Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 1051–1125

1303 questions total · 18pages · All types, answers revealed

Page 14

Page 15 of 18

Page 16
1051
Multi-Selecthard

Which THREE techniques would you use in Microsoft Sentinel to hunt for data exfiltration over DNS?

Select 3 answers
A.Analyze DNS query logs for high volume or long subdomains
B.Examine network traffic logs for large data transfers to known cloud storage IPs
C.Correlate DNS events with process creation events to identify the process making queries
D.Review email forwarding rules for external domains
E.Use ASIM DNS parsers to normalize DNS logs and detect anomalies
AnswersA, C, E

DNS tunneling commonly encodes data in the subdomain portion of a query name, so attackers craft unusually long subdomains (often 50+ characters) and generate a high query volume to a single authoritative domain. By analyzing DNS query logs for these patterns—such as label length, entropy, and query frequency per domain—you can directly detect the covert channel. This technique is effective because DNS traffic is frequently allowed through firewalls without deep inspection, making the logs the primary evidence of the exfiltration.

Why this answer

Option A is correct because DNS tunneling and exfiltration typically manifest as unusually high query volumes to a single domain or abnormally long subdomain labels that encode stolen data, so analyzing DNS query logs for these patterns is a core hunting technique in Microsoft Sentinel. Option C is correct because correlating DNS events with process creation events (for example via SecurityEvent 4688 or Sysmon Event ID 1) lets you identify which executable or script is generating the suspicious queries, distinguishing malicious tooling from legitimate resolvers. Option E is correct because ASIM (Advanced Security Information Model) DNS parsers normalize DNS logs from multiple sources into a common schema, enabling consistent anomaly detection and cross-source correlation across the workspace.

Option B is not part of DNS exfiltration hunting since it focuses on large transfers to cloud storage IPs, which is HTTP/HTTPS exfiltration rather than DNS-based. Option D is also unrelated, as email forwarding rules address exfiltration via email (for example Exchange transport rules) and not DNS tunneling.

Exam trap

SC-200 often tests whether candidates confuse DNS exfiltration with other exfiltration channels (HTTP, email), so options describing large transfers or email rules are distractors for a DNS-specific hunt.

1052
Multi-Selecthard

Which THREE Microsoft Sentinel features are specifically designed to assist with threat hunting?

Select 3 answers
A.Livestream for real-time hunting.
B.Workbooks for interactive dashboards.
C.Bookmarks to record interesting results.
D.Automation rules to respond to incidents.
E.The Hunting blade with built-in and custom queries.
AnswersA, C, E

Livestream streams events in real time as they are ingested, letting hunters watch activity unfold without waiting for scheduled analytics rules to fire. This satisfies the scenario's requirement for a hunting feature, since interactive, near-instant event visibility directly supports proactive investigation rather than automated detection alone.

Why this answer

Option A, Livestream for real-time hunting, is correct because Microsoft Sentinel's Livestream feature lets analysts run a hunting query continuously and view results as they occur, which is specifically built for interactive, real-time threat hunting rather than post-incident reporting. Option C, Bookmarks to record interesting results, is correct because bookmarks preserve notable entities, events, or query results from hunting activities so they can be retained, tagged, and later promoted into incidents or used in investigations. Option E, The Hunting blade with built-in and custom queries, is correct because the Hunting blade in Microsoft Sentinel provides prebuilt KQL hunting queries mapped to MITRE ATT&CK techniques plus the ability to create and run custom queries, making it the core hunting workspace.

Option B, Workbooks for interactive dashboards, is not marked correct because workbooks are primarily used for visualization, monitoring, and reporting on data rather than being a dedicated hunting tool. Option D, Automation rules to respond to incidents, is not marked correct because automation rules orchestrate incident handling, triage, and response actions, which is an SOAR capability rather than a threat-hunting feature.

1053
Multi-Selecthard

Your organization uses Microsoft Sentinel. A security incident related to a compromised user account has been fully investigated and remediated. Which THREE steps should you take to close the incident properly? (Choose three.)

Select 3 answers
A.Verify that all related alerts are resolved or closed.
B.Create a new analytics rule to detect similar activity.
C.Change the incident status to Closed and select an appropriate classification.
D.Add comments summarizing the investigation and remediation steps.
E.Delete the incident to clean up the workspace.
AnswersA, C, D

Closing an incident while child alerts remain active leaves orphaned detections that can regenerate the incident or skew metrics. Confirming every linked alert is resolved or closed ensures the remediation is genuinely complete before the incident itself is finalised.

Why this answer

Options A, C, and D are correct. Verifying that all related alerts are resolved or closed (A) ensures no lingering issues. Changing the incident status to Closed with an appropriate classification (C) provides proper closure.

Adding comments summarizing the investigation and remediation steps (D) documents the process. Option B (creating a new analytics rule) is not required for closing an incident. Option E (deleting the incident) is not recommended; incidents should be closed, not deleted.

1054
MCQmedium

Your organization uses Microsoft Defender for Office 365 and Microsoft Sentinel. You discover that phishing emails are bypassing Defender for Office 365 and being reported by users. You need to ensure that user-reported emails are automatically analyzed and incidents are created in Sentinel for high-confidence phishing. What should you configure?

A.Set up a custom connector using Microsoft Graph API to ingest user-reported messages into Sentinel.
B.Use the Microsoft 365 Defender portal to create a submission rule for user-reported messages.
C.Configure a mail flow rule to forward user-reported messages to a dedicated mailbox monitored by Sentinel.
D.Enable the 'User reported messages' feature in Defender for Office 365 and ensure the Microsoft Defender XDR connector is enabled in Sentinel.
AnswerD

Enabling the 'User reported messages' feature in Defender for Office 365 ensures that user-reported emails are automatically submitted for analysis by Microsoft's threat intelligence systems, including detonation and reputation checks. When the Microsoft Defender XDR connector is enabled in Microsoft Sentinel, the resulting alerts and incidents—such as high-confidence phishing verdicts—are streamed into Sentinel automatically, creating security incidents without manual intervention. This native integration is the correct method to meet the requirement for automated analysis and incident creation.

Why this answer

Enabling the 'User reported messages' feature in Defender for Office 365 allows user-reported phishing emails to be automatically submitted to Microsoft for analysis. When the Microsoft Defender XDR connector is enabled in Sentinel, high-confidence phishing verdicts from this analysis are ingested as incidents, creating a seamless automated pipeline without custom infrastructure.

Exam trap

The trap here is that candidates often assume a custom connector or mail flow rule is necessary for ingestion, overlooking that the built-in Defender for Office 365 user-reported messages feature, when combined with the Microsoft Defender XDR connector, provides a fully automated and integrated solution for high-confidence phishing incident creation in Sentinel.

How to eliminate wrong answers

Option A is wrong because while a custom Graph API connector could ingest messages, it would require manual development and maintenance, and it bypasses the built-in automated analysis and verdict pipeline that Defender for Office 365 provides for user-reported messages. Option B is wrong because the Microsoft 365 Defender portal submission rule is for administrators to submit messages for analysis, not for automatically processing user-reported emails into Sentinel incidents. Option C is wrong because a mail flow rule forwarding to a dedicated mailbox would require a separate logic app or custom connector to parse and analyze the messages, lacking the integrated high-confidence phishing verdict that the built-in feature provides.

1055
MCQeasy

Your organization wants to use Microsoft Copilot for Security to generate incident summaries. What is the minimum license required?

A.Microsoft 365 E5
B.Microsoft Sentinel
C.Microsoft Defender for Office 365 P2
D.Microsoft Copilot for Security standalone or add-on
AnswerD

Microsoft Copilot for Security is the only licensing option that actually grants access to the embedded AI features in Microsoft security products, whether you purchase it as a standalone capacity-based SKU with Security Compute Units or as an add-on to an eligible plan such as Microsoft 365 E5. This license provides the entitlement for Copilot experiences across Defender, Sentinel, and Entra, which is why it is the required license for the organization's goal.

Why this answer

Microsoft Copilot for Security is a standalone product that can be licensed independently or as an add-on to existing security subscriptions. It is not included in any Microsoft 365 or Defender plan by default; therefore, the minimum license required is either the standalone Copilot for Security SKU or the add-on license. This ensures the organization has the necessary entitlements to generate incident summaries using Copilot for Security.

Exam trap

The trap here is that candidates often assume Copilot for Security is included with high-tier licenses like Microsoft 365 E5 or Microsoft Sentinel, but Microsoft explicitly requires a separate Copilot for Security license (standalone or add-on) to use its AI capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 E5 provides advanced security features like Defender for Office 365 P2 and Microsoft Sentinel, but it does not include Microsoft Copilot for Security; a separate license is required. Option B is wrong because Microsoft Sentinel is a SIEM/SOAR solution that ingests and analyzes security data, but it does not include Copilot for Security; Copilot for Security is a separate AI-powered tool that can integrate with Sentinel but requires its own license. Option C is wrong because Microsoft Defender for Office 365 P2 offers advanced threat protection for email and collaboration tools, but it does not include Copilot for Security; the Copilot for Security add-on or standalone license is needed to access its AI capabilities.

1056
MCQmedium

A security analyst is investigating a potential data exfiltration incident in Microsoft 365 Defender. They have identified a suspicious email sent to an external recipient containing an attachment. They want to know if the attachment has been opened and if any sensitive data was accessed. Which advanced hunting table should the analyst query to find email attachment activities, such as file download or view?

A.DeviceFileEvents
B.EmailEvents
C.EmailAttachmentInfo
D.UrlClickEvents
AnswerB

EmailEvents is the correct Advanced Hunting table because it contains the action types for user interactions with email attachments. Specifically, it includes columns like ActionType with values such as EmailAttachmentOpened or EmailAttachmentDownloaded, and it records the email metadata (sender, recipient, subject, and timestamp) associated with those actions. This table directly ties the attachment open event to the email message, making it ideal for investigating potential data exfiltration or phishing attachment engagement.

Why this answer

B is correct because EmailEvents is the advanced hunting table in Microsoft 365 Defender that captures email-level activities, including whether an attachment was opened or viewed by the recipient. This table contains actions such as 'Email open' and 'Attachment open', which directly answer the analyst's question about attachment access and potential data exfiltration.

Exam trap

The trap here is that candidates often confuse EmailAttachmentInfo (which only provides static metadata) with EmailEvents (which includes user actions), leading them to select the wrong table for activity tracking.

How to eliminate wrong answers

Option A is wrong because DeviceFileEvents logs file operations (create, modify, delete) on endpoints, not email attachment activities like opening or viewing within an email client. Option C is wrong because EmailAttachmentInfo provides metadata about attachments (e.g., file name, size, hash) but does not include actions such as download or view. Option D is wrong because UrlClickEvents tracks clicks on URLs in emails or documents, not attachment open events.

1057
MCQhard

Your Microsoft Sentinel workspace is receiving a high volume of false positive alerts from a specific analytics rule. You need to suppress these alerts without disabling the rule. Which feature should you use?

A.Create an automation rule to close incidents
B.Adjust the alert threshold in the analytics rule
C.Configure alert suppression in the analytics rule
D.Disable incident creation for the rule
AnswerC

The correct approach is to enable Alert suppression in the analytics rule's 'Set rule logic' settings. When the rule fires, you can configure it to stop running the query for a specified duration (e.g., 1, 6, or 12 hours), so the same matching condition does not immediately generate multiple duplicate alerts. This suppresses additional alerts from that rule during the suppression window while preserving the rule for future detections.

Why this answer

Alert suppression in a Microsoft Sentinel analytics rule lets you define conditions (such as matching entity, IP address, or account) under which subsequent matching alerts are suppressed for a configurable time window. This stops the false-positive noise without turning off the rule, so genuine detections from other entities or conditions still fire. It is configured directly on the analytics rule's 'Incident settings' / suppression section, making it the precise tool for this requirement.

Exam trap

SC-200 often tests the distinction between suppressing alerts at the rule level versus closing incidents after the fact with automation rules — candidates pick automation because it sounds like 'handling' the noise, but it does not prevent incident creation.

How to eliminate wrong answers

Option A is wrong because an automation rule that closes incidents still allows the incident to be created and logged, so the false positives continue to consume analyst attention and incident quota. Option B is wrong because changing the alert threshold alters when the rule triggers at all, which can cause true positives to be missed and does not target the specific recurring false positives. Option D is wrong because disabling incident creation for the rule stops the rule from generating incidents entirely, effectively neutering the detection rather than selectively suppressing noise.

1058
MCQmedium

You manage a Microsoft Sentinel workspace with multiple analytics rules. You notice that an analytics rule has not generated any alerts in the past month despite relevant data being ingested. The rule uses a custom KQL query that joins two tables. What is the most likely cause?

A.The join condition in the KQL query is incorrect, resulting in no matching records
B.The rule is using an unsupported KQL function
C.The data connector for the tables is disabled
D.The rule is running on a schedule of 5 minutes but the data arrives every hour
AnswerA

The join condition in the KQL query is incorrect, which means the query syntactically runs but produces no matching rows. For example, joining on fields with different names, data types, or case values (since KQL joins are case-sensitive) prevents any records from pairing. As a result, the rule's query returns an empty result set each time it executes, so no alerts are created even though both tables contain relevant data.

Why this answer

The most likely cause is an incorrect join condition in the KQL query. When a custom analytics rule uses a JOIN operation between two tables, if the join keys or conditions do not match any records in the ingested data, the query returns zero results, and no alerts are generated. Since the question states that relevant data is being ingested, the issue is not with data availability but with the query logic itself.

Exam trap

The trap here is that candidates may assume the schedule or data connector is the problem, but the key clue is that 'relevant data is being ingested' — this forces you to focus on the query logic, specifically the JOIN condition, as the root cause.

How to eliminate wrong answers

Option B is wrong because unsupported KQL functions would typically cause a query execution error, not a silent failure to generate alerts; the rule would show as 'error' in the analytics rule status. Option C is wrong because if the data connector for the tables were disabled, no data would be ingested at all, contradicting the premise that relevant data is being ingested. Option D is wrong because a 5-minute schedule with hourly data arrival would still generate alerts when data does arrive (e.g., once per hour), not result in zero alerts over an entire month.

1059
MCQmedium

You are managing a Microsoft Sentinel environment with multiple workspaces across different regions. You need to centralize incident management and allow security analysts to triage incidents from all workspaces in a single view. What should you configure?

A.Configure a central Microsoft Sentinel workspace with cross-workspace analytics rules.
B.Create a workbook that queries all workspaces.
C.Use the Microsoft Sentinel SIEM Migration experience.
D.Use Azure Lighthouse to manage all workspaces from a single pane of glass.
AnswerA

A central Microsoft Sentinel workspace with cross-workspace analytics rules is the correct approach because it lets you define detection rules that query multiple workspaces (e.g., via the workspace() expression or union operator) and route resulting alerts into a single incident queue. This consolidates detection and incident management so security teams can investigate correlated events across all environments without manually stitching incidents together. It also aligns with Sentinel's native support for centralized SOC operations, where one workspace serves as the primary monitoring and response hub.

Why this answer

Cross-workspace analytics rules in Microsoft Sentinel allow you to define a single analytics rule that queries multiple workspaces, enabling centralized incident creation and management. This configuration ensures that security analysts can view and triage incidents from all workspaces in a single Microsoft Sentinel instance, without needing to switch between different workspace blades.

Exam trap

The trap here is that candidates often confuse Azure Lighthouse's cross-tenant management capabilities with the specific need to aggregate incidents into a single view, overlooking that Lighthouse alone does not merge incident queues across workspaces.

How to eliminate wrong answers

Option B is wrong because a workbook is a visualization and reporting tool, not an incident management interface; it cannot centralize incident triage or provide a unified incident queue. Option C is wrong because the SIEM Migration experience is designed to help migrate from a third-party SIEM to Microsoft Sentinel, not to centralize incident management across existing Sentinel workspaces. Option D is wrong because Azure Lighthouse provides cross-tenant management capabilities but does not natively aggregate incidents from multiple Sentinel workspaces into a single incident view; it still requires navigating separate Sentinel instances per workspace.

1060
Multi-Selectmedium

Your organization is responding to a ransomware incident. Which TWO actions should be taken first to contain the incident while preserving forensic evidence?

Select 2 answers
A.Isolate affected devices using Microsoft Defender for Endpoint.
B.Reset passwords for all users in the organization.
C.Disable compromised user accounts in Microsoft Entra ID.
D.Perform a factory reset on all affected devices.
E.Shut down network switches to isolate the network segment.
AnswersA, C

Isolating affected devices through Microsoft Defender for Endpoint halts lateral spread and further encryption while keeping the machine powered on, so volatile memory, running processes and network connections remain intact for forensic capture. This directly satisfies the stem's dual constraint: contain the ransomware outbreak yet preserve evidential artefacts.

Why this answer

Option A is correct because isolating affected devices through Microsoft Defender for Endpoint (using the "Isolate device" action) severs network communication while keeping the device powered on, so volatile memory and forensic artifacts remain intact for investigation. Option C is correct because disabling compromised user accounts in Microsoft Entra ID immediately blocks the attacker's ability to authenticate, move laterally, or access cloud resources, and it is a reversible containment step that preserves sign-in and audit logs as evidence. Option B is not appropriate as a first action because a blanket password reset across all users is disruptive, does not stop an active session or token-based access, and can destroy or complicate evidence of which accounts were actually compromised.

Option D is wrong because a factory reset wipes the device and destroys the forensic evidence needed for the investigation. Option E is wrong because shutting down network switches disrupts the entire segment and business operations, and powering off systems can lose volatile evidence, making it a disproportionate and evidence-destructive containment measure.

Exam trap

SC-200 often tests the balance between containment and evidence preservation, where candidates may choose destructive actions like factory reset or network shutdown, which hinder forensic investigation.

1061
MCQmedium

An analyst is investigating a file that was detected as malicious on several devices. In Microsoft 365 Defender, where can the analyst find information about the file's prevalence, global reputation, and related incidents?

A.File entity page
B.Device entity page
C.User entity page
D.Email entity page
AnswerA

The file entity page is the designated central repository for file intelligence in Microsoft Defender XDR, consolidating the file name, SHA-1 and SHA-256 hashes, file size, publisher/signing information, global and organization prevalence, observed devices, and current verdict. It aggregates detonation outcomes from deep analysis, related alerts, and the complete set of machines where the file was seen, enabling an analyst to determine both maliciousness and organizational exposure in one place. This is why it is the correct starting point for investigating a detected file.

Why this answer

The File entity page in Microsoft 365 Defender aggregates file-level telemetry, including prevalence (number of devices/users), global reputation (Microsoft's cloud-based threat intelligence), and a timeline of related incidents. This page is the single pane of glass for file-centric investigations, pulling data from Microsoft Defender for Endpoint, Office 365, and other XDR sources.

Exam trap

Microsoft often tests the distinction between entity pages by making candidates confuse the File entity page (which shows prevalence and reputation) with the Device entity page (which shows device-specific alerts but not file-level global data).

How to eliminate wrong answers

Option B is wrong because the Device entity page focuses on device-level details (OS, alerts, logged-on users, network connections) and does not show file prevalence or global reputation. Option C is wrong because the User entity page displays user-centric data (sign-ins, roles, alerts) and lacks file-specific prevalence or reputation metrics. Option D is wrong because the Email entity page is scoped to email messages (headers, attachments, delivery status) and does not provide file prevalence across devices or global reputation scores.

1062
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to ensure that alerts from Defender for Cloud Apps are forwarded to Microsoft Sentinel. Which connector should you use in Sentinel?

A.Windows Security Events via AMA connector
B.Microsoft Defender for Cloud Apps connector
C.Microsoft 365 Defender connector
D.Azure Activity connector
AnswerB

This is the dedicated Microsoft Sentinel data connector for ingesting alerts and anomalies from Microsoft Defender for Cloud Apps, including policy violations, activity anomalies, and threat detection from cloud applications. It uses the Defender for Cloud Apps API to pull alerts into Log Analytics when enabled. Choosing this connector ensures that all cloud app security alerts are available for investigation and for use in analytics rules.

Why this answer

The Microsoft Defender for Cloud Apps connector in Microsoft Sentinel is specifically designed to ingest alerts and logs from Defender for Cloud Apps, including anomaly detection, policy violations, and threat intelligence alerts. This connector uses the Microsoft Graph API to pull data directly from the Defender for Cloud Apps service, ensuring that all relevant security alerts are forwarded to Sentinel for centralized monitoring and incident response.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender connector as a catch-all for all Microsoft security alerts, but it does not include Defender for Cloud Apps alerts, which require their own dedicated connector.

How to eliminate wrong answers

Option A is wrong because the Windows Security Events via AMA connector is used to collect security event logs from Windows machines, not alerts from Defender for Cloud Apps. Option C is wrong because the Microsoft 365 Defender connector ingests alerts and incidents from Microsoft 365 Defender (which includes Defender for Endpoint, Defender for Office 365, etc.), but it does not directly pull alerts from Defender for Cloud Apps; those alerts must be routed through the dedicated Defender for Cloud Apps connector. Option D is wrong because the Azure Activity connector captures subscription-level operational logs from Azure Resource Manager, not security alerts from a cloud app security broker like Defender for Cloud Apps.

1063
Multi-Selectmedium

A security analyst is triaging security alerts in Microsoft Defender for Cloud. Which of the following are valid ways to suppress a specific alert type to reduce noise? (Choose all that apply.)

Select 2 answers
A.Create an alert suppression rule based on alert entity
B.Modify the alert's severity
C.Set an automatic response action
D.Define a rule to automatically dismiss alerts that meet criteria
AnswersA, D

Alert suppression rules in Microsoft Defender XDR and Sentinel allow you to build conditions directly around entity attributes such as IP address, hostname, or user account. When an alert is generated that matches the specified entity, the rule automatically hides it from the queue, preventing it from consuming analyst time. This is a true suppression mechanism because it acts at the detection level, reducing alert volume before triage.

Why this answer

Microsoft Defender for Cloud allows you to create suppression rules that automatically dismiss alerts based on specific alert entities (such as alert ID, title, or severity) to reduce noise. These rules are configured in the security alerts settings and can be scoped to a subscription or management group, ensuring that alerts matching the defined criteria are silently dismissed without generating incidents.

Exam trap

The trap here is that candidates often confuse 'suppression' with 'automation' or 'severity modification', thinking that changing severity or adding a response action will reduce noise, when in fact only suppression rules (or automatic dismissal rules) actually remove alerts from the queue.

1064
Multi-Selecteasy

Which TWO roles in Microsoft Entra ID can manage Microsoft Defender for Cloud Apps? (Select two.)

Select 2 answers
A.Compliance Administrator
B.Security Administrator
C.Global Administrator
D.Security Reader
E.Application Administrator
AnswersB, C

Security Administrator is one of the two Microsoft Entra ID roles that can manage Microsoft Defender. It has broad permissions to read, configure, and manage security settings across the organization, including threat protection policies, security alerts, and Defender for Endpoint and Defender for Office 365 configurations. This role is designed for day-to-day security operations.

Why this answer

The Security Administrator role in Microsoft Entra ID has the necessary permissions to manage Microsoft Defender for Cloud Apps, including configuring policies, investigating alerts, and managing app permissions. This role is specifically designed for security-related tasks within Microsoft 365 security products, making it a correct choice for managing Defender for Cloud Apps.

Exam trap

The trap here is that candidates often confuse the Compliance Administrator role as having security management capabilities due to its name, but it is strictly limited to compliance tasks and cannot manage Defender for Cloud Apps.

1065
MCQmedium

In Microsoft 365 Defender, a security analyst wants to get a detailed report on a newly discovered malware campaign, including indicators of compromise, recommended actions, and impacted devices. Where should the analyst go to find this information?

A.Alerts queue
B.Incident page
C.Threat analytics
D.Action center
AnswerC

Threat analytics is the correct choice because it is Microsoft's dedicated threat intelligence experience within Microsoft Defender XDR (formerly Microsoft 365 Defender). Each threat analytics report provides detailed analysis of an ongoing or impactful threat, including its attack methods (TTPs), associated indicators of compromise (IoCs), affected platforms, relevant CVE vulnerabilities, and concrete mitigation steps. The reports are curated by Microsoft researchers and are tied to the latest global threat activity, making them the authoritative source for understanding and responding to a broad threat campaign beyond just your own alerts.

Why this answer

Threat analytics in Microsoft 365 Defender provides detailed reports on active malware campaigns, including indicators of compromise (IoCs), recommended actions, and impacted devices. This is the dedicated workspace for tracking and responding to emerging threats, offering curated intelligence from Microsoft security researchers.

Exam trap

The trap here is that candidates confuse the Incident page (which handles active investigations) with Threat analytics (which provides pre-built campaign intelligence and proactive guidance), leading them to select the Incident page for campaign details instead of the dedicated threat intelligence hub.

How to eliminate wrong answers

Option A is wrong because the Alerts queue shows individual security alerts (e.g., from Defender for Endpoint or Defender for Office 365) but does not aggregate campaign-level context, IoCs, or recommended actions. Option B is wrong because the Incident page groups related alerts into an incident for investigation but does not provide the pre-built campaign analysis, threat intelligence, or remediation guidance found in Threat analytics. Option D is wrong because the Action center lists pending and completed remediation actions (e.g., running antivirus scans or isolating devices) but does not contain threat campaign reports or IoCs.

1066
MCQeasy

During an incident response, a SOC analyst needs to automatically collect relevant evidence from multiple Microsoft 365 services. Which Microsoft Sentinel playbook trigger should the analyst configure?

A.Microsoft Sentinel Playbook trigger 'When a response action is executed'.
B.Microsoft Sentinel Scheduled Analytics rule trigger.
C.Microsoft Sentinel Alert trigger.
D.Microsoft Sentinel Incident trigger with action 'Collect evidence'.
AnswerD

The Microsoft Sentinel Incident trigger with the action 'Collect evidence' is the correct choice because it fires when an incident is created, providing a single orchestration point for gathering evidence across multiple sources. This trigger can invoke a playbook automatically via an automation rule or manually, and the playbook can connect to various connectors to collect related evidence and append it to the incident. This aligns with best practice for incident-centric automation.

Why this answer

The Microsoft Sentinel Incident trigger with the 'Collect evidence' action is specifically designed to automate evidence collection across Microsoft 365 services during incident response. This trigger fires when an incident is created or updated, allowing the playbook to gather relevant data from sources like Microsoft Defender for Endpoint, Microsoft 365 Defender, and Azure Active Directory without manual intervention.

Exam trap

The trap here is that candidates often confuse the Alert trigger (which fires on individual alerts) with the Incident trigger (which aggregates alerts into incidents), and fail to recognize that only the Incident trigger has the dedicated 'Collect evidence' action for multi-service evidence gathering.

How to eliminate wrong answers

Option A is wrong because 'When a response action is executed' is a trigger for Microsoft 365 Defender playbooks, not Microsoft Sentinel, and it fires after a manual response action is taken, not for automated evidence collection. Option B is wrong because a Scheduled Analytics rule trigger is used for periodic queries on log data, not for real-time incident response or evidence collection from multiple services. Option C is wrong because the Microsoft Sentinel Alert trigger fires on individual alerts, not on incidents, and lacks the built-in 'Collect evidence' action that aggregates data from multiple Microsoft 365 services.

1067
Multi-Selectmedium

Which TWO are valid methods for performing threat hunting in Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Using playbooks to respond to incidents
B.Using the Hunting blade with built-in queries
C.Using the MITRE ATT&CK dashboard
D.Using Jupyter notebooks with MSTICpy
E.Using watchlists to create alerts
AnswersB, D

The Hunting blade provides built-in, pre-built queries that run directly against your Log Analytics workspace, letting analysts pivot on entities and surface suspicious activity without authoring KQL from scratch. This satisfies the stem's requirement for a valid threat-hunting method in Microsoft Sentinel, complementing custom query development.

Why this answer

Option B is correct because the Hunting blade in Microsoft Sentinel provides built-in, pre-designed hunting queries (based on KQL) that analysts can run across Log Analytics workspaces to proactively search for suspicious activity, which is a core threat-hunting method. Option D is correct because Microsoft Sentinel supports Jupyter notebooks integrated with MSTICpy, a Python library that enables advanced, customizable threat-hunting workflows such as querying logs, enriching data with threat intelligence, and visualizing results. Option A is not a hunting method but an automated incident-response capability (playbooks built on Logic Apps).

Option C is incorrect because the MITRE ATT&CK dashboard/page in Sentinel is used for coverage mapping and understanding detections, not as a primary threat-hunting technique. Option E is incorrect because watchlists are used to store reference data (e.g., IPs, users) for correlation and can drive analytics rules, but creating alerts from watchlists is detection engineering, not threat hunting.

Exam trap

SC-200 often tests the distinction between hunting (proactive, query-driven) and detection/response (playbooks, watchlists, analytics rules), causing candidates to select response-oriented features as hunting methods.

1068
MCQmedium

You are configuring a Microsoft Sentinel workbook to display incident metrics. You want to show the average time to triage incidents over the last 30 days. Which data source should you use?

A.CommonSecurityLog table.
B.SecurityIncident table.
C.SecurityAlert table.
D.SigninLogs table.
AnswerB

SecurityIncident is the canonical Microsoft Sentinel table for incident records, generated by the incident management service. Each row represents a single incident and includes authoritative fields such as IncidentNumber, Title, Status, Owner, CreatedTimeUTC, FirstActivityTimeUTC, LastActivityTimeUTC, and TriageTimeUTC. Querying this table directly lets a workbook aggregate incidents by time or status without joins or approximations, making it the correct source for incident lifecycle metrics like created and triaged times.

Why this answer

The SecurityIncident table in Microsoft Sentinel contains all incident-related data, including timestamps for creation, triage, and resolution. To calculate the average time to triage (e.g., the time between incident creation and the first triage action), you query this table using KQL to compute the mean duration. The other tables (CommonSecurityLog, SecurityAlert, SigninLogs) do not store incident lifecycle metadata.

Exam trap

The trap here is that candidates confuse the SecurityAlert table (which holds raw alert data) with the SecurityIncident table (which holds the correlated incident record), leading them to incorrectly choose SecurityAlert for incident-level metrics.

How to eliminate wrong answers

Option A is wrong because CommonSecurityLog stores syslog-style security events from third-party appliances (e.g., firewalls), not incident triage timestamps. Option C is wrong because SecurityAlert records individual alert details (e.g., alert name, severity) but lacks the incident-level triage or closure timestamps needed for time-to-triage calculations. Option D is wrong because SigninLogs captures user authentication events (e.g., success/failure, location) and has no relation to incident management workflows.

1069
MCQmedium

Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. What will happen when a new incident is created?

A.The incident severity will be changed
B.A new analytics rule will be created
C.The playbook 'BlockIPPlaybook' will be executed
D.The incident will be automatically closed
AnswerC

The automation rule in the exhibit includes a 'Run playbook' action that explicitly references the playbook named 'BlockIPPlaybook'. When the rule's trigger conditions are met, Microsoft Sentinel invokes the associated Logic App, which likely performs a connection- or firewall-blocking action against the offending IP. This is a standard way to automate response actions directly from an incident, and it is the sole effect defined in the automation rule's configured actions.

Why this answer

The automation rule is configured to trigger a playbook when an incident is created. The rule's action specifies 'Run playbook' with 'BlockIPPlaybook' selected, and the trigger condition is set to 'When incident is created'. This means that upon incident creation, Sentinel will execute the playbook as an automated response.

Exam trap

The trap here is that candidates may confuse automation rules with analytics rules, assuming that any rule in Sentinel must either create or modify incidents, rather than recognizing that automation rules are purely for orchestrated responses like playbook execution.

How to eliminate wrong answers

Option A is wrong because the automation rule does not contain any action to change the incident severity; it only triggers a playbook. Option B is wrong because automation rules do not create analytics rules; they respond to incidents generated by existing analytics rules. Option D is wrong because the rule has no condition or action to close the incident; it only runs a playbook.

1070
MCQmedium

During a threat hunt, you discover suspicious PowerShell commands executed on multiple workstations. Which KQL function in Microsoft Sentinel is most effective for aggregating similar commands to identify a pattern?

A.summarize
B.extend
C.search
D.project
AnswerA

summarize groups rows by chosen keys and computes aggregates such as count or make_set, letting you collapse many similar PowerShell command lines into per-host or per-command patterns. That aggregation exposes commands recurring across workstations, which raw row-by-row output obscures.

Why this answer

The summarize operator in KQL groups rows by specified columns and computes aggregations such as count, making it ideal for aggregating similar PowerShell commands to reveal patterns. By summarizing on CommandLine or a normalized field, analysts can count occurrences and spot outliers. The other operators transform or filter but do not aggregate.

Exam trap

SC-200 often tests KQL operator semantics — candidates confuse extend (adds columns) with summarize (aggregates rows), or pick search because it sounds like it finds patterns.

How to eliminate wrong answers

Option B is wrong because extend adds calculated columns to each row without grouping or aggregating, so it cannot identify patterns across multiple events. Option C is wrong because search performs a text search across tables and columns but does not aggregate results into counts or grouped patterns. Option D is wrong because project selects and renames columns, shaping output but not aggregating rows.

1071
MCQmedium

During an incident investigation, an analyst notices a compromised user account that was used to access sensitive data from SharePoint Online. Which Microsoft 365 Defender workload would provide the most relevant alerts for suspicious file access patterns?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Identity
AnswerC

Microsoft Defender for Cloud Apps functions as a cloud access security broker (CASB) with API connectors to SharePoint Online and other SaaS apps. It aggregates file access and sharing events, applies user and entity behavior analytics (UEBA) to detect impossible travel, mass downloads, and abnormal external sharing, and can generate the exact type of suspicious file access alert an analyst would investigate in this scenario.

Why this answer

Microsoft Defender for Cloud Apps (Option C) is the correct workload because it provides visibility into cloud application usage, including SharePoint Online, and can generate alerts for suspicious file access patterns such as mass download, unusual file sharing, or access from anomalous locations. It uses behavioral analytics and anomaly detection to identify compromised accounts accessing sensitive data in SaaS applications like SharePoint.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming Office 365 covers all cloud workloads, but Cloud Apps is specifically designed for SaaS app security and anomaly detection in services like SharePoint.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint focuses on endpoint devices (e.g., Windows, macOS, Linux) and detects threats like malware or suspicious processes on those devices, not file access patterns in SharePoint Online. Option B is wrong because Microsoft Defender for Office 365 primarily protects email and collaboration tools (Exchange Online, Teams) from threats like phishing and malware, but does not specialize in monitoring file access patterns in SharePoint. Option D is wrong because Microsoft Defender for Identity monitors on-premises Active Directory and hybrid identities for attacks like Kerberos abuse or lateral movement, not cloud-based SharePoint file access.

1072
Multi-Selectmedium

Which TWO actions can be performed using automation rules in Microsoft Sentinel? (Select TWO.)

Select 2 answers
A.Create a new incident from an alert.
B.Modify the query of an existing analytics rule.
C.Assign an incident to a specific owner.
D.Delete an incident automatically.
E.Trigger a playbook when an incident is created.
AnswersC, E

Automation rules run on incidents after creation and can assign an owner, change severity, add tags, or run a playbook. Assigning an incident to a specific owner is a supported action, letting triage routing happen automatically without manual analyst intervention.

Why this answer

Option C is correct because Microsoft Sentinel automation rules can perform incident management actions such as changing the owner, status, severity, or adding tags to an incident when their conditions are met. Option E is correct because automation rules can invoke a playbook (Logic App) in response to an incident being created, which is a core use case for orchestrating automated responses. Option A is not correct because incidents are generated from alerts by analytics rules, not by automation rules.

Option B is not correct because automation rules cannot modify the query or logic of an existing analytics rule. Option D is not correct because automation rules do not support deleting incidents; they can close or change incident properties but not remove the incident record.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rules, mistakenly thinking automation rules can create incidents or modify analytics rule logic, when in fact automation rules only act on existing incidents and cannot alter detection logic or delete incidents.

1073
MCQeasy

A security analyst wants to quickly check the number of incidents created in Microsoft Sentinel in the last 7 days, grouped by severity. Which KQL query should the analyst use?

A.SecurityIncident | where TimeGenerated > ago(7d) | summarize count() by Severity
B.SecurityAlert | where TimeGenerated > ago(7d) | summarize count() by Severity
C.SigninLogs | where TimeGenerated > ago(7d) | summarize count() by Status
D.DeviceEvents | where TimeGenerated > ago(7d) | summarize count() by ActionType
AnswerA

The SecurityIncident table in Microsoft Sentinel stores incident records generated by the analytics and correlation engine. By filtering on TimeGenerated > ago(7d), this KQL query limits results to incidents that were created in the past week, and the summarize count() by Severity then aggregates those incidents into buckets of Informational, Low, Medium, and High. Because the analyst specifically asked for the number of incidents, this is the correct table and aggregation.

Why this answer

The SecurityIncident table in Microsoft Sentinel stores incident records, and the query filters for incidents created in the last 7 days using `where TimeGenerated > ago(7d)`, then groups them by severity with `summarize count() by Severity`. This directly answers the analyst's need to check the number of incidents grouped by severity.

Exam trap

The trap here is confusing the SecurityIncident table (for incidents) with the SecurityAlert table (for alerts), as many candidates mistakenly use SecurityAlert when the question explicitly asks for incident counts.

How to eliminate wrong answers

Option B is wrong because SecurityAlert contains alert data, not incidents; alerts can be grouped into incidents but are not the same entity, so this query would count alerts, not incidents. Option C is wrong because SigninLogs tracks user sign-in events and uses Status (e.g., success/failure), not incident severity, so it is irrelevant to incident counts. Option D is wrong because DeviceEvents logs device-level activities and uses ActionType (e.g., 'CreateProcess'), not incident severity, making it unrelated to incident management.

1074
MCQhard

Your SOC team uses Microsoft Sentinel's UEBA to detect insider threats. You want to ensure that UEBA can correlate activities across multiple data sources. Which data source must be enabled for UEBA to function properly?

A.Azure Activity logs
B.Office 365 audit logs
C.Windows Security Events
D.Microsoft Entra ID audit logs
AnswerD

Microsoft Entra ID audit logs are the correct primary source for UEBA because they contain identity-centric actions such as user sign-ins, conditional access evaluations, and directory modifications (e.g., password changes, role assignments). UEBA uses these logs to construct user profiles and establish behavioral baselines, enabling detection of anomalous activity like impossible travel or unusual authentication patterns. Since UEBA is fundamentally about user entity behavior, Entra ID logs provide the identity context that other logs lack.

Why this answer

Microsoft Sentinel's UEBA relies on Microsoft Entra ID (formerly Azure AD) audit logs as the primary identity source to establish a baseline of user behavior and correlate activities across different data sources. Without these logs, UEBA cannot map activities to specific user identities, which is essential for detecting anomalous behavior patterns indicative of insider threats.

Exam trap

The trap here is that candidates often assume Office 365 audit logs (Option B) are the primary identity source because they contain user actions, but Microsoft Sentinel's UEBA specifically requires Entra ID audit logs to establish the foundational identity baseline before correlating other data sources.

How to eliminate wrong answers

Option A is wrong because Azure Activity logs provide operational data about Azure resource management (e.g., VM creation, resource group changes) but do not contain user-level identity context required for UEBA correlation. Option B is wrong because Office 365 audit logs capture user actions in Exchange, SharePoint, and Teams, but they are a secondary data source that UEBA can ingest after identity mapping is established via Entra ID logs. Option C is wrong because Windows Security Events record local system-level activities (e.g., logon events, process creation) but lack the centralized identity context needed for cross-source user behavior correlation.

1075
MCQeasy

You are hunting for privileged account abuse in Microsoft Entra ID. Which table in Microsoft Sentinel contains audit logs for changes to directory roles?

A.IdentityLogonEvents
B.AuditLogs
C.SigninLogs
D.DeviceLogonEvents
AnswerB

AuditLogs records Microsoft Entra ID directory activity, including role membership and role definition changes, so it directly satisfies the requirement to hunt privileged account abuse through directory role modifications. SigninLogs covers authentication events instead, not administrative role changes.

Why this answer

AuditLogs in Microsoft Sentinel contain audit data from Microsoft Entra ID, including changes to directory roles. Option A (IdentityLogonEvents) is incorrect as it contains identity protection events. Option C (SigninLogs) is incorrect because it contains user sign-in events.

Option D (DeviceLogonEvents) is incorrect as it logs device logon events.

1076
Multi-Selectmedium

Which TWO actions should you perform to contain a ransomware incident in Microsoft Defender for Endpoint?

Select 2 answers
A.Reset the local administrator password.
B.Isolate the device from the network.
C.Run a full antivirus scan.
D.Kill the malicious processes.
E.Collect the ransomware sample for analysis.
AnswersB, D

Isolating the device from the network is the immediate containment action because it severs the ransomware's C2 channel, preventing key exchange, additional payload downloads, and SMB-based worm-like propagation to adjacent systems. Physically disconnecting the network cable, disabling the Wi-Fi adapter, or applying a host-based firewall rule to block all inbound and outbound traffic ensures the encryption process cannot phone home or spread. This preserves evidence while stopping the attack in place, making it the first priority in any ransomware containment playbook.

Why this answer

Isolating the device from the network (Option B) is a critical containment step in a ransomware incident because it immediately stops the ransomware from communicating with its command-and-control (C2) server and prevents lateral movement to other devices. In Microsoft Defender for Endpoint, device isolation can be initiated from the Security Center, which applies a network-level block that only allows communication with the Defender for Endpoint service, effectively quarantining the device while preserving forensic data.

Exam trap

The trap here is that candidates confuse containment actions (like isolation and killing processes) with post-incident steps (like password resets, scanning, or sample collection), leading them to select options that are reactive rather than immediately preventive.

1077
MCQeasy

A security analyst is using Microsoft Defender for Cloud's adaptive application controls (AAC) to allowlist trusted applications on Azure VMs. After enabling AAC and running in 'Audit' mode for a week, the analyst wants to switch to 'Enforce' mode. Which pre-requisite must be met before enforcement can be applied?

A.The VM must have the Guest Configuration extension installed.
B.A valid Microsoft Defender for Servers Plan 2 license must be assigned to the VM.
C.The VM must have a baseline of allowed applications generated from at least two weeks of audit data.
D.The VM must be running on a supported operating system like Windows Server 2016 or later.
AnswerC

Adaptive Application Controls must first run in audit-only mode for at least two weeks so Defender for Cloud can observe normal application usage and build a baseline of known-good executables, including file paths, publishers, and hashes. This audit-derived baseline is the specific prerequisite for switching a policy to enforce mode; without it, the allowlist would be incomplete and would cause legitimate applications to be blocked. Therefore, having a baseline generated from at least two weeks of audit data is the required condition before enforcement can be safely enabled.

Why this answer

Adaptive application controls require a minimum of two weeks of audit data to establish a reliable baseline of allowed applications before enforcement can be applied. This baseline ensures that legitimate applications are not blocked when switching from Audit to Enforce mode, reducing false positives and operational disruptions.

Exam trap

The trap here is that candidates may assume any supported OS or license is sufficient, but Microsoft specifically requires the two-week audit baseline to prevent enforcement from blocking legitimate applications.

How to eliminate wrong answers

Option A is wrong because the Guest Configuration extension is used for Azure Policy guest configuration assignments, not for adaptive application controls. Option B is wrong because while Defender for Servers Plan 2 is required to use adaptive application controls, it is a prerequisite for enabling the feature itself, not specifically for switching from Audit to Enforce mode. Option D is wrong because although supported operating systems are necessary, the specific prerequisite for enforcement is the two-week audit baseline, not just OS version support.

1078
MCQeasy

A security analyst receives a Microsoft Defender for Identity alert about a suspicious Kerberos attack. The analyst needs to contain the compromised account immediately. What should the analyst do?

A.Disable the user account in Microsoft Entra ID.
B.Remove the user from all privileged groups.
C.Require the user to change their password at next sign-in.
D.Reset the user's password and notify the user.
AnswerA

Disabling the account in Microsoft Entra ID immediately blocks authentication, satisfying the requirement to contain the compromised identity. For a hybrid user, however, this alone may not stop on-premises Kerberos activity, since the domain controller still validates tickets until directory sync propagates the change.

Why this answer

Disabling the user account in Microsoft Entra ID immediately prevents any further authentication and access, containing the compromised account. This is the fastest and most direct containment action for a suspicious Kerberos attack alert in Microsoft Defender for Identity.

Exam trap

The trap is choosing a less immediate action like password reset or group removal, which does not stop an attacker who already has valid Kerberos tickets or credentials.

How to eliminate wrong answers

Option B is wrong because removing the user from privileged groups does not prevent the attacker from using the compromised account for other access; it only reduces privileges but leaves the account active. Option C is wrong because requiring a password change at next sign-in does not stop an attacker who already has valid credentials or Kerberos tickets; they can continue until the password is changed. Option D is wrong because resetting the password and notifying the user is reactive and does not immediately block the attacker; the attacker may still have active sessions or tickets.

1079
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You are configuring Microsoft Defender for Identity to protect against lateral movement attacks. Which configuration should you prioritize to detect pass-the-hash attacks?

A.Configure port mirroring for domain controllers
B.Enable 'SAM-R' (Remote SAM) in the Microsoft Defender for Identity sensor configuration
C.Configure Windows Event Forwarding (WEF) for domain controllers
D.Enable 'Capture NTLM hashes' in the Microsoft Defender for Identity sensor configuration
AnswerD

Enabling the 'Capture NTLM hashes' setting in the Microsoft Defender for Identity sensor configuration instructs the sensor to intercept NTLM authentication traffic on the network and extract the NTLM hashes used during the handshake. This is the foundational telemetry for pass-the-hash detection because the sensor can then correlate these captured hashes against account logon events to identify when a hash is reused from a different source. Without this setting, the sensor lacks the specific data needed to trigger pass-the-hash alerts, making it the correct configuration for this scenario.

Why this answer

Enabling 'Capture NTLM hashes' in the Microsoft Defender for Identity sensor configuration allows the sensor to extract NTLM hashes from network traffic. Pass-the-hash attacks rely on capturing and reusing NTLM hashes to authenticate laterally; by capturing these hashes, Defender for Identity can detect anomalies such as a hash being used from a different source or for suspicious logon attempts, directly identifying the attack.

Exam trap

The trap here is that candidates confuse prerequisites (port mirroring) or supporting features (SAM-R for lateral movement paths, WEF for event collection) with the specific configuration needed to detect pass-the-hash, which is the direct capture of NTLM hashes from network traffic.

How to eliminate wrong answers

Option A is wrong because port mirroring for domain controllers is a prerequisite for network traffic capture but does not itself enable detection of pass-the-hash attacks; it only provides the raw data. Option B is wrong because enabling SAM-R (Remote SAM) is used for lateral movement path detection (e.g., enumerating local admin groups) but does not capture or analyze NTLM hashes for pass-the-hash detection. Option C is wrong because configuring Windows Event Forwarding (WEF) for domain controllers collects Windows security events (e.g., 4624 logon events) but does not capture NTLM hashes from network traffic, which is essential for detecting pass-the-hash.

1080
MCQmedium

A large enterprise uses Microsoft Defender for Cloud with all enhanced security plans enabled. They want to automatically enable the Defender for Cloud plans on new Azure subscriptions that are created under their management group. Which approach should they use?

A.Assign the built-in Azure Policy initiative 'Enable Microsoft Defender for Cloud on all subscriptions' at the management group level.
B.Configure 'Continuous export' settings in Defender for Cloud to export policies to Log Analytics for each subscription.
C.Set the default security policies at the management group level in Defender for Cloud's environment settings.
D.Enable 'Auto provisioning' for the Log Analytics agent in Defender for Cloud.
AnswerA

The built-in Azure Policy initiative 'Enable Microsoft Defender for Cloud on all subscriptions' is a policy set designed to apply the Defender plans (including Servers, SQL, and Storage) to every subscription within the assigned scope. When assigned at the management group level, Azure Policy automatically deploys the necessary plan enablement and pricing tier configuration to both existing and future subscriptions, removing the need for manual per-subscription setup. This is the intended native mechanism for centralizing the enablement of Defender plans across an enterprise.

Why this answer

The built-in Azure Policy initiative 'Enable Microsoft Defender for Cloud on all subscriptions' is designed to be assigned at a management group scope, automatically enabling all Defender for Cloud plans on new subscriptions as they are created under that management group. This leverages Azure Policy's compliance evaluation and remediation tasks to enforce the security plans across the entire hierarchy without manual intervention.

Exam trap

The trap here is that candidates often confuse configuring default security policies (which only set recommendation baselines) with the Azure Policy initiative that actually enables the pricing tiers for Defender for Cloud plans on new subscriptions.

How to eliminate wrong answers

Option B is wrong because 'Continuous export' in Defender for Cloud is used to stream security alerts and recommendations to Log Analytics or Event Hubs for external analysis, not to enable Defender for Cloud plans on new subscriptions. Option C is wrong because setting default security policies at the management group level in Defender for Cloud's environment settings only defines the security configurations (e.g., which recommendations are enforced) but does not automatically enable the enhanced security plans themselves on new subscriptions. Option D is wrong because 'Auto provisioning' for the Log Analytics agent installs the agent on existing VMs to collect data, but it does not enable Defender for Cloud plans or apply to new subscriptions automatically.

1081
MCQhard

A security analyst is investigating a ransomware incident and needs to find all files that were written to a specific device within a 5-minute window before the ransomware process started. The analyst knows the device name and the ransomware process start time. Which advanced hunting table and KQL operator combination would be most efficient to find the file creation events?

A.DeviceFileEvents with where
B.DeviceProcessEvents with join
C.DeviceEvents with where
D.DeviceImageLoadEvents with where
AnswerA

DeviceFileEvents records file creation, modification and rename activity, including the FileName, FolderPath, InitiatingProcessFileName and Timestamp columns. Filtering with `where` on DeviceName and a Timestamp range narrows results to the five-minute window, satisfying the requirement to enumerate files written before the ransomware process started.

Why this answer

DeviceFileEvents is the correct table because it specifically captures file creation, modification, and deletion events on devices. Using the `where` operator to filter by device name and a timestamp range (5 minutes before the ransomware process start time) is the most efficient way to retrieve the exact file creation events needed for the investigation.

Exam trap

The trap here is that candidates often confuse DeviceProcessEvents (process creation) with file creation events, or they think a `join` is needed to correlate process start time with file events, when a simple `where` on DeviceFileEvents is sufficient and more efficient.

How to eliminate wrong answers

Option B is wrong because DeviceProcessEvents tracks process creation events, not file creation events, and using `join` would be unnecessarily complex and less efficient than a simple `where` filter. Option C is wrong because DeviceEvents is a generic table that captures various security events (e.g., Windows Defender alerts, exploit guard events) but does not specifically log file creation events. Option D is wrong because DeviceImageLoadEvents records when a process loads a DLL or executable image, not file creation events.

1082
Multi-Selecteasy

Which TWO techniques are commonly used in threat hunting to identify potential malicious activity? (Choose two.)

Select 2 answers
A.Searching for known indicators of compromise (IoCs).
B.Disabling security controls to observe attacker behavior.
C.Analyzing anomalies in baseline behavior.
D.Waiting for alerts from automated detection tools.
E.Automatically blocking all suspicious traffic.
AnswersA, C

Searching for known indicators of compromise lets hunters match observed artefacts — file hashes, IP addresses, domains — against threat intelligence. This reactive technique rapidly confirms whether known malicious infrastructure or payloads are present in the environment, satisfying one recognised threat hunting methodology.

Why this answer

Option A is correct because threat hunting commonly begins with searching for known indicators of compromise (IoCs) such as malicious IP addresses, file hashes, domain names, and registry keys, which can reveal evidence of past or ongoing attacks. Option C is correct because analyzing anomalies in baseline behavior—deviations from normal user, endpoint, or network activity—helps hunters uncover unknown or evasive threats that signature-based tools may miss. Disabling security controls (B) is not a threat-hunting technique; it weakens defenses and is unsafe.

Waiting for alerts from automated detection tools (D) is reactive monitoring rather than proactive hunting. Automatically blocking all suspicious traffic (E) is a prevention/response action, not an investigative hunting method.

Exam trap

The trap is selecting 'wait for alerts' or 'block traffic' — both are operational security activities, not threat hunting techniques, and distract from the proactive, investigative nature of hunting.

1083
Multi-Selecteasy

Which TWO of the following are valid data connectors for Microsoft Sentinel? (Select TWO.)

Select 2 answers
A.Docker containers
B.Amazon RDS
C.Azure Firewall
D.Google Cloud Storage
E.Microsoft Entra ID
AnswersC, E

Azure Firewall is a supported Microsoft Sentinel data connector, streaming firewall network and application rule logs into the workspace via Azure Monitor diagnostic settings. This satisfies the question's requirement to identify valid connectors, alongside Microsoft Entra ID.

Why this answer

Azure Firewall and Microsoft Entra ID are both supported data connectors in Microsoft Sentinel. Azure Firewall can be connected via the Azure Firewall connector, and Microsoft Entra ID (formerly Azure Active Directory) has built-in connectors for auditing and sign-in logs. Docker containers (A) are not a native data source for Sentinel; they would require a custom solution.

Amazon RDS (B) is not directly supported; you would need to ingest via AWS CloudTrail or similar. Google Cloud Storage (D) also requires custom ingestion methods.

1084
MCQmedium

During an investigation, you need to check if any user has been assigned privileged roles in Microsoft Entra ID outside of normal business hours. Which data source would provide this information?

A.OfficeActivity (Office 365)
B.SecurityEvent (Windows Event Logs)
C.SigninLogs (Microsoft Entra ID)
D.AuditLogs (Microsoft Entra ID)
AnswerD

AuditLogs (Microsoft Entra ID) is the authoritative log for directory administrative changes, capturing activities such as 'Add member to role,' 'Remove member from role,' and 'Activate role' in the RoleManagement category. Each log entry includes the actor, target user, role name, and timestamp, enabling full visibility into who was granted elevated permissions and when. In Log Analytics or Microsoft 365 Defender, this appears as the AuditLogs table in the EntraID sign-in/logs connector. Therefore, it is the correct data source for verifying whether any user has been added to a privileged role.

Why this answer

AuditLogs in Microsoft Entra ID (formerly Azure AD) capture all directory-level changes, including privileged role assignments (e.g., Global Administrator, Privileged Role Administrator) along with the timestamp and user who performed the action. This allows you to filter for role assignments occurring outside normal business hours, making it the correct data source for this investigation.

Exam trap

The trap here is that candidates often confuse SigninLogs (which show when a user logs in) with AuditLogs (which show administrative changes like role assignments), leading them to choose Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because OfficeActivity (Office 365) logs cover user actions in Exchange Online, SharePoint, and Teams, but do not include Entra ID role assignments. Option B is wrong because SecurityEvent logs are Windows Event Logs from on-premises or hybrid-joined devices, not from Microsoft Entra ID, and they do not track cloud directory role changes. Option C is wrong because SigninLogs record authentication events (successful/failed sign-ins) and do not capture administrative role assignment operations.

1085
MCQmedium

A security analyst suspects a user's device is exfiltrating data via DNS queries to a known malicious domain. Which Advanced Hunting table should the analyst query to find DNS requests made from the device?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.IdentityLogonEvents
D.EmailUrlInfo
AnswerA

This table in Microsoft 365 Defender (Advanced Hunting) captures network connections initiated by devices, including DNS queries when ActionType is DnsQuery. For exfiltration suspicion, DNS queries to known malicious domains or unusual patterns (e.g., high volume, TXT record payloads) can be detected. Also includes other network actions like ConnectionSuccess, so it's the primary table for network egress.

Why this answer

DeviceNetworkEvents is the correct table because it contains network-level events, including DNS queries, from devices monitored by Microsoft Defender for Endpoint. The analyst needs to inspect DNS requests to identify exfiltration to a known malicious domain, and this table specifically logs the destination URL (including FQDNs) and the initiating process, making it the appropriate source for such queries.

Exam trap

The trap here is that candidates may confuse DeviceProcessEvents with network activity because processes initiate network connections, but DeviceProcessEvents only logs process creation details, not the actual network traffic or DNS queries.

How to eliminate wrong answers

Option B (DeviceProcessEvents) is wrong because it logs process creation events (e.g., command-line arguments, parent processes), not network traffic like DNS queries. Option C (IdentityLogonEvents) is wrong because it captures authentication and logon events from Azure Active Directory, not network-level DNS activity. Option D (EmailUrlInfo) is wrong because it records URLs found in email messages, not DNS queries made from a device.

1086
MCQmedium

A SOC team wants to automate response to incidents detected by Microsoft Sentinel. When a new incident is created with severity "High" and contains a specific tag "malware", they want to run a playbook that isolates the affected device. What is the correct way to configure this automation?

A.Create an automation rule that triggers on "When incident is created" and set conditions for severity equals High and tag contains "malware", then set a playbook action.
B.Create a custom analytics rule that runs the playbook directly when triggered.
C.Configure a logic app with a trigger on "When a Microsoft Sentinel incident is created" and use conditions inside the logic app.
D.Use the Microsoft Sentinel API to create a webhook that triggers the playbook.
AnswerA

This is the correct approach because Microsoft Sentinel automation rules are the native, first-class mechanism for responding to incidents. By triggering on 'When incident is created' and setting conditions that check for severity equals High and tag contains 'malware', the rule will evaluate every new incident and conditionally run the chosen playbook. This keeps response logic centralized in Sentinel, is easy to audit via the automation rule list, and does not require custom code or external integrations.

Why this answer

Automation rules in Microsoft Sentinel are specifically designed to trigger playbooks based on incident creation events and conditions like severity and tag. By setting the trigger to 'When incident is created' and conditions for severity equals 'High' and tag contains 'malware', the rule will invoke the playbook to isolate the affected device automatically, without manual intervention.

Exam trap

The trap here is that candidates may think a custom analytics rule or a direct Logic App trigger is equivalent to an automation rule, but Microsoft Sentinel's automation rules are the intended and most efficient way to conditionally invoke playbooks based on incident properties like severity and tags.

How to eliminate wrong answers

Option B is wrong because custom analytics rules generate alerts or incidents based on query results, but they do not directly run playbooks; playbooks are invoked by automation rules or as part of incident response. Option C is wrong because while a Logic App with a 'When a Microsoft Sentinel incident is created' trigger can work, it bypasses the native automation rule framework and requires manual condition handling inside the Logic App, making it less efficient and not the recommended configuration for this scenario. Option D is wrong because using the Microsoft Sentinel API to create a webhook is an indirect, custom integration method that lacks the built-in triggering and condition evaluation of automation rules, and is not the standard way to automate incident response.

1087
MCQhard

A security analyst uses advanced hunting in Microsoft 365 Defender to investigate a potential lateral movement attack. The analyst suspects that an attacker used stolen credentials to authenticate to multiple workstations via RDP. Which KQL query would return a list of devices where a single user account (user@contoso.com) had successful interactive logons on more than 5 distinct devices within a 10-minute window?

A.DeviceNetworkEvents | where RemoteIP == 'user@contoso.com' | summarize dcount(DeviceName) by bin(Timestamp, 10m) | where dcount_DeviceName > 5
B.IdentityLogonEvents | where AccountUpn == 'user@contoso.com' and LogonType == 'Interactive' | summarize dcount(DeviceName) by bin(Timestamp, 10m) | where dcount_DeviceName > 5
C.DeviceLogonEvents | where AccountUpn == 'user@contoso.com' and LogonType == 'Interactive' | summarize dcount(DeviceName) by bin(Timestamp, 10m) | where dcount_DeviceName > 5
D.DeviceLogonEvents | where AccountUpn == 'user@contoso.com' | summarize count() by DeviceName, bin(Timestamp, 10m) | where count_ > 5
AnswerC

DeviceLogonEvents records successful interactive logons with AccountUpn and DeviceName. Filtering by that account and LogonType, then summarising distinct devices per 10-minute bin, surfaces any window where one account touched more than five workstations, matching the lateral-movement hypothesis.

Why this answer

DeviceLogonEvents is the Microsoft 365 Defender table that captures logon events on devices, including RDP interactive logons. The query filters for the specific user account and interactive logon type, then uses summarize with dcount(DeviceName) by bin(Timestamp, 10m) to count distinct devices within each 10-minute window, and finally filters for windows where the distinct device count exceeds 5, which matches the lateral movement scenario.

Exam trap

The trap here is that candidates often confuse DeviceLogonEvents with IdentityLogonEvents or DeviceNetworkEvents, mistakenly thinking network events or identity provider logs can reveal device-level interactive logon patterns, but only DeviceLogonEvents contains the necessary fields (AccountUpn, LogonType, DeviceName) for this specific lateral movement detection.

How to eliminate wrong answers

Option A is wrong because DeviceNetworkEvents captures network-level events (like connections), not logon events, and filtering RemoteIP by a UPN (user@contoso.com) is semantically incorrect—RemoteIP is an IP address, not a user identifier. Option B is wrong because IdentityLogonEvents tracks authentication events from identity providers (like Azure AD) and does not include device-level interactive logon details such as RDP logons on workstations. Option D is wrong because it uses count() instead of dcount(DeviceName), which counts total logon events per device rather than distinct devices, and it lacks the LogonType filter for 'Interactive', so it would include non-interactive logons and fail to identify lateral movement via RDP.

1088
MCQmedium

A SOC analyst receives a high-severity alert for a user who downloaded a malicious file from a phishing email. The analyst needs to quickly assess the scope of the incident across endpoints, email, and identities. Which Microsoft Defender XDR feature should the analyst use to get a unified view of the incident?

A.Microsoft Defender XDR incident queue
B.Microsoft Purview compliance portal
C.Microsoft Intune device compliance dashboard
D.Microsoft Sentinel incidents blade
AnswerA

The Microsoft Defender XDR incident queue is the correct location because it consolidates alerts from Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and other Microsoft 365 security signals into a single correlated incident. This gives the SOC analyst the full attack story, affected assets, and evidence, along with integrated investigation and response actions. High-severity alerts originating from Microsoft Defender workloads are automatically aggregated here, making it the primary triage and investigation surface.

Why this answer

The Microsoft Defender XDR incident queue is the correct choice because it aggregates alerts from Microsoft Defender for Endpoint, Office 365, and Identity into a single incident view, enabling the analyst to correlate the malicious file download across endpoints, email, and user identities without switching consoles. This unified incident management is a core feature of Microsoft Defender XDR, designed specifically for rapid triage and scope assessment in multi-domain threats.

Exam trap

The trap here is that candidates often confuse the Microsoft Defender XDR incident queue with Microsoft Sentinel incidents, assuming Sentinel is the primary unified view, but the question specifically asks for the Microsoft Defender XDR feature, not a separate SIEM product.

How to eliminate wrong answers

Option B is wrong because the Microsoft Purview compliance portal focuses on data governance, eDiscovery, and compliance policies (e.g., DLP, retention), not on real-time incident correlation across endpoints, email, and identities. Option C is wrong because the Microsoft Intune device compliance dashboard provides device compliance status and policy enforcement for managed devices, but it does not aggregate security alerts or provide a unified incident view across email and identity domains. Option D is wrong because the Microsoft Sentinel incidents blade is a SIEM/SOAR tool that can ingest alerts from multiple sources, but it is not the native Microsoft Defender XDR incident queue; using Sentinel for this purpose would require additional configuration and is not the direct, built-in feature for unified incident management within the Defender XDR ecosystem.

1089
Multi-Selectmedium

Which THREE steps should be included in a Microsoft Sentinel playbook for automatic incident response when a high-severity alert fires?

Select 3 answers
A.Investigate the alert by enriching with threat intelligence
B.Notify the security team via email or Teams
C.Pause the incident for 24 hours before taking action
D.Create a new Azure resource for logging
E.Contain the threat by blocking indicators
AnswersA, B, E

In Microsoft Sentinel, enriching an alert with threat intelligence is a standard investigative step: you pivot on entities such as IPs, domains, or hashes to query TI feeds and identify known malicious context, which helps validate the alert's severity and false-positive risk. This enrichment often leverages the built-in Threat Intelligence workbook or the hunting queries, enabling the analyst to correlate the current alert with historical compromise activity. It directly supports the 'Investigate' phase of the incident response lifecycle, making it a correct step.

Why this answer

Microsoft Sentinel playbooks, built on Azure Logic Apps, can automatically enrich alerts with threat intelligence from sources like the Threat Intelligence API or integrated TI platforms (e.g., VirusTotal, AlienVault OTX). This enrichment provides context (e.g., known malicious IPs, hashes, or domains) directly within the incident, enabling faster triage and informed response decisions without manual investigation.

Exam trap

The trap here is that candidates may confuse 'pausing' an incident with 'suppression' or 'tuning' rules, but in the context of automated response, any delay for high-severity alerts is unacceptable because it contradicts the goal of immediate containment.

1090
MCQmedium

You are responding to an incident where a user's credentials were used to access a federated SaaS application from an IP address associated with a known threat actor. The user's account is not disabled. Which action is most effective to prevent further unauthorized access?

A.Reset the user's password and revoke active sessions
B.Create a Conditional Access policy to block the IP
C.Disable the user's account
D.Block the source IP address on the firewall
AnswerA

Resetting the password invalidates the attacker's knowledge of the compromised secret, while explicitly revoking the user's active sessions and refresh tokens terminates the attacker's existing authenticated access to Microsoft 365/Entra ID apps. This should be done before any other investigation step because it limits dwell time and prevents further lateral movement or data exfiltration as long as the attacker is not already using alternate backdoors. The 'Revoke user sessions' action in the Entra ID admin center (or Microsoft Graph `revokeSignInSessions`) closes current bearer/refresh tokens, not just the password-based login path.

Why this answer

Resetting the user's password and revoking active sessions immediately invalidates the compromised credentials and terminates any existing authenticated sessions, including the session used by the threat actor. This directly addresses the root cause—credential compromise—without unnecessarily disrupting the user's account permanently. In a federated SaaS scenario, password reset combined with session revocation ensures the threat actor cannot re-authenticate even if they possess the previous password hash or tokens.

Exam trap

The trap here is that candidates often choose to block the IP (Option B or D) because it seems immediate and technical, but they overlook that the attacker can easily change IPs and that the core issue is credential compromise, not network-level access.

How to eliminate wrong answers

Option B is wrong because creating a Conditional Access policy to block the IP only addresses the specific source IP, which can be easily changed by the threat actor (e.g., via proxy or VPN), and does not remediate the compromised credentials. Option C is wrong because disabling the user's account is overly disruptive and may block legitimate access for the user, while the threat actor could still use other compromised accounts or lateral movement; it also does not revoke existing sessions or tokens. Option D is wrong because blocking the source IP on the firewall is a network-level control that does not affect federated authentication flows (which occur over HTTPS) and does not invalidate the stolen credentials or active sessions.

1091
MCQeasy

A security analyst is reviewing a threat hunting query in Microsoft Sentinel that uses the Kusto Query Language (KQL) to identify potential lateral movement. The query returns a large number of false positives. What is the most effective way to reduce false positives while maintaining detection coverage?

A.Increase the threshold for the anomaly score in the query.
B.Add allowlist conditions to exclude known administrative tools.
C.Reduce the time range of the query to the last 1 hour.
D.Replace the query with a different data source that has less noise.
AnswerB

Allowlisting known administrative tools removes legitimate remote-management activity from the result set, cutting false positives without narrowing the query's scope. Detection coverage for genuine lateral movement persists, since only trusted binaries are excluded rather than whole event categories.

Why this answer

Adding allowlist conditions, such as excluding known administrative tools or approved remote management traffic, directly reduces false positives without removing the core logic. Option A is wrong because increasing the threshold may miss true positives. Option C is wrong because reducing the time range may miss true positives and does not address false positives.

Option D is wrong because changing the data source may reduce detection coverage and does not necessarily reduce false positives in the current query.

1092
MCQmedium

A SOC team wants to automatically categorize incidents in Microsoft Sentinel with MITRE ATT&CK tactics (e.g., 'Initial Access', 'Execution') when an analytics rule triggers. How can they achieve this?

A.Use the incident details custom fields
B.Map MITRE ATT&CK tactics in the analytics rule
C.Use automation rule to set tactics
D.Use playbook to update incident
AnswerB

The analytics rule in Microsoft Sentinel includes a configuration pane where you can select one or more MITRE ATT&CK tactics and techniques (such as Initial Access, Execution, or Command and Control) that the rule is designed to detect. When the rule fires and creates an incident, the selected tactics are automatically applied to the incident's MITRE ATT&CK fields, enabling immediate categorization and correlation with other threat intelligence. This is the intended, first-party mechanism for tagging incidents with tactics, and it requires no additional overhead or post-processing, making it the correct and most reliable approach for automatic categorization.

Why this answer

Microsoft Sentinel analytics rules include a dedicated 'MITRE ATT&CK' configuration section where you can map specific tactics (e.g., Initial Access, Execution) to the rule. When the rule triggers and generates an incident, Sentinel automatically populates the incident's MITRE ATT&CK tactics field based on this mapping, enabling automated categorization without additional configuration.

Exam trap

Microsoft often tests the distinction between native analytics rule configuration (which directly sets MITRE ATT&CK tactics) versus post-processing methods like automation rules or playbooks, leading candidates to overcomplicate the solution when the simplest, built-in option is correct.

How to eliminate wrong answers

Option A is wrong because incident details custom fields are user-defined fields for storing arbitrary data, not a mechanism to automatically set MITRE ATT&CK tactics from an analytics rule trigger. Option C is wrong because automation rules can modify incident properties (e.g., severity, status) but cannot directly set MITRE ATT&CK tactics; they lack a dedicated action for MITRE ATT&CK fields. Option D is wrong because while a playbook (Azure Logic App) could theoretically update incident tactics via the Microsoft Sentinel API, this is an indirect, complex approach that requires custom code and is not the intended or simplest method—the native analytics rule mapping is the correct design.

1093
MCQeasy

During a threat hunting exercise, you need to pivot from a suspicious IP address to find all related alerts and incidents in Microsoft Sentinel. Which feature should you use?

A.Workbook
B.Incidents blade
C.Investigation graph
D.Playbook
AnswerC

The Investigation graph is Microsoft Sentinel's entity-centric exploration tool, modeling relationships between IPs, hosts, accounts, and alerts as a visual map. From a suspicious IP entity you can double-click or expand to immediately surface all connected alerts, related incidents, and adjacent entities, making it the correct pivot path for threat hunting. It leverages the entity schema and graph data to show both direct and indirect connections.

Why this answer

The investigation graph in Microsoft Sentinel allows visual pivoting and exploration of entities, making it the correct tool for pivoting from a suspicious IP to find related alerts and incidents. Option A (Workbooks) is incorrect because workbooks are for creating dashboards and reports. Option B (Incidents blade) is incorrect because it shows incidents but does not provide entity relationship visualization.

Option D (Playbook) is incorrect because playbooks automate responses, not pivot investigations.

1094
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. A security analyst receives an alert for a suspicious sign-in from an IP address in a sanctioned app. The analyst needs to immediately block the user from accessing the app. Which action should the analyst take?

A.Suspend the user account in Microsoft Entra ID.
B.Add the IP address to the blocked IP list in Defender for Cloud Apps.
C.Create a new access policy in Defender for Cloud Apps to block the user.
D.Revoke the user's session tokens in Microsoft Entra ID.
AnswerA

Suspending the user account in Microsoft Entra ID immediately disables the user object, preventing any fresh authentication and token issuance for all applications, including the sanctioned app protected by Defender for Cloud Apps. This is the most direct and effective containment action because it blocks all sign-in attempts regardless of device, network, or app, and takes effect nearly immediately across Microsoft's identity plane.

Why this answer

Suspending the user account in Microsoft Entra ID immediately revokes all access tokens and prevents the user from authenticating to any app, including the sanctioned app. This is the fastest way to block access because it disables the user's ability to sign in entirely, regardless of the app or IP address. Defender for Cloud Apps alerts often require immediate containment, and account suspension is a direct, irreversible action that stops all ongoing sessions.

Exam trap

The trap here is that candidates confuse a Defender for Cloud Apps policy (which is a conditional access-like rule that applies to future traffic) with the immediate, account-level containment action available in Microsoft Entra ID, which is the fastest way to stop an active threat.

How to eliminate wrong answers

Option B is wrong because adding the IP address to the blocked IP list in Defender for Cloud Apps blocks traffic from that IP, but does not block the specific user—if the user signs in from a different IP, they can still access the app. Option C is wrong because creating a new access policy in Defender for Cloud Apps takes time to propagate and may not apply retroactively to an ongoing session; it is a preventive measure, not an immediate containment action. Option D is wrong because revoking session tokens in Microsoft Entra ID terminates current sessions but does not prevent the user from re-authenticating immediately with valid credentials, whereas suspending the account blocks all future sign-ins.

1095
MCQeasy

You are configuring Microsoft Sentinel to ingest logs from Azure Active Directory (now Microsoft Entra ID). Which of the following connectors should you use to collect sign-in logs and audit logs?

A.Microsoft Defender for Cloud connector.
B.Office 365 connector.
C.Azure Activity connector.
D.Microsoft Entra ID connector.
AnswerD

The Microsoft Entra ID connector pulls sign-in and audit logs through the Microsoft Entra ID diagnostic settings pipeline into the workspace. It is the supported data connector for these identity event tables, matching the stem's collection requirement.

Why this answer

The Microsoft Entra ID connector (formerly Azure AD connector) is the correct choice because it is specifically designed to ingest sign-in logs, audit logs, and provisioning logs from Microsoft Entra ID into Microsoft Sentinel. This connector uses the Microsoft Graph API to pull these logs, enabling security monitoring of user authentication and administrative activities.

Exam trap

The trap here is that candidates often confuse the Azure Activity connector (which logs Azure resource operations) with the Entra ID connector (which logs identity and authentication events), leading them to incorrectly select option C.

How to eliminate wrong answers

Option A is wrong because the Microsoft Defender for Cloud connector is used to ingest security alerts and recommendations from Defender for Cloud, not Azure AD sign-in or audit logs. Option B is wrong because the Office 365 connector ingests logs from Exchange Online, SharePoint Online, Teams, and other Office 365 workloads, but it does not include Azure AD sign-in or audit logs. Option C is wrong because the Azure Activity connector ingests subscription-level operational logs from Azure Resource Manager (e.g., create/delete resources), not Azure AD sign-in or audit logs.

1096
MCQmedium

You are responding to an incident where a malicious PowerShell script was executed on multiple endpoints. You need to collect the script content from the affected devices for analysis. What should you use?

A.Microsoft Defender for Cloud Apps activity logs
B.Microsoft Defender for Endpoint live response
C.Microsoft Purview eDiscovery
D.Azure Automation runbook
AnswerB

Microsoft Defender for Endpoint Live Response is the correct choice because it provides a remote, real-time shell for a compromised device. You can initiate a session from the MDE portal, run PowerShell commands, execute a script from the library, collect forensic artifacts, and retrieve the malicious script file for analysis. This interactive capability allows you to inspect the exact script content, confirm its behavior, and gather evidence directly from the endpoint.

Why this answer

Microsoft Defender for Endpoint live response (Option B) is the correct tool because it provides a remote shell connection to an endpoint, allowing you to collect the malicious PowerShell script content directly from the device's file system or memory. This is essential for forensic analysis when a script has been executed, as you can use commands like `Get-Content` or `Get-File` to retrieve the script file. Other options lack the direct, real-time access needed to extract script content from affected endpoints.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps activity logs with endpoint-level forensic data, assuming cloud logs contain script execution details, when in fact they only track cloud service interactions.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps activity logs capture cloud application usage and sign-in events, not local script execution on endpoints. Option C is wrong because Microsoft Purview eDiscovery is designed for searching and exporting content from Microsoft 365 data sources (e.g., Exchange, SharePoint) for legal or compliance purposes, not for collecting live forensic data from endpoint file systems. Option D is wrong because Azure Automation runbooks are used for automating cloud management tasks (e.g., VM configuration, patching) and cannot directly connect to endpoints to retrieve script content without additional infrastructure like hybrid workers or custom scripts.

1097
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. A critical server in Azure was compromised by ransomware. The incident response team needs to ensure that no other resources in the same resource group are affected. What is the most immediate containment action?

A.Delete the virtual machine immediately to stop the ransomware.
B.Disable the public IP address and apply an NSG rule to block all inbound/outbound traffic to the server's subnet.
C.Change the local administrator password on the VM.
D.Move the VM to a different virtual network and subnet.
AnswerB

Disabling the public IP and applying an NSG rule that blocks all inbound and outbound traffic at the server's subnet effectively isolates the VM from both external attackers and internal lateral movement while leaving the machine powered on for evidence preservation. Because NSGs are stateful and evaluated for every flow, this drops current network conversations and prevents new ones, cutting off command-and-control or data exfiltration. This is the proper immediate containment action in an incident response playbook, as it contains the threat without destroying forensic artifacts.

Why this answer

The most immediate containment action is to isolate the compromised server's subnet by disabling its public IP and applying an NSG rule that blocks all inbound and outbound traffic. This prevents lateral movement of ransomware to other resources in the same resource group while preserving the VM for forensic analysis. In Microsoft Defender for Cloud and Sentinel, network isolation at the subnet level is the fastest way to contain a breach without destroying evidence.

Exam trap

The trap here is that candidates often choose to delete or move the VM, not realizing that immediate network isolation is the fastest way to contain lateral movement while preserving evidence for investigation.

How to eliminate wrong answers

Option A is wrong because deleting the VM destroys forensic evidence (memory, disk artifacts) and does not stop ransomware that may have already spread to other resources via network connections. Option C is wrong because changing the local administrator password does not block active network connections or lateral movement; ransomware often uses current sessions or service accounts, not just local credentials. Option D is wrong because moving the VM to a different virtual network and subnet requires the VM to be running and connected, which could propagate the ransomware during the move; it also does not immediately block traffic to other resources in the original resource group.

1098
Multi-Selecthard

Which THREE are valid ways to ingest data into Microsoft Sentinel? (Select three.)

Select 3 answers
A.Configuring Syslog using Azure Monitor Agent (AMA)
B.Using the Microsoft Sentinel API to push custom logs
C.Connecting to Azure DevOps directly
D.Importing from Power BI datasets
E.Using a built-in data connector for Microsoft Entra ID
AnswersA, B, E

Configuring Syslog using Azure Monitor Agent (AMA) is a fully supported ingestion path in Microsoft Sentinel. AMA runs on Linux virtual machines and uses Data Collection Rules (DCRs) to define which facilities and severities to forward to the Log Analytics workspace that Sentinel monitors. This method replaces the legacy Log Analytics agent, allowing you to collect syslog events from on-premises and cloud Linux servers, and it is a first-party, no-code option in the data connectors gallery.

Why this answer

The Azure Monitor Agent (AMA) can collect Syslog events from Linux-based sources and forward them to a Log Analytics workspace, which is the underlying data store for Microsoft Sentinel. By configuring a Data Collection Rule (DCR) that specifies the Syslog facility and severity levels, AMA streams these logs into the Syslog table in the workspace, making them available for detection and analysis within Sentinel.

Exam trap

The trap here is that candidates may assume any Microsoft service (like Azure DevOps or Power BI) can be directly connected via a built-in connector, but Sentinel only provides connectors for services that generate security-relevant logs, not for project management or BI analytics tools.

1099
MCQmedium

A Defender for Cloud alert repeatedly fires for a known test VM used by the security team. The alert type is valid, but it should not create noise for that VM. What should the analyst configure?

A.Create an alert suppression rule scoped to the test VM and alert type.
B.Disable Defender for Servers for the entire subscription.
C.Change the VM name.
D.Delete the recommendation from secure score.
AnswerA

Creating an alert suppression rule scoped to the test VM and the specific alert type is the correct noise-control method in Defender for Cloud. You define conditions such as the VM resource and alert name, so truly benign alerts from this known test asset are hidden or muted without disabling any threat detection. Other VMs remain fully monitored, and if the alert pattern changes, you can edit or disable the rule.

Why this answer

An alert suppression rule in Microsoft Defender for Cloud allows you to define a scope (e.g., a specific VM) and a condition (e.g., a specific alert type) to automatically dismiss alerts that are valid but not actionable for that resource. This reduces noise without affecting detection coverage for other resources. The rule is configured at the subscription or resource group level and applies only to matching alerts.

Exam trap

The trap here is that candidates may confuse alert suppression (which dismisses alerts without affecting detection) with disabling a security plan or modifying secure score, leading them to choose overly broad or irrelevant actions like disabling Defender for Servers or deleting recommendations.

How to eliminate wrong answers

Option B is wrong because disabling Defender for Servers for the entire subscription would remove all threat detection and security monitoring from every VM, not just the test VM, which is an extreme and unnecessary measure. Option C is wrong because changing the VM name does not affect the alert logic; Defender for Cloud identifies VMs by resource ID, not name, so the alert would still fire for the same resource. Option D is wrong because deleting a recommendation from secure score only removes it from the score calculation; it does not suppress alerts, and alerts are independent of secure score recommendations.

1100
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that incidents created in Microsoft Defender XDR are automatically synchronized to Microsoft Sentinel with the least administrative effort. What should you configure?

A.Create a Logic App that uses the Microsoft Defender XDR API to fetch incidents and push them to Microsoft Sentinel.
B.Use the Microsoft Sentinel API to pull incidents from Microsoft Defender XDR.
C.Enable raw data ingestion from Microsoft Defender for Endpoint to Microsoft Sentinel.
D.Enable the Microsoft Defender XDR data connector in Microsoft Sentinel.
AnswerD

The Microsoft Defender XDR data connector is the supported, out-of-the-box integration that automatically imports incidents and alerts generated by Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps into Microsoft Sentinel. It leverages the Microsoft Graph security API, preserves the full incident schema, and provides bidirectional synchronization of incident status and comments between Sentinel and the Microsoft 365 Defender portal, requiring no custom code and minimal configuration.

Why this answer

The Microsoft Defender XDR data connector in Microsoft Sentinel provides a built-in, one-click integration that automatically synchronizes incidents from Microsoft Defender XDR to Microsoft Sentinel with no custom development required. This connector uses the Microsoft Graph Security API to ingest incidents, alerts, and evidence, ensuring seamless bidirectional synchronization with the least administrative effort.

Exam trap

The trap here is that candidates often confuse raw data ingestion (e.g., streaming raw logs from Defender for Endpoint) with incident synchronization, leading them to select Option C, when in fact incidents require the dedicated Microsoft Defender XDR data connector for automated, low-effort synchronization.

How to eliminate wrong answers

Option A is wrong because creating a custom Logic App to fetch incidents via the Microsoft Defender XDR API introduces unnecessary complexity, maintenance overhead, and administrative effort, contradicting the requirement for the least administrative effort. Option B is wrong because using the Microsoft Sentinel API to pull incidents from Microsoft Defender XDR would require custom scripting and polling logic, which is not a built-in or automated solution and adds administrative burden. Option C is wrong because enabling raw data ingestion from Microsoft Defender for Endpoint only ingests raw telemetry (e.g., advanced hunting tables) into a Log Analytics workspace, not incidents; incidents require the dedicated Microsoft Defender XDR data connector for proper synchronization.

1101
Multi-Selecthard

Which TWO actions are valid for automation rules in Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Change the severity of an incident.
B.Delete an incident.
C.Run a playbook.
D.Add tags to an incident.
E.Modify an existing analytics rule.
AnswersA, C

Automation rules can directly change an incident's severity by specifying a new severity value (e.g., Low, Medium, High, or Critical) as part of the rule's action set. This is a built-in action that does not require a playbook and is commonly used to reclassify incidents based on custom logic, such as elevating severe events for priority response.

Why this answer

Automation rules in Microsoft Sentinel allow you to automate incident management tasks without requiring a playbook. Changing the severity of an incident is a supported action, enabling you to adjust the priority based on custom criteria such as incident properties or enrichment data.

Exam trap

The trap here is that candidates often confuse automation rule actions with playbook actions, assuming that any action available in a playbook (like adding tags or deleting incidents) is also available in automation rules, but automation rules have a fixed, limited set of direct actions.

1102
MCQmedium

Your organization uses Microsoft Defender XDR. You want to ensure that all incidents with severity 'High' are automatically assigned to the 'Tier1' group and have a playbook executed. What should you use?

A.Microsoft Defender XDR incident assignment manually by analysts
B.Custom analytics rules in Microsoft Sentinel
C.Automation rules in Microsoft Sentinel
D.Playbooks in Microsoft Sentinel
AnswerC

Automation rules in Microsoft Sentinel are the correct mechanism because they are designed to trigger automatically when an incident is created. They can perform actions such as assigning the incident to a specific owner or group, modifying severity, adding tags, or invoking a playbook, all without manual intervention. These rules provide consistent, policy-based incident assignment directly within the Sentinel incident lifecycle.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to a specific group (e.g., 'Tier1') and trigger a playbook based on incident properties such as severity. This directly meets the requirement to assign 'High' severity incidents to the 'Tier1' group and execute a playbook without manual intervention.

Exam trap

The trap here is that candidates often confuse playbooks with automation rules, thinking playbooks alone can handle assignment and triggering, but playbooks are just the action component and require an automation rule to define the trigger and assignment logic.

How to eliminate wrong answers

Option A is wrong because manual assignment by analysts does not automate the process; it requires human action for each incident, which contradicts the requirement for automatic assignment. Option B is wrong because custom analytics rules in Microsoft Sentinel are used to generate alerts from raw data, not to manage incident assignment or trigger playbooks after an incident is created. Option D is wrong because playbooks in Microsoft Sentinel are automated response workflows that can be triggered by automation rules, but they cannot by themselves assign incidents to groups or set conditions for execution; they require an automation rule to define the trigger and assignment logic.

1103
MCQeasy

You are threat hunting for credential dumping activity. Which Windows event ID is commonly associated with the use of tools like Mimikatz?

A.4624 (Successful Logon)
B.4768 (Kerberos Authentication Ticket Request)
C.4688 (Process Creation)
D.4672 (Special Logon)
AnswerC

Event ID 4688 records process creation with command-line auditing enabled, capturing Mimikatz execution and its suspicious arguments. This contrasts with 4624 logons or 4672 privilege assignment, which show access but not the credential-dumping tool itself.

Why this answer

Windows Event ID 4688 (Process Creation) logs every new process spawned on the system, including the execution of tools like Mimikatz. When Mimikatz runs, it creates a process (e.g., mimikatz.exe), and the 4688 event captures the command line, parent process, and user context, which are critical for detecting credential dumping activity.

Exam trap

Microsoft often tests the misconception that credential dumping is tied to authentication events (like 4624 or 4768), but the key indicator is the process creation event (4688) that captures the execution of the dumping tool itself.

How to eliminate wrong answers

Option A is wrong because Event ID 4624 (Successful Logon) records authentication events, not the execution of a process like Mimikatz; credential dumping occurs after logon, not during it. Option B is wrong because Event ID 4768 (Kerberos Authentication Ticket Request) tracks TGT requests to a domain controller, which is unrelated to local credential dumping via Mimikatz. Option D is wrong because Event ID 4672 (Special Logon) logs when a user is granted special privileges (e.g., SeTcbPrivilege), but it does not directly indicate process creation or execution of a credential dumping tool.

1104
MCQeasy

A threat hunter wants to use Microsoft Defender for Cloud Apps to hunt for suspicious OAuth app permissions. Which activity type should the analyst investigate?

A.Failed logon attempts
B.File download from SharePoint
C.Mailbox forwarding rule created
D.OAuth app granting permissions
AnswerD

OAuth app granting permissions directly records consent events, capturing the scopes granted to each application. This satisfies the hunter's requirement to identify suspicious OAuth permissions, as the activity log exposes the specific delegated or application permissions assigned, enabling detection of illicit access or over-privileged third-party apps.

Why this answer

Suspicious OAuth app permissions are directly indicated by the activity type 'OAuth app granting permissions'. Option A (Failed logon attempts) is incorrect because it relates to authentication failures, not OAuth permissions. Option B (File download from SharePoint) is incorrect because it concerns data access, not permission grants.

Option C (Mailbox forwarding rule created) is incorrect because it involves email rules, not OAuth authorizations.

1105
MCQmedium

During a threat hunt in Microsoft Sentinel, you find a series of suspicious sign-ins to Microsoft Entra ID from an IP address known to be associated with a threat actor. Which entity should you pivot on to investigate further?

A.IP address
B.User account
C.Application
D.Device
AnswerA

The IP address is the shared entity linking every suspicious sign-in, letting you pivot to enumerate all related authentication events, affected accounts and associated alerts. Pivoting on the IP exposes the full scope of the threat actor's activity.

Why this answer

The IP address is the key entity that links all suspicious sign-ins and is the initial pivot point for investigation. Option A is correct because the IP address is the common element across the sign-ins. Options B, C, and D are incorrect: the user account, application, and device may be related but are not the primary pivot from the IP address.

1106
MCQhard

Your SOC uses Microsoft Sentinel. An analytics rule produces an incident, and your runbook requires that when a specific high-severity incident is created, a playbook must automatically post a summary to a Microsoft Teams channel and create a tracking task. You need the playbook to run without a human clicking anything. What should you configure?

A.A scheduled analytics rule that calls the playbook from within its query logic.
B.An automation rule with the trigger When incident is created and an action that runs the playbook.
C.A workbook that refreshes on a schedule and triggers the playbook through a data connector.
D.A playbook with an HTTP trigger that an analyst runs manually from the incident page.
AnswerB

Automation rules in Microsoft Sentinel evaluate incident conditions and can invoke playbooks automatically when their trigger conditions match, such as on incident creation with a specific severity or title. This satisfies the runbook requirement that no analyst clicks anything. The playbook then performs the Teams posting and task creation through its connectors, so the response is fully automated and repeatable for every matching incident.

Why this answer

Automation rules are the Microsoft Sentinel component that watches for incident creation or update events and can launch playbooks automatically when conditions match. Pairing an incident-created trigger with a playbook action delivers the unattended Teams notification and task creation the runbook demands. Analytics rules, workbooks, and manual triggers either detect, display, or require human initiation, so none provides the event-driven response.

Exam trap

The trap here is assuming an analytics rule can call a playbook directly, when playbook execution is wired through automation rules.

1107
Multi-Selectmedium

Which THREE components are part of Microsoft Sentinel's SOAR capabilities? (Choose three.)

Select 3 answers
A.Workbooks
B.Incident management
C.Watchlists
D.Automation rules
E.Playbooks
AnswersB, D, E

Incident management is a core SOAR component in Microsoft Sentinel because incidents serve as the central case-management entity for investigation and response. Sentinel's SOAR capabilities are centered on the full incident lifecycle—creation, assignment, triage, investigation, and resolution—enabling consistent handling. Incident management integrates with automation rules and playbooks to drive orchestrated response, making it essential to the SOAR framework.

Why this answer

Incident management is a core SOAR component in Microsoft Sentinel because it provides the structured workflow for security analysts to triage, investigate, and respond to security incidents. It integrates with automation rules and playbooks to orchestrate response actions, enabling consistent and efficient handling of threats.

Exam trap

The trap here is that candidates confuse data enrichment or visualization tools (Workbooks, Watchlists) with SOAR components, when only incident management, automation rules, and playbooks directly enable automated response and orchestration workflows.

1108
MCQhard

You are investigating a potential compromise of a service account in Microsoft Sentinel. You need to identify all actions performed by this account across Azure and Microsoft 365. Which Sentinel feature should you use?

A.Entity behavior analytics
B.Logs query with KQL
C.Automation rules
D.Workbooks
AnswerB

Using KQL to query logs in Microsoft Sentinel allows you to search across connected data sources, such as AzureActivity and OfficeActivity, for actions performed by the service account. This provides a detailed and customizable view of all activities, enabling thorough investigation.

Why this answer

Logs query with KQL in Microsoft Sentinel enables analysts to search across multiple data sources for activities related to a specific account. This is essential for identifying all actions performed by a compromised service account. Other features like UEBA, Workbooks, and Automation rules serve different purposes and do not provide the detailed, cross-service activity list needed.

Exam trap

The trap here is confusing UEBA's anomaly detection with a comprehensive activity audit, which is best achieved through direct log queries.

1109
MCQhard

Your security team uses Microsoft Sentinel UEBA to detect anomalous user behavior. You need to configure UEBA to baseline user activities and generate alerts for deviations. What must you do first?

A.Create an Azure Machine Learning workspace for anomaly detection.
B.Enable UEBA in the Sentinel Settings blade and select relevant data sources.
C.Assign Microsoft 365 E5 licenses to all users.
D.Deploy a custom data connector for HR systems.
AnswerB

In Microsoft Sentinel, UEBA is disabled by default; you must open Settings > UEBA, toggle it on, and select the relevant data sources such as Azure AD sign-in logs, Azure AD audit logs, and Microsoft Defender for Identity data. Once enabled, Sentinel creates entity profiles, establishes behavioral baselines over time, and uses built-in ML to detect anomalies including impossible travel and sign-in from unusual locations. This is the definitive prerequisite step; without it, no entity behavior analytics or anomaly scoring runs in Sentinel.

Why this answer

Microsoft Sentinel UEBA requires explicit enablement in the Sentinel Settings blade under the 'Entity behavior analytics' section. Once enabled, you must select the relevant data sources (e.g., Azure Active Directory sign-in logs, Office 365 audit logs, Windows Security Events) so that Sentinel can baseline normal user behavior patterns and generate alerts for anomalous deviations. Without this initial configuration, UEBA cannot process any data or produce behavioral analytics.

Exam trap

The trap here is that candidates often assume UEBA is automatically enabled or that it requires external ML services (like Azure Machine Learning) or premium licenses (like M365 E5), when in fact the first step is simply toggling the feature on and selecting data sources within Sentinel's own settings.

How to eliminate wrong answers

Option A is wrong because Azure Machine Learning workspace is not required for Sentinel UEBA; UEBA uses built-in machine learning models within Sentinel itself, not an external ML workspace. Option C is wrong because Microsoft 365 E5 licenses are not a prerequisite for UEBA; Sentinel UEBA works with any license that provides the necessary data sources (e.g., Azure AD P1/P2, Office 365 E3/E5) and does not mandate E5 for all users. Option D is wrong because deploying a custom data connector for HR systems is an optional enhancement for enriching entity data (e.g., employee role, manager), but it is not the first step; UEBA must be enabled and data sources selected before any custom connectors can contribute to baselining.

1110
Multi-Selecteasy

Which TWO are legitimate sources of threat intelligence that can be ingested into Microsoft Sentinel?

Select 2 answers
A.STIX/TAXII threat intelligence feeds
B.Microsoft Defender Threat Intelligence
C.Exchange Online Protection
D.Microsoft Intune
E.Microsoft Purview Compliance Manager
AnswersA, B

STIX/TAXII threat intelligence feeds are legitimate because STIX (Structured Threat Information eXpression) standardizes how threat indicators and malicious behaviors are described, while TAXII (Trusted Automated eXchange of Indicator Information) provides the standardized transport protocol for sharing those feeds. Microsoft Sentinel natively supports ingestion from TAXII servers via the Threat Intelligence TAXII data connector, allowing organizations to pull in indicators of compromise and campaign context from public or commercial providers. This standards-based interoperability is exactly why these feeds are a recognized, first-class source of threat intelligence in a SIEM.

Why this answer

A is correct because STIX/TAXII is an open-source standard for sharing cyber threat intelligence (CTI). Microsoft Sentinel can ingest threat indicators from any TAXII 2.0 or 2.1 server using the built-in Threat Intelligence - TAXII data connector, allowing organizations to consume structured threat feeds (e.g., from MITRE ATT&CK or third-party providers) directly into Sentinel for correlation and alerting.

Exam trap

The trap here is that candidates confuse security management tools (like EOP, Intune, or Compliance Manager) with actual threat intelligence sources, assuming any Microsoft security product can be a threat feed, whereas only dedicated CTI platforms or feeds (STIX/TAXII, Microsoft Defender Threat Intelligence) provide structured indicator ingestion.

1111
MCQhard

You are a threat hunter at Northwind Traders. The organization uses Microsoft Defender for Identity (MDI) and Microsoft Sentinel. You suspect a golden ticket attack may have occurred in the domain. You need to create a hunting query in Microsoft Sentinel that leverages data from MDI to detect possible golden ticket usage. Which of the following queries or approaches is most appropriate?

A.Query DeviceProcessEvents for processes related to Kerberos
B.Query SecurityAlert where AlertName contains 'Golden Ticket' or 'Suspicious Kerberos'
C.Query CommonSecurityLog for unusual DNS queries related to Kerberos
D.Query IdentityLogonEvents for failed Kerberos authentication
AnswerB

Querying SecurityAlert for alert names containing 'Golden Ticket' or 'Suspicious Kerberos' is correct because Microsoft Defender for Identity, which is integrated into Microsoft 365 Defender and surfaces alerts in the SecurityAlert table, provides high-fidelity detections specifically for forged TGT activity. MDI signals such as anomalous ticket granting service requests, unusual TGT size, or encryption downgrade attacks are aggregated here, making it the direct, authoritative source for identifying golden ticket usage without needing to reconstruct indicators from raw logs.

Why this answer

Microsoft Defender for Identity (MDI) generates security alerts for suspicious Kerberos activity, including golden ticket attacks, which are surfaced in Microsoft Sentinel via the SecurityAlert table. Querying SecurityAlert for AlertName containing 'Golden Ticket' or 'Suspicious Kerberos' directly leverages MDI's built-in detections. This is the most appropriate approach because MDI already analyzes domain controller traffic and creates high-fidelity alerts.

Exam trap

The trap is assuming you need to query raw event tables like DeviceProcessEvents or IdentityLogonEvents; candidates may overlook that MDI already provides pre-built alerts in SecurityAlert, which is the intended data source for MDI detections.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents contains process creation events from Defender for Endpoint, not MDI Kerberos alerts; it would not directly detect golden ticket usage. Option C is wrong because CommonSecurityLog typically ingests syslog from non-Microsoft sources like firewalls, not MDI alerts, and DNS queries are not the primary indicator of golden ticket attacks. Option D is wrong because IdentityLogonEvents contains logon events but failed Kerberos authentication is not indicative of a golden ticket, which often succeeds; golden tickets allow attackers to forge valid tickets, so failures are not the key signal.

1112
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You have a custom analytics rule that triggers on a Defender for Endpoint alert. When the rule triggers, a playbook is executed that creates an incident in Microsoft Sentinel and sends a message to a Teams channel. The playbook fails to execute. Which permission should you verify first?

A.The Teams channel has the appropriate permissions for incoming webhooks
B.The analyst has Microsoft Sentinel Reader role
C.The user has Microsoft Entra ID Global Administrator role
D.The automation rule has the correct managed identity or connection permissions
AnswerD

Automation rules in Microsoft Sentinel invoke playbooks by using either a managed identity or an OAuth connection to authenticate against the Logic App resource. If the managed identity lacks the required RBAC role on the Logic App (for example, Logic App Operator), or if the connection used by the rule has been removed, expired, or lacks the necessary permissions, the automation rule cannot trigger the playbook. This is the most direct and common cause of playbook execution failure, making it the correct answer.

Why this answer

The playbook executes as part of an automation rule triggered by a custom analytics rule. For the playbook to run successfully, the automation rule must have the correct permissions to invoke the playbook. This is typically configured via a managed identity (recommended) or a connection resource.

Without this, the automation rule cannot trigger the playbook, regardless of other permissions.

Exam trap

The trap here is that candidates often focus on the downstream action (Teams webhook) or user roles (Reader, Global Admin) instead of the critical link between the automation rule and the playbook execution permissions.

How to eliminate wrong answers

Option A is wrong because the Teams channel webhook permissions are only relevant after the playbook has been successfully invoked; the failure occurs before the playbook even runs. Option B is wrong because the Microsoft Sentinel Reader role grants read-only access to Sentinel data but does not grant the automation rule the ability to execute playbooks. Option C is wrong because the Global Administrator role is a highly privileged Entra ID role unrelated to the automation rule's ability to invoke a playbook; it is not required for this operation.

1113
MCQhard

Your organization has deployed Microsoft Sentinel and uses the Microsoft 365 connector to ingest audit logs. You receive an alert from Microsoft Defender for Office 365 about a phishing email that was delivered to a user's inbox. You need to create an incident in Sentinel and automatically quarantine the email. What is the most efficient way to achieve this?

A.Use Microsoft Defender for Cloud Apps to investigate the alert and manually quarantine the email
B.Create a custom analytics rule that triggers when an alert is generated, and configure the rule to run a playbook that quarantines the email
C.Create an automation rule in Microsoft Sentinel that is triggered when this specific alert is generated, and associate a playbook that uses the Microsoft 365 Defender connector to quarantine the email
D.Manually create an incident in Microsoft Sentinel and then run a playbook to quarantine the email
AnswerC

The correct approach is to create an automation rule in Microsoft Sentinel that triggers when the specific alert from Microsoft 365 Defender is generated. In the automation rule, you associate a playbook that uses the Microsoft 365 Defender connector to quarantine the email. This enables an automated, immediate response without human intervention, leveraging the built-in alert as the trigger and the Logic Apps playbook to execute the quarantine action.

Why this answer

Automation rules in Microsoft Sentinel can be triggered by specific alert generation (e.g., from Microsoft Defender for Office 365) and can execute a playbook. The playbook uses the Microsoft 365 Defender connector, which includes the 'Quarantine email' action, enabling automated quarantine without manual intervention. This is the most efficient method as it combines automatic incident creation with immediate remediation.

Exam trap

The trap here is that candidates confuse 'custom analytics rules' (which generate alerts from raw data) with 'automation rules' (which react to existing alerts), leading them to choose Option B instead of C.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is not designed to handle email quarantine actions; it focuses on cloud app security and would require manual steps, which is inefficient. Option B is wrong because custom analytics rules in Sentinel are used to generate alerts from raw data, not to react to existing alerts from Defender for Office 365; they would duplicate effort and cannot directly trigger a playbook on an external alert. Option D is wrong because manually creating an incident defeats automation and efficiency; the goal is to automate the entire workflow from alert to quarantine.

1114
MCQhard

Your organization uses Microsoft Defender XDR and Microsoft Sentinel. You need to ensure that when a device is identified as compromised by Defender for Endpoint, an incident is automatically created in Sentinel with high severity. What should you configure?

A.Configure the Defender XDR connector to create incidents
B.Write an analytics rule that queries Defender for Endpoint data
C.Create a playbook to create an incident from the alert
D.Create an automation rule that triggers when an incident is created and set severity to High
AnswerD

Automation rules in Microsoft Sentinel run immediately when an incident is created (or updated) and can modify incident properties, including the severity field. By creating an automation rule that triggers on the 'Incident created' condition and sets the severity to 'High', you ensure that all incidents generated from Defender XDR alerts are classified consistently without manual intervention or duplicate incident creation. This is the correct approach because automation rules are designed for such property-level adjustments and do not interfere with the existing connector workflow.

Why this answer

Automation rules in Microsoft Sentinel can be configured to run when an incident is created, and they can set the severity of the incident to High. In this scenario, when Defender for Endpoint identifies a compromised device, the Defender XDR connector creates an incident in Sentinel. The automation rule then immediately elevates the severity to High, meeting the requirement without additional manual steps or complex logic.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, thinking that a playbook is required to modify incident properties, when in fact automation rules can directly change severity without invoking a playbook.

How to eliminate wrong answers

Option A is wrong because configuring the Defender XDR connector to create incidents is already the default behavior that generates the incident, but it does not automatically set the severity to High; severity is inherited from the source alert. Option B is wrong because writing an analytics rule that queries Defender for Endpoint data would create a separate scheduled query rule, which is redundant and less efficient than using the existing incident creation from the connector, and it does not directly set severity on the connector-generated incident. Option C is wrong because creating a playbook to create an incident from the alert adds unnecessary complexity and latency; playbooks are better suited for response actions, while automation rules are the native, lightweight method to modify incident properties like severity.

1115
Multi-Selecthard

Which THREE of the following are valid methods to archive logs in Microsoft Sentinel to reduce costs?

Select 3 answers
A.Configure continuous export to Azure Data Lake Storage Gen2
B.Set the workspace to free tier
C.Enable Basic Logs ingestion for all tables
D.Use a Logic App to export logs to Azure Storage
E.Change the table's retention period to include archival
AnswersA, D, E

Continuous export is a native feature that automatically copies ingested log data from a Log Analytics workspace to an Azure Data Lake Storage Gen2 account in near real time, storing each table as a set of Parquet files. This provides long-term retention and cost-effective archival because you can delete the data from the workspace after export or keep it only for the required interactive period. It supports filtering per table and is fully managed, so it is a valid archival method, especially for compliance or big-data analytics scenarios.

Why this answer

Microsoft Sentinel supports continuous export of logs to Azure Data Lake Storage Gen2, which allows you to retain raw log data at lower storage costs while still being able to query it using Azure Synapse or other analytics tools. This method reduces the cost of high-volume log retention in Sentinel's native workspace by moving data to a cheaper long-term storage tier.

Exam trap

The trap here is that candidates often confuse 'Basic Logs' (which reduce ingestion cost but not storage cost) with archival methods, or mistakenly think the free tier can be manually selected for cost savings, when in fact it is a temporary promotional offering.

1116
MCQhard

You are designing a Microsoft Sentinel deployment for a multinational organization that must comply with GDPR and local data residency requirements. They have offices in the US, EU, and Asia. They want to use a single Microsoft Sentinel workspace for global visibility but need to ensure that data from EU sources remains within the EU. What is the best approach to meet these requirements?

A.Deploy a single Microsoft Sentinel workspace in the US and use Azure Policy to restrict data ingestion from EU sources.
B.Deploy separate Microsoft Sentinel workspaces in the US, EU, and Asia, and use cross-workspace queries and Azure Lighthouse to manage them centrally.
C.Deploy a single workspace in the EU and enable UEBA to analyze all data.
D.Use Azure Lighthouse to project a single workspace into multiple regions, which automatically separates data storage.
AnswerB

Separate Sentinel workspaces placed in the US, EU, and Asia keep each region's log data stored within its corresponding geopolitical boundary, satisfying data-residency requirements. Cross-workspace queries use the workspace() KQL operator to query all three workspaces in one investigation, while Azure Lighthouse grants the central SOC delegated RBAC permissions across subscriptions or tenants without duplicating data. This architecture combines regional compliance with a single-pane-of-glass management experience.

Why this answer

Deploying separate Microsoft Sentinel workspaces in each required region (US, EU, Asia) ensures that data from EU sources remains within the EU, satisfying GDPR and local data residency requirements. Cross-workspace queries and Azure Lighthouse allow centralized management and global visibility across these workspaces without moving data between regions.

Exam trap

The trap here is that candidates may think Azure Lighthouse or cross-workspace queries can magically split a single workspace's storage across regions, when in fact a workspace is a regional resource and data residency requires separate workspaces per region.

How to eliminate wrong answers

Option A is wrong because Azure Policy can restrict data ingestion but cannot enforce data residency; data ingested into a single US-based workspace would still be stored in the US, violating GDPR requirements for EU data to remain in the EU. Option C is wrong because a single workspace in the EU would store all global data there, failing data residency requirements for US and Asia data that must remain in their respective regions. Option D is wrong because Azure Lighthouse does not project a single workspace into multiple regions or separate data storage; it only enables cross-tenant management, and a single workspace stores all data in one region regardless of Lighthouse use.

1117
MCQmedium

You are investigating a series of failed logon attempts across multiple on-premises servers. You want to use Microsoft Sentinel to hunt for patterns of brute-force attacks. Which data source should you ingest to capture detailed authentication events from domain controllers?

A.Syslog from domain controllers
B.Windows Security Events via Windows Event Forwarding
C.Azure Activity Log
D.Microsoft 365 Defender events
AnswerB

Windows Security Events, collected via Windows Event Forwarding (WEF), are the authoritative source for on-premises failed-logon hunting because domain controllers log Event ID 4625 for every failed NTLM/Kerberos logon attempt. WEF uses HTTP/HTTPS (WinRM) and a collector-initiated subscription, preserving the full payload: source IP address, workstation name, logon type, and authentication package. This enables centralized correlation across all DCs in the domain and direct ingestion into a SIEM such as Sentinel.

Why this answer

Windows Security Events from domain controllers, collected via Windows Event Forwarding (WEF) or directly, include Event ID 4625 (failed logon) and other authentication events necessary for brute-force hunting. Option A is incorrect because Syslog from domain controllers does not capture Windows Security Events; Syslog is typically used for network devices or Linux systems. Option C is incorrect because Azure Activity Log records Azure resource management operations, not on-premises authentication events.

Option D is incorrect because Microsoft 365 Defender events cover cloud and endpoint alerts but not detailed authentication logs from on-premises domain controllers.

1118
MCQeasy

A SOC analyst wants to create a scheduled analytics rule in Microsoft Sentinel that detects when a user is added to a privileged Microsoft Entra ID role (e.g., Global Administrator). Which data table is essential for the query?

A.AuditLogs
B.SigninLogs
C.SecurityEvent
D.CommonSecurityLog
AnswerA

Role assignments in Microsoft Entra ID, including additions to privileged roles such as Global Administrator, are recorded in the AuditLogs table. Querying AuditLogs with the Add member to role operation captures the directory change, which SigninLogs and SecurityEvent do not record.

Why this answer

The AuditLogs table in Microsoft Sentinel captures all directory-level audit activities, including modifications to Microsoft Entra ID (formerly Azure AD) role assignments. When a user is added to a privileged role like Global Administrator, the event is logged as an 'Add member to role' activity in the AuditLogs table. This makes AuditLogs the essential data source for detecting such privileged role changes.

Exam trap

Microsoft often tests the distinction between sign-in logs (SigninLogs) and audit logs (AuditLogs), trapping candidates who confuse authentication events with directory configuration changes.

How to eliminate wrong answers

Option B (SigninLogs) is wrong because it records user authentication events (sign-ins), not directory configuration changes like role assignments. Option C (SecurityEvent) is wrong because it contains Windows security events from on-premises or Azure VMs, not Microsoft Entra ID role activities. Option D (CommonSecurityLog) is wrong because it aggregates syslog-style logs from third-party security appliances (e.g., firewalls, IDS/IPS), not Microsoft Entra ID audit data.

1119
MCQmedium

Your organization uses Microsoft Sentinel with the UEBA (User and Entity Behavior Analytics) feature enabled. A security analyst notices that a user account has been flagged with an anomaly indicating a possible compromised credential. Which entity type in Microsoft Sentinel's UEBA is most relevant for this alert?

A.Device
B.Application
C.IP address
D.User account
AnswerD

In Microsoft Sentinel UEBA, the user account is the primary entity type for detecting credential compromise because authentication and authorization are fundamentally tied to accounts. Attacks such as password spray, brute force, impossible travel, and anomalous sign-in all manifest as unusual activity on a user account, and UEBA builds a behavioral baseline per user to score these deviations. The investigation timeline aggregates sign-in events, machine activity, and assigned alerts around the account, enabling analysts to trace the full scope of a compromise. Therefore, User account is the correct answer.

Why this answer

The UEBA anomaly alert for a possible compromised credential is specifically tied to the User account entity because UEBA profiles user behavior over time and detects deviations from established baselines, such as unusual logon times, locations, or impossible travel. The alert directly reflects a risk to the user's identity, making the User account the most relevant entity type for this scenario.

Exam trap

The SC-200 exam often tests the distinction between entity types in UEBA, and the trap here is that candidates may confuse the IP address entity (which is associated with network-level anomalies) with the user account entity, failing to recognize that credential compromise is fundamentally a user identity anomaly.

How to eliminate wrong answers

Option A is wrong because Device entity in UEBA tracks anomalies related to device behavior (e.g., unusual OS version, rare software installation), not credential compromise. Option B is wrong because Application entity monitors anomalies in application usage patterns (e.g., unusual API calls or access frequency), not user credential risks. Option C is wrong because IP address entity in UEBA is used for network-level anomalies (e.g., unusual geolocation or proxy usage), but the alert specifically flags a compromised credential, which is a user identity issue, not a network endpoint.

1120
MCQeasy

An incident in Microsoft Defender XDR shows a device with high severity alert: 'Suspicious PowerShell command line.' The device is currently isolated from the network. What is the best next step to investigate the alert?

A.Review the device timeline for related alerts.
B.Run a live response session on the device.
C.Restore network connectivity to allow the device to communicate with the cloud for analysis.
D.Initiate a full antivirus scan on the device.
AnswerB

Running a live response session on the device establishes an interactive, remote shell through the Microsoft Defender for Endpoint management plane. It enables the incident responder to execute PowerShell scripts, collect forensic artifacts such as memory, registry, and files, and apply remediation actions directly on the endpoint. Crucially, this can be done even while the device remains isolated, because the live response channel uses an outbound HTTPS connection to the cloud service.

Why this answer

Running a live response session on the isolated device lets the analyst execute commands, collect forensic artifacts (process list, network connections, file hashes), and investigate the suspicious PowerShell activity without restoring network connectivity. This is the recommended next step in Microsoft Defender XDR when a device is already isolated, because live response provides direct, interactive access for evidence gathering. It preserves containment while enabling deeper investigation.

Exam trap

SC-200 often tests whether candidates understand that isolation is a containment step and that live response — not restoring connectivity or running a generic AV scan — is the correct investigative action on an isolated device.

How to eliminate wrong answers

Option A is wrong because reviewing the device timeline is useful but passive; it does not provide the interactive forensic depth needed to investigate a high-severity PowerShell alert on an isolated device. Option C is wrong because restoring network connectivity would remove containment and allow potential attacker command-and-control or lateral movement — a dangerous step during active investigation. Option D is wrong because a full antivirus scan is a broad, slow action that may not surface fileless PowerShell activity and does not provide the targeted forensic insight that live response does.

1121
Drag & Dropmedium

Arrange the steps to deploy Microsoft Defender for Cloud Apps (formerly MCAS) and connect it to a cloud app.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Deploying Cloud App Security involves adding an app connector and authenticating to enable monitoring and control.

1122
MCQmedium

A security analyst wants to create a custom detection rule in Microsoft 365 Defender that alerts when a user receives more than 5 emails with the same attachment name within 1 hour, indicating a possible malware campaign. Which advanced hunting tables should be joined to achieve this detection?

A.Join EmailEvents and EmailAttachmentInfo on NetworkMessageId
B.Join EmailEvents and EmailUrlInfo on NetworkMessageId
C.Use only EmailAttachmentInfo table with a filter on file name
D.Join EmailEvents and DeviceFileEvents on SHA1 hash
AnswerA

Joining EmailEvents to EmailAttachmentInfo on NetworkMessageId is correct because NetworkMessageId uniquely identifies a single email message in both tables, and this preserves the relationship between the recipient (in EmailEvents) and each attached file (in EmailAttachmentInfo). This join lets you count emails by RecipientEmailAddress and FileName within a specified time bucket, which is exactly what a detection rule for attachment-based threats requires. Because EmailAttachmentInfo contains one row per attachment, you can aggregate with summarize count() and optionally bin the Timestamp to detect spikes in attachments per user.

Why this answer

To detect when a user receives more than 5 emails with the same attachment name within 1 hour, you need to correlate email metadata with attachment details. The EmailEvents table contains email-level information (e.g., recipient, timestamp), while the EmailAttachmentInfo table stores attachment-level data (e.g., file name). Joining these on NetworkMessageId allows you to count occurrences of the same attachment name per recipient within a time window, enabling the custom detection rule.

Exam trap

The trap here is that candidates may think they need to join with endpoint file events (DeviceFileEvents) to detect malware, but the question specifically requires detecting the email receipt pattern, not post-delivery execution.

How to eliminate wrong answers

Option B is wrong because EmailUrlInfo contains URL data from emails, not attachment names, so it cannot be used to count attachments by file name. Option C is wrong because using only EmailAttachmentInfo lacks recipient and timestamp fields from EmailEvents, making it impossible to filter by user and time window. Option D is wrong because DeviceFileEvents tracks files on endpoints, not email attachments, and joining on SHA1 hash would require hash values, not file names, and would not capture email-specific metadata like recipient.

1123
Multi-Selecthard

Which TWO actions should you take when responding to a confirmed ransomware incident in Microsoft Defender for Endpoint?

Select 2 answers
A.Run a full antivirus scan on the affected devices.
B.Allow the ransomware executable in the firewall.
C.Collect an investigation package from the affected devices.
D.Isolate the affected devices from the network.
E.Initiate a live response session to delete files.
AnswersA, D

Running a full antivirus scan on affected devices is a primary eradication step because it identifies known ransomware signatures, quarantines the malicious binary, and cleans any dropped files or artifacts. In the context of Microsoft Defender for Endpoint, the scan leverages cloud-delivered protection and tamper protection to remove the threat from all local drives. This action is most effective after isolating the device, because the scan itself does not prevent lateral movement while it is running.

Why this answer

Running a full antivirus scan on affected devices helps identify and remove any remaining ransomware artifacts or secondary payloads that may not have been detected during the initial response. In Microsoft Defender for Endpoint, a full scan leverages the cloud-delivered protection and behavior monitoring to thoroughly examine all files and processes, reducing the risk of reinfection.

Exam trap

The trap here is that candidates often prioritize forensic collection (Option C) or file deletion (Option E) over immediate containment, not realizing that isolation and scanning are the mandated first steps in the Microsoft Defender for Endpoint ransomware response playbook.

1124
MCQeasy

A security team uses Microsoft Sentinel to hunt for signs of credential theft. They want to detect when a user account has been used to log in from an unusual location and then immediately performs a password reset for another user. Which hunting approach is most effective for this scenario?

A.Use a Microsoft Sentinel playbook to automatically flag any password reset
B.Write a KQL query that joins SigninLogs with AuditLogs on user principal name and times within a short window
C.Search the SigninLogs table for logins from unusual locations
D.Create a watchlist of known unusual locations and use it in a query against AuditLogs
AnswerB

Joining SigninLogs and AuditLogs on user principal name, constrained to a short time window, correlates an anomalous sign-in with a subsequent password reset. This temporal correlation across both tables surfaces the credential-theft sequence, which neither log alone reveals.

Why this answer

The most effective hunting approach is a KQL query that correlates SigninLogs (login events, including location) with AuditLogs (password reset operations) by joining on UserPrincipalName and filtering for events within a short time window. This detects the specific behavioral pattern: an unusual-location login immediately followed by a password reset for another user, which is a classic credential theft and privilege abuse indicator.

Exam trap

SC-200 often tests whether candidates understand that effective hunting requires correlating multiple log sources — the trap is selecting a single-table query or an automation that lacks the temporal and cross-table correlation needed to detect multi-step attack patterns.

How to eliminate wrong answers

Option A is wrong because a playbook that flags any password reset generates excessive false positives — password resets are routine, and the playbook lacks the correlation logic to identify the suspicious sequence. Option C is wrong because searching SigninLogs alone for unusual locations misses the second half of the attack pattern (the password reset) and cannot establish the temporal correlation. Option D is wrong because a watchlist of unusual locations used against AuditLogs alone ignores the sign-in context entirely — AuditLogs don't contain login location data, so the watchlist can't be applied meaningfully.

1125
MCQhard

During a threat hunt, you discover a previously unknown malware variant that communicates over HTTPS to a command-and-control (C2) server. You want to create a custom detection in Microsoft Sentinel that triggers when any device in the organization resolves the C2 domain via DNS. Which data connector should you ensure is enabled?

A.DNS (Preview) via AMA
B.Azure Activity
C.Office 365 (Preview)
D.Windows Security Events via AMA
AnswerA

The DNS (Preview) via AMA connector ingests DNS query events from devices, which is the only telemetry that records domain resolution. Enabling it satisfies the requirement to trigger when any device resolves the C2 domain, since network connectors alone would not capture resolution.

Why this answer

The DNS (Preview) via AMA connector ingests DNS query logs from onboarded devices into Microsoft Sentinel, which is exactly the telemetry needed to detect when any device resolves the malicious C2 domain. Since the detection requirement is specifically about DNS resolution of the C2 domain, this connector provides the authoritative query events (including queried domain names and client IPs) that a custom analytics rule can match against. Without DNS logs flowing into the workspace, no KQL rule can trigger on domain resolution regardless of how well it is written.

Exam trap

SC-200 often tests whether candidates confuse endpoint security event telemetry with network-layer telemetry — the trap is picking 'Windows Security Events via AMA' because it sounds like it captures everything on the device, when in fact DNS query logs require the dedicated DNS connector.

How to eliminate wrong answers

Option B is wrong because Azure Activity only captures control-plane operations on Azure resources (e.g., role assignments, resource creation) and contains no DNS query telemetry. Option C is wrong because Office 365 (Preview) ingests audit and activity logs from Exchange, SharePoint, Teams, and similar workloads — it does not record endpoint DNS resolutions. Option D is wrong because Windows Security Events via AMA collects event log data such as logons, process creation, and object access, but not DNS client query events (those come from the DNS Client operational log, which is ingested by the DNS connector, not the Security Events connector).

Page 14

Page 15 of 18

Page 16