR protocol. The IdentityDirectoryEvents table in Microsoft Defender for Identity captures directory service replication activities, including the DirectoryReplication request action. Querying this table for the domain controller allows you to confirm if unauthorized replication requests were made, directly indicating a successful DCSync attack.

Exam trap

The trap here is that candidates may confuse the IdentityLogonEvents table (logon events) with the IdentityDirectoryEvents table (directory service events), or assume a visualization workbook can replace direct querying for forensic evidence of a DCSync attack.

How to eliminate wrong answers

Option A is wrong because the Microsoft Sentinel workbook for MDI provides visualizations and timelines but does not allow direct querying of the IdentityDirectoryEvents table to confirm specific replication requests; it is a reporting tool, not an investigative query tool. Option B is wrong because the IdentityLogonEvents table tracks authentication events (logons), not directory replication activities; DCSync attacks are not logon events but directory service replication requests. Option D is wrong because Microsoft Defender for Cloud Apps activity log focuses on cloud application activities, not on-premises Active Directory replication events; it would not capture MS-DRSR replication requests from a domain controller.

814
MCQhard

Your organization uses Microsoft Sentinel with a Log Analytics workspace in the East US region. You have deployed the Microsoft Defender for Cloud connector. You notice that security alerts from Defender for Cloud are not appearing as incidents in Sentinel. You have confirmed that the connector is enabled and data is flowing. What is the most likely cause?

A.The Sentinel workspace does not have required permissions to create incidents.
B.There is a delay in incident creation; wait for 24 hours.
C.You need to create an analytics rule with a rule template that uses the SecurityAlert table.
D.The Microsoft Defender for Cloud connector is not properly configured.
AnswerC

Microsoft Sentinel does not automatically create incidents from ingested security alerts; it requires an analytics rule to generate them. The Microsoft Defender for Cloud connector only ingests alerts into the SecurityAlert table in the Log Analytics workspace. To create incidents, you must create or enable an analytics rule that queries the SecurityAlert table and defines the incident properties. Without such a rule, alerts remain as raw log data and never appear in the Incidents queue.

Why this answer

The Microsoft Defender for Cloud connector ingests security alerts into the Log Analytics workspace's SecurityAlert table, but incidents in Microsoft Sentinel are generated only by analytics rules. Without a configured analytics rule that queries the SecurityAlert table (such as the built-in 'Create incidents based on Microsoft Defender for Cloud alerts' template), no incidents will be created even if data is flowing. Option C correctly identifies this missing step.

Exam trap

The trap here is that candidates assume enabling the connector automatically creates incidents, but Microsoft Sentinel requires an explicit analytics rule to generate incidents from any data source, including Defender for Cloud alerts.

How to eliminate wrong answers

Option A is wrong because the Sentinel workspace uses a system-assigned managed identity with built-in permissions (e.g., 'Microsoft Sentinel Contributor') to create incidents; if data is flowing, permissions are sufficient. Option B is wrong because incident creation is not subject to a 24-hour delay; it occurs within minutes of an alert being ingested if an analytics rule is active. Option D is wrong because the connector is confirmed enabled and data is flowing, so the connector itself is properly configured; the issue lies in the absence of an analytics rule.

815
MCQmedium

A security analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect multiple failed logon attempts from the same source IP address. The rule should generate an incident only when the count of failed logons exceeds 10 within a 5-minute window. Which configuration setting is essential to limit the incident generation to this threshold?

A.Event grouping set to 'Group all events into a single alert'
B.Alert threshold set to a value of 10
C.Query scheduling set to run every 5 minutes
D.Entity mapping for source IP address
AnswerB

Alert threshold set to a value of 10 specifies the minimum number of records that the rule's query must return before an alert is generated. Runs that produce fewer than 10 results are completely ignored, which filters out low-volume, benign matches and ensures an incident is created only when at least 10 events match the rule's logic. This is the correct mechanism for requiring a statistically significant number of results before escalating to an incident.

Why this answer

The alert threshold setting in a Microsoft Sentinel scheduled analytics rule directly controls the minimum number of query results required to generate an incident. By setting the threshold to 10, the rule will only fire when the query returns more than 10 failed logon events within the 5-minute window, matching the requirement exactly.

Exam trap

The trap here is confusing the alert threshold with query scheduling or event grouping, leading candidates to think that setting the run interval to 5 minutes alone ensures the threshold is met, when in fact the threshold is a separate mandatory configuration.

How to eliminate wrong answers

Option A is wrong because 'Group all events into a single alert' controls how matching events are bundled into one alert, not the count threshold for triggering an incident. Option C is wrong because query scheduling set to run every 5 minutes defines the evaluation frequency, not the threshold for the number of failed logons. Option D is wrong because entity mapping for source IP address is used to enrich alerts with entity information for investigation, not to limit incident generation based on event count.

816
Matchingmedium

Match each incident severity level to its description in Microsoft 365 Defender.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

No impact, but may indicate an issue

Minimal impact, likely false positive

Potential impact, requires investigation

Significant impact, immediate action needed

Widespread impact, urgent response required

Why these pairings

Severity levels in Microsoft 365 Defender help prioritize incident response. Informational provides visibility, Low indicates minor issues, Medium requires investigation, High denotes significant threats, and Critical demands immediate action. The distractors swap or misrepresent these definitions.

817
MCQhard

Your company uses Microsoft Sentinel and has enabled the Microsoft Defender XDR connector. You notice that incidents from Microsoft Defender for Cloud Apps are not appearing in Microsoft Sentinel. All other Defender XDR incidents appear correctly. What is the most likely cause?

A.The security operations team does not have the appropriate permissions.
B.The Microsoft Defender XDR connector only ingests incidents from Microsoft Defender for Endpoint.
C.The Microsoft 365 E5 license is not assigned to the users.
D.The Microsoft Defender for Cloud Apps data connector is not enabled in Microsoft Sentinel.
AnswerD

Microsoft Defender for Cloud Apps has its own dedicated data connector in Microsoft Sentinel, and it must be explicitly enabled through the Sentinel data connectors page or content hub. Without this connector, Sentinel has no API subscription to Defender for Cloud Apps, so incidents, alerts, and cloud discovery logs are not imported. Enabling the Microsoft Defender XDR connector alone does not guarantee delivery of all Cloud Apps incidents—the two connectors subscribe to different data streams. Thus, the missing Cloud Apps incidents are exactly what would be observed when this connector has not been turned on.

Why this answer

The Microsoft Defender XDR connector ingests incidents from all Microsoft Defender products, including Defender for Cloud Apps, but only if the corresponding data connector is enabled in Microsoft Sentinel. Option D is correct because the Microsoft Defender for Cloud Apps data connector must be explicitly enabled to allow incident ingestion from that source; without it, incidents from Defender for Cloud Apps will not appear even though the XDR connector is active.

Exam trap

The trap here is that candidates assume the Microsoft Defender XDR connector automatically ingests incidents from all Defender products, but in reality, each product requires its own data connector to be enabled in Microsoft Sentinel.

How to eliminate wrong answers

Option A is wrong because permissions control who can view incidents, not whether incidents are ingested; if the XDR connector is working for other products, permissions are not the issue. Option B is wrong because the Microsoft Defender XDR connector ingests incidents from all Defender products (Endpoint, Office 365, Identity, Cloud Apps), not just Defender for Endpoint. Option C is wrong because the Microsoft 365 E5 license is required for Defender for Cloud Apps functionality, but the question states that the connector is enabled and other incidents appear, so licensing is not the cause of missing incidents.

818
Multi-Selectmedium

Which TWO actions should you take to optimize cost in Microsoft Sentinel while maintaining security coverage? (Choose two.)

Select 2 answers
A.Enable continuous export for all tables.
B.Purchase a Pay-as-you-go commitment tier.
C.Adjust the interactive retention period for tables that don't need long-term interactive access.
D.Add more tables to ingest data.
E.Use Basic Logs for high-volume, low-value data sources.
AnswersC, E

Correct. Adjusting the interactive retention period lets you move data out of the expensive, fast-query interactive tier into lower-cost long-term retention or archive after a short time. For tables that rarely need immediate access or advanced analytics, shortening this period directly reduces your monthly storage cost without losing the ability to retrieve older data later. This is a table-level cost-control technique that aligns storage spending with actual query needs.

Why this answer

Reducing interactive retention for tables that do not require long-term, fast query access directly lowers storage costs. Microsoft Sentinel charges per GB for data stored in the interactive retention tier, while data moved to long-term retention (up to 12 years) is significantly cheaper. By tailoring retention periods to actual operational needs, you avoid paying premium rates for data that is rarely queried interactively.

Exam trap

The trap here is that candidates often confuse 'commitment tiers' (which reduce per-GB cost) with a direct cost-optimization action, but the question asks for specific actions you take, not pricing models; also, 'continuous export' sounds like a way to offload data, but it actually adds cost and complexity unless used for a specific purpose.

819
MCQmedium

You are responding to a phishing incident. The investigation reveals that a user clicked a link in a phishing email and entered credentials on a fake site. You need to contain the incident and prevent further compromise. What should you do first?

A.Report the phishing site to Microsoft.
B.Block the phishing URL in Microsoft Defender for Office 365.
C.Reset the user's password and revoke sessions.
D.Delete the phishing email from the user's mailbox.
AnswerC

Resetting the user's password changes the credential so the stolen password is no longer valid for authentication, while revoking sessions through Microsoft Entra ID invalidates any refresh tokens and access tokens the attacker may have obtained. This directly severs the attacker's ability to continue using the compromised account, including mailbox access and other applications. It is the proper immediate containment action for a credential-phishing incident.

Why this answer

The immediate priority when credentials have been compromised is to invalidate them, preventing the attacker from using them for further access. Resetting the password and revoking sessions (e.g., via Azure AD 'Revoke-AzureADUserAllRefreshToken' or 'Revoke-MgUserSignInSession') ensures the attacker cannot authenticate again, even if they have the password hash or active tokens. This aligns with the NIST SP 800-61 incident response containment phase.

Exam trap

The trap here is that candidates focus on blocking the phishing URL or deleting the email (technical controls for the attack vector) instead of recognizing that the core containment priority is neutralizing the compromised credentials (the attacker's foothold).

How to eliminate wrong answers

Option A is wrong because reporting the phishing site to Microsoft is a post-containment reporting step that does not stop the attacker from using the stolen credentials or accessing resources. Option B is wrong because blocking the phishing URL in Defender for Office 365 prevents future clicks but does not remediate the already-compromised credentials or active sessions. Option D is wrong because deleting the phishing email from the user's mailbox removes evidence but does not invalidate the stolen credentials or prevent the attacker from using them to log in.

820
MCQmedium

Your Microsoft 365 tenant is protected by Microsoft Defender for Office 365. A user reports receiving a suspicious email with a link. You need to investigate whether the link was malicious and if any other users clicked it. Which tool should you use first?

A.Microsoft Entra ID sign-in logs
B.Microsoft Purview compliance portal
C.Email Entity page in Microsoft Defender XDR
D.Threat Explorer
E.Attack Simulation Training
AnswerD

Threat Explorer is the correct tool because it is a security hunting and investigation engine built into Microsoft Defender for Office 365 that provides queryable access to email message data and user click activities. It includes a dedicated URL view that reports each click on a Safe Links-protected URL, the identity of the user who clicked it, the verdict applied, and the client app used, with the ability to filter by time, user, and threat type. This makes it ideal for investigating a potential phishing click and correlating it with email delivery and threat intelligence.

Why this answer

Threat Explorer (Option D) is the correct first tool because it provides a centralized view of email threats, including malicious links and clicks. You can filter by URL or sender to identify if the specific link was detected as malicious and then use the 'Click to allow/block' feature or the 'URL clicks' view to see which users clicked it. This aligns with the incident response workflow for investigating phishing campaigns in Defender for Office 365.

Exam trap

The trap here is that candidates often confuse the Email Entity page (which shows details for a single email) with Threat Explorer (which provides aggregated, searchable data across all emails and clicks), leading them to pick Option C instead of the correct tool for multi-user investigation.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID sign-in logs track authentication events, not email content or link clicks; they would not show whether a link in an email was malicious or clicked. Option B is wrong because the Microsoft Purview compliance portal focuses on data governance, eDiscovery, and compliance policies, not real-time email threat investigation or link click analysis. Option C is wrong because the Email Entity page in Microsoft Defender XDR provides details about a single email message but does not natively aggregate click data across multiple users or allow bulk investigation of link clicks; Threat Explorer is the dedicated tool for that.

Option E is wrong because Attack Simulation Training is used to create and run simulated phishing campaigns for user training, not to investigate real-world suspicious emails or link clicks.

821
MCQmedium

A SOC analyst wants to automate a response in Microsoft Sentinel: whenever an incident is created that contains a compromised user entity (e.g., a user whose credentials were used in a breach), a playbook should run to disable that user in Microsoft Entra ID. Which condition should be configured in the automation rule to trigger this playbook?

A.Set the trigger to 'When incident is created' with no additional condition.
B.Set the condition to 'When incident is created with entity type IP'.
C.Set the condition to 'When incident is created with entity type Account'.
D.Set the condition to 'When incident is updated with entity type Host'.
AnswerC

Selecting 'When incident is created with entity type Account' is the correct and precise condition because the Account entity type in Microsoft Sentinel represents user accounts, including the attributes needed to disable a user (e.g., user principal name, NT domain, or account SID). This condition ensures the playbook runs only on new incidents that actually contain a compromised user entity, directly aligning with the SOC analyst's goal of disabling that user. It avoids the extra latency and noise of an unscoped trigger while guaranteeing the playbook receives the necessary entity data to perform the account triage.

Why this answer

The automation rule must trigger when an incident is created with an entity type of 'Account' to match the compromised user entity. In Microsoft Sentinel, a user whose credentials were used in a breach is represented as an 'Account' entity, not an 'IP' or 'Host'. The playbook to disable the user in Microsoft Entra ID requires this entity type to pass the user principal name (UPN) or object ID to the action.

Exam trap

The trap here is that candidates often confuse 'Account' with 'User' or assume 'IP' is sufficient for user compromise, but Microsoft Sentinel uses the specific entity type 'Account' for user identities, and the automation rule condition must match exactly that type to trigger the playbook correctly.

How to eliminate wrong answers

Option A is wrong because setting the trigger to 'When incident is created' with no additional condition would run the playbook on every incident, regardless of whether it contains a compromised user entity, leading to unnecessary or incorrect executions. Option B is wrong because 'entity type IP' represents an IP address, not a user account; disabling an IP address in Microsoft Entra ID is not a valid action for user compromise. Option D is wrong because 'entity type Host' represents a device or computer, not a user account, and the condition 'When incident is updated' would not capture the initial creation of the incident containing the compromised user.

822
MCQhard

Your company uses Microsoft Defender XDR. During a ransomware incident, you need to isolate a compromised Windows 10 device from the network while allowing connectivity to the Microsoft Defender for Endpoint service. Which action should you take?

A.Initiate a Full isolation from the device's action menu.
B.Contain the device from the Microsoft Defender XDR portal.
C.Apply a firewall rule to block all outbound traffic.
D.Run a selective isolation to block only external connections.
AnswerA

Initiating Full isolation from the device's action menu in Microsoft Defender XDR is the correct response because it immediately blocks all network traffic to and from the compromised device except for communication with the Defender for Endpoint service. This keeps the sensor and cloud command channel alive, allowing remediation actions like antivirus scans and collected forensic packages to be delivered. It is a policy-driven, reversible action that prevents ransomware from spreading laterally or reaching command-and-control while preserving your ability to investigate and respond.

Why this answer

Full isolation from the device's action menu is correct because in Microsoft Defender XDR, full isolation blocks all network traffic to and from the device except for the Defender for Endpoint service communication channel. This allows the security team to contain ransomware spread while still managing the device and running remediation actions through the Defender portal. Selective isolation, by contrast, only blocks external connections and permits internal ones, which is insufficient for ransomware containment.

Exam trap

SC-200 often tests the difference between full and selective isolation; the trap is choosing selective isolation thinking it blocks external threats while allowing internal management, when ransomware containment requires full isolation.

How to eliminate wrong answers

Option B is wrong because 'Contain the device' is not the correct action name in Defender XDR for network isolation; containment is a broader concept and does not match the specific isolation action. Option C is wrong because a firewall rule blocking all outbound traffic would also block the Defender for Endpoint service, breaking management and remediation. Option D is wrong because selective isolation allows internal network connectivity, which would not stop ransomware from spreading laterally.

823
MCQmedium

Your security team receives an alert from Microsoft Defender for Endpoint indicating a suspicious PowerShell command was executed on a device. The command attempted to download a payload from a known malicious IP. After confirming the alert is a true positive, what should be your first containment step?

A.Search for similar commands across all devices using advanced hunting
B.Disable the user account in Microsoft Entra ID
C.Isolate the device from the network using Microsoft Defender for Endpoint
D.Reset the user's password
AnswerC

Isolation immediately cuts the device's network connectivity, halting any further command-and-control communication or payload download from the malicious IP. This contains the true-positive compromise before lateral movement or additional payloads occur, satisfying the requirement for a first containment step.

Why this answer

Isolating the device via Microsoft Defender for Endpoint is the correct first containment step because it immediately cuts the endpoint off from the network while preserving the Defender agent's communication channel for further investigation and remediation. This stops lateral movement and C2 traffic from the compromised host without destroying forensic evidence. It is the standard 'contain first, investigate second' playbook for confirmed endpoint compromise.

Exam trap

The trap is choosing an investigative or identity-focused action (hunting, disabling account, resetting password) as the 'first' step when the question asks for containment — candidates conflate investigation with containment and miss that stopping the active threat takes priority.

How to eliminate wrong answers

Option A is wrong as a first step because advanced hunting is a threat-hunting/investigation activity, not containment — the malicious process is still running and could spread while you hunt. Option B is wrong because disabling the Entra ID account addresses identity compromise, but the endpoint is already executing malicious code; disabling the account does not stop the running payload or its network activity. Option D is wrong because resetting the user's password is a remediation step for credential compromise and does nothing to halt the active malware on the device.

824
MCQeasy

A SOC analyst wants to ingest firewall logs from a Palo Alto Networks appliance into Microsoft Sentinel using the Common Event Format (CEF) connector. The analyst has already set up a Linux syslog forwarder. What is the next required step to complete the data ingestion?

A.Install the Azure Monitor Agent on the Linux forwarder.
B.Run the installation script provided by the Sentinel CEF connector page on the Linux forwarder.
C.Create a Syslog data connector in Sentinel and specify the Palo Alto facility.
D.Enable Azure Arc on the firewall appliance.
AnswerB

Running the script from the Sentinel CEF connector page is the correct action — it performs an end-to-end setup on the Linux forwarder by installing and connecting the Log Analytics agent, configuring rsyslog or syslog-ng to listen for CEF over TCP, and deploying the CEF parser that maps incoming events to the CommonSecurityLog table. The script also starts the required services and opens the appropriate firewall ports, turning the Linux box into a dedicated CEF forwarder for Palo Alto and other appliances.

Why this answer

The CEF connector for Palo Alto Networks in Microsoft Sentinel requires a Linux syslog forwarder to have the CEF agent installed and configured. The installation script provided on the Sentinel CEF connector page automates the setup of the Log Analytics agent (formerly OMS agent) with the correct syslog daemon configuration to parse and forward CEF-formatted logs. Since the forwarder is already deployed, running this script is the immediate next step to enable log ingestion.

Exam trap

The trap here is that candidates confuse the CEF connector's agent installation step with the Azure Monitor Agent (AMA) or think that creating the data connector in the portal alone is sufficient, when in fact the Linux forwarder must first run the CEF installation script to enable log parsing and forwarding.

How to eliminate wrong answers

Option A is wrong because the Azure Monitor Agent (AMA) is not used for the CEF connector; the CEF connector relies on the legacy Log Analytics agent (OMS agent) installed via the CEF installation script. Option C is wrong because creating a Syslog data connector in Sentinel is a separate step that configures the data source in the portal, but it does not install or configure the forwarder; the installation script must be run first to set up the agent on the Linux machine. Option D is wrong because Azure Arc is not required for CEF log ingestion; the firewall appliance sends syslog to the Linux forwarder, and the forwarder communicates directly with the Log Analytics workspace without needing Azure Arc.

825
MCQeasy

Your organization is implementing Microsoft Sentinel. You need to design a solution to automatically disable a user account in Microsoft Entra ID when a high-severity incident is triggered in Microsoft Sentinel related to that user. Which component should you use?

A.A playbook that uses the Microsoft Graph API to disable the user.
B.An analytics rule that includes a query to disable the user.
C.An automation rule that runs a PowerShell script on a hybrid worker.
D.A workbook that triggers a webhook to disable the user.
AnswerA

A playbook triggered by the incident calls the Microsoft Graph API to disable the user account in Microsoft Entra ID. Graph exposes the account management operation, and Logic Apps provides the automation, satisfying the requirement to disable the user automatically on high-severity incidents.

Why this answer

A playbook is the correct component because it is an automated workflow that can be triggered by a Microsoft Sentinel incident. By using the Microsoft Graph API within the playbook, you can programmatically disable a user account in Microsoft Entra ID, which is the required action for a high-severity incident. This aligns with the need for an automated response that integrates Sentinel with identity management.

Exam trap

The trap here is that candidates may confuse automation rules with playbooks, thinking that automation rules can directly execute scripts or API calls, when in fact automation rules only trigger playbooks or run actions like changing incident status, not performing external remediation.

How to eliminate wrong answers

Option B is wrong because an analytics rule is designed to generate alerts based on query results, not to execute remediation actions like disabling a user; it lacks the capability to perform API calls or modify Entra ID objects. Option C is wrong because an automation rule in Sentinel can trigger a playbook or run a script on a hybrid worker, but running a PowerShell script directly on a hybrid worker does not natively integrate with Microsoft Graph API to disable a user without additional custom logic; the standard pattern is to use a playbook for such actions. Option D is wrong because a workbook is a visualization tool for data analysis and reporting; it cannot trigger webhooks or execute actions to disable user accounts.

Page 10

Page 11 of 18

Page 12