Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 826–900

1303 questions total · 18pages · All types, answers revealed

Page 11

Page 12 of 18

Page 13
826
MCQeasy

Your organization uses Microsoft Sentinel. An incident is created for a possible data exfiltration via an unapproved external IP address. Which type of Microsoft Sentinel automation should you use to automatically block the IP address in the firewall?

A.Data connector.
B.Analytics rule.
C.Watchlist.
D.Playbook.
AnswerD

Playbooks are Logic Apps triggered by Microsoft Sentinel automation rules, enabling an automated response that calls firewall APIs to block the IP. This satisfies the requirement to block the unapproved external address automatically upon incident creation.

Why this answer

Playbooks in Microsoft Sentinel are automated workflows based on Azure Logic Apps that can perform response actions, such as blocking an IP address in a firewall. When an incident indicates data exfiltration via an unapproved external IP, a playbook can be triggered automatically or manually to execute the block action via integration with firewall APIs or management tools.

Exam trap

The SC-200 exam often tests the distinction between detection (analytics rules) and response (playbooks), so candidates may confuse an analytics rule's ability to generate alerts with the capability to perform automated remediation actions.

How to eliminate wrong answers

Option A is wrong because a data connector is used to ingest logs and events from various sources into Sentinel, not to perform automated response actions like blocking an IP. Option B is wrong because an analytics rule generates alerts or incidents based on query logic; it does not execute remediation actions such as firewall changes. Option C is wrong because a watchlist is a collection of data (e.g., known malicious IPs) for correlation in queries, but it cannot directly trigger a block action in a firewall.

827
MCQhard

Your organization has Microsoft Defender for Endpoint deployed. You need to configure automatic attack disruption for ransomware attacks. What should you enable?

A.Attack surface reduction rules.
B.Live Response capabilities.
C.Device discovery settings.
D.Automatic attack disruption in Microsoft 365 Defender.
AnswerD

Automatic attack disruption is the Microsoft 365 Defender incident response feature that continuously monitors correlated XDR signals—endpoint, identity, email, and cloud apps—for evidence of active hands-on-keyboard attacks, ransomware, or malware campaigns. When an active attack is detected, it automatically triggers containment actions such as isolating compromised devices, disabling user accounts, and blocking malicious indicators to stop lateral movement while responders intervene. This is exactly the capability that automatically contains compromised assets during an active attack.

Why this answer

Automatic attack disruption in Microsoft 365 Defender is the correct feature to enable because it uses advanced detection signals to automatically contain compromised assets during ransomware attacks, such as isolating devices or blocking accounts, without manual intervention. This capability is specifically designed to stop the spread of ransomware in real time by leveraging Microsoft's threat intelligence and behavioral analytics.

Exam trap

The trap here is that candidates often confuse preventive controls like Attack surface reduction rules with reactive automated response capabilities, assuming that blocking malware execution is equivalent to disrupting an active attack, but automatic attack disruption is a distinct, post-breach containment feature.

How to eliminate wrong answers

Option A is wrong because Attack surface reduction rules are a set of policies that block common malware behaviors (e.g., script execution, Office macro abuse) but do not provide automatic containment of an ongoing ransomware attack; they are preventive, not reactive. Option B is wrong because Live Response capabilities allow security analysts to remotely investigate and remediate devices via a command-line interface, but they require manual initiation and do not automatically disrupt attacks. Option C is wrong because Device discovery settings control how endpoints are identified and inventoried on the network (e.g., via passive or active scanning), which is unrelated to automatic attack disruption.

828
Multi-Selecteasy

Which TWO are valid methods to collect forensic evidence from a compromised Windows endpoint during an incident? (Choose TWO.)

Select 2 answers
A.Run Windows Update to fix vulnerabilities.
B.Reboot the system and boot from a forensic USB drive.
C.Use FTK Imager to create a forensically sound image of the hard drive.
D.Run KAPE (Kroll Artifact Parser and Extractor) to collect artifacts.
E.Take a memory dump using DumpIt or similar tool.
AnswersD, E

KAPE is specifically designed for live incident response: it collects targeted artifacts such as browser history, prefetch files, registry hives, and recently accessed documents directly from the running system while preserving their timestamps and metadata. Its output is organized and can be processed with timelines, and its operation avoids installing persistent software or altering core system files, so the evidence collection is faster and less intrusive than full disk imaging. By running KAPE during the incident, you capture volatile and semi-volatile evidence that would be lost after a reboot or shutdown, which is why it is a valid live collection method.

Why this answer

KAPE (Kroll Artifact Parser and Extractor) is a purpose-built tool for collecting and parsing forensic artifacts from live Windows endpoints during incident response. It efficiently gathers critical evidence such as prefetch files, registry hives, event logs, and browser history without altering the system state, making it a valid method for forensic collection.

Exam trap

The SC-200 exam often tests the distinction between live forensic collection tools (like KAPE and DumpIt) and traditional forensic imaging tools (like FTK Imager) that require a dead-box approach, leading candidates to incorrectly select FTK Imager for live collection.

829
MCQeasy

Your incident response team uses Microsoft Sentinel. You need to automatically assign incidents to the appropriate analyst based on the type of alert. What should you create?

A.An automation rule with an 'Assign owner' action
B.A playbook that runs when an incident is created
C.A watchlist containing analyst names
D.A hunting bookmark to track assignments
AnswerA

An automation rule with an 'Assign owner' action is correct because Sentinel automation rules run natively on incident creation or update and can evaluate conditions such as alert type, severity, or entity. The Assign owner action directly sets the incident's Owner property to a designated user or Azure AD group, enabling immediate assignment without requiring Azure Logic Apps. Unlike playbooks, this built-in action is low-latency and doesn't need an external connector.

Why this answer

Automation rules in Microsoft Sentinel allow you to define conditions (e.g., alert type) and corresponding actions, including 'Assign owner' to automatically route incidents to the appropriate analyst. This is the native, no-code mechanism for incident assignment based on alert properties, making it the correct choice for this requirement.

Exam trap

The trap here is that candidates often confuse playbooks (which can also assign owners via a Microsoft Teams or Azure Logic Apps connector) with the simpler, purpose-built automation rule action, leading them to choose the more complex option unnecessarily.

How to eliminate wrong answers

Option B is wrong because playbooks are designed for complex, multi-step automation (e.g., enrichment, remediation) and require additional logic to assign ownership, whereas automation rules provide a simpler, direct 'Assign owner' action. Option C is wrong because a watchlist is a static reference list used for correlation or enrichment, not a mechanism to automatically assign incidents to analysts. Option D is wrong because a hunting bookmark is used to save and track interesting queries or results during threat hunting, not to manage incident assignments.

830
MCQhard

You are a security operations analyst for a company that uses Microsoft Sentinel. You need to ensure that when an incident is created from a Microsoft Defender for Identity alert, the incident is automatically assigned to the 'Identity Protection' team and a specific tag 'Identity' is added. You have already created an automation rule that triggers on incident creation and has the condition 'Product name' contains 'Azure Advanced Threat Protection'. What should you do next to meet the requirement?

A.Create a playbook that uses the Microsoft Sentinel API to assign the incident and add tags, then attach it to the automation rule.
B.Add actions to the automation rule: 'Assign owner' with the Identity Protection team, and 'Add tags' with 'Identity'.
C.Use a workbook to monitor incidents and manually assign them to the Identity Protection team and add tags.
D.Modify the analytics rule that generates the incident to include the assignment and tagging logic in its query.
AnswerB

Automation rules in Microsoft Sentinel support multiple actions, including assigning an owner and adding tags. By configuring these actions in the existing automation rule, you fulfill the requirement to automatically assign and tag incidents from Defender for Identity alerts. This is the most direct and efficient method.

Why this answer

Automation rules in Microsoft Sentinel can perform multiple actions on incidents, including assigning an owner and adding tags. Since the automation rule already triggers on the correct incidents, adding these actions directly satisfies the requirement without the need for additional playbooks or manual intervention.

Exam trap

The trap here is thinking that a playbook is needed for owner assignment and tagging, but automation rules natively support these actions.

831
Multi-Selectmedium

Which THREE components are part of the Microsoft Defender XDR incident management process?

Select 3 answers
A.Entities
B.Alerts
C.User settings
D.Playbooks
E.Evidence
AnswersA, B, E

Entities are the discrete actors, assets, and resources involved in an incident—such as user accounts, devices, IP addresses, and mailboxes. In the Microsoft Defender XDR incident data model, these are not just attached labels; they are contextualized and linked to alerts and evidence to establish the attack's scope and blast radius. This makes them a foundational component for threat hunting and investigation because they, unlike alerts or evidence, represent the 'who' and 'what' that are impacted.

Why this answer

Entities are a core component of the Microsoft Defender XDR incident management process because they represent the assets (such as users, devices, mailboxes, and applications) that are involved in an incident. The incident graph automatically links related entities to provide a unified view of the attack story, enabling analysts to pivot from an alert to the affected resources for investigation and response.

Exam trap

The trap here is that candidates often confuse the components of the Microsoft Defender XDR incident management process (entities, alerts, evidence) with automation features like playbooks, which belong to Microsoft Sentinel, not Defender XDR.

832
MCQmedium

You are a SOC analyst investigating a high-severity incident. The incident involves a user who received a phishing email and clicked a link. Microsoft Defender for Office 365 detected the email as phishing and blocked the URL at time of click, but a follow-up investigation reveals that the user's mailbox has suspicious forwarding rules. You need to ensure that similar incidents are automatically remediated in the future. What should you configure in Microsoft Sentinel?

A.Configure entity behavior analytics to automatically block the user.
B.Create an analytics rule that detects suspicious forwarding rules and automatically removes them.
C.Create an automation rule that triggers a playbook to remove the forwarding rule when an incident with the 'Phishing' tactic is created.
D.Add the user to a watchlist that triggers an automated investigation.
AnswerC

This is the correct approach because automation rules in Microsoft Sentinel are specifically designed to run when an incident is created (or updated), and they can trigger a playbook as a remediation action. The automation rule can match incidents with the 'Phishing' tactic and logically invoke a playbook that, for example, connects to Exchange Online PowerShell to remove the suspicious forwarding rule. This separation of concerns—analytics rule detects, automation rule orchestrates, playbook executes—is exactly how automated remediation should be implemented in Microsoft Sentinel.

Why this answer

Microsoft Sentinel automation rules can trigger a playbook (an Azure Logic Apps workflow) when an incident is created with a specific tactic, such as 'Phishing'. This allows automatic remediation of suspicious forwarding rules without manual intervention, ensuring similar incidents are handled consistently.

Exam trap

The trap here is that candidates confuse the detection capability of analytics rules (Option B) with the remediation capability of automation rules and playbooks, assuming that analytics rules can directly perform actions like removing rules, when in fact they only generate alerts.

How to eliminate wrong answers

Option A is wrong because entity behavior analytics (UEBA) in Microsoft Sentinel profiles user behavior and generates alerts, but it cannot automatically block a user or remove forwarding rules; it only provides insights. Option B is wrong because analytics rules in Sentinel detect threats and generate incidents, but they do not have the capability to automatically remove forwarding rules; remediation requires an automation rule with a playbook. Option D is wrong because adding a user to a watchlist can trigger alerts or investigations, but it does not directly automate the removal of forwarding rules; watchlists are for enrichment and correlation, not automated remediation.

833
MCQmedium

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector to ingest alerts and incidents from Defender for Endpoint, Defender for Office 365, and Defender for Identity. As a threat hunter, you want to proactively search for devices that may be communicating with known malicious IP addresses that have not yet triggered an alert. You have a list of known malicious IP addresses from an external threat intelligence feed. Which approach should you take to perform this hunt efficiently?

A.Create a Logic App that runs hourly and checks each IP against DeviceNetworkEvents, then creates incidents.
B.Create a Watchlist in Microsoft Sentinel containing the IP addresses, then write a KQL query in the Hunting blade that joins the Watchlist with DeviceNetworkEvents from Defender for Endpoint.
C.Use the ThreatIntelligenceIndicator table in Microsoft Sentinel, which automatically ingests the feed if you configure a Threat Intelligence - TAXII connector.
D.Manually add each IP address as a custom detection rule in Microsoft Sentinel for each device.
AnswerB

A Watchlist stores the external IP indicators as a reference table, letting a KQL query join them against DeviceNetworkEvents to surface devices contacting those addresses. This satisfies the requirement to hunt proactively across Defender for Endpoint telemetry without waiting for an alert.

Why this answer

The most efficient approach. By creating a Watchlist in Microsoft Sentinel containing the list of known malicious IP addresses, you can write a KQL query in the Hunting blade that joins the Watchlist with the DeviceNetworkEvents table from Defender for Endpoint. This allows you to proactively query for any devices that have communicated with those IPs, even if no alert was generated.

Option A is inefficient because Logic App is designed for automation and orchestration, not for ad-hoc hunting queries. Option C would require configuring a Threat Intelligence - TAXII connector with the specific feed, and the ThreatIntelligenceIndicator table may not contain the custom IP list. Option D is impractical for a large number of IPs and devices.

834
MCQhard

A security analyst is investigating a sophisticated attack that involved multiple devices. The analyst needs to create a custom detection rule in Microsoft 365 Defender that triggers when a process with a specific SHA256 hash is executed on any device AFTER an attacker-controlled file is created on another device. Which approach should the analyst use to build this detection?

A.Create a custom detection rule using an advanced hunting query that joins DeviceFileEvents and DeviceProcessEvents, and schedule it in Microsoft 365 Defender.
B.Use the Microsoft 365 Defender incident creation rule to generate an incident when the behavior is observed.
C.Use Microsoft Sentinel analytics rules with a data connector to Microsoft 365 Defender.
D.Use Microsoft Defender for Cloud's workload protection alerts.
AnswerA

A custom detection rule in Microsoft 365 Defender lets you run a KQL advanced hunting query on a schedule, joining DeviceFileEvents and DeviceProcessEvents to correlate file creation and process execution events across devices. This enables alerting on multi-stage attack sequences that individual alert rules might miss, with full flexibility to define thresholds, time windows, and affected device groups. Because the rule runs natively in the same environment that ingests the endpoint telemetry, it provides direct, low-latency detection without extra data transfer or licensing.

Why this answer

The requirement is to correlate two distinct events (file creation on one device and process execution on another) across time and devices. An advanced hunting query in Microsoft 365 Defender can join DeviceFileEvents and DeviceProcessEvents tables using a common indicator (e.g., attacker-controlled file hash) and schedule the query as a custom detection rule. This is the only native Microsoft 365 Defender approach that supports multi-device, multi-event correlation with scheduled evaluation.

Exam trap

The trap here is that candidates often confuse incident creation rules (which only react to existing alerts) with custom detection rules (which can query raw telemetry), leading them to select Option B despite its inability to perform cross-table joins.

How to eliminate wrong answers

Option B is wrong because incident creation rules in Microsoft 365 Defender only trigger on existing alerts or incidents, not on raw telemetry; they cannot perform multi-table joins or detect custom behavioral sequences. Option C is wrong because while Microsoft Sentinel can ingest Microsoft 365 Defender data and create analytics rules, the question explicitly asks for a detection built within Microsoft 365 Defender, not a separate SIEM. Option D is wrong because Microsoft Defender for Cloud's workload protection alerts focus on cloud infrastructure and resource-level threats, not on device-level process and file events across endpoints.

835
MCQhard

A SOC analyst is investigating a Microsoft Sentinel incident involving a compromised service principal. The analyst needs to enrich the incident with information from an external threat intelligence platform that exposes a REST API and requires an API key. The enrichment must run automatically each time a matching incident is created and must not require manual steps. Which Microsoft Sentinel component should the analyst use to implement this enrichment?

A.A data connector for the threat intelligence platform
B.A workbook with a custom parameter
C.A scheduled analytics rule with entity mapping
D.A Microsoft Sentinel playbook triggered by an automation rule
AnswerD

Playbooks are Logic Apps workflows that can call external REST APIs, handle API keys via secure inputs, and post results back to the incident as comments, tags, or entities. Automation rules can trigger a playbook automatically when an incident is created, matching the requirement for automatic enrichment on matching incidents. This combination provides the required no-touch, repeatable enrichment using the external threat intelligence platform.

Why this answer

Automated enrichment using an external API with an API key requires a Logic Apps-based playbook, which can securely store secrets, make HTTP calls, and write results back to the incident. Automation rules provide the trigger mechanism when an incident is created, ensuring the playbook runs without manual intervention. Analytics rules, workbooks, and data connectors serve different purposes and cannot fulfill the automated external enrichment requirement.

Exam trap

The trap here is assuming a data connector or analytics rule can call an external API; only playbooks (Logic Apps) can perform outbound API calls with secrets and write enrichment back to the incident.

836
MCQmedium

Your organization uses Microsoft Sentinel with custom analytics rules. During a threat hunt, you want to identify lateral movement using pass-the-hash techniques. Which data source combination is most effective?

A.Azure AD sign-in logs and Office 365 audit logs
B.DeviceEvents and DeviceLogonEvents from Microsoft Defender for Endpoint
C.Sysmon Event ID 3 (Network connect) and Windows Firewall logs
D.Windows Security Event ID 4624 (Logon) with LogonType 3 and NTLM attributes
AnswerD

Event 4624 with LogonType 3 and authentication package NTLM indicates a network logon using NTLM, which is exactly what a pass-the-hash attack performs. The logon process NtLmSsp and the authentication package NTLM in the event are key indicators; LogonType 3 signifies remote access to a resource. While normal network shares also create such events, filtering for unusual source workstations or privileged accounts can reveal pass-the-hash activity. This is the most direct Windows Security log source for detecting NTLM-based lateral movement.

Why this answer

Windows Security Event ID 4624 with LogonType 3 (network logon) and NTLM authentication attributes are key indicators of pass-the-hash attacks, as NTLM is the protocol typically exploited. Option A is wrong because Azure AD sign-in logs only cover cloud authentication, not on-premises lateral movement. Option B is wrong because DeviceEvents and DeviceLogonEvents from Microsoft Defender for Endpoint focus on endpoint behavior and do not provide the detailed NTLM attributes needed.

Option C is wrong because Sysmon Event ID 3 and Windows Firewall logs capture network connections, not authentication details.

837
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to automatically isolate a device when a high-severity incident is created. What is the most efficient way to achieve this?

A.Manually isolate the device from the Microsoft Defender for Endpoint console after the incident is created.
B.Create an automation rule in Microsoft Sentinel that runs a PowerShell script to isolate the device.
C.Create a custom detection rule in Microsoft Defender XDR that triggers device isolation.
D.Create an automation rule in Microsoft Sentinel that triggers a playbook, which uses the Microsoft Defender for Endpoint connector to isolate the device.
AnswerD

This is the correct approach because an automation rule in Microsoft Sentinel can be configured to trigger immediately upon incident creation and invoke a playbook. The playbook, built in Azure Logic Apps, uses the Microsoft Defender for Endpoint connector's 'Isolate machine' action to send an isolation command to the device. This provides a fully integrated, automated response that directly ties Sentinel's incident detection to the prescribed containment action, without manual intervention or custom script execution.

Why this answer

It leverages Microsoft Sentinel's automation rules to trigger a playbook that uses the Microsoft Defender for Endpoint connector, enabling automated device isolation in response to a high-severity incident. This approach is the most efficient as it combines Sentinel's incident-driven automation with Defender for Endpoint's native isolation action, eliminating manual intervention and ensuring rapid response.

Exam trap

The trap here is that candidates may confuse automation rules with direct script execution or assume that Defender XDR detection rules can natively perform response actions like isolation, when in fact isolation requires a playbook or automated response configuration outside the detection rule.

How to eliminate wrong answers

Option A is wrong because manual isolation from the Microsoft Defender for Endpoint console is not automated and contradicts the requirement for efficiency, as it requires human action after incident creation. Option B is wrong because automation rules in Microsoft Sentinel cannot directly run PowerShell scripts; they trigger playbooks (Logic Apps) or other actions, and running a script natively is not supported. Option C is wrong because custom detection rules in Microsoft Defender XDR can trigger alerts but cannot directly execute device isolation actions; isolation is an automated response action that must be configured via automation rules or playbooks, not within the detection rule itself.

838
MCQeasy

A security analyst is investigating a potential phishing campaign and has identified a malicious attachment with a known SHA256 hash. The analyst needs to find all email messages that were delivered to users and contained this exact attachment. Which advanced hunting table should the analyst query to obtain the network message IDs of the relevant emails?

A.EmailEvents
B.EmailAttachmentInfo
C.EmailUrlInfo
D.EmailPostDeliveryEvents
AnswerB

EmailAttachmentInfo records each attachment's SHA256 hash alongside the network message ID and recipient, letting the analyst match the known hash and retrieve the corresponding message IDs. This table directly satisfies the requirement to trace delivered emails containing that exact attachment.

Why this answer

The EmailAttachmentInfo table in Microsoft 365 Advanced Hunting contains records of every attachment in email messages, including the SHA256 hash. By querying this table with the known hash, the analyst can retrieve the NetworkMessageId values for all emails that contained that specific malicious attachment, enabling further investigation into delivery and impact.

Exam trap

The trap here is that candidates often confuse EmailEvents (which has delivery status) with EmailAttachmentInfo (which has attachment hashes), failing to recognize that only the latter contains the SHA256 hash needed to match a known malicious file.

How to eliminate wrong answers

Option A is wrong because EmailEvents contains metadata about email delivery events (e.g., delivery status, sender, recipient) but does not include attachment-level details like SHA256 hashes. Option C is wrong because EmailUrlInfo stores information about URLs present in email bodies or attachments, not attachment file hashes. Option D is wrong because EmailPostDeliveryEvents records actions taken on emails after delivery (e.g., user clicks, ZAP actions) and does not contain attachment hash data.

839
Multi-Selecteasy

Your organization plans to use Microsoft Sentinel for incident management. Which TWO are native incident management features in Sentinel?

Select 2 answers
A.Incident comments and collaboration
B.Incident assignment to specific analysts
C.Automated email notifications on incident creation
D.Integration with ServiceNow via out-of-the-box connector
E.Integration with Microsoft Teams for incident chat
AnswersA, B

Sentinel natively supports incident comments and collaboration through the Comments pane on the incident details page. Analysts can append notes, tag colleagues with @mentions, and preserve a chronological audit trail of investigation decisions without leaving the portal. This capability requires no additional connectors or playbooks, because it is part of the core incident management surface.

Why this answer

Microsoft Sentinel provides native incident comments and collaboration features that allow analysts to add notes, tag team members, and maintain a running audit trail directly within the incident record. This is a built-in capability, not requiring any external integration or additional licensing.

Exam trap

The trap here is that candidates confuse native features with integrations or automations that require additional configuration, such as email notifications or Teams chat, which are not built into Sentinel's core incident management.

840
MCQmedium

A SOC team uses Microsoft Sentinel and wants to automatically enrich incidents with threat intelligence from a third-party feed. Which feature should they configure to ingest the threat intelligence and correlate it with alerts?

A.Analytics rules
B.Threat intelligence connectors
C.Data connectors
D.Watchlists
AnswerB

Threat intelligence connectors are purpose-built data connectors that pull indicators from external sources—such as TAXII feeds, Microsoft Defender Threat Intelligence, or third-party platforms—directly into the normalized ThreatIntelligenceIndicator table. Once ingested, Sentinel automatically enables matching and correlation across analytics rules and detections. This is the correct mechanism for automatically importing and operationalizing TI feeds.

Why this answer

Threat intelligence connectors in Microsoft Sentinel allow ingestion of TI feeds and enable correlation with alerts. The other options do not provide this capability.

841
MCQmedium

A SOC analyst suspects a user account is compromised based on anomalous sign-in activity detected by Microsoft Entra ID Protection. The analyst needs to confirm and contain the threat. What is the first action the analyst should take?

A.Reset the user's password immediately
B.Review the user's risk level and sign-in logs in Microsoft Entra ID Protection
C.Disable the user account in Microsoft Entra ID
D.Block the user's sign-in from all locations
AnswerB

Reviewing the user's risk level and sign-in logs in Microsoft Entra ID Protection is the correct initial action because it provides aggregated risk detections and contextual details, such as impossible travel or unfamiliar sign-in properties, to confirm whether a compromise has actually occurred. This investigation-first approach enables you to make an informed decision about whether to require a password reset, revoke sessions, or take other containment steps.

Why this answer

The first step when investigating a potential account compromise is to review the user's risk level and sign-in logs in Microsoft Entra ID Protection. This allows the analyst to confirm the threat by examining risk detections, sign-in patterns, and contextual details before taking any containment actions. Prematurely resetting passwords or disabling accounts could disrupt legitimate user activity or alert the attacker without a full understanding of the scope.

Exam trap

The trap here is that candidates often jump to containment actions like resetting passwords or disabling accounts, but the SC-200 exam emphasizes the 'investigate before remediate' principle, where reviewing risk detections and sign-in logs in Entra ID Protection is the mandatory first step to confirm the threat.

How to eliminate wrong answers

Option A is wrong because resetting the user's password immediately without first reviewing the risk level and sign-in logs may lock out a legitimate user or fail to address the root cause, such as a token theft or MFA bypass. Option C is wrong because disabling the user account in Microsoft Entra ID is a containment step that should only be taken after confirming the compromise through risk investigation, as it could cause unnecessary service disruption. Option D is wrong because blocking the user's sign-in from all locations is a reactive containment measure that should follow confirmation of the threat, not precede it, and may not address risks like leaked credentials or session hijacking.

842
MCQmedium

Refer to the exhibit. A security analyst runs the KQL query in Microsoft Defender XDR to find devices running encoded PowerShell commands in the last hour. The query returns results showing a device named 'DESKTOP-123' with account 'jdoe'. The analyst suspects malicious activity. Which immediate next step should the analyst take?

A.Delete the query because it returned results
B.Modify the query to increase the time range to 24 hours
C.Click on the result to open the full device timeline and analyze the process tree
D.Isolate the device 'DESKTOP-123' from the network
AnswerC

Opening the device timeline reveals the full process tree, parent-child relationships and command lines behind the encoded PowerShell. This lets the analyst confirm whether the activity is genuinely malicious before containment, satisfying the need for immediate triage evidence.

Why this answer

When a KQL query in Microsoft Defender XDR returns suspicious results — such as encoded PowerShell commands on a device — the immediate next step is to investigate by clicking the result to open the full device timeline and analyze the process tree. This provides context on parent processes, command-line arguments, and related events to determine whether the activity is truly malicious before taking disruptive action.

Exam trap

SC-200 often tests the incident response sequence, tricking candidates into choosing immediate containment (isolation) when the correct first step is investigation to confirm the threat — a classic 'respond vs. investigate' trap.

How to eliminate wrong answers

Option A is wrong because deleting the query does not address the potential threat and would destroy the detection logic. Option B is wrong because expanding the time range to 24 hours is a broader search, not an immediate investigative step on the specific suspicious device — it delays triage and may return excessive noise. Option D is wrong because isolating the device is a containment action that should follow confirmation of malicious activity; isolating prematurely can disrupt business operations and should not be the immediate first step without investigation.

843
Multi-Selectmedium

Which TWO actions are appropriate when responding to a confirmed data exfiltration incident via email?

Select 2 answers
A.Block the recipient domain on the email gateway
B.Place a legal hold on the user's mailbox
C.Disable the user's account immediately
D.Delete all sent items from the user's mailbox
E.Run a full antivirus scan on the user's device
AnswersA, B

Blocking the recipient domain on the email gateway is an appropriate containment action because it immediately halts the active data exfiltration channel by rejecting any further outbound messages destined for that domain. This measure is applied at the transport layer, so it stops the bleeding without deleting any previously sent evidence, and it preserves the ability to later analyze the full extent of the breach while preventing additional data loss.

Why this answer

Blocking the recipient domain on the email gateway (A) is appropriate because it immediately prevents further data exfiltration to that external domain by rejecting all outbound emails to that domain at the transport layer. Placing a legal hold on the user's mailbox (B) preserves all mailbox content, including deleted items, as an immutable copy for forensic investigation and potential legal proceedings, ensuring evidence is not lost during the incident response.

Exam trap

The trap here is that candidates often confuse immediate containment (disabling the account) with proper forensic preservation, forgetting that disabling the account can destroy volatile evidence and alert the adversary, while blocking the recipient domain is a more precise containment action.

844
MCQmedium

Your organization uses Microsoft Defender XDR. A user reports that their device is behaving erratically, with unexpected pop-ups and high CPU usage. You suspect malware infection. You need to collect forensic data from the device for analysis. What should you do?

A.Create a custom detection rule in Microsoft Defender for Endpoint to capture the behavior.
B.Offboard the device and re-onboard it to trigger a fresh investigation.
C.Initiate a live response session on the device from the Microsoft 365 Defender portal.
D.Run a full antivirus scan using Microsoft Defender Antivirus.
AnswerC

Initiating a live response session from the Microsoft 365 Defender portal opens a secure, interactive remote shell to the device, allowing an analyst to execute built-in and custom commands to collect registry keys, running processes, network connections, and specific files into an evidence package. It is the correct choice for immediate forensic triage because it provides direct, time-sensitive access to volatile artifacts without relying on automated detection. The session is fully audited and can be used to run live response scripts or collect suspicious binaries for further analysis.

Why this answer

Initiating a live response session from the Microsoft 365 Defender portal allows you to remotely connect to the device and perform real-time forensic data collection, such as running scripts, capturing memory dumps, and collecting files, without disrupting the device's state. This is the appropriate method for gathering forensic evidence when malware is suspected, as it provides deep, interactive access for analysis.

Exam trap

The trap here is that candidates often confuse remediation actions (like running a scan or re-onboarding) with forensic data collection, failing to recognize that live response is the only option that provides interactive, real-time access for gathering evidence without altering the system state.

How to eliminate wrong answers

Option A is wrong because creating a custom detection rule in Microsoft Defender for Endpoint is used to detect future occurrences of specific behaviors, not to collect forensic data from an already compromised device. Option B is wrong because offboarding and re-onboarding a device does not trigger a fresh investigation; it simply reconnects the device to the service and may destroy existing forensic evidence by resetting the device's state. Option D is wrong because running a full antivirus scan using Microsoft Defender Antivirus is a remediation step that may alter or delete malware artifacts, making forensic analysis impossible, and it does not provide the interactive data collection capabilities needed for in-depth investigation.

845
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. An alert indicates that a user is downloading large amounts of data from SharePoint Online. What should you do first to investigate?

A.Govern the user by suspending their account.
B.Review the user's activity log in Defender for Cloud Apps.
C.Create a new IP address range for the organization.
D.Block the SharePoint Online app for all users in Defender for Cloud Apps.
AnswerB

Reviewing the user's activity log in Defender for Cloud Apps is the foundational step for incident investigation. It provides forensic detail such as exact timestamps, source IP addresses, user agents, and the number of files downloaded, allowing you to compare this behavior against the user's baseline and organizational anomalies. This evidence is required to determine whether the downloads constitute a real exfiltration threat or are an outlier caused by a legitimate business task.

Why this answer

The first step in investigating a potential data exfiltration alert is to review the user's activity log in Defender for Cloud Apps. This log provides granular details about the specific files downloaded, the volume of data, the time frame, and the source IP address, allowing you to validate whether the activity is anomalous or legitimate before taking any restrictive action.

Exam trap

The trap here is that candidates may confuse immediate governance actions (like suspending or blocking) with the proper investigative first step, failing to recognize that Defender for Cloud Apps requires log review to confirm the alert's validity before applying any automated or manual response.

How to eliminate wrong answers

Option A is wrong because suspending the user account is a reactive governance action that should only be taken after confirming malicious intent through investigation; prematurely suspending could disrupt legitimate business operations. Option C is wrong because creating a new IP address range is a configuration for defining trusted locations or policies, not an investigative step to analyze a specific alert. Option D is wrong because blocking SharePoint Online for all users is an overly broad and disruptive action that would halt all SharePoint access across the organization, which is not warranted for a single user alert and bypasses the necessary investigation.

846
Matchingmedium

Match each Microsoft Purview compliance feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Prevents accidental sharing of sensitive data

Searches and exports data for legal cases

Logs user and admin activities

Classifies and protects sensitive data with labels

Manages retention and disposal of records

Why these pairings

The correct matches are: Data Lifecycle Management with retention/deletion, MIP with classification/protection, Insider Risk Management with internal risk detection, and Communication Compliance with monitoring communications. Common confusions arise from overlapping scopes, such as communication monitoring being mistaken for data lifecycle or classification being misattributed to insider risk.

847
Multi-Selectmedium

Your organization uses Microsoft Defender for Cloud and Microsoft Sentinel. You need to ensure that security alerts from Defender for Cloud are automatically synchronized to Sentinel and assigned to the cloud security team. Which three actions should you take?

Select 3 answers
A.Create an automation rule that sets the incident owner to the cloud security team.
B.Manually export alerts from Defender for Cloud to Sentinel daily.
C.Create a playbook that periodically pulls alerts from Defender for Cloud.
D.Enable the Microsoft Defender for Cloud data connector in Sentinel.
E.Configure the connector to create incidents automatically from alerts.
AnswersA, D, E

Assigning the incident owner via an automation rule is the correct approach because automation rules can perform built-in incident actions immediately after the incident is created. This rule can use conditions such as the alert being generated from Defender for Cloud to set the owner field to the cloud security team, ensuring proper routing without requiring a playbook. Automation rules run after the connector or analytics rule creates the incident, making them the precise mechanism for ownership assignment in the incident lifecycle.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incident owners based on conditions such as alert severity or source connector. By creating an automation rule that sets the incident owner to the cloud security team, you ensure that every Defender for Cloud alert synchronized to Sentinel is immediately assigned to the appropriate team without manual intervention.

Exam trap

The trap here is that candidates may think a custom playbook or manual export is needed for synchronization, when in fact the native data connector handles ingestion automatically, and automation rules handle assignment without custom code.

848
Multi-Selecthard

You are configuring Microsoft Defender for Cloud Apps with Cloud Discovery. You need to ensure that logs from your network proxies are processed correctly. Which THREE steps are required?

Select 3 answers
A.Upload the log files manually or configure automatic log upload using the log collector.
B.Install the Microsoft Defender for Cloud Apps connector in Sentinel.
C.Enable Azure Information Protection for labeling.
D.Ensure proxy logs are in a supported format such as Common Log Format (CLF).
E.Configure the source IP address ranges of your organization in Defender for Cloud Apps settings.
AnswersA, D, E

Defender for Cloud Apps Cloud Discovery has no visibility into your network traffic unless it receives the raw logs from your proxy, firewall, or other network appliances. You must either manually upload a flat log file through the Cloud Discovery 'Upload' dialog for an ad-hoc snapshot, or deploy the log collector to automate continuous ingestion, parsing, and forwarding. The log collector runs on Windows or Linux, receives logs via FTP/Syslog/HTTP, and is the standard for ongoing discovery. Without this step, no shadow IT analysis can occur, making it a required configuration action.

Why this answer

Microsoft Defender for Cloud Apps Cloud Discovery requires log data from network proxies to be ingested either by manually uploading log files or by configuring automatic log upload via the log collector. The log collector is a Docker-based container that parses and normalizes proxy logs before forwarding them to Defender for Cloud Apps, enabling shadow IT discovery without manual intervention.

Exam trap

The trap here is that candidates often confuse the log collector with the Sentinel connector, thinking both are required for log ingestion, but the Sentinel connector is for SIEM integration, not for Cloud Discovery log processing.

849
MCQeasy

An incident is opened in Microsoft Sentinel for multiple sign-in failures from a single IP address targeting a privileged user account. Which action is most effective in automatically responding to this incident?

A.Create a playbook to block the IP address in the firewall.
B.Enable conditional access policy to require MFA for the user.
C.Create a playbook to automatically disable the user account.
D.Report the IP address to Microsoft for threat intelligence.
AnswerA

Creating a playbook that invokes a firewall API (via Azure Logic Apps) to block the offending IP is a direct containment action. It severs the attacker's communication path to your environment at the network boundary, without affecting the legitimate user's ability to sign in. This is the immediate, low-disruption response that stops the ongoing brute-force attempts from that source.

Why this answer

The most effective automated response is to block the IP address in the firewall via a playbook, as it directly stops the attack source. Disabling the user account is too broad and may affect legitimate access. Enabling MFA does not stop the current attack.

Reporting the IP is not immediate.

850
MCQmedium

A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect sign-ins from IP addresses known to be associated with a threat actor. The list of threat actor IPs is maintained in a custom Microsoft Sentinel watchlist and is updated daily. The analyst wants the rule to query the SigninLogs table and compare the IP address against this list. What is the most efficient way to reference the list in the KQL query?

A.Use the externaldata operator to read from a blob storage URL.
B.Use the let statement to define a static list inline.
C.Use the _GetWatchlist() function to retrieve the watchlist.
D.Use the datatable operator to define the list directly in the query.
AnswerC

_GetWatchlist('name') is the purpose-built Kusto function for retrieving Microsoft Sentinel watchlist content inside an analytics rule. The watchlist data is cached by Sentinel, and updates made through the portal, API, or PowerShell are automatically reflected without changing the rule query. This centralization enables SOC teams to maintain and version reference data independently from detection logic, while still supporting efficient joins and lookups in scheduled queries, making it the recommended pattern.

Why this answer

The `_GetWatchlist()` function is the built-in, optimized way to reference a Microsoft Sentinel watchlist within a KQL query. It retrieves the watchlist data directly from the Sentinel workspace, ensuring the query always uses the latest daily-updated list without manual maintenance or external dependencies. This approach is both efficient and aligns with Sentinel's intended design for dynamic threat intelligence.

Exam trap

The trap here is that candidates may confuse `_GetWatchlist()` with other data retrieval methods like `externaldata` or `datatable`, not realizing that watchlists are a first-class Sentinel feature designed for exactly this use case—dynamic, centrally managed threat intelligence that updates automatically without query modification.

How to eliminate wrong answers

Option A is wrong because the `externaldata` operator reads data from an external blob storage URL, which introduces latency, requires managing access keys, and bypasses Sentinel's native watchlist caching and update mechanisms. Option B is wrong because a `let` statement defines a static list inline, which would require manual editing of the query every time the threat actor IP list changes, defeating the purpose of a daily-updated watchlist. Option D is wrong because the `datatable` operator defines a hardcoded list directly in the query, similar to a static `let` statement, and cannot be dynamically updated without modifying the analytics rule itself.

851
MCQhard

Your organization uses Microsoft Sentinel with User and Entity Behavior Analytics (UEBA) enabled. You notice that the UEBA is not generating any anomalies for a particular user who has been inactive for 30 days. You have verified that the user's data is being ingested into the workspace. What is the most likely reason?

A.UEBA requires a minimum of 14 days of activity to establish a baseline.
B.The user's license does not include UEBA.
C.UEBA only works with Active Directory data, not Microsoft Entra ID.
D.UEBA is not enabled for the workspace.
AnswerA

UEBA in Microsoft Sentinel relies on machine learning to learn what 'normal' behavior looks like for each user or entity. A minimum of 14 days of historical activity must be ingested into the workspace before a reliable baseline is established; without that baseline, UEBA cannot differentiate anomalous activity from ordinary variations. Even though UEBA is enabled, the lack of detections within the initial period is expected and not due to configuration errors.

Why this answer

UEBA in Microsoft Sentinel requires a minimum of 14 days of historical data to build a behavioral baseline for each user. If a user has been inactive for 30 days, the baseline may have expired or never been established, so no anomalies are generated. The data ingestion is confirmed, but without recent activity, UEBA cannot compare current behavior against a meaningful profile.

Exam trap

The trap here is that candidates may assume data ingestion alone is sufficient for UEBA, but the feature specifically requires a minimum baseline period of 14 days of activity to generate anomalies, and inactivity beyond that period breaks the baseline.

How to eliminate wrong answers

Option B is wrong because UEBA is a feature of Microsoft Sentinel itself, not a separate user license; it is enabled at the workspace level and does not require individual user licenses. Option C is wrong because UEBA works with multiple data sources, including Microsoft Entra ID (formerly Azure AD), not just Active Directory; it ingests sign-in logs, audit logs, and activity logs from Entra ID. Option D is wrong because the question states UEBA is enabled, and the issue is specific to one user, not the entire workspace; if UEBA were disabled, no anomalies would be generated for any user.

852
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender for Office 365. You have configured incident creation from Microsoft Defender for Office 365 alerts in Microsoft Sentinel. However, you notice that some alerts are not creating incidents. Which step should you take to troubleshoot this issue?

A.Examine the analytics rule that creates incidents from Microsoft Defender for Office 365 alerts and verify the severity threshold.
B.Check the Microsoft 365 Defender portal to confirm that the alerts are being generated.
C.Review the Microsoft Sentinel workbooks for any visualization errors.
D.Verify that the Microsoft Defender for Office 365 data connector in Microsoft Sentinel is connected and data is ingested.
AnswerA

The correct action is to examine the analytics rule that creates incidents from Microsoft Defender for Office 365 alerts, because Microsoft Sentinel does not automatically create incidents from every raw alert. Analytics rules use KQL queries to match incoming alerts and apply conditions, and if the rule's severity threshold (e.g., only Medium and higher) is too high, alerts with lower severity won't trigger an incident. Verifying the rule's query, alert grouping, and severity filter directly addresses the symptom of users receiving Microsoft 365 Defender alerts while Sentinel incidents are missing.

Why this answer

The analytics rule that maps Microsoft Defender for Office 365 alerts to incidents in Microsoft Sentinel includes a severity threshold filter. If the rule is configured to only create incidents for alerts with a severity of 'High' or 'Medium', alerts with 'Low' severity or 'Informational' will be silently dropped and not generate incidents. Verifying and adjusting this threshold directly addresses the root cause of missing incidents.

Exam trap

The trap here is that candidates often assume the issue is with data ingestion (Option D) or alert generation (Option B), but the actual cause is a misconfigured severity threshold within the analytics rule that silently filters out lower-severity alerts before they can become incidents.

How to eliminate wrong answers

Option B is wrong because checking the Microsoft 365 Defender portal only confirms that alerts are generated at the source, but it does not troubleshoot why those alerts fail to create incidents in Microsoft Sentinel; the issue is in the ingestion or rule logic, not in alert generation. Option C is wrong because Microsoft Sentinel workbooks are visualization tools that display data already ingested; they do not affect incident creation and cannot diagnose why alerts are not being turned into incidents. Option D is wrong because verifying the data connector status ensures data ingestion from Microsoft Defender for Office 365, but if the connector is connected and data is flowing, the problem lies in the analytics rule's configuration (e.g., severity threshold or rule logic), not in the connector itself.

853
MCQmedium

You are hunting for signs of credential dumping using Mimikatz. Which process events in Microsoft Defender for Endpoint would most likely indicate this activity?

A.A process opening lsass.exe with access to process memory (e.g., PROCESS_VM_READ)
B.A process named powershell.exe making network connections to an external IP
C.A process named svchost.exe spawning from explorer.exe
D.A process named cmd.exe executing whoami
AnswerA

Mimikatz reads credential material directly from LSASS memory, so a process requesting PROCESS_VM_READ against lsass.exe is the strongest signal. Legitimate tools rarely open LSASS with memory-read rights, making this access mask the specific indicator Microsoft Defender for Endpoint surfaces for credential-dumping detection.

Why this answer

Mimikatz typically opens lsass.exe with specific access permissions like PROCESS_VM_READ to read process memory and dump credentials. Options B, C, and D are not specific indicators: PowerShell making network connections is too broad, svchost spawning from explorer is a normal pattern, and cmd executing whoami is not credential dumping.

854
MCQmedium

An organization uses Microsoft 365 Defender. A security analyst is investigating an incident where a user's device was compromised. The analyst wants to determine if the attacker attempted to access sensitive files stored in SharePoint Online from that device. Which advanced hunting table should the analyst query to find file access events from cloud apps?

A.CloudAppEvents
B.IdentityLogonEvents
C.DeviceFileEvents
D.EmailEvents
AnswerA

CloudAppEvents is the correct table because it specifically records activities performed in Microsoft 365 cloud services, including SharePoint Online. This schema captures rich details about file operations such as downloads, uploads, modifications, and file access by users and apps. A security analyst querying for suspicious file access in SharePoint would filter this table by Application and ActionType fields to identify the exact activity.

Why this answer

The CloudAppEvents table in Microsoft 365 Defender captures audit logs for cloud applications, including SharePoint Online. It records file access events such as viewing, downloading, or modifying files, making it the correct table to query when investigating attacker attempts to access sensitive files from a compromised device.

Exam trap

The trap here is that candidates confuse DeviceFileEvents (local file events) with cloud file access events, not realizing that SharePoint Online actions are logged only in CloudAppEvents, not in device-level tables.

How to eliminate wrong answers

Option B (IdentityLogonEvents) is wrong because it tracks authentication events (logon attempts, success/failure) but does not include file-level access events within cloud apps. Option C (DeviceFileEvents) is wrong because it captures file events on the local device (e.g., file creation, modification, deletion) but not access to files stored in SharePoint Online. Option D (EmailEvents) is wrong because it focuses on email-related events (delivery, phishing, malware) and has no data on SharePoint file access.

855
MCQhard

You are a security operations engineer for a company that uses Microsoft Defender XDR. You need to create a custom detection rule that alerts when a user performs more than 10 failed logon attempts within 5 minutes from different IP addresses. The rule should use the IdentityLogonEvents table. You have written the KQL query and now need to configure the rule settings in Microsoft 365 Defender. Which configuration should you use for the rule frequency and lookback period to minimize false positives while ensuring timely detection?

A.Run every 5 minutes with a 5-minute lookback.
B.Run every 5 minutes with a 1-hour lookback.
C.Run every 1 hour with no lookback.
D.Run every 24 hours with a 24-hour lookback.
AnswerA

Running every 5 minutes with a 5-minute lookback is optimal because the lookback exactly matches the execution interval, ensuring each event is evaluated exactly once within its own time window. This configuration minimizes detection latency to at most five minutes while avoiding both data gaps and overlapping evaluations. It's the standard baseline for near-real-time security alerting in tools like Microsoft Sentinel.

Why this answer

To detect more than 10 failed logons within 5 minutes, the rule should run every 5 minutes with a 5-minute lookback so it evaluates the most recent 5-minute window each time. This minimizes false positives by focusing on the exact time window and ensures timely detection.

Exam trap

The trap is assuming a longer lookback always improves detection, but it actually increases false positives and can duplicate alerts; candidates may pick 1-hour lookback thinking it catches more, but it violates the 5-minute condition.

How to eliminate wrong answers

Option B is wrong because a 1-hour lookback would include older events and could trigger on failures spread over an hour, increasing false positives and not matching the 5-minute condition. Option C is wrong because running every 1 hour with no lookback would miss the 5-minute window and delay detection. Option D is wrong because a 24-hour frequency and lookback is far too slow and broad, causing delayed alerts and many false positives.

856
MCQhard

Your organization uses Microsoft Sentinel and has several analytics rules that generate incidents from various data sources. The SOC team is overwhelmed by the number of incidents. You need to implement a triage system that automatically assigns incidents to different analysts based on the incident's tactics and severity. You also want to send a notification to the assigned analyst via Teams. What should you do?

A.Create multiple automation rules that trigger on incident creation, each with conditions for specific tactics and severity, and then run a playbook that assigns the incident to an analyst and sends a Teams notification.
B.Use a workbook to create a triage dashboard and instruct analysts to manually claim incidents from the dashboard.
C.Modify each analytics rule to include a custom details field that specifies the analyst, and use a playbook to send Teams notification based on that field.
D.Create a single playbook that checks the incident's tactics and severity, assigns it to the appropriate analyst, and sends a Teams notification, then configure that playbook to run automatically on all new incidents.
AnswerA

Automation rules trigger on incident creation and can filter by tactics and severity, then invoke a playbook. The playbook performs the assignment and posts the Teams notification, satisfying both the triage routing and alerting requirements without manual intervention.

Why this answer

Automation rules in Microsoft Sentinel trigger on incident creation and support conditions based on incident properties such as tactics and severity, and they can invoke a playbook. Creating multiple automation rules with tactic/severity conditions that each run an assignment-and-notification playbook delivers the required automatic triage and Teams alerting. This is the native, supported pattern for conditional incident routing.

Exam trap

The trap is choosing a single catch-all playbook or a manual dashboard instead of using automation rules with tactic/severity conditions — the exam tests whether you know automation rules are the conditional trigger layer and playbooks are the action layer.

How to eliminate wrong answers

Option B is wrong because a workbook is a visualization/reporting tool; it cannot automatically assign incidents or send notifications, and manual claiming does not meet the 'automatically assigns' requirement. Option C is wrong because custom details fields are static metadata set by analytics rules and cannot dynamically determine the correct analyst based on tactics/severity at incident time. Option D is wrong because a single playbook triggered on all incidents lacks the conditional routing logic at the automation-rule layer; while a playbook can branch internally, the question's requirement for tactic/severity-based assignment is best met with automation rules that filter and trigger, and a blanket playbook on every incident is less precise and not the recommended design.

857
MCQeasy

Your organization uses Microsoft Sentinel. You need to ensure that an incident is automatically assigned to a specific analyst when it is created. What should you create?

A.An analytics rule with an output to a specific user.
B.A playbook triggered by incident creation.
C.An automation rule with an 'Assign incident' action.
D.A watchlist that maps incident types to owners.
AnswerC

An automation rule with an 'Assign incident' action is the intended, built-in method for automatically setting the incident owner when an incident is created. Automation rules run immediately after an incident is created (or updated) and support a dedicated action that writes the owner property, optionally based on a condition such as the incident's severity or its associated analytics rule. This makes it the simplest and most reliable way to ensure ownership is always assigned.

Why this answer

An automation rule in Microsoft Sentinel can be configured to run when an incident is created and includes an 'Assign incident' action that automatically assigns the incident to a specific analyst or group. This is the native, no-code method for incident assignment without requiring external logic or playbooks.

Exam trap

The trap here is that candidates may think a playbook is required for any automation, but Microsoft Sentinel's automation rules provide a native, code-free 'Assign incident' action that is the correct and simplest solution for this scenario.

How to eliminate wrong answers

Option A is wrong because analytics rules generate alerts or incidents based on queries, but they do not have an 'output to a specific user' action; they trigger playbooks or automation rules for post-creation actions. Option B is wrong because a playbook triggered by incident creation can assign incidents, but it is an overengineered solution requiring a Logic Apps instance and additional configuration; automation rules are the simpler, built-in mechanism for this task. Option D is wrong because a watchlist is a static reference table for correlating data, not an active mechanism to assign incidents to owners upon creation.

858
MCQmedium

An organization uses Microsoft 365 Defender and receives an alert for a suspicious email sent to multiple recipients. The analyst wants to view the email metadata, including the sender, subject, and any attachments. Which advanced hunting table should the analyst use?

A.EmailEvents
B.EmailAttachmentInfo
C.EmailUrlInfo
D.DeviceEmailEvents
AnswerA

EmailEvents is the central advanced hunting table in Microsoft 365 Defender for email message-level data within Exchange Online. It exposes fields such as SenderFromAddress, SenderDisplayName, RecipientEmailAddress, Subject, and EmailDirection, as well as the delivery action (e.g., Delivered, Junked, Blocked, Failed) via the DeliveryAction column. For any scenario requiring the identity of the sender, the subject, or the final disposition of an email, EmailEvents is the correct table to query first.

Why this answer

The EmailEvents table in Advanced Hunting stores the core metadata for every email processed by Microsoft Defender for Office 365, including sender, subject, recipient, and delivery status. Since the analyst needs to view the sender, subject, and attachments for a suspicious email sent to multiple recipients, EmailEvents is the correct starting point because it contains the primary email envelope information.

Exam trap

The trap here is that candidates often confuse the purpose of EmailAttachmentInfo (which only has attachment metadata) with EmailEvents (which has the full email header), or they mistakenly choose DeviceEmailEvents thinking it covers all email activity, when it only logs client-side email events on endpoints.

How to eliminate wrong answers

Option B (EmailAttachmentInfo) is wrong because it only contains details about the attachment file name, size, and hash, but does not include the sender or subject metadata. Option C (EmailUrlInfo) is wrong because it stores URLs extracted from the email body or attachments, not the email's sender or subject. Option D (DeviceEmailEvents) is wrong because it is part of Microsoft Defender for Endpoint and logs email events on devices (e.g., from Outlook client), not server-side email metadata from Exchange Online or Defender for Office 365.

859
MCQhard

A security operations center (SOC) uses Microsoft Sentinel for log management. The SOC manager wants to reduce storage costs by automatically archiving logs that are older than 90 days to long-term retention, but retains the ability to search them if needed. What should the manager configure?

A.Change the table plan to Basic Logs for logs older than 90 days
B.Create a retention policy that deletes logs older than 90 days
C.Configure a data archiving policy in the Log Analytics workspace to archive logs after 90 days
D.Export logs older than 90 days to an Azure Storage account
AnswerC

Configuring a data archiving policy in the Log Analytics workspace automatically moves logs from the interactive retention tier to an archive tier after a defined period, such as 90 days, while preserving the ability to search them through archived log search jobs. Archived data is retained at a lower cost and remains accessible for compliance and incident investigations, subject to a separate total retention duration and additional search costs. This is the intended native method for long-term, queryable log retention in Microsoft Sentinel.

Why this answer

Configuring a data archiving policy in the Log Analytics workspace automatically moves logs older than 90 days to long-term, low-cost storage while keeping them searchable via the search job or restore feature. This directly meets the SOC manager's requirement to reduce costs without losing the ability to query archived data.

Exam trap

The trap here is that candidates confuse 'archiving' with 'deleting' or 'exporting,' assuming that moving data to cheaper storage must mean losing queryability, whereas Microsoft Sentinel's archive tier preserves searchability through restore or search jobs.

How to eliminate wrong answers

Option A is wrong because changing the table plan to Basic Logs affects all data in the table, not just logs older than 90 days, and Basic Logs have reduced query capabilities and higher ingestion costs, not archival. Option B is wrong because a retention policy that deletes logs older than 90 days permanently removes the data, eliminating the ability to search them later. Option D is wrong because exporting logs to an Azure Storage account moves them out of Log Analytics, making them unsearchable via KQL without additional tooling and breaking the requirement for retained searchability.

860
MCQmedium

A Microsoft Defender XDR incident involves a compromised endpoint. Your containment policy requires isolating the device from the network while still allowing you to run live response commands to collect evidence. You need to choose the appropriate device isolation type in Microsoft Defender for Endpoint. Which isolation type should you select?

A.Selective isolation, which blocks most network traffic but permits the Defender for Endpoint service and live response.
B.Device containment via a firewall rule that blocks the device's IP address at the perimeter.
C.Full isolation, which blocks all network traffic to and from the device.
D.App execution restriction via an indicator that blocks the malicious process hash.
AnswerA

Selective isolation limits outbound and inbound communication to the Defender for Endpoint service channel and permits live response, so you can still run commands to gather forensic artifacts while the attacker is cut off from command-and-control and lateral movement. This matches the requirement to isolate the device yet retain live response capability. You can later release the device from isolation once remediation is verified.

Why this answer

Selective isolation in Microsoft Defender for Endpoint cuts the device off from normal network communication while allowing the Defender for Endpoint service channel and live response. That preserves the analyst's ability to collect evidence through live response commands during containment. Full isolation, perimeter firewall rules, and hash-based indicators either over-restrict, fail to contain roaming devices, or address only a single artifact instead of the host.

Exam trap

The trap here is assuming full isolation is always the safest choice, when it can remove the management path needed for live response evidence collection.

861
MCQhard

Refer to the exhibit. You run this KQL query in Microsoft 365 Defender advanced hunting to investigate an incident involving IP address 203.0.113.1. The query returns results, but you need to also see which devices communicated with this IP. How should you modify the query?

A.Join with IdentityLogonEvents on AccountUpn
B.Join with DeviceNetworkEvents on DeviceId where RemoteIP == "203.0.113.1"
C.Join with DeviceInfo on DeviceId
D.Join with EmailEvents on AlertId
AnswerB

Joining DeviceNetworkEvents on DeviceId and filtering RemoteIP to 203.0.113.1 correlates the existing results with endpoint network telemetry, satisfying the requirement to identify which devices communicated with that IP. DeviceNetworkEvents records inbound and outbound connections per device, so the join surfaces the missing device context.

Why this answer

The goal is to find which devices communicated with the suspicious IP 203.0.113.1. DeviceNetworkEvents is the advanced hunting table that records network connections from devices, including the RemoteIP field. Joining on DeviceId and filtering where RemoteIP equals the target IP directly surfaces the devices that contacted it.

Exam trap

SC-200 often tests whether candidates know which advanced hunting table holds which telemetry type, so the trap is choosing a table that sounds related (like DeviceInfo or IdentityLogonEvents) instead of the one that actually records network connections.

How to eliminate wrong answers

Option A is wrong because IdentityLogonEvents tracks authentication events keyed on AccountUpn, not device-to-IP network communications, so it cannot reveal which devices talked to the IP. Option C is wrong because DeviceInfo only provides device inventory and configuration metadata; it contains no remote IP connection data to correlate. Option D is wrong because EmailEvents deals with email message metadata and AlertId linkage, which is unrelated to identifying devices that communicated with an external IP.

862
Multi-Selectmedium

Which THREE of the following are valid sources of threat intelligence that can be ingested into Microsoft Sentinel for threat hunting? (Select three.)

Select 3 answers
A.Syslog from a firewall
B.Microsoft Threat Intelligence feed
C.TAXII server
D.Custom threat intelligence via API
E.Azure Policy
AnswersB, C, D

Microsoft Threat Intelligence feed is natively integrated with Microsoft Sentinel, providing curated indicators of compromise from Microsoft's global telemetry. It satisfies the stem's ingestion requirement without custom connectors, unlike external feeds needing API configuration. This built-in source enriches threat hunting queries directly.

Why this answer

Microsoft Sentinel natively ingests threat intelligence through the Microsoft Defender Threat Intelligence (MDTI) connector, so option B (Microsoft Threat Intelligence feed) is a valid source that populates the ThreatIntelligenceIndicator table for hunting. Option C (TAXII server) is correct because Sentinel supports the Threat Intelligence - TAXII data connector, which pulls STIX/TAXII 2.x indicators from a TAXII 2.0/2.1 endpoint. Option D (Custom threat intelligence via API) is correct because Sentinel exposes the Upload Indicators API (Microsoft Sentinel Threat Intelligence Upload API) and the Graph Security tiIndicators API, allowing custom or third-party feeds to be pushed programmatically.

Option A (Syslog from a firewall) is not a threat intelligence source; it is raw log telemetry ingested via the Syslog/CEF connector for detection, not curated indicator data. Option E (Azure Policy) is a governance/compliance service for enforcing resource configurations and has no role in ingesting threat intelligence indicators.

863
MCQmedium

A cloud security administrator receives an alert from Microsoft Defender for Cloud indicating that a virtual machine has been compromised. The administrator wants to quickly isolate the VM from the network to prevent further spread while preserving the disk for forensic analysis. Which action should the administrator take?

A.Apply a just-in-time (JIT) access policy to the VM.
B.Use the "Isolate VM" action in the security alert.
C.Enable the Azure Security Benchmark initiative for the VM.
D.Configure a custom Azure Policy to deny network access.
AnswerB

Use the 'Isolate VM' action in the security alert is the correct immediate response because Defender for Cloud dynamically attaches a network security group to the VM's network interface that blocks all inbound and outbound traffic, while still allowing only the Defender service's management and forensic paths. This quarantines the compromised VM without deleting or detaching its disk, preserving evidence for investigation. The action is designed for exactly this kind of incident-response need: rapid, built-in network containment without disrupting connectivity to other Azure services that the investigation depends on.

Why this answer

The 'Isolate VM' action in Microsoft Defender for Cloud is designed specifically for compromised VMs. It applies a network security group (NSG) rule that denies all inbound and outbound traffic to the VM, effectively quarantining it from the network while leaving the disk intact for forensic analysis. This is the fastest and most direct method to contain the threat without altering the VM's configuration or disk state.

Exam trap

The trap here is that candidates confuse Just-In-Time (JIT) access with network isolation, mistakenly thinking restricting management ports is sufficient to contain a compromise, when in fact JIT does not block lateral movement or outbound malicious traffic.

How to eliminate wrong answers

Option A is wrong because Just-In-Time (JIT) access policy controls inbound RDP/SSH access via NSG rules but does not isolate the VM from all network traffic; it only restricts management ports, leaving other traffic and outbound connections active. Option C is wrong because enabling the Azure Security Benchmark initiative applies compliance policies and recommendations, not an immediate network isolation action; it is a long-term governance framework, not a response to an active compromise. Option D is wrong because configuring a custom Azure Policy to deny network access is a declarative, non-immediate control that requires policy assignment and evaluation cycles, and it does not provide the real-time, one-click isolation needed during an active incident.

864
Multi-Selectmedium

Which TWO of the following are valid methods to reduce Microsoft Sentinel data ingestion costs?

Select 2 answers
A.Disable all analytics rules.
B.Switch all data sources to basic logs.
C.Configure basic logs for high-volume verbose data sources.
D.Increase the retention period for all tables.
E.Set a daily data ingestion cap.
AnswersC, E

Configuring Basic Logs for high-volume verbose data sources is a valid cost-reduction method because Basic Logs are billed at a lower ingestion rate and stored in a low-cost, high-volume tier compared to Analytics Logs. High-volume verbose sources (e.g., DNS query logs, firewall logs, or raw network traffic) that are useful for occasional threat hunting or compliance but not for continuous alerting can be sent to Basic Logs tables, dramatically reducing the cost of data that does not need full interactive analytics. This approach preserves detection capabilities for critical security data while offloading noisy, expensive data to a cheaper storage tier.

Why this answer

Microsoft Sentinel allows you to configure basic logs for high-volume, verbose data sources (e.g., DNS or firewall logs) to reduce costs. Basic logs are stored at a lower ingestion price and support only simple queries, making them ideal for debugging or compliance data that doesn't require advanced analytics.

Exam trap

The trap here is that candidates confuse 'reducing ingestion costs' with 'reducing storage costs' or assume disabling features like analytics rules affects ingestion volume, when in fact ingestion costs are driven by data volume and log type, not rule activity.

865
Multi-Selecthard

Which TWO playbook actions can be used to automatically contain a compromised user account in Microsoft Entra ID during an incident? (Choose TWO.)

Select 2 answers
A.Reset the user's password.
B.Send a notification email to the user.
C.Disable the user account via Microsoft Graph API.
D.Add the user to a group that has access to critical resources.
E.Revoke all refresh tokens and sessions for the user.
AnswersC, E

Disabling the user account via the Microsoft Graph API (PATCH /users/{id} with accountEnabled set to false) immediately prevents the user from authenticating and blocks new token issuance. This identity-level control stops the attacker from accessing any Microsoft 365 resources and is a strong containment measure. Because it also prevents legitimate use, it is often reserved for confirmed compromises and is followed by investigation and remediation.

Why this answer

Disabling a user account via Microsoft Graph API is a direct containment action that immediately prevents the compromised account from authenticating and accessing resources. This is a standard automated response in Microsoft Sentinel or Microsoft 365 Defender playbooks to stop an active incident.

Exam trap

The trap here is that candidates often confuse 'password reset' (a remediation step) with 'containment,' or they think 'sending a notification' is an automated response, when in fact only actions that immediately block access (disable account, revoke tokens) qualify as containment in Microsoft 365 Defender playbooks.

866
MCQmedium

You are a security operations analyst for a company that uses Microsoft Defender XDR. You need to configure a custom detection rule that will trigger an alert when a specific process is executed on any device. The process name is 'malicious.exe'. You want the alert to be generated only when the process is executed with a command line containing '--encrypt'. Which query language should you use to define the custom detection rule?

A.Kusto Query Language (KQL) against the DeviceProcessEvents table.
B.SQL against the SecurityEvent table in Microsoft Sentinel.
C.PowerShell script that queries the Windows Event Log for process creation events.
D.Azure Resource Graph query against the Microsoft Defender for Endpoint resources.
AnswerA

Custom detection rules in Microsoft Defender XDR use KQL to query advanced hunting tables. The DeviceProcessEvents table contains process creation events, including process name and command line. Using KQL, you can filter for FileName == 'malicious.exe' and ProcessCommandLine contains '--encrypt' to trigger the alert as required.

Why this answer

Custom detection rules in Microsoft Defender XDR are created by writing KQL queries against advanced hunting tables. For process execution events, the DeviceProcessEvents table is appropriate. By filtering on the process file name and command line, you can precisely trigger alerts for the specified condition.

Exam trap

The trap here is confusing the query languages used by different Microsoft security products; Defender XDR custom detections use KQL, not SQL or PowerShell.

867
MCQhard

You are a security analyst at Contoso. Microsoft Sentinel is deployed with the Microsoft Defender for Cloud Apps connector. An incident is generated for a high-risk sign-in from a user named JaneDoe@contoso.com. The incident severity is Medium. The incident details show that the sign-in originated from an IP address in a country where Contoso has no business presence, and the user recently changed their password. You suspect account compromise. You need to take immediate action to contain the threat and prevent further unauthorized access. The user is currently active in Microsoft Entra ID. You have the following options: A) Force the user to re-authenticate by revoking their sessions in Microsoft Entra ID. B) Disable the user account in Microsoft Entra ID. C) Block the IP address in Microsoft Defender for Cloud Apps. D) Create a Sentinel automation rule to automatically disable accounts on similar alerts. Which action should you take first to contain the current incident?

A.Force the user to re-authenticate by revoking their sessions.
B.Disable the user account in Microsoft Entra ID.
C.Block the IP address in Microsoft Defender for Cloud Apps.
D.Create a Sentinel automation rule to automatically disable accounts on similar alerts.
AnswerB

Disabling the user account in Microsoft Entra ID is the most effective immediate containment step because it blocks all new token issuance and denies sign-in for every application that trusts Entra ID as the identity provider. This cuts off the attacker's access to Microsoft 365, Azure, and any federated SaaS apps using the account. You should also reset the user's password and revoke tokens after disabling, but the disable itself stops the attack in progress.

Why this answer

Disabling the user account immediately stops any further access using that account, which is the most direct containment action. Option A (Revoke sessions) would end current sessions but the user could still authenticate again if credentials are compromised. Option C (Block IP) is less effective as the attacker may use other IPs.

Option D (Create automation rule) is a long-term solution, not immediate containment.

868
MCQeasy

A security analyst wants to see the delivery status and phishing verdict of an email. Which advanced hunting table should the analyst query in Microsoft 365 Defender?

A.EmailEvents
B.EmailPostDeliveryEvents
C.EmailAttachmentInfo
D.EmailUrlInfo
AnswerA

EmailEvents is the primary advanced hunting schema for email security in Microsoft 365 Defender. Each row represents a distinct email message and includes fields such as DeliveryAction (e.g., Delivered, Junked, Blocked), ThreatTypes (e.g., Phish, Malware), and DetectionMethods. The Phish filter in Threat Explorer relies on this table because it contains the original verdict determined at the time of delivery, making it exactly what the analyst needs.

Why this answer

The EmailEvents table in Microsoft 365 Defender's advanced hunting schema contains the delivery status (e.g., Delivered, Failed, Filtered as spam) and the phishing verdict (e.g., Phish, Normal) for each email. This table records the initial processing and classification of the email, making it the correct source for both pieces of information.

Exam trap

The trap here is that candidates often confuse EmailEvents (initial delivery and verdict) with EmailPostDeliveryEvents (post-delivery actions), mistakenly thinking the latter includes the original verdict when it only records changes after delivery.

How to eliminate wrong answers

Option B (EmailPostDeliveryEvents) is wrong because it captures actions taken after delivery (e.g., user clicks, ZAP actions), not the initial delivery status or phishing verdict. Option C (EmailAttachmentInfo) is wrong because it stores metadata about email attachments (e.g., file name, SHA-256 hash), not delivery or verdict data. Option D (EmailUrlInfo) is wrong because it contains URLs found in the email body or attachments, not the email's delivery status or phishing classification.

869
MCQhard

You are designing an automation rule in Microsoft Sentinel that should automatically assign incidents to the appropriate analyst based on the incident type. However, the rule fails to assign correctly for some incidents. What should you verify?

A.The order of conditions in the automation rule; ensure more specific conditions are evaluated first.
B.That a playbook has been created to perform the assignment.
C.That the incident assignment rule in Microsoft Entra ID is configured correctly.
D.That the owner (analyst) has the required permissions in Microsoft Sentinel.
AnswerA

In Sentinel, automation rules evaluate conditions in top-down order; placing more specific conditions before general ones ensures that incidents matching a narrow scenario are handled by the intended rule before a broader rule can claim them. For example, if you have a rule assigning incidents from a specific asset to a specialized analyst, it must be listed before a rule that assigns all incidents to a general queue. This ordering is critical because the first matching rule takes action; otherwise, a generic rule may consume the incident first.

Why this answer

Automation rules in Microsoft Sentinel evaluate conditions in order, and the first matching condition triggers the associated action. If a broad condition (e.g., 'all incidents') is placed before a more specific condition (e.g., 'incident type equals Phishing'), the broad rule will match first and assign incorrectly, preventing the specific rule from ever running. Reordering conditions so that the most specific ones are evaluated first ensures correct assignment based on incident type.

Exam trap

Microsoft often tests the misconception that automation rules run in parallel or that all matching conditions are applied, when in fact they are evaluated sequentially and only the first match executes its action.

How to eliminate wrong answers

Option B is wrong because a playbook is not required for simple assignment; automation rules can directly set the owner (analyst) without invoking a playbook. Option C is wrong because Microsoft Entra ID (formerly Azure AD) does not have an 'incident assignment rule'—incident ownership is managed within Microsoft Sentinel, not via Entra ID configuration. Option D is wrong because the owner (analyst) does not need special permissions in Microsoft Sentinel to be assigned an incident; the automation rule itself runs with the system's permissions, and the assigned user only needs standard Sentinel reader/responder roles to interact with the incident.

870
MCQhard

During a ransomware response in Microsoft Defender XDR, you identify that multiple devices are communicating with a known C2 server over port 443. You need to block this communication across all devices immediately. What is the most effective course of action?

A.Add the C2 server domain to the Microsoft Defender for Office 365 Tenant Allow/Block List
B.Create a firewall rule to block outbound traffic to the C2 server IP address
C.Create an indicator of compromise (IoC) in Microsoft Defender for Endpoint with action 'Block'
D.Add the C2 server URL to the custom indicator list in Microsoft Defender for Cloud Apps
AnswerC

A Defender for Endpoint indicator with action 'Block' blocks the malicious IP or domain on all onboarded endpoints immediately through Network Protection, regardless of where the devices connect.

Why this answer

Creating an indicator of compromise in Microsoft Defender for Endpoint with action 'Block' is the most effective immediate action. The indicator is enforced by the Defender for Endpoint sensor and blocks the known C2 IP or domain across all onboarded devices, regardless of network location. Option A applies only to email and collaboration content.

Option B only blocks traffic that passes through the firewall and may miss remote devices or non-firewall paths. Option D applies only to cloud app sessions, not general C2 network traffic.

871
MCQeasy

A security analyst is investigating a phishing incident in Microsoft Defender XDR. The analyst wants to see the full email content and attachments. Where should the analyst look?

A.The incident timeline
B.The action center
C.The email entity page
D.The user entity page
AnswerC

The email entity page in Microsoft Defender XDR aggregates the full message body, headers, attachments and related alerts for a specific email, giving the analyst the complete content needed for phishing triage. It is reached from the incident graph or Explorer, unlike the summary views that only show metadata.

Why this answer

The Email entity page in Microsoft Defender XDR provides detailed information about an email, including content and attachments. Option A is wrong because the incident timeline shows events related to the incident, not full email content. Option B is wrong because the action center is for managing response actions, not viewing email details.

Option D is wrong because the user entity page shows user information, not email content.

872
MCQeasy

A security administrator wants to ensure that all Azure virtual machines have automatic provisioning of the Log Analytics agent enabled by default in Microsoft Defender for Cloud. Where should this configuration be set?

A.In the Azure portal under each virtual machine's 'Extensions + applications' blade
B.In Microsoft Defender for Cloud, under 'Environment settings' > 'Data collection'
C.In Microsoft Sentinel, under 'Data connectors' for Defender for Cloud
D.In Azure Policy, by assigning the 'Deploy Log Analytics agent' initiative
AnswerB

Microsoft Defender for Cloud's 'Environment settings' > 'Data collection' page is the correct central location to enable auto-provisioning of the Log Analytics agent (or Azure Monitor Agent) across all subscriptions. Toggling the agent here creates the underlying policy assignments that automatically install the agent on every VM without per-VM manual interaction, ensuring consistent security monitoring coverage.

Why this answer

The automatic provisioning of the Log Analytics agent for all Azure virtual machines in Defender for Cloud is configured under 'Environment settings' > 'Data collection'. This setting enables Defender for Cloud to automatically deploy the Log Analytics agent to new and existing VMs, ensuring security monitoring without manual intervention.

Exam trap

The trap here is that candidates often confuse the centralized 'Data collection' setting in Defender for Cloud with per-VM manual extension installation (Option A) or with Azure Policy assignments (Option D), not realizing that Defender for Cloud provides a built-in toggle to enable automatic provisioning across all VMs in a subscription.

How to eliminate wrong answers

Option A is wrong because the 'Extensions + applications' blade under each VM only allows manual installation of the Log Analytics agent on a per-VM basis, not a default, automated provisioning for all VMs. Option C is wrong because Microsoft Sentinel's 'Data connectors' for Defender for Cloud is used to ingest security alerts and events from Defender for Cloud into Sentinel, not to configure automatic agent provisioning. Option D is wrong because while Azure Policy can enforce agent deployment, the specific 'Deploy Log Analytics agent' initiative is a broader policy that can be assigned independently, but the question asks for the configuration location within Defender for Cloud itself, which is the 'Data collection' setting under 'Environment settings'.

873
MCQmedium

During a threat hunt, you discover a PowerShell script that downloads and executes a payload from a known malicious URL. The script was run on multiple workstations. Which Microsoft Defender XDR action should you take to contain the threat?

A.Run a full antivirus scan on all affected workstations.
B.Add the URL to the custom indicator list in Microsoft Defender XDR.
C.Initiate a device isolation on the affected workstations using Microsoft Defender for Endpoint.
D.Create a custom detection rule in Microsoft Sentinel.
AnswerC

Device isolation severs network connectivity while preserving the endpoint for investigation, immediately halting the malicious PowerShell script's payload execution and preventing lateral movement across the affected workstations. This directly contains the active threat identified during the hunt.

Why this answer

Device isolation in Microsoft Defender for Endpoint immediately contains the threat by disconnecting the affected workstations from the network, preventing further spread or command-and-control communication. Option A only scans but does not prevent re-infection if the payload is still active. Option B blocks the URL but does not remediate already infected machines.

Option D is about detection in Sentinel, not containment.

874
MCQmedium

An organization uses Microsoft Sentinel with the Microsoft Defender for Cloud connector enabled. A security analyst receives an alert from Defender for Cloud about a potential brute-force attack on an Azure VM. The analyst wants to automatically create an incident in Sentinel and trigger a playbook that blocks the attacker's IP using a firewall. Which type of Sentinel automation rule should the analyst configure?

A.Analytics rule automation
B.Incident automation rule
C.Playbook trigger
D.Custom log ingestion
AnswerB

Incident automation rules are the central mechanism in Microsoft Sentinel for defining automated responses at the incident level. They execute when an incident is created or updated, and can trigger playbooks to perform actions such as blocking an IP address, assigning an owner, or adding tags. They support conditions, ordering, and multiple actions, making them essential for SOAR workflows.

Why this answer

Incident automation rules in Microsoft Sentinel allow you to automatically trigger a playbook when an incident is created or updated. Since the Defender for Cloud alert generates an incident in Sentinel, an incident automation rule can be configured to run a playbook that blocks the attacker's IP via a firewall, meeting the requirement without needing to modify the analytics rule itself.

Exam trap

The trap here is confusing 'analytics rule automation' with 'incident automation rule'—candidates often think the automation must be tied to the rule that generated the alert, but Sentinel separates alert generation (analytics rules) from incident-level actions (incident automation rules).

How to eliminate wrong answers

Option A is wrong because analytics rule automation is used to automatically run a playbook when an analytics rule generates an alert, not when an incident is created from an existing alert (like from Defender for Cloud). Option C is wrong because a playbook trigger is not a type of Sentinel automation rule; playbooks are triggered by automation rules or directly from incidents/alerts, but 'Playbook trigger' is not a valid rule type. Option D is wrong because custom log ingestion is a data collection method, not an automation rule, and cannot trigger playbooks based on incidents.

875
MCQhard

Your organization uses Microsoft Defender XDR. A security administrator reports that a user's device is showing high severity alerts for 'Tampering with Microsoft Defender Antivirus' but the device is not isolated. You need to ensure that when such alerts occur, the device is automatically isolated in Microsoft Defender for Endpoint. What should you do?

A.Create an automation rule in Microsoft Sentinel
B.Create an endpoint detection and response policy in Microsoft Intune
C.Create a custom detection rule in Microsoft Defender XDR
D.Configure an attack surface reduction rule
AnswerC

Custom detection rules in Microsoft Defender XDR are built with KQL queries over the advanced hunting schema (such as DeviceProcessEvents or DeviceNetworkEvents) and allow you to set automatic response actions directly, including 'Isolate device' as a triggered action. When the query matches a device, the rule natively instructs the Defender for Endpoint sensor to isolate that machine immediately, which is exactly the capability the scenario requires. This is the only option that both detects a suspicious behavior and executes a device-level containment action without relying on external automation.

Why this answer

Microsoft Defender XDR's custom detection rules allow you to create automated actions based on specific alert triggers, such as 'Tampering with Microsoft Defender Antivirus'. By configuring a custom detection rule with an automated response action (e.g., 'Isolate device'), you can ensure the device is automatically isolated in Microsoft Defender for Endpoint when the alert occurs, without requiring manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules in Microsoft Sentinel (which handle incidents) with custom detection rules in Defender XDR (which handle raw alerts and can trigger direct automated actions), leading them to choose Option A despite Sentinel not being the native tool for this specific Defender-for-Endpoint isolation requirement.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel automation rules operate on incidents ingested into Sentinel, not directly on Defender XDR alerts; they would require Sentinel to be connected and the alert to be forwarded, adding latency and complexity. Option B is wrong because endpoint detection and response (EDR) policies in Microsoft Intune are used to configure device compliance and security baselines, not to define automated response actions triggered by specific alerts. Option D is wrong because attack surface reduction (ASR) rules are designed to block malicious behaviors (e.g., script execution), not to trigger automated isolation actions in response to specific high-severity alerts like tampering.

876
MCQmedium

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos ticket request. What is the most appropriate first step?

A.Disable the user account.
B.Investigate the alert in the Microsoft 365 Defender portal.
C.Reset the user's password.
D.Reset the krbtgt account password.
AnswerB

Investigating the alert in the Microsoft 365 Defender portal is the correct first step because it provides the full attack story, including the involved source and target entities, activity timelines, and evidence-based recommendations. The portal correlates signals from Microsoft Defender for Identity with identity and service events, letting you confirm whether the alert is a true positive and determine the scope of compromise. Only after this investigation should you choose a containment or remediation action such as resetting the password or disabling the account.

Why this answer

The first step when receiving any security alert, including a suspicious Kerberos ticket request from Microsoft Defender for Identity, is to investigate the alert in the Microsoft 365 Defender portal. This portal provides the unified security operations console where you can view the full alert details, related entities, and the MITRE ATT&CK mapping to understand the scope and severity before taking any remediation actions. Prematurely disabling accounts or resetting passwords without investigation can destroy forensic evidence and potentially disrupt legitimate user activity.

Exam trap

The trap here is that candidates often jump to immediate remediation actions like disabling accounts or resetting passwords, forgetting that the first step in any incident response process (as per NIST 800-61 and Microsoft's own guidance) is always investigation and triage to confirm the alert and understand the attack context.

How to eliminate wrong answers

Option A is wrong because disabling the user account without investigation may be premature; the alert could be a false positive or part of a larger attack chain that requires analysis before containment. Option C is wrong because resetting the user's password does not address the root cause of a suspicious Kerberos ticket request, which may involve ticket forgery (e.g., Golden Ticket or Silver Ticket) or Kerberoasting, and password reset alone will not invalidate already issued tickets. Option D is wrong because resetting the krbtgt account password is a drastic, high-impact action that should only be performed as part of a structured response to a confirmed domain compromise (e.g., KRBTGT reset procedure), not as a first step for a single suspicious ticket alert.

877
MCQeasy

Your SOC team uses Microsoft Sentinel incident management. They want to automatically assign high-severity incidents to a senior analyst and send a notification to Microsoft Teams. What should you use?

A.Create an automation rule that triggers on incident creation, assigns the incident, and runs a playbook to post to Teams.
B.Create a playbook and attach it directly to the analytics rule.
C.Create a watchlist to define assignment rules and configure a workbook for notifications.
D.Create an analytics rule with incident grouping and assignment.
AnswerA

Automation rules are the native incident orchestration mechanism in Microsoft Sentinel. You can define a trigger on incident creation and add actions that assign the incident to an owner, set status/tags, and invoke a playbook—a Logic App—that posts a message to Teams. This directly meets both requirements and is the intended pattern for incident assignment and notification.

Why this answer

Automation rules in Microsoft Sentinel can trigger on incident creation (e.g., when severity is 'High'), automatically assign the incident to a specific owner (senior analyst), and then invoke a playbook (Azure Logic App) to post a message to Microsoft Teams. This combines assignment logic with automated notification in a single, manageable rule.

Exam trap

The trap here is that candidates confuse analytics rules (which only generate alerts) with automation rules (which handle post-creation actions like assignment and playbook execution), leading them to incorrectly select option B or D.

How to eliminate wrong answers

Option B is wrong because playbooks cannot be attached directly to analytics rules; they must be invoked via automation rules or as part of an incident trigger. Option C is wrong because watchlists are used for reference data (e.g., IP addresses) and workbooks are for visualization, not for automated assignment or notification. Option D is wrong because analytics rules generate alerts and can group incidents, but they do not support assignment or notification actions; those require automation rules or playbooks.

878
MCQeasy

Refer to the exhibit. An analyst runs the command to install the Azure Monitor Agent on a VM. What is the primary purpose of installing this agent in the context of security incident response?

A.To collect security events and performance data for analysis in Microsoft Sentinel.
B.To integrate the VM with Microsoft Defender for Cloud.
C.To scan the VM for vulnerabilities.
D.To enable real-time malware protection on the VM.
AnswerA

The Azure Monitor Agent uses data collection rules to gather Windows or Linux security events and performance counters from the VM, forwarding them to the Log Analytics workspace that Microsoft Sentinel ingests. This supplies the telemetry analysts need during incident response.

Why this answer

The Azure Monitor Agent (AMA) is the modern replacement for the Log Analytics agent (MMA/OMS) and is used to collect security events, Windows Event Logs, Syslog, and performance counters from VMs and forward them to a Log Analytics workspace. In Microsoft Sentinel, that workspace is the data lake that powers analytics rules, hunting queries, and workbooks — so AMA's primary purpose in incident response is feeding telemetry into Sentinel for detection and investigation.

Exam trap

The trap is conflating the telemetry-collection agent with the endpoint-protection agent — candidates pick 'real-time malware protection' or 'vulnerability scanning' because those sound like security agent functions, but AMA only ships logs and metrics.

How to eliminate wrong answers

Option B is wrong because Defender for Cloud integration is achieved through the Defender for Cloud auto-provisioning of the agent, but the agent's purpose is data collection, not 'integration' — and Defender for Cloud is a separate posture/protection service. Option C is wrong because vulnerability scanning is performed by Defender for Servers' integrated Qualys scanner or by Defender Vulnerability Management, not by AMA itself. Option D is wrong because real-time malware protection is provided by Microsoft Defender for Endpoint (MDE), which is a separate agent/onboarding, not AMA.

879
Multi-Selectmedium

Which TWO conditions must be met to enable Microsoft Sentinel UEBA? (Choose two.)

Select 2 answers
A.Microsoft Entra ID P2 licenses must be assigned to users.
B.KQL queries must be created for entity behavior.
C.Microsoft Defender XDR must be onboarded.
D.The SecurityInsights solution must be installed in the workspace.
E.Azure SQL Database must be deployed.
AnswersA, D

Microsoft Entra ID P2 licenses are a hard prerequisite for UEBA because Sentinel derives user entity behavior across the identity plane from Microsoft Entra ID Protection, which only emits risk signals and rich user context under a P2 license (e.g., risk detections, risky sign-ins, and user risk history). Without P2, the identity baseline that Sentinel's UEBA machine-learning models rely on is never populated, so user-centric anomaly detection cannot be calculated even though other data sources are connected.

Why this answer

Microsoft Sentinel UEBA requires the SecurityInsights solution to be installed in the Log Analytics workspace, as this solution provides the UEBA data connectors and analytics rules. Additionally, Microsoft Entra ID P2 licenses are required because UEBA relies on the identity protection and risk detection capabilities that are only available with P2 licensing, enabling the enrichment of entity behavior profiles with risk data.

Exam trap

The trap here is that candidates often confuse enabling UEBA with simply having Sentinel deployed, overlooking the specific licensing requirement (Entra ID P2) and the need for the SecurityInsights solution to be installed, rather than assuming UEBA is automatically available with any Sentinel workspace.

880
MCQhard

Your organization uses Microsoft Sentinel. You have a requirement to automatically add a tag to incidents that involve a specific user. The tag should be added when the incident is created. What should you configure?

A.Add the user to a watchlist and create a fusion rule.
B.Create an automation rule that triggers on incident creation and runs a playbook with the 'Add tag' action.
C.Modify the analytics rule to include a tag in the incident configuration.
D.Enable entity behavior analytics to automatically tag incidents.
AnswerB

Automation rules in Microsoft Sentinel are the native orchestration mechanism that can trigger on incident creation (or status change) and execute a playbook. A playbook built in Azure Logic Apps can include the 'Add tag' action from the Sentinel connector, which appends the desired tag to the incident. This directly satisfies the requirement by applying the tag automatically, and it is the documented method for enriching incidents with custom labels because analytics rules and watchlists lack this capability.

Why this answer

Automation rules in Microsoft Sentinel can be configured to trigger when an incident is created, and they can run a playbook that includes the 'Add tag' action. This allows you to automatically tag incidents involving a specific user by incorporating logic within the playbook to check for that user's presence in the incident entities.

Exam trap

The trap here is that candidates may confuse the ability to configure tags directly in an analytics rule (which is not supported) with the correct method of using automation rules and playbooks to add tags after incident creation.

How to eliminate wrong answers

Option A is wrong because a watchlist is a data source for matching and enrichment, but a fusion rule is designed to detect multi-stage attacks by correlating alerts, not to add tags to incidents. Option C is wrong because analytics rules can define incident properties like severity or tactics, but they do not support adding tags directly; tags must be added post-creation via automation rules or playbooks. Option D is wrong because entity behavior analytics (UEBA) profiles entity behavior and generates anomalies, but it does not automatically tag incidents; it relies on analytics rules to create incidents from those anomalies.

881
Multi-Selecteasy

Which TWO response actions are available in Microsoft Defender for Endpoint for a compromised device? (Choose two.)

Select 2 answers
A.Disable the user account
B.Run a full antivirus scan
C.Change the Windows Firewall rules
D.Isolate the device from the network
E.Reset the device to factory defaults
AnswersB, D

A full antivirus scan is an available device response action in Microsoft Defender for Endpoint, running alongside quick scan to detect and remediate malware on the compromised endpoint. It supports containment and eradication without isolating the device or requiring manual intervention.

Why this answer

Options B and D are correct because Microsoft Defender for Endpoint includes predefined response actions such as running a full antivirus scan and isolating a device from the network. Option A is incorrect because disabling the user account is an identity mitigation action in Azure AD, not a device response in Defender for Endpoint. Option C is incorrect because changing Windows Firewall rules is not a standard response action in Defender for Endpoint.

Option E is incorrect because resetting a device to factory defaults is not a supported response action.

882
MCQmedium

A security analyst in Microsoft 365 Defender is using advanced hunting to investigate a suspected data exfiltration. The analyst wants to find all outbound network connections from a specific device that occurred in the last hour, ordered by timestamp. Which table and KQL query should the analyst use?

A.DeviceNetworkEvents | where DeviceName == "deviceA" and Timestamp > ago(1h) | project Timestamp, RemoteIP, RemotePort | order by Timestamp asc
B.DeviceProcessEvents | where DeviceName == "deviceA" and Timestamp > ago(1h) | project Timestamp, RemoteIP, RemotePort | order by Timestamp asc
C.DeviceFileEvents | where DeviceName == "deviceA" and Timestamp > ago(1h) | project Timestamp, RemoteIP, RemotePort | order by Timestamp asc
D.EmailEvents | where SenderUpn == "deviceA" and Timestamp > ago(1h) | project Timestamp, RemoteIP, RemotePort | order by Timestamp asc
AnswerA

Correct. DeviceNetworkEvents is Microsoft 365 Defender's advanced hunting table for actual network connection sessions, capturing fields such as Timestamp, DeviceName, RemoteIP, RemotePort, and direction. Filtering on DeviceName == 'deviceA' and Timestamp > ago(1h) isolates only that host's traffic over the last hour, and projecting then ordering by Timestamp ascending gives a precise chronological timeline of each connection for investigation.

Why this answer

The DeviceNetworkEvents table in Microsoft 365 Defender captures outbound network connections, including remote IP addresses and ports. The query filters for a specific device (DeviceName == 'deviceA'), limits results to the last hour using Timestamp > ago(1h), projects the relevant columns, and orders by Timestamp ascending to show the earliest connections first.

Exam trap

The trap here is that candidates may confuse the purpose of different Microsoft 365 Defender tables, mistakenly selecting DeviceProcessEvents or DeviceFileEvents for network-related queries because they associate processes or files with data exfiltration, rather than recognizing that network connections are stored exclusively in DeviceNetworkEvents.

How to eliminate wrong answers

Option B is wrong because DeviceProcessEvents logs process creation events, not network connections, and does not contain RemoteIP or RemotePort fields. Option C is wrong because DeviceFileEvents logs file creation, modification, and deletion events, not network connections, and lacks RemoteIP/RemotePort. Option D is wrong because EmailEvents tracks email messages, not device network connections, and uses SenderUpn (a user principal name) instead of DeviceName, making the filter invalid.

883
Multi-Selectmedium

An incident in Microsoft Sentinel involves multiple alerts indicating a potential data exfiltration via SharePoint Online. You need to respond and remediate. Which THREE actions should be taken?

Select 3 answers
A.Remove external sharing permissions on SharePoint sites.
B.Block the user account in Microsoft Entra ID.
C.Reset the user's password and enforce MFA.
D.Isolate the user's device using Microsoft Defender for Endpoint.
E.Create a custom detection rule for similar activity.
AnswersA, B, D

In the context of a Sentinel incident, external sharing on SharePoint sites is a common data exfiltration vector when accounts are compromised. Removing external sharing permissions—via the SharePoint admin center or PowerShell cmdlets like Set-SPOTenant -SharingCapability—immediately revokes external users' ability to access shared links, cutting off the attacker's current path to exfiltrate data. This is a direct containment action at the data plane, and it is crucial to perform before or alongside user-level blocking to stop exfiltration that has already been enabled.

Why this answer

Removing external sharing permissions on SharePoint sites (A) prevents further data leaks via sharing. Blocking the user account in Microsoft Entra ID (B) stops further access immediately. Isolating the user's device using Microsoft Defender for Endpoint (D) contains the threat by preventing lateral movement.

Resetting the user's password and enforcing MFA (C) is a good follow-up but less immediate than blocking the account. Creating a custom detection rule (E) is proactive but not a direct response to the current incident.

884
MCQhard

You are analyzing the KQL query above in Microsoft Sentinel. The query is designed to find devices with high outbound SMB (port 445) connections to suspicious public IPs. However, the query returns no results. What is the most likely issue?

A.Port 445 is not used for SMB.
B.The column RemoteIPType does not exist in DeviceNetworkEvents.
C.The materialize function is not allowed in this context.
D.The syntax for the second query is incorrect.
AnswerB

DeviceNetworkEvents lacks a RemoteIPType column, so referencing it makes the query fail silently or return nothing. The schema exposes RemoteIP, RemoteUrl and RemotePort instead; filtering public addresses requires an ipv4_is_private() or similar check on RemoteIP. This schema mismatch, not the SMB filter, explains the empty result set.

Why this answer

The query returns no results most likely because it references a column, RemoteIPType, that does not exist in the DeviceNetworkEvents table in Microsoft Sentinel. Referencing a non-existent column causes a query error or empty result, and RemoteIPType is not a standard schema field in that table.

Exam trap

SC-200 often tests schema familiarity by presenting a plausible-looking but non-existent column, tempting candidates to blame syntax or functions instead of the invalid field reference.

How to eliminate wrong answers

Option A is wrong because port 445 is indeed the standard port for SMB, so the premise of the query is correct. Option C is wrong because the materialize function is allowed in KQL and is commonly used to cache intermediate results; it is not the cause of empty results here. Option D is wrong because the syntax of the second query is not inherently incorrect — the issue is the invalid column reference, not the query structure.

885
Multi-Selecteasy

Which THREE are valid incident classification categories in Microsoft Sentinel? (Select THREE.)

Select 3 answers
A.False Positive
B.Malicious
C.Informational
D.True Positive
E.Benign Positive
AnswersA, D, E

Microsoft Sentinel permits analysts to classify incidents as False Positive, meaning the alert was triggered but represents no genuine malicious activity. It is one of the platform's built-in classification values used to close incidents and tune analytics rules.

Why this answer

In Microsoft Sentinel, incident classification captures the analyst's triage verdict on an incident, and the three supported values are True Positive, Benign Positive, and False Positive. Option D (True Positive) is correct because it marks an incident confirmed as a genuine security threat requiring action. Option E (Benign Positive) is correct because it marks an incident that triggered legitimately but represents expected or authorized activity rather than an attack.

Option A (False Positive) is correct because it marks an incident caused by inaccurate or misconfigured detection logic that does not reflect real activity. Option B (Malicious) is not a classification value — maliciousness is conveyed through severity and tactics/entities, not the classification field. Option C (Informational) is not a classification value either; it is not one of the three triage verdicts Sentinel exposes for incident classification.

Exam trap

The trap is that candidates might assume only two categories are valid, but in fact, three are recognized: False Positive, True Positive, and Benign Positive. Many confuse Benign Positive with False Positive or Informational, but all three are distinct and valid.

886
Multi-Selecthard

Which THREE are valid components of a Microsoft Sentinel automation rule?

Select 3 answers
A.Actions (e.g., Run playbook, Change severity)
B.Watchlist
C.KQL query
D.Conditions (e.g., If severity equals Medium)
E.Trigger (e.g., When incident is created)
AnswersA, D, E

Actions in a Microsoft Sentinel automation rule are the operational steps that execute when the rule's trigger and conditions are satisfied. These include invoking playbooks, modifying incident severity, assigning ownership, adding tags, or closing the incident. Actions run sequentially in the order defined in the rule and are the only components that actually change the state of the incident or perform external responses.

Why this answer

Automation rules in Microsoft Sentinel allow you to define actions such as running a playbook or changing the severity of an incident. These actions are executed automatically when the rule's trigger and conditions are met, enabling streamlined incident response without manual intervention.

Exam trap

The trap here is that candidates often confuse the components of an automation rule with those of an analytics rule, mistakenly selecting KQL queries or watchlists as valid automation rule components.

887
MCQeasy

You are a SOC analyst using Microsoft Sentinel. You receive an incident with high severity. You need to quickly gather additional context about the affected user account, including recent sign-in logs and role assignments. Which feature should you use?

A.Sentinel Workbooks
B.Analytics rules
C.Entity pages
D.Hunting queries
AnswerC

Entity pages in Sentinel are the correct investigation surface because they aggregate everything known about a specific entity (user, host, IP, mailbox, etc.) into a single timeline, including related alerts, incidents, bookmarks, and anomalies. They leverage UEBA to present risk scores, behavioral insights, and peer anomaly comparisons, which are essential for understanding whether the entity is compromised or merely active. This entity-centric view directly supports the 'entity timeline' requirement that other tools lack.

Why this answer

Entity pages in Microsoft Sentinel provide a centralized, pre-built view of a specific entity (such as a user account), aggregating related alerts, incidents, and data from connected sources like Azure Active Directory sign-in logs and role assignments. This allows a SOC analyst to quickly gather contextual information without manually querying multiple data sources, making it the ideal feature for high-severity incidents requiring rapid investigation.

Exam trap

The trap here is that candidates confuse the investigative, entity-focused nature of Entity pages with the broader, dashboard-oriented purpose of Workbooks, leading them to choose Option A because both involve visual data presentation.

How to eliminate wrong answers

Option A is wrong because Sentinel Workbooks are customizable dashboards for visualizing data trends and metrics, not for drilling into a single entity's recent activity like sign-in logs or role assignments. Option B is wrong because Analytics rules are used to generate alerts and incidents based on predefined detection logic, not to investigate or retrieve context about an existing incident's affected user. Option D is wrong because Hunting queries are proactive, ad-hoc KQL searches for potential threats across historical data, not a structured, entity-specific context gathering tool for an active incident.

888
MCQmedium

A security analyst in Microsoft 365 Defender uses advanced hunting to detect possible credential theft. They want to find instances where a user signed in from an IP address that is not in their organization's known IP range. Which table should they query to get sign-in location and IP address?

A.DeviceLogonEvents
B.IdentityLogonEvents
C.EmailEvents
D.AlertInfo
AnswerB

IdentityLogonEvents is the advanced hunting table that stores authentication events for identities across Azure AD and on-premises Active Directory, including both cloud-based and hybrid sign-ins. It includes the user principal name, the source IP address, the application or service targeted, and the authentication result, which makes it the correct table for reviewing a suspicious cloud sign-in IP. Analysts can filter by Timestamp, AccountUpn, and IPAddress to isolate the specific login attempt.

Why this answer

IdentityLogonEvents is the correct table because it contains cloud identity logon data from Microsoft Entra ID (formerly Azure AD), including sign-in location, IP address, and user details. This table is specifically designed for hunting authentication-related events like credential theft, where you need to correlate user sign-ins with IP addresses to detect anomalies against known IP ranges.

Exam trap

The trap here is that candidates often confuse DeviceLogonEvents (local device logs) with IdentityLogonEvents (cloud identity logs), failing to recognize that credential theft via cloud sign-ins requires cloud authentication data, not local OS event logs.

How to eliminate wrong answers

Option A is wrong because DeviceLogonEvents captures local device logon events (e.g., Windows security events like Event ID 4624) and does not include cloud sign-in IP addresses or location data from Microsoft Entra ID. Option C is wrong because EmailEvents focuses on email-related events (e.g., delivery, phishing) and does not contain sign-in location or IP address data. Option D is wrong because AlertInfo provides metadata about alerts (e.g., severity, title) but does not contain raw sign-in logs with IP addresses or location information.

889
MCQeasy

A security analyst is investigating a malware outbreak and needs to find all devices where a specific malicious file with a known SHA1 hash has been observed in the last 24 hours. Which Advanced Hunting table in Microsoft 365 Defender should be the primary source for this query?

A.DeviceFileEvents
B.EmailAttachmentInfo
C.DeviceProcessEvents
D.DeviceNetworkEvents
AnswerA

DeviceFileEvents is the correct table because it records every file creation, modification, rename, and deletion event on endpoints via Microsoft Defender for Endpoint, including the file's SHA1/SHA256 hashes, full path, device ID, and timestamp. This makes it ideal for a query that screens all devices for a specific malware hash, since the file must exist on disk before it can be executed or otherwise cause network activity. The table is filesystem-centric, so it directly identifies affected machines regardless of whether the file has been run.

Why this answer

DeviceFileEvents is the correct table because it specifically records file creation, modification, and deletion events on endpoints, including the SHA1 hash of files. To find all devices where a specific malicious file with a known SHA1 hash has been observed, this table provides the direct file-level telemetry needed for the query.

Exam trap

The trap here is that candidates may confuse file observation with process execution or network activity, leading them to choose DeviceProcessEvents or DeviceNetworkEvents, but DeviceFileEvents is the only table that directly records the presence of a file by its hash on a device.

How to eliminate wrong answers

Option B is wrong because EmailAttachmentInfo tracks email attachments and their metadata, but it does not record file events on devices after the attachment is opened or saved, so it cannot show where the file was observed on endpoints. Option C is wrong because DeviceProcessEvents logs process creation events, not file events; while a malicious file might be executed as a process, the table does not directly record the SHA1 hash of the file itself unless it is the process image. Option D is wrong because DeviceNetworkEvents logs network connections and traffic, not file-level events, so it cannot be used to find devices where a specific file was observed.

890
MCQmedium

Your organization has Microsoft Defender for Office 365. You need to review a user's reported phishing email in Microsoft Defender XDR. Which section of the Microsoft Defender portal should you check?

A.Submissions
B.Threat Explorer
C.Alerts
D.Action center
AnswerA

The Submissions page in Microsoft Defender XDR is the centralized, dedicated queue for user-reported messages, surfaced through the Report Message and Report Phishing add-ins in Outlook. It provides security admins with the message details, report type, and source, and allows them to triage, analyze, and take remediation actions such as release, purge, or submit to Microsoft for analysis. This page is the only location specifically designed to display what users have manually flagged, making it the correct place to find user-reported messages.

Why this answer

The Submissions page in the Microsoft Defender portal is the dedicated section for reviewing user-reported phishing emails. It allows security operators to view, analyze, and take action on messages that users have reported as suspicious or malicious, directly integrating with Microsoft Defender for Office 365's threat intelligence pipeline.

Exam trap

The trap here is that candidates confuse the Submissions page (for user-reported messages) with Threat Explorer (for querying historical threat data), leading them to choose B instead of A.

How to eliminate wrong answers

Option B is wrong because Threat Explorer is a real-time investigation tool for querying email and collaboration data, not a repository for user-reported submissions. Option C is wrong because Alerts are generated by detection rules and policies, not by direct user reporting of phishing emails. Option D is wrong because Action center is used for managing remediation actions (like device isolation or automated investigation responses), not for reviewing user-reported messages.

891
MCQeasy

During an incident response, you need to collect forensic data from a compromised Linux server that is not managed by Microsoft Defender for Endpoint. You plan to use a manual collection script. Which tool should you use to securely upload the collected data to Azure for analysis?

A.Azure CLI to upload the data to an Azure Files share.
B.AzCopy to upload the data to Azure Blob Storage.
C.PowerShell to send the data to Log Analytics workspace.
D.The Log Analytics agent to forward the data.
AnswerB

AzCopy transfers data directly into Azure Blob Storage over HTTPS, satisfying the requirement to securely upload forensic artefacts from an unmanaged Linux host. Because the server lacks Microsoft Defender for Endpoint, the built-in live response collection is unavailable, so a manual script paired with AzCopy provides the supported upload path.

Why this answer

AzCopy, is the correct tool because it is designed for efficient, secure data transfer to Azure Blob Storage, supports Linux, and does not require a managed agent. Option A is incorrect because Azure CLI is a management tool, not optimized for large file uploads. Option C is incorrect because PowerShell is not natively installed on Linux typically, and Log Analytics works with structured log data, not arbitrary forensic files.

Option D is incorrect because the Log Analytics agent forwards structured log data, not raw files.

892
MCQeasy

A security analyst in Microsoft Sentinel wants to create a custom analytics rule that triggers when more than 10 failed logon attempts from a single source IP address occur within 5 minutes. The analyst writes a KQL query to aggregate sign-in logs. Which KQL operator should the analyst use to group events by source IP and count each failure?

A.extend
B.project
C.summarize
D.where
AnswerC

The summarize operator is the core aggregation mechanism in Kusto Query Language, grouping rows by one or more key columns and applying an aggregate function such as count(), sum(), or dcount() to each group, returning a single row per unique combination of those keys. In a Microsoft Sentinel context, using summarize with count() is the direct way to produce event counts by entity, user, or time interval, especially when combined with the bin() function for time-bucketed counts. This operator is functionally equivalent to SQL's GROUP BY and is indispensable for creating security analytics that require totals, averages, or distinct counts across segmented data.

Why this answer

The `summarize` operator is correct because it groups rows by a specified key (source IP) and applies an aggregation function (like `count()`) to produce a single output row per group. In this scenario, the analyst needs to count failed logon attempts per source IP, which requires grouping and counting—exactly what `summarize` does.

Exam trap

The trap here is that candidates often confuse `extend` or `project` with aggregation, thinking they can count events by adding a column, but only `summarize` performs the required grouping and counting operation.

How to eliminate wrong answers

Option A is wrong because `extend` adds a new calculated column to each row but does not group or aggregate data; it would not produce a count per IP. Option B is wrong because `project` selects or reorders columns without any aggregation or grouping; it cannot count events. Option D is wrong because `where` filters rows based on a condition but does not group or aggregate; it would only reduce the dataset without producing counts per IP.

893
MCQeasy

A company uses Microsoft Defender for Cloud to protect Azure virtual machines. The security team wants to identify which VMs have missing system updates such as critical security patches. Which Defender for Cloud feature should they use?

A.Adaptive application controls
B.Just-in-time VM access
C.Vulnerability assessment
D.File integrity monitoring
AnswerC

Vulnerability assessment in Microsoft Defender for Cloud uses an integrated scanner, like Microsoft Defender Vulnerability Management or Qualys, to continuously inspect VMs for known CVEs, missing OS patches, and security misconfigurations. This scanner evaluates the guest operating system state and correlates findings against vulnerability intelligence to produce actionable recommendations such as 'Machines should have vulnerability findings resolved.' Therefore, it is the only listed option that directly identifies missing security updates and is the correct control for this scenario.

Why this answer

Vulnerability assessment in Microsoft Defender for Cloud scans Azure VMs for missing system updates, including critical security patches, by integrating with built-in or partner vulnerability scanners (e.g., Qualys). This feature provides a continuous assessment of OS and application vulnerabilities, directly addressing the need to identify VMs with missing patches.

Exam trap

The trap here is confusing vulnerability assessment (which identifies missing patches and misconfigurations) with adaptive application controls (which restricts application execution) or file integrity monitoring (which detects file changes), leading candidates to pick a feature that addresses a different security control objective.

How to eliminate wrong answers

Option A is wrong because Adaptive application controls use machine learning to define allowlists for applications running on VMs, focusing on controlling which executables can run, not on identifying missing system updates. Option B is wrong because Just-in-time VM access reduces the attack surface by managing inbound network access to VMs on specific ports, but it does not scan for missing patches or vulnerabilities. Option D is wrong because File integrity monitoring tracks changes to critical system files and registry keys, alerting on unauthorized modifications, but it does not assess the state of system updates or patch levels.

894
Multi-Selectmedium

Which THREE actions can be performed by automation rules in Microsoft Sentinel?

Select 3 answers
A.Modify a data connector to ingest more logs
B.Create a new analytics rule
C.Assign an incident to a specific owner
D.Run a playbook on an incident
E.Add a tag to an incident
AnswersC, D, E

Automation rules respond to incident creation by applying triage actions, and owner assignment is one of the supported operations. The rule can route an incident to a named analyst or group automatically, removing manual queue handling without invoking a logic app.

Why this answer

Automation rules in Microsoft Sentinel are designed to triage and manage incidents, so option C is correct because they can assign an incident to a specific owner (for example, setting the Owner field to a user or group) as part of incident handling. Option D is correct because automation rules can trigger a playbook on an incident, which is a core capability used to run automated response logic when an incident is created or updated. Option E is correct because automation rules can add tags to an incident, enabling classification, filtering, and later automation based on those tags.

Options A and B are not correct: automation rules cannot modify a data connector to ingest more logs, and they cannot create a new analytics rule; those are configuration tasks performed through the Sentinel data connectors and analytics rule creation interfaces, not through incident automation rules.

Exam trap

The trap here is that candidates may confuse automation rules with analytics rules or data connectors, assuming automation rules can modify data sources or create detection logic, when in fact automation rules are limited to post-ingestion incident management actions.

895
Multi-Selectmedium

Which TWO actions are part of managing a security operations environment in Microsoft Sentinel? (Select two.)

Select 2 answers
A.Configuring physical access controls to the data center
B.Installing the Azure Monitor Agent on servers
C.Creating automation rules to triage incidents
D.Configuring data retention policies for Log Analytics workspaces
E.Creating Microsoft Purview sensitivity labels
AnswersC, D

Creating automation rules to triage incidents is a core security operations management task because it directly shapes how the SOC handles alerts. Automation rules can assign incidents to analysts, apply custom tags, suppress false positives automatically, and trigger playbooks for standardized response actions. By embedding triage decisions into Sentinel, the SOC reduces response time and ensures consistent handling according to established procedures.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically triage incidents by applying actions such as assigning ownership, changing severity, or running playbooks. This is a core operational task within the security operations environment to streamline incident response and reduce manual effort.

Exam trap

The trap here is that candidates confuse data collection or infrastructure security tasks with operational management actions, but the domain 'Manage a security operations environment' specifically focuses on incident handling, automation, and workspace configuration within Sentinel, not on data ingestion or physical security.

896
MCQeasy

A threat hunter wants to correlate alerts from multiple Microsoft security products in Microsoft Sentinel. Which feature should be used to create a unified incident?

A.Threat Intelligence
B.Jupyter Notebooks
C.Analytics Rules
D.Investigation Graph
AnswerC

Analytics Rules (also called scheduled or incident creation rules) are the correct mechanism in Microsoft Sentinel for correlating alerts from multiple security products into a unified incident. These rules are built on Kusto Query Language (KQL) and can use entity mapping and alert grouping to combine multiple separate alerts—whether from Microsoft Defender, Azure, or third-party connectors—into one incident based on common entities and a defined time window. When a query returns results and incident creation is enabled, Sentinel creates an incident enriched with the matching alerts, which is exactly what a threat hunter needs for correlation.

Why this answer

Analytics Rules in Microsoft Sentinel can be configured to create incidents from alerts across multiple security products, enabling unified incident creation for threat hunting. Option A (Threat Intelligence) is used to import and use threat intelligence feeds, not to create incidents. Option B (Jupyter Notebooks) provides a platform for security analysis and automation using Python, not for incident creation.

Option D (Investigation Graph) is a visual tool for exploring connections between entities in an investigation, not for creating incidents.

897
Drag & Dropmedium

Arrange the steps to run a Microsoft 365 Defender advanced hunting query and create a custom detection rule from it.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

After running a query in Advanced hunting, you can create a detection rule directly from the results to alert on future matches.

898
Multi-Selecteasy

Which TWO Microsoft Sentinel features allow you to organize and prioritize incidents for better triage?

Select 2 answers
A.Entity mapping in analytics rules.
B.Automation rules with incident creation triggers.
C.Workbooks for dashboard reporting.
D.Incident assignment to analysts.
E.Incident classification and tagging.
AnswersD, E

Incident assignment to analysts is a core incident management feature that directly supports organization and triage by designating a specific owner for each incident. This establishes accountability, prevents duplicate overlapping work, and makes it clear who is responsible for investigation and resolution. Assignment is an operational state that structures workflow, unlike enrichment or reporting features.

Why this answer

Incident assignment allows security operations center (SOC) analysts to take ownership of specific incidents, ensuring accountability and preventing duplicate work. This feature directly supports triage by routing incidents to the appropriate team member based on skills or workload. Option E is correct because classification and tagging let analysts categorize incidents by severity, attack type, or status, enabling efficient filtering and prioritization across the incident queue.

Exam trap

The trap here is that candidates often confuse features that create or enrich incidents (like entity mapping or automation triggers) with features that organize and prioritize them after creation, leading them to select options A or B instead of the correct assignment and classification capabilities.

899
MCQhard

You are investigating a lateral movement incident in Microsoft Defender for Endpoint. The timeline shows that a user's credentials were used from a compromised workstation to access a sensitive server. Which action should you take to contain the incident?

A.Disable the sensitive server's network account.
B.Isolate the compromised workstation only.
C.Block all network traffic from the compromised workstation to the server.
D.Reset the compromised user's password and revoke all active sessions.
AnswerD

Resetting the compromised user's password and revoking all active sessions directly invalidates the stolen credentials—making any cached NTLM hashes, Kerberos TGTs, or delegating artifacts unusable for further authentication. Revoking active sessions (e.g., forcing sign-out or invalidating refresh tokens) ensures that any already-established remote sessions are terminated immediately, rather than waiting for ticket expiry. This stops lateral movement regardless of which workstation the attacker is using or which network path they choose, because the root cause—compromised identity—has been remediated.

Why this answer

The incident involves lateral movement using stolen credentials. Resetting the compromised user's password and revoking all active sessions immediately invalidates the credentials the attacker used, preventing further unauthorized access to any resource, including the sensitive server. This directly addresses the root cause (credential theft) rather than just blocking network paths or isolating a single device.

Exam trap

The trap here is that candidates focus on the network path (blocking traffic or isolating the workstation) instead of recognizing that credential theft is the core issue, and only resetting the password and revoking sessions stops the lateral movement at its source.

How to eliminate wrong answers

Option A is wrong because disabling the sensitive server's network account does not address the compromised user credentials; the attacker could still use those credentials to access other resources. Option B is wrong because isolating only the compromised workstation does not prevent the attacker from using the stolen credentials from another device to access the sensitive server. Option C is wrong because blocking network traffic from the compromised workstation to the server is a temporary network-level fix that does not revoke the attacker's access via the stolen credentials, and the attacker could pivot from a different machine.

900
Multi-Selectmedium

Which TWO actions can you perform in Microsoft Defender XDR as part of incident response?

Select 2 answers
A.Create a Microsoft Sentinel workbook
B.Modify a Microsoft Entra ID conditional access policy
C.Run a KQL query in Azure Data Explorer
D.Collect an investigation package from a device
E.Isolate a device from the network
AnswersD, E

Collecting an investigation package from a device is a legitimate Defender for Endpoint response action that bundles the device's relevant forensic artifacts—such as the registry, running processes, network connections, and memory information—into a zip file for offline analysis. It is initiated through the device's action menu, and the package is stored in secure storage for the analyst to download. This action is complementary to isolation and is used to gather evidence without requiring a live remote-command channel to the device.

Why this answer

Option D is correct because Microsoft Defender XDR's device response actions include collecting an investigation package, which gathers forensic artifacts (such as running processes, network connections, and event logs) from an endpoint for offline analysis. Option E is correct because isolating a device from the network is a core Defender XDR live response action that cuts off an endpoint's network connectivity (while optionally allowing Defender communications) to contain a compromised host during incident response. The other options fall outside Defender XDR's native incident response capabilities: Microsoft Sentinel workbooks (A) are authored in Microsoft Sentinel, modifying an Entra ID conditional access policy (B) is done in the Microsoft Entra admin center, and running a KQL query in Azure Data Explorer (C) is an Azure Data Explorer operation, not a Defender XDR response action.

Exam trap

The trap here is that candidates may confuse actions available in Microsoft Defender XDR with those in other Microsoft security services like Microsoft Sentinel or Azure Data Explorer, leading them to select options that are valid in those separate tools but not within Defender XDR's incident response workflow.

Page 11

Page 12 of 18

Page 13