Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 1126–1200

1303 questions total · 18pages · All types, answers revealed

Page 15

Page 16 of 18

Page 17
1126
Multi-Selectmedium

Your organization uses Microsoft Sentinel. You need to ensure that incident response times are monitored and reported. Which TWO capabilities should you use?

Select 2 answers
A.Playbooks
B.UEBA
C.Automation rules
D.Watchlists
E.Workbooks
AnswersC, E

Automation rules in Sentinel are the correct choice because they let you define conditions and run actions when an incident is created or updated, including updating fields and setting tags. By configuring a rule that stamps the incident's 'Created' time and another that records when the incident transitions to 'In Progress' or is assigned, you can capture the exact response start time. This information is stored in the incident's properties and can later be queried to compute time-to-respond, directly enabling monitoring of response times.

Why this answer

Automation rules (C) are correct because they allow you to define conditions and actions that automatically trigger when an incident is created or updated, enabling consistent assignment, severity changes, and tagging. Workbooks (E) are correct because they provide customizable visualizations and reports that can track key metrics like incident response times, mean time to acknowledge (MTTA), and mean time to remediate (MTTR) using KQL queries against Sentinel's security data.

Exam trap

The trap here is that candidates often confuse playbooks (automated response actions) with automation rules (incident orchestration) and overlook workbooks in favor of UEBA or watchlists, which are unrelated to monitoring response times.

1127
MCQmedium

A SOC analyst has created a custom scheduled analytics rule in Microsoft Sentinel that runs every hour and generates an incident when a certain pattern is detected. The analyst notices that the same set of events is causing a new incident every hour, leading to duplicates. What should the analyst configure to prevent duplicate incident generation from the same events?

A.Set the alert suppression setting in the analytics rule
B.Use an automation rule to close duplicates
C.Modify the query to use the 'summarize' operator
D.Change the query to use the 'take' operator
AnswerA

Alert suppression is a native analytic rule setting in Microsoft Sentinel that prevents duplicate alerts by silencing the rule for a defined period after the first alert fires. When the same events or query results are processed in subsequent scheduled runs within that period, no new alert or incident is created. This is the most efficient method because it eliminates duplication at the source, reducing noise without consuming automation resources or requiring custom KQL logic.

Why this answer

The alert suppression setting in a Microsoft Sentinel scheduled analytics rule allows you to configure a time window during which duplicate alerts from the same events are suppressed. When enabled, Sentinel will not generate a new incident from the same set of events until the suppression window expires, preventing the hourly duplication the analyst observed.

Exam trap

The trap here is that candidates often confuse alert suppression (preventing duplicate alerts) with incident closing mechanisms (automation rules), leading them to choose Option B instead of the correct suppression setting.

How to eliminate wrong answers

Option B is wrong because automation rules can close incidents after they are created, but they do not prevent the generation of duplicate incidents from the same events; duplicates would still be created and then closed, which is inefficient and does not address the root cause. Option C is wrong because using the 'summarize' operator in the query would aggregate events but would not prevent the same events from being evaluated again in the next hourly run; it could also alter the detection logic and miss patterns. Option D is wrong because the 'take' operator limits the number of rows returned by the query, which would arbitrarily drop events and could cause missed detections, not prevent duplicates from the same events.

1128
MCQhard

During a threat hunt, you discover a suspicious PowerShell command that decoded a base64 string and executed a script. Which Microsoft Defender for Endpoint advanced hunting table should you query to find the decoded command line?

A.IdentityLogonEvents
B.DeviceProcessEvents
C.DeviceNetworkEvents
D.DeviceEvents
AnswerB

DeviceProcessEvents is the correct table because it captures process creation events on endpoints, and its ProcessCommandLine column stores the exact command line used to launch each process. This includes the PowerShell executable path, individual arguments, flags like -EncodedCommand or -ExecutionPolicy Bypass, and any obfuscated script text. The table also provides process ID, parent process, and initiating process command line, which are crucial for gaining full context on the suspicious PowerShell invocation during a threat hunt.

Why this answer

DeviceProcessEvents in Microsoft Defender for Endpoint advanced hunting contains process creation events, including the full command line used to launch processes. Since the suspicious PowerShell command executed a script, the decoded command line would be captured in this table under the ProcessCommandLine column.

Exam trap

SC-200 often tests the distinction between process-level telemetry (DeviceProcessEvents) and network or identity telemetry, causing candidates to choose DeviceEvents or DeviceNetworkEvents when the question asks for command-line details.

How to eliminate wrong answers

Option A is wrong because IdentityLogonEvents records authentication events (logon attempts, failures) and does not contain process command lines. Option C is wrong because DeviceNetworkEvents captures network connections and related metadata, not process execution details. Option D is wrong because DeviceEvents is a general table for various event types (e.g., file creation, registry changes) but does not specifically store process command lines — that is the domain of DeviceProcessEvents.

1129
MCQmedium

Your organization uses Microsoft Sentinel. A security analyst receives an alert indicating that a user account was used to sign in from an unfamiliar location. You need to investigate the incident using Microsoft Defender XDR. Which action should you take first?

A.Create an automated playbook to reset the user's password.
B.Review the alert in the Microsoft Defender XDR portal and classify it as a true or false positive.
C.Turn off the user account in Microsoft Entra ID.
D.Reset the user's password immediately to prevent further access.
AnswerB

The Microsoft Defender XDR portal is the central console for investigating alerts and incidents across the Microsoft 365 Defender suite. The first step in any incident response is to verify the alert's validity by examining the evidence, related entities, and the incident timeline. Classifying the alert as a true or false positive determines whether subsequent containment, eradication, or closure actions are necessary, making this the correct initial action.

Why this answer

The first step in incident response is to validate the alert by reviewing it in the Microsoft Defender XDR portal. This allows the analyst to assess the alert's context, such as sign-in logs, user risk, and related entities, before taking any corrective action. Classifying the alert as a true or false positive ensures that subsequent steps (like password reset or account disablement) are based on accurate threat assessment, preventing unnecessary disruption.

Exam trap

The trap here is that candidates often jump to immediate containment actions like password reset or account disablement, forgetting that the first step in any incident response process is to verify and classify the alert to avoid unnecessary operational impact.

How to eliminate wrong answers

Option A is wrong because creating an automated playbook to reset the password is a remediation step that should only occur after the alert is validated and classified; automating without investigation could lock out legitimate users. Option C is wrong because turning off the user account in Microsoft Entra ID is a drastic containment action that should follow confirmation of a true positive, not be the first step. Option D is wrong because resetting the password immediately bypasses the investigation phase, potentially disrupting the user if the alert is a false positive or a benign anomaly.

1130
MCQeasy

Your company is deploying Microsoft Defender for Endpoint. You need to ensure that all devices report their security baseline compliance to Microsoft Intune. Which configuration should you use?

A.Configure a device configuration profile in Microsoft Intune
B.Deploy Windows Update for Business reports
C.Assign a Security Baseline policy in Microsoft Intune to the device groups
D.Enable Microsoft Defender for Cloud Apps session controls
AnswerC

Assigning a Security Baseline policy in Microsoft Intune to the device groups is the correct mechanism because security baselines are pre-defined collections of recommended security settings (e.g., from Microsoft's security baseline for Windows) that Intune applies and then evaluates against each device. The Intune console provides a 'Security Baselines' node that shows per-device compliance status, listing every setting that deviates from the baseline version you assigned. This gives you the exact report of compliance against a security baseline, including the ability to compare against different baseline versions.

Why this answer

Security Baseline policies in Microsoft Intune define a set of pre-configured security settings recommended by Microsoft to harden devices. When assigned to device groups, these policies automatically evaluate and report compliance status for each device, ensuring all devices meet the required security baseline. This directly fulfills the requirement to report security baseline compliance to Intune.

Exam trap

The trap here is that candidates often confuse a generic device configuration profile (Option A) with a Security Baseline policy, not realizing that only the latter provides built-in compliance evaluation and reporting for security baselines.

How to eliminate wrong answers

Option A is wrong because a device configuration profile in Intune is used to configure device settings (e.g., Wi-Fi, certificates) but does not inherently report compliance against a security baseline; it lacks the built-in compliance evaluation and reporting capabilities of a Security Baseline policy. Option B is wrong because Windows Update for Business reports focus on update compliance and deployment status, not security baseline compliance. Option D is wrong because Microsoft Defender for Cloud Apps session controls are designed to monitor and control cloud app access in real-time, not to manage or report device-level security baseline compliance.

1131
MCQmedium

Your organization uses Microsoft Sentinel and has enabled UEBA (User and Entity Behavior Analytics). You notice that the UEBA timeline is not populating for some users. You have verified that the data sources are connected and the UEBA feature is enabled. What could be the issue?

A.There is insufficient data to build baselines for those users; UEBA needs at least 14 days of data.
B.Users must opt in to UEBA tracking.
C.UEBA only works with Azure Active Directory (now Microsoft Entra ID) audit logs.
D.The data sources are not sending logs for those users.
AnswerA

Microsoft Sentinel UEBA uses proprietary machine learning to build behavioral baselines for entities such as users, and it requires at least 14 days of historical telemetry before it can produce analytical timelines. If a user is newly on-boarded or has only sporadic log activity, the available data does not meet that minimum threshold, so no anomaly or timeline appears. This is a documented prerequisite, not a configuration error or a connectivity problem.

Why this answer

UEBA requires a minimum of 14 days of historical data to establish behavioral baselines for each user. Without sufficient data, the timeline cannot detect anomalies or populate entries. Even if data sources are connected and UEBA is enabled, the feature will not generate timeline events until baselines are built.

Exam trap

The trap here is that candidates assume UEBA will work immediately after enabling it, overlooking the mandatory 14-day baseline requirement, and instead blame data source connectivity or user permissions.

How to eliminate wrong answers

Option B is wrong because UEBA does not require user opt-in; it operates automatically on all users once enabled and data is flowing. Option C is wrong because UEBA works with multiple data sources, including Windows Security Events, Azure AD (now Microsoft Entra ID) audit logs, and Office 365 activity logs, not just Azure AD audit logs. Option D is wrong because the question states data sources are connected and verified, so the issue is not missing logs but insufficient data duration for baseline calculation.

1132
MCQeasy

During an incident response, you need to collect forensic evidence from a compromised Windows device using Microsoft Defender for Endpoint live response. Which command should you use to gather running processes?

A.dir
B.reg query
C.netstat
D.processes
AnswerD

The 'processes' command enumerates running processes on the target device, returning process names, IDs, and related details. This satisfies the forensic requirement to capture volatile evidence of active processes before the compromised Windows host is remediated or shut down.

Why this answer

The `processes` command in Microsoft Defender for Endpoint live response enumerates all currently running processes on the target device, returning details such as PID, name, and user context. It is one of the built-in live response commands specifically designed for forensic triage and incident investigation without needing to install third-party tooling. This makes it the correct choice for gathering running process evidence during an active incident.

Exam trap

SC-200 often tests whether candidates confuse standard Windows CLI commands (dir, netstat, reg query) with Defender for Endpoint live response's purpose-built command set, so candidates must memorise the live response command inventory rather than assume familiar OS tools are available.

How to eliminate wrong answers

Option A is wrong because `dir` is a file-system listing command that shows directory contents, not running processes. Option B is wrong because `reg query` reads registry keys/values and does not enumerate processes. Option C is wrong because `netstat` displays active network connections and listening ports, not the full process list (though it may show owning PIDs, it is not the process enumeration command).

1133
MCQhard

A security analyst is writing a Kusto Query Language (KQL) advanced hunting query in Microsoft 365 Defender to detect lateral movement using Remote Desktop Protocol (RDP). Which table should the analyst join with the DeviceNetworkEvents table to identify processes initiating outgoing RDP connections?

A.DeviceProcessEvents
B.DeviceLogonEvents
C.DeviceFileEvents
D.DeviceRegistryEvents
AnswerA

DeviceProcessEvents is the correct table because it records every process creation event, including the process ID, parent process, command line, and execution timestamp. In a KQL hunt for RDP-initiated connections, you can join DeviceProcessEvents with DeviceNetworkEvents on ProcessId and filter for RemotePort 3389 to pinpoint the exact process that launched the RDP session. Without these process-creation details, you cannot establish the process-to-network correlation required to answer the question.

Why this answer

The DeviceNetworkEvents table logs network connections, including outgoing RDP traffic (port 3389). To identify which process initiated a specific outgoing RDP connection, you must join with the DeviceProcessEvents table on DeviceId and Timestamp (or ProcessId), because DeviceProcessEvents contains the process creation details (e.g., mstsc.exe) that launched the network connection. This join reveals the parent process responsible for the lateral movement attempt.

Exam trap

The trap here is that candidates often confuse DeviceLogonEvents (which logs RDP logon events) with the process initiation side, but the question asks for the table that identifies the process initiating the outgoing connection, not the authentication event on the target machine.

How to eliminate wrong answers

Option B is wrong because DeviceLogonEvents tracks authentication events (logon sessions), not process-to-network mappings; it cannot identify which process initiated the RDP connection. Option C is wrong because DeviceFileEvents logs file creation, modification, and deletion events, which are unrelated to network connection initiation. Option D is wrong because DeviceRegistryEvents records registry key changes, which have no direct role in identifying the process that started an outgoing RDP session.

1134
Multi-Selecthard

A Microsoft Sentinel incident contains alerts from multiple analytics rules. The analyst suspects the same compromised account performed impossible travel followed by suspicious mailbox access. Which two actions best help correlate identity and mailbox activity?

Select 2 answers
A.Query SigninLogs for the account around the alert timestamps
B.Delete the incident to force it to regenerate
C.Disable all analytics rules that contributed alerts
D.Query OfficeActivity or relevant Microsoft 365 Defender email/cloud activity tables for mailbox operations
AnswersA, D

Querying SigninLogs provides critical identity context: each authentication event records timestamp, source IP, user agent, risk level, and applied conditional access policies. By filtering this table for the account around the alert timestamps, an analyst can determine whether the account actually authenticated during the alert's activity window and from which location, directly linking the alerts to a known sign-in session. This correlation is fundamental for validating whether the alerts represent genuine account compromise or a false positive triggered by a legitimate user action.

Why this answer

Querying SigninLogs for the account around the alert timestamps directly retrieves Azure AD authentication events, which are essential for identifying the source IP addresses, locations, and timestamps that define the impossible travel pattern. This data is the primary evidence for the first part of the suspected compromise.

Exam trap

The trap here is that candidates may think deleting or disabling rules will fix the correlation gap, but the correct approach is to manually query the relevant data sources (SigninLogs and OfficeActivity) to perform the correlation, as Sentinel does not automatically link identity and mailbox events across different data connectors.

1135
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. An incident is generated for a user who received a phishing email that bypassed Exchange Online Protection. The user clicked the link and entered credentials on a fake login page. The incident includes alerts from Microsoft Defender for Office 365 and Microsoft Entra ID. You need to respond to the incident. The affected user has administrative privileges. Which of the following should you do FIRST?

A.Reset the user's password and revoke sessions in Microsoft Entra ID.
B.Report the phishing email to Microsoft for analysis.
C.Create a transport rule to block similar phishing emails.
D.Delete the phishing email from the user's mailbox.
AnswerA

Because the user holds administrative privileges, credential reset alone is insufficient — active refresh tokens and sessions must be revoked in Microsoft Entra ID to evict the attacker immediately. This contains the compromised privileged identity before any further investigation, satisfying the stem's requirement to act first.

Why this answer

Resetting the user's password and revoking sessions immediately prevents attacker use of stolen credentials, especially given the user has administrative privileges. Option B is wrong because reporting the email is not the highest priority. Option C is wrong because creating a transport rule is a longer-term action.

Option D is wrong because deleting the email does not address the compromised credentials.

1136
MCQmedium

During threat hunting, you identify a suspicious PowerShell process that executed encoded commands. Which Microsoft Defender XDR hunting capability would best help you trace the parent process and command-line arguments across the enterprise?

A.Automated investigation and response
B.Threat analytics
C.Device inventory
D.Advanced hunting
AnswerD

Advanced Hunting is the Microsoft 365 Defender tool purpose-built for proactively querying across deep time series and event tables via KQL, including DeviceProcessEvents, DeviceEvents, and associated network/file events. With schema-aware queries such as process parent-child joins, an analyst can pivot from a suspicious PowerShell process to its parent chain, command-line, file hashes, and related lateral-movement indicators. This makes it the correct surface for ad-hoc threat hunting and validating a specific suspicious process observed in the environment.

Why this answer

Advanced hunting in Microsoft Defender XDR uses KQL queries to trace parent processes and command-line arguments across devices, enabling detailed investigation of suspicious PowerShell activity. Option A is incorrect because automated investigation and response focuses on containment and remediation, not deep forensic tracing. Option B is incorrect because threat analytics provides threat intelligence and vulnerability information, not raw process event data.

Option C is incorrect because device inventory shows device configurations and status, but lacks process lineage and command-line details.

1137
MCQmedium

A security analyst is investigating a potential malware outbreak detected by Microsoft 365 Defender. The analyst needs to identify all devices that have executed a specific parent process with a given ProcessId. Which column in the DeviceProcessEvents table should be used to find processes whose parent is the specified process?

A.ParentProcessId
B.InitiatingProcessId
C.ProcessId
D.LogonId
AnswerA

ParentProcessId is the process identifier of the process that created the current process; it directly represents the immediate parent in the process tree. By filtering on this field, an analyst can quickly isolate all child processes spawned by a suspected malware process, enabling lineage-based detection. This is the correct field for defining direct process ancestry, unlike ProcessId or LogonId.

Why this answer

The ParentProcessId column in the DeviceProcessEvents table stores the process ID (PID) of the parent process that initiated the current process. To find all child processes spawned by a specific parent process with a known ProcessId, you query the ParentProcessId column for that value. This directly links child processes to their parent, enabling the analyst to trace the malware's execution chain.

Exam trap

The trap here is that candidates confuse InitiatingProcessId (which often appears in alert schemas for the root process of an incident) with ParentProcessId, not realizing that in DeviceProcessEvents, the direct parent-child relationship is stored in ParentProcessId, not InitiatingProcessId.

How to eliminate wrong answers

Option B (InitiatingProcessId) is wrong because it refers to the process ID of the process that initiated the event, which is often the same as the parent process in some contexts, but in Microsoft 365 Defender's schema, InitiatingProcessId is used for the process that started the entire chain (e.g., from an alert), not for direct parent-child relationships in DeviceProcessEvents. Option C (ProcessId) is wrong because it is the unique identifier of the current process itself, not its parent; using it would only find the process with that specific PID, not its children. Option D (LogonId) is wrong because it identifies the user logon session under which the process runs, not the parent process relationship; it is used for grouping processes by session, not for parent-child lineage.

1138
MCQmedium

You are a security analyst for a company using Microsoft Defender XDR. An incident is detected involving a device that has been communicating with a known command-and-control (C2) server. The device is currently online and the user is active. What should you do first to contain the threat?

A.Isolate the device from the network using Microsoft Defender for Endpoint
B.Run a full antivirus scan on the device
C.Notify the user to disconnect the device
D.Kill the suspicious processes on the device
AnswerA

Microsoft Defender for Endpoint's device isolation severs all network connectivity except to the MDE cloud service, instantly breaking command and control channels and laterally used protocols such as SMB and RDP. Because isolation is enforced at the operating system's network stack, it does not rely on killing a process that may simply respawn or on user compliance. This action also preserves volatile memory and active connections for subsequent forensic analysis, making it the preferred first response to a compromised, actively communicating endpoint.

Why this answer

Isolating the device from the network using Microsoft Defender for Endpoint immediately cuts off all communication with the C2 server, preventing data exfiltration and further command execution. This is the fastest containment action that does not rely on user compliance or process-level responses, and it preserves the device's state for forensic analysis. In an active incident, stopping network-level communication is the priority over scanning or process termination.

Exam trap

The trap here is that candidates often choose to kill suspicious processes (Option D) thinking it directly stops the threat, but they overlook that network isolation is the only action that guarantees the C2 channel is severed immediately and completely, regardless of process behavior.

How to eliminate wrong answers

Option B is wrong because running a full antivirus scan is a detection and remediation step, not a containment action; the device is already compromised and actively communicating with a C2 server, so scanning does not stop the ongoing threat. Option C is wrong because notifying the user to disconnect the device relies on human action, introduces delay, and may not be reliable; the user could be compromised or unresponsive, and the device remains connected to the network during the notification process. Option D is wrong because killing suspicious processes is a reactive step that does not prevent the device from re-establishing C2 communication or other processes from taking over; network isolation is required to fully sever the connection.

1139
MCQhard

Refer to the exhibit. You are reviewing a Microsoft Sentinel analytics rule created via ARM template. What is the effect of the grouping configuration?

A.Groups alerts into one incident if any entity matches.
B.Creates a separate incident for each alert.
C.Suppresses alerts for 5 hours after the first alert.
D.Groups alerts into one incident if all entities match within a 5-hour lookback.
AnswerD

This is correct because the rule groups alerts into a single incident when all entities match within the 5-hour lookback. The entitiesMatchingMethod is All, and lookbackDuration is 5 hours, so only alerts that share every entity value (such as account, host, and IP) in that window will be merged. This consolidates related alerts while minimizing the chance of grouping unrelated activity, and the same incident can be reopened or updated as more matching alerts arrive.

Why this answer

The grouping configuration in the exhibit sets the grouping condition to 'Group alerts into a single incident if all entities match' with a 5-hour lookback period. This means that alerts generated within 5 hours that share identical entities (e.g., same IP, host, or account) will be merged into one incident, reducing alert noise. Option D correctly describes this behavior, as it specifies both the entity matching requirement and the time window.

Exam trap

The trap here is confusing the grouping lookback window with alert suppression or mistaking 'any entity matches' for 'all entities match,' which leads candidates to pick Option A or C instead of D.

How to eliminate wrong answers

Option A is wrong because it states 'if any entity matches,' but the configuration requires all entities to match, not any single entity. Option B is wrong because it describes creating a separate incident for each alert, which is the opposite of grouping; the configuration explicitly enables grouping. Option C is wrong because it refers to suppressing alerts for 5 hours after the first alert, which is a different feature (alert suppression) not related to grouping configuration; the 5-hour value here is the lookback window for grouping, not a suppression period.

1140
MCQmedium

A cloud security team uses Microsoft Defender for Cloud with Defender for Servers enabled. They want to integrate a third-party vulnerability assessment solution for their Azure VMs and ensure findings appear in the Defender for Cloud recommendations. What must be done?

A.Configure a data connector in Microsoft Sentinel to forward the partner's findings.
B.Enable the 'Integrated' partner solution in Defender for Cloud and install the scanner on VMs.
C.Deploy the Microsoft Defender Vulnerability Management solution instead of a third-party tool.
D.Use Azure Policy to assign a built-in initiative that mandates vulnerability scanning.
AnswerB

In Defender for Cloud, the Vulnerability assessment settings let you enable an integrated partner solution such as Qualys or Rapid7; after selecting the partner, you install the designated scanner agent on each virtual machine. The scanner transmits identified vulnerabilities to Defender for Cloud, which ingests them into the recommendation 'Vulnerabilities in your virtual machines should be remediated' and includes them in the secure score and regulatory compliance assessments. This is the only mechanism that directly integrates the existing third-party tool's findings into Defender for Cloud.

Why this answer

Defender for Cloud supports integrating third-party vulnerability assessment solutions through the 'Integrated' partner solution setting. Once enabled, you must install the partner's scanner agent on each Azure VM. The findings are then ingested into Defender for Cloud and appear in the 'Vulnerabilities in your virtual machines should be remediated' recommendation, allowing the security team to view and manage them alongside built-in assessments.

Exam trap

The trap here is that candidates often confuse the role of Microsoft Sentinel (a SIEM) with Defender for Cloud's native vulnerability assessment integration, thinking that any security data can be funneled through Sentinel to populate Defender for Cloud recommendations, which is incorrect because Sentinel does not write to Defender for Cloud's recommendation engine.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a SIEM for collecting and analyzing security logs, not a mechanism to ingest vulnerability assessment findings into Defender for Cloud recommendations; it would not populate the specific Defender for Cloud vulnerability recommendation. Option C is wrong because the question explicitly requires integrating a third-party solution, not replacing it with Microsoft Defender Vulnerability Management. Option D is wrong because Azure Policy can enforce that a vulnerability assessment solution is deployed, but it does not directly cause findings from a third-party tool to appear in Defender for Cloud recommendations; the 'Integrated' partner solution must be enabled and the scanner installed.

1141
Multi-Selecthard

Which THREE of the following are features of Microsoft Defender XDR that help manage a security operations environment?

Select 3 answers
A.Sentinel SIEM integration
B.Threat analytics
C.Automated investigation and response
D.Advanced hunting
E.Unified incident management
AnswersC, D, E

Automated investigation and response (AIR) is a core feature of Microsoft Defender XDR because it enables the platform to orchestrate playbooks across email, endpoints, identities, and cloud apps following an alert trigger. When a suspicious entity is detected, AIR automatically runs investigations, pauses or blocks malicious activities, and takes remediation actions such as quarantining files or disabling accounts — all while keeping security teams informed via the Action Center. This cross-product automation is what distinguishes XDR from individual Defender products, and it is explicitly listed as a primary capability of Defender XDR. The process uses AI-driven assessments to determine whether a threat is malicious, and it helps contain breaches before human analysts can intervene.

Why this answer

Automated Investigation and Response (AIR) in Microsoft Defender XDR uses AI-driven playbooks to automatically investigate alerts and take remediation actions, such as isolating a compromised device or blocking a malicious file, without requiring manual intervention. This directly supports managing a security operations environment by reducing alert fatigue and accelerating incident response.

Exam trap

The trap here is that candidates often confuse 'features of Microsoft Defender XDR' with 'features of Microsoft Sentinel' or other Microsoft security products, leading them to select SIEM integration (Option A) or Threat Analytics (Option B) as operational management features when they are not core to Defender XDR's incident management and response capabilities.

1142
MCQeasy

Your organization uses Microsoft Defender for Cloud. You need to view a list of all security recommendations for your Azure subscriptions. Which blade should you use?

A.Workbooks
B.Regulatory Compliance
C.Inventory
D.Recommendations
AnswerD

The Recommendations blade in Microsoft Defender for Cloud is the single, central pane that gathers every security recommendation for your organization's resources. It lists recommendations with severity, affected resources, remediation steps, security control, and impact on your secure score, enabling immediate triage and action. This is exactly the page needed to simply view security recommendations, so it is the correct answer.

Why this answer

The Recommendations blade in Microsoft Defender for Cloud is the centralized hub that lists all security recommendations for your Azure subscriptions, including those from Azure Security Benchmark and custom initiatives. It provides a prioritized view of security posture improvements, such as remediating vulnerabilities or enabling encryption, directly actionable from the blade.

Exam trap

The trap here is that candidates confuse the Inventory blade (which shows resources and their security state) with the Recommendations blade (which shows the actionable list of security improvements), leading them to select Inventory instead of the correct Recommendations blade.

How to eliminate wrong answers

Option A is wrong because Workbooks are used for creating custom visualizations and reports from Azure Monitor data, not for viewing the list of security recommendations. Option B is wrong because Regulatory Compliance focuses on compliance scores and controls against standards like SOC 2 or ISO 27001, not the full set of security recommendations. Option C is wrong because Inventory shows a list of Azure resources and their security posture, but it does not display the aggregated list of recommendations; it is a resource-centric view, not a recommendation-centric one.

1143
Multi-Selecteasy

Which TWO data sources in Microsoft Sentinel are commonly used for threat hunting related to lateral movement?

Select 2 answers
A.DeviceNetworkEvents
B.Syslog
C.SecurityEvent
D.DnsEvents
E.AzureActivity
AnswersA, C

DeviceNetworkEvents, ingested via Microsoft Defender for Endpoint, records inbound and outbound connection attempts with initiating process and remote IP. This connection-level telemetry exposes the internal host-to-host traffic patterns that characterise lateral movement, satisfying the stem's threat-hunting requirement.

Why this answer

Options A and C are correct. DeviceNetworkEvents (Microsoft Defender for Endpoint) logs network connections, which can reveal lateral movement attempts between devices. SecurityEvent (Windows Event Logs) contains Event ID 4624 (logon) and 4688 (process creation), both critical for identifying lateral movement.

Option B (Syslog) is a general logging protocol not specific to lateral movement. Option D (DnsEvents) is more relevant to command and control or data exfiltration. Option E (AzureActivity) tracks Azure resource operations, not lateral movement within the environment.

1144
MCQmedium

You are reviewing the KQL query shown in the exhibit. What is the purpose of this query?

A.Count the number of high-severity alerts per hour
B.Return the timestamp of each high-severity alert
C.Identify high-severity alert names that occurred more than 10 times in the last 24 hours
D.List all high-severity incidents in the last 24 hours
AnswerC

This is the correct interpretation because the query explicitly filters for high-severity alerts within the last 24 hours using `where Severity == "High"` and `where TimeGenerated > ago(24h)`, then groups by `AlertName`. The `summarize count() by AlertName` computes the occurrence frequency for each alert name, and the subsequent `where count_ > 10` (or `having count_ > 10`) enforces the threshold. The result is exactly the set of high-severity alert names observed more than 10 times in the specified period.

Why this answer

The query uses `summarize` with `count()` on `AlertName`, then filters with `where count_ > 10`. This groups high-severity alerts by name and returns only those names that appear more than 10 times in the last 24 hours. The `project` statement outputs only the `AlertName` and its count, confirming the purpose is to identify frequently occurring high-severity alert names.

Exam trap

The trap here is that candidates confuse `summarize count()` with `summarize count() by bin(TimeGenerated, 1h)` and mistakenly think the query counts alerts per hour, when it actually counts total occurrences per alert name over the entire time range.

How to eliminate wrong answers

Option A is wrong because the query groups by `AlertName`, not by time bins (e.g., `bin(TimeGenerated, 1h)`), so it does not count alerts per hour. Option B is wrong because the query does not include `TimeGenerated` in the output; it projects only `AlertName` and `count_`. Option D is wrong because the query filters on `AlertName` and counts occurrences, not on incidents; it also does not list all incidents, only aggregated alert names meeting a threshold.

1145
MCQeasy

A security analyst in Microsoft 365 Defender is investigating an incident that involves multiple devices. The analyst wants to see a visual representation of the attack, showing how the attacker moved from one device to another. Which feature provides this view?

A.Alert queue
B.Incident graph
C.Advanced hunting
D.Action center
AnswerB

The Incident graph is a dedicated visualization that maps the full attack story by showing nodes for entities such as devices, users, and alerts, and edges representing causal relationships and movement. It automatically aggregates related alerts from the merged incident and provides a timeline-based view of how the attacker entered and expanded across the environment. This allows the analyst to identify the attack path and affected scope at a glance.

Why this answer

The Incident graph in Microsoft 365 Defender provides a visual, interactive representation of an attack, showing how the attacker moved from one device to another, including lateral movement paths and related alerts. This feature is specifically designed to help analysts understand the full scope of an incident by mapping out the relationships between entities such as devices, users, and alerts.

Exam trap

The trap here is that candidates often confuse the Incident graph with Advanced hunting, thinking that a query-based tool is needed to visualize attack paths, but the Incident graph provides this visualization automatically without requiring any query writing.

How to eliminate wrong answers

Option A is wrong because the Alert queue is a list of individual alerts, not a visual graph showing lateral movement between devices. Option C is wrong because Advanced hunting is a query-based tool for searching raw data using KQL, not a pre-built visual attack path. Option D is wrong because the Action center is used to view and approve remediation actions (e.g., isolating devices, running antivirus scans), not to visualize attack progression.

1146
MCQeasy

You are a security operations analyst for a company that uses Microsoft Defender XDR. You need to ensure that when a high-severity alert is generated in Microsoft Defender for Endpoint, an incident is automatically created in Microsoft Defender XDR and appears in the incident queue. What should you do?

A.Enable the Microsoft Defender for Endpoint integration in Microsoft Defender XDR and set the alert severity threshold to High.
B.Create a custom detection rule in Microsoft Defender for Endpoint that triggers on high-severity alerts.
C.Verify that the alert is not suppressed and that incident creation is enabled in the Microsoft Defender XDR settings.
D.Configure a Microsoft Sentinel analytics rule to ingest high-severity alerts from Defender for Endpoint and create incidents.
AnswerC

Microsoft Defender XDR automatically correlates alerts into incidents when incident creation is enabled and alerts are not suppressed. Ensuring these settings are correct allows high-severity alerts from Defender for Endpoint to generate incidents, meeting the requirement.

Why this answer

Microsoft Defender XDR automatically creates incidents from alerts generated by its component services, including Defender for Endpoint, when incident creation is enabled and alerts are not suppressed. Checking these settings ensures that high-severity alerts result in incidents. The other options involve unnecessary customizations or misconfigured features that do not directly control incident creation in Defender XDR.

Exam trap

The trap here is confusing alert generation with incident creation, and assuming that custom detection rules or severity thresholds control incident creation in Defender XDR.

1147
Multi-Selecthard

Which TWO actions are valid containment steps for a compromised user account in Microsoft Defender XDR?

Select 2 answers
A.Create a new email rule to forward emails
B.Disable the user account in Microsoft Entra ID
C.Add the user to a privileged role
D.Reset the user's password
E.Run a full antivirus scan on the user's device
AnswersB, D

Disabling the user account in Microsoft Entra ID is a valid containment step because it immediately prevents any further authentication attempts using that identity, cutting off the attacker's current access path to cloud applications, Microsoft 365, and other Entra ID-integrated resources. This reversible, non-destructive action preserves all user data and activity logs for forensic analysis while stopping ongoing malicious activity. It is one of the first actions an incident responder should take when a user identity is known to be compromised.

Why this answer

Disabling the user account in Microsoft Entra ID is a valid containment step because it immediately revokes the user's access to all cloud resources, including Microsoft 365, Azure, and any applications relying on Entra ID authentication. This prevents the compromised account from being used for further malicious activities while preserving the account for investigation. It is a core incident response action in Microsoft Defender XDR for containing identity-based threats.

Exam trap

The trap here is that candidates often confuse remediation steps (like running an antivirus scan) with containment steps, or they mistakenly think that adding a user to a privileged role could help monitor the account, when in fact it escalates the compromise.

1148
MCQhard

Your organization uses Microsoft Sentinel. An incident is created from a fusion detection that combines multiple signals. You need to ensure that when the incident is resolved, all related alerts are also resolved automatically. What should you do?

A.Create an automation rule triggered when an incident is closed, with the action 'Close alert'
B.Create a playbook triggered on incident creation that closes alerts
C.Create an automation rule triggered when an alert is created
D.Configure the analytics rule to close alerts when the incident is resolved
AnswerA

In Microsoft Sentinel, an automation rule can be triggered when an incident's status changes to Closed, and its 'Close alert' action explicitly resolves all linked alerts. This ensures that the security operations team does not have to manually close each alert and that the alert-state lifecycle matches the incident-state lifecycle. Conditions such as severity, owner, or tactic can also be applied, making this the correct, supported mechanism to accomplish the goal.

Why this answer

An automation rule triggered when an incident is closed can include the action 'Close alert', which automatically closes all alerts linked to that incident. This ensures that when the incident is resolved, all related alerts are also resolved without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rule triggers (incident creation vs. closure) or assume that closing an incident automatically closes its alerts, which is not the default behavior in Microsoft Sentinel.

How to eliminate wrong answers

Option B is wrong because a playbook triggered on incident creation would close alerts immediately when the incident is created, not when it is resolved, which does not meet the requirement. Option C is wrong because an automation rule triggered when an alert is created would run on alert creation, not on incident closure, and cannot close alerts retroactively. Option D is wrong because analytics rules do not have a setting to close alerts when the incident is resolved; alert closure must be handled via automation rules or playbooks.

1149
MCQeasy

A security analyst wants to identify all devices in the organization that have a specific software vulnerability (CVE-2023-1234) installed using Microsoft 365 Defender Advanced Hunting. Which table should be queried?

A.DeviceInfo
B.DeviceTvmSoftwareVulnerabilities
C.DeviceTvmSoftwareInventory
D.DeviceNetworkInfo
AnswerB

DeviceTvmSoftwareVulnerabilities is the Threat & Vulnerability Management (TVM) table containing one row for each software vulnerability detected on a device, with fields such as CveId, DeviceId, SoftwareVendor, SoftwareName, SoftwareVersion, and exploitability/severity information. Filtering on a specific CveId returns every affected device, which is exactly the required result. This makes it the canonical and correct data source for the analyst's query.

Why this answer

The DeviceTvmSoftwareVulnerabilities table in Microsoft 365 Defender Advanced Hunting contains records of software vulnerabilities discovered on devices, including specific CVE identifiers like CVE-2023-1234. This table is designed to answer questions about which devices have a particular vulnerability installed, as it links device IDs to vulnerability details such as CVE ID, severity, and exploitability.

Exam trap

The trap here is that candidates often confuse DeviceTvmSoftwareInventory (which lists installed software) with DeviceTvmSoftwareVulnerabilities (which lists actual vulnerabilities), leading them to pick Option C because they think software inventory implies vulnerability presence.

How to eliminate wrong answers

Option A is wrong because DeviceInfo provides general device metadata (e.g., OS version, device name, last seen time) but does not include vulnerability or software inventory details. Option C is wrong because DeviceTvmSoftwareInventory lists installed software products and versions on devices, but it does not map those to specific CVEs or vulnerabilities. Option D is wrong because DeviceNetworkInfo contains network-related data such as IP addresses, network adapters, and connection details, and has no relation to software vulnerabilities.

1150
MCQeasy

A SOC manager wants to quickly view the number of incidents generated in Microsoft Sentinel over the past 7 days, grouped by Azure subscription. Which KQL query should be used on the SecurityIncident table?

A.SecurityIncident | where CreatedTime > ago(7d) | summarize count() by SubscriptionId
B.SecurityAlert | where TimeGenerated > ago(7d) | summarize count() by SubscriptionId
C.SecurityIncident | where TimeGenerated > ago(7d) | summarize count() by SubscriptionId
D.SecurityIncident | where CreatedTime > ago(7d) | summarize count() by WorkspaceSubscriptionId
AnswerA

SecurityIncident is the correct table because it stores the definitive incident records that a SOC triages, and CreatedTime is the standard timestamp column indicating when an incident was generated. Filtering with ago(7d) limits results to the last seven days, while summarize count() by SubscriptionId groups the incidents by the Azure subscription containing the affected resources, directly satisfying the manager's request to see incident counts per subscription.

Why this answer

The SecurityIncident table stores incident records, and the CreatedTime field records when each incident was generated. Filtering with `where CreatedTime > ago(7d)` limits results to the past 7 days, and `summarize count() by SubscriptionId` groups the count by the Azure subscription that owns the resources involved in the incident. This directly meets the SOC manager's requirement to view the number of incidents per subscription over the last week.

Exam trap

The trap here is confusing the SecurityIncident table's SubscriptionId with WorkspaceSubscriptionId, or using the wrong time field (TimeGenerated instead of CreatedTime), leading candidates to pick options that either query the wrong table or group by the wrong subscription identifier.

How to eliminate wrong answers

Option B is wrong because it queries the SecurityAlert table instead of SecurityIncident, which contains alerts rather than incidents; incidents are the higher-level grouping of alerts, so this would not show incident counts. Option C is wrong because it uses TimeGenerated on the SecurityIncident table, but SecurityIncident does not have a TimeGenerated column; this would cause a query error or return no results. Option D is wrong because it groups by WorkspaceSubscriptionId, which is the subscription of the Log Analytics workspace, not the Azure subscription associated with the incident's resources; the SOC manager specifically needs incidents grouped by the subscription where the resources reside, which is SubscriptionId.

1151
MCQmedium

Your organization uses Microsoft Sentinel to monitor a hybrid environment consisting of on-premises servers and cloud workloads in Azure. As a threat hunter, you have been tasked with identifying potential lateral movement using pass-the-hash (PtH) attacks. You have enabled UEBA and connected Windows Event Logs, including Event ID 4624 (logon) and 4648 (explicit credentials). You need to create a hunting query that surfaces anomalous remote logons where the same account logon from a non-domain joined machine using NTLM authentication. Which KQL query should you use to start your hunt?

A.SecurityEvent | where EventID == 4624 and AccountType == 'User' and LogonType == 3 | where IpAddress != '' | summarize count() by Account, IpAddress
B.SecurityEvent | where EventID == 4624 and LogonType == 3 and LogonProcessName contains 'NTLM' | where TargetUserName !endswith '$' | where Computer !in (list of domain controllers) | project TimeGenerated, Account=TargetUserName, SourceWorkstation=WorkstationName, LogonProcessName
C.SecurityEvent | where EventID == 4624 and LogonType == 2 and LogonProcessName contains 'NTLM' | project TimeGenerated, Account=TargetUserName
D.SecurityEvent | where EventID == 4624 and LogonType == 10 and AuthenticationPackageName == 'NTLM' | project TimeGenerated, Account=TargetUserName, SourceIP=IpAddress
AnswerB

This query precisely identifies NTLM network logons by combining EventID 4624, LogonType 3, and LogonProcessName containing 'NTLM', which is the signature of pass-the-hash authentication. The `TargetUserName !endswith '$'` filter removes machine accounts, and the `Computer !in (list of domain controllers)` exclusion eliminates the large volume of legitimate DC-to-DC NTLM activity, leaving only suspicious user logons from non-DC hosts. By projecting TimeGenerated, Account, SourceWorkstation, and LogonProcessName, it retains the forensic context needed for incident investigation, making it the correct detection for PtH lateral movement.

Why this answer

Filters for logon type 3 (network), NTLM authentication (LogonProcessName contains NTLM), and non-domain joined workstations (WorkstationName not in list of domain controllers). Option A misses PtH indicators; Option C incorrectly uses RDP logon type 10; Option D focuses on interactive logons.

1152
MCQmedium

During an incident investigation, you discover that an attacker used a legitimate account to access sensitive data in Microsoft Purview Information Protection. You need to identify what data was accessed and by whom. Which log source should you query?

A.Microsoft 365 Defender alerts
B.Microsoft Purview data access logs
C.Microsoft Entra ID sign-in logs
D.Office 365 audit logs (unified audit log)
AnswerB

Microsoft Purview data access logs are the authoritative source for item-level access events in Office 365, recording details such as the specific document downloaded, the user identity, the timestamp, and the device or client IP. These logs are generated by Purview's content discovery and classification pipeline and capture both interactive and background access by apps or users. For an attacker exfiltrating sensitive files, these logs provide the precise chain of access needed to confirm what data was compromised, so this is the correct choice for the investigation.

Why this answer

Microsoft Purview data access logs (option B) are the correct source because they specifically record when users access sensitive data labeled with Microsoft Purview Information Protection, including details about what data was accessed and by whom. Unlike other logs, these capture data-level access events such as viewing, downloading, or modifying protected documents, which is essential for investigating an attacker using a legitimate account to exfiltrate sensitive information.

Exam trap

The trap here is that candidates often confuse the unified audit log (option D) with Purview data access logs, not realizing that while the unified audit log captures many activities, Purview data access logs are the only source that specifically records label-based access events for sensitive data.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Defender alerts provide aggregated threat detection signals and incident summaries, not granular data access logs for Purview-protected content. Option C is wrong because Microsoft Entra ID sign-in logs record authentication events (successful/failed logins) but do not track what specific data was accessed after authentication. Option D is wrong because Office 365 audit logs (unified audit log) capture a broad range of administrative and user activities, but they do not include the detailed data-level access events for Purview Information Protection labels; those are only available in Purview data access logs.

1153
MCQeasy

During a threat hunt, you identify a user account that has been logging in from multiple geographic regions within a short time. Which Microsoft Defender for Cloud Apps feature should you use to investigate this anomaly?

A.Cloud Discovery
B.App permissions
C.File policy
D.Activity log
AnswerD

The activity log records every user action and sign-in event with source IP, location and timestamp, letting analysts correlate the impossible-travel sign-ins and trace subsequent suspicious activity. It directly satisfies the requirement to investigate an account authenticating from multiple geographic regions within a short window.

Why this answer

The Activity log in Microsoft Defender for Cloud Apps provides detailed records of user activities, including login locations and times, making it ideal for investigating anomalies like logins from multiple geographic regions. Option A (Cloud Discovery) is used to identify shadow IT and cloud app usage, not user login anomalies. Option B (App permissions) focuses on permissions granted to OAuth apps, not user activity.

Option C (File policy) is for monitoring and protecting files, not login events.

1154
MCQhard

Your organization uses Microsoft Defender for Endpoint. You need to configure a device group that automatically assigns devices to the group based on their domain membership. Devices joined to 'contoso.com' should be in the 'Corporate' group, and all others in 'Non-Corporate'. What should you use?

A.Use a custom detection rule to move devices based on risk level.
B.Create a device group with a rule using the device tag 'Contoso' and assign tags via GPO.
C.Create two device groups and manually move devices.
D.Create a device group with a rule using the domain field 'contoso.com'.
AnswerB

This is the correct approach because Microsoft Defender for Endpoint device groups support rule criteria based on device tags, and device tags can be assigned centrally via Group Policy or Intune. By tagging all Contoso devices with the same device tag and creating a device group rule that matches that tag, you automatically assign the correct devices and keep the group in sync as new devices are onboarded. This is dynamic and scalable, avoiding manual, one-off reconfiguration.

Why this answer

Microsoft Defender for Endpoint device groups can use device tags to automatically assign devices based on domain membership. By creating a device group with a rule that matches the device tag 'Contoso' and assigning that tag to domain-joined machines via Group Policy Object (GPO), you ensure that devices joined to 'contoso.com' are placed in the 'Corporate' group, while all others fall into the default 'Non-Corporate' group.

Exam trap

The trap here is that candidates assume the domain field can be used directly in device group rules, but Defender for Endpoint does not expose the domain attribute for rule creation; instead, you must use tags applied via GPO or other management tools to achieve domain-based grouping.

How to eliminate wrong answers

Option A is wrong because custom detection rules are used for creating custom alerts and automated actions based on threat indicators, not for assigning devices to groups based on domain membership. Option C is wrong because manually moving devices is not scalable and does not meet the requirement for automatic assignment based on domain membership. Option D is wrong because device group rules in Defender for Endpoint do not support filtering directly on the domain field; they support tags, device names, OS platforms, and other attributes, but not the domain field itself.

1155
MCQmedium

Your organization uses Microsoft Defender for Endpoint and Microsoft Sentinel. As part of a threat hunting exercise, you need to detect potential lateral movement using remote desktop protocol (RDP). You want to identify devices that have initiated multiple RDP connections to different internal IP addresses within a short time frame. Which hunting query should you use in Microsoft Sentinel's Log Analytics workspace?

A.Syslog | where Facility == 'auth' and Message contains 'RDP' | summarize count() by HostName
B.DeviceProcessEvents | where ProcessCommandLine contains 'mstsc.exe' | summarize count() by DeviceName
C.DeviceNetworkEvents | where RemotePort == 3389 and ActionType == 'ConnectionSuccess' | summarize dcount(RemoteIP) by DeviceName
D.IdentityLogonEvents | where LogonType == 'RemoteInteractive' | summarize dcount(IPAddress) by DeviceName
AnswerC

DeviceNetworkEvents with RemotePort 3389 and ActionType 'ConnectionSuccess' captures successful RDP sessions, and summarising dcount(RemoteIP) by DeviceName surfaces devices connecting to many distinct internal addresses — exactly the fan-out pattern the stem's lateral movement hunt requires.

Why this answer

DeviceNetworkEvents is the Microsoft Defender for Endpoint table that records network connection telemetry, including the RemotePort and ActionType fields. Filtering on RemotePort == 3389 (the RDP port) with ActionType == 'ConnectionSuccess' and then using dcount(RemoteIP) by DeviceName surfaces devices that successfully connected to many distinct internal IPs — the classic signature of RDP-based lateral movement. This is the query pattern Microsoft recommends in Sentinel hunting workbooks for detecting RDP fan-out behavior.

Exam trap

SC-200 often tests whether candidates know which Defender for Endpoint advanced hunting table contains network connection metadata versus process or identity data — picking DeviceProcessEvents or IdentityLogonEvents instead of DeviceNetworkEvents is the classic mistake.

How to eliminate wrong answers

Option A is wrong because Syslog with Facility == 'auth' captures Linux authentication events, not Windows RDP connection telemetry, and it lacks the RemotePort/RemoteIP fields needed to count distinct destinations. Option B is wrong because DeviceProcessEvents only shows that mstsc.exe was launched locally — it cannot reveal the remote IPs contacted, so it cannot detect fan-out to multiple internal hosts. Option D is wrong because IdentityLogonEvents with LogonType == 'RemoteInteractive' records successful interactive logons but does not enumerate the network-level RDP connection attempts or the distinct RemoteIP targets needed to identify lateral movement patterns.

1156
Multi-Selecteasy

Which TWO data sources can you connect to Microsoft Sentinel to ingest security logs? (Select TWO.)

Select 2 answers
A.Google Cloud Platform audit logs
B.Azure Active Directory (Microsoft Entra ID) audit logs
C.Amazon Web Services (AWS) CloudTrail
D.Trello activity logs
E.GitHub Actions logs
AnswersB, C

Azure Active Directory (Microsoft Entra ID) audit logs are a first-party data source for Sentinel. The built-in Microsoft Entra ID connector ingests both sign-in logs and audit logs through the Microsoft Graph API after you enable diagnostic settings to stream them to Sentinel. This integration gives security teams identity-related telemetry such as sign-in failures, password changes, and conditional access activity without extra infrastructure.

Why this answer

Azure Active Directory (Microsoft Entra ID) audit logs are a native data source for Microsoft Sentinel. They can be connected directly via the Azure AD connector, which ingests sign-in logs, audit logs, and provisioning logs into the Log Analytics workspace. This integration is essential for monitoring identity-related security events and is a standard requirement for SC-200 scenarios.

Exam trap

The trap here is that candidates often assume any cloud or SaaS service can be connected via a generic API, but Microsoft Sentinel only supports specific, pre-built connectors for security-relevant sources like AWS CloudTrail and Azure AD, not for productivity tools like Trello or GitHub Actions logs.

1157
MCQeasy

Your organization uses Microsoft Sentinel. You need to design a solution to automatically respond to a specific type of incident by sending an email to the SOC manager and creating a ticket in ServiceNow. What should you use?

A.Create an analytics rule that directly sends an email.
B.Create a workbook that triggers a webhook.
C.Create an automation rule that sends an email and creates a ticket.
D.Create a playbook in Microsoft Sentinel and trigger it with an automation rule.
AnswerD

Playbooks are Azure Logic Apps that can integrate with external systems through connectors, enabling actions like sending email, creating tickets, or posting to chat. An automation rule can be configured to run a playbook automatically when an incident is created or updated, providing a scalable and customizable response. This design correctly separates detection (analytics rule) from orchestration (automation rule + playbook) and is the standard pattern for complex actions.

Why this answer

Microsoft Sentinel uses Azure Logic Apps-based playbooks to execute complex, multi-step automated responses, such as sending an email and creating a ServiceNow ticket. An automation rule is required to trigger the playbook when an incident meets specific criteria, as analytics rules alone cannot directly invoke external systems like ServiceNow.

Exam trap

The trap here is that candidates confuse automation rules with playbooks, thinking automation rules can directly perform actions like sending emails, when in fact they only orchestrate the triggering of playbooks that contain the actual logic.

How to eliminate wrong answers

Option A is wrong because analytics rules generate alerts or incidents but cannot directly send emails; they require a playbook or automation rule for external actions. Option B is wrong because workbooks are visualization tools that do not trigger automated responses or webhooks for incident handling. Option C is wrong because automation rules can trigger playbooks but cannot natively send emails or create ServiceNow tickets; those actions require a playbook (Logic App) with the appropriate connectors.

1158
Multi-Selecteasy

Which TWO roles can be used to manage Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Compliance Administrator
B.Microsoft Sentinel Responder
C.Security Reader
D.Global Administrator
E.Microsoft Sentinel Contributor
AnswersB, E

Microsoft Sentinel Responder is one of the two built-in Sentinel-specific roles that can manage the day-to-day operational tasks within the product. It allows the assigned user to view and manage incidents, triage alerts, and execute playbooks when responding to threats, while intentionally omitting resource-creation permissions. This makes it the appropriate role for security operations analysts who need to act on active detections without reconfiguring the overall Sentinel environment.

Why this answer

Microsoft Sentinel Contributor (Option E) is a built-in Azure RBAC role that grants full permissions to create and manage Sentinel resources, including data connectors, analytics rules, and workbooks. Microsoft Sentinel Responder (Option B) is a dedicated role that allows users to manage incidents, perform investigations, and respond to threats without having full write access to the Sentinel workspace. Both roles are specifically designed for managing Microsoft Sentinel operations.

Exam trap

The trap here is that candidates often confuse Azure AD roles (like Global Administrator or Security Reader) with Sentinel-specific RBAC roles, assuming that broad administrative roles automatically grant Sentinel management capabilities, when in fact Sentinel requires dedicated roles scoped to the Log Analytics workspace.

1159
Multi-Selecthard

Which THREE steps are part of the containment phase of incident response in a hybrid environment using Microsoft Defender XDR?

Select 3 answers
A.Remove malware from affected systems
B.Restore data from backups
C.Disable compromised user accounts in Microsoft Entra ID
D.Isolate affected devices using Microsoft Defender for Endpoint
E.Block malicious IP addresses at the firewall
AnswersC, D, E

Disabling compromised accounts in Microsoft Entra ID immediately revokes authentication, blocking the attacker from re-entering the environment via cloud or hybrid identity paths. This directly satisfies containment by stopping lateral movement and further compromise while investigation continues, rather than merely detecting or documenting the incident.

Why this answer

Option C is correct because disabling compromised user accounts in Microsoft Entra ID is a classic containment action that stops an attacker from continuing to use stolen credentials for lateral movement or further access. Option D is correct because isolating affected devices via Microsoft Defender for Endpoint cuts off the endpoint's network communication while preserving it for investigation, which is a core containment step in a hybrid environment. Option E is correct because blocking malicious IP addresses at the firewall prevents ongoing command-and-control or exfiltration traffic to known-bad infrastructure, containing the spread of the incident.

Options A and B are not containment: removing malware is part of eradication, and restoring data from backups belongs to the recovery phase, which occurs after the threat has been fully eliminated.

Exam trap

The trap is mixing up incident response phases — candidates often select eradication or recovery actions (like removing malware or restoring backups) thinking they are containment.

1160
MCQmedium

A company uses Microsoft Defender for Cloud with Defender for Servers enabled. The security team wants to integrate a third-party vulnerability assessment solution (e.g., Qualys) and have findings appear in the Defender for Cloud recommendations. What must be done?

A.Install the Qualys agent on the VMs and configure the vulnerability assessment solution in Defender for Cloud.
B.Enable the built-in Microsoft Defender Vulnerability Management (MDVM) solution; it automatically integrates with any third-party scanner.
C.Set up automatic provisioning of the Log Analytics agent and enable vulnerability assessment in the regulatory compliance dashboard.
D.Nothing; Defender for Cloud automatically scans all Azure VMs for vulnerabilities using the integrated Qualys scanner.
AnswerA

Deploying the Qualys agent on every Virtual Machine is mandatory because Defender for Cloud uses that agent to collect and transmit vulnerability data to the Qualys cloud service. After installation, the solution must be registered under Defender for Cloud's Vulnerability assessment settings, which patches the security policy with the associated plan. Once configured, the Qualys findings appear in the 'Vulnerabilities in your virtual machines should be remediated' recommendation, and auto-provisioning can later be enabled for new VMs.

Why this answer

To integrate a third-party vulnerability assessment solution like Qualys with Microsoft Defender for Cloud, you must install the Qualys agent on the VMs and then configure the vulnerability assessment solution in Defender for Cloud. This allows Defender for Cloud to receive and display the vulnerability findings from Qualys as part of its security recommendations. Without this explicit configuration, Defender for Cloud cannot ingest third-party scanner data.

Exam trap

The trap here is that candidates assume Defender for Cloud automatically integrates with any third-party scanner or that enabling MDVM will bridge to third-party tools, when in fact a specific agent installation and connector configuration is required for third-party solutions.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender Vulnerability Management (MDVM) is a built-in solution that does not automatically integrate with third-party scanners; it is a separate offering that replaces the need for third-party tools, not a bridge to them. Option C is wrong because automatic provisioning of the Log Analytics agent and enabling vulnerability assessment in the regulatory compliance dashboard does not integrate a third-party scanner; it only enables built-in vulnerability assessment or MDVM, not Qualys. Option D is wrong because Defender for Cloud does not automatically scan all Azure VMs using an integrated Qualys scanner; it uses its own built-in vulnerability assessment or requires explicit integration of a third-party solution.

1161
MCQmedium

A company uses Microsoft Defender for Cloud with enhanced security features enabled. The security team wants to automatically disable the local administrative account on all existing and future Azure virtual machines by applying a guest configuration policy. Which Defender for Cloud feature should they use?

A.Just-In-Time (JIT) VM access
B.Guest configuration (Azure Policy)
C.Adaptive application controls
D.Regulatory compliance dashboard
AnswerB

Guest configuration (Azure Policy) is the correct mechanism because it deploys the guest configuration agent into the VM or Arc-enabled machine to audit and remediate settings inside the guest OS. It can apply policy definitions that target local accounts, including disabling unused or default accounts, using PowerShell Desired State Configuration. With the DeployIfNotExists effect, the policy can automatically apply the remediation, making it the only option that physically changes the local account state.

Why this answer

Guest configuration (Azure Policy) is the only feature that can audit and remediate settings inside a virtual machine's operating system, such as disabling the local administrative account. Defender for Cloud integrates with Azure Policy's guest configuration extension to enforce desired state configurations on both existing and future VMs via policy assignments.

Exam trap

The trap here is confusing network-level access controls (JIT) or application whitelisting (Adaptive application controls) with OS-level configuration management, which is exclusively handled by Guest configuration (Azure Policy).

How to eliminate wrong answers

Option A is wrong because Just-In-Time (JIT) VM access controls network-level access to management ports (e.g., RDP/SSH) and does not modify local user accounts or enforce guest OS configurations. Option C is wrong because Adaptive application controls define allowlists for applications running on VMs to prevent malware, not manage local user accounts or disable administrative privileges. Option D is wrong because the Regulatory compliance dashboard provides visibility into compliance standards (e.g., ISO 27001, NIST) but does not perform any automated remediation or configuration changes on VMs.

1162
MCQhard

A SOC analyst is responding to a ransomware incident. The analyst identifies that the ransomware encrypted files on a file share and left a ransom note. The analyst needs to prevent the ransomware from spreading to other shares. Which action should the analyst take first?

A.Revoke the user's access to the file share.
B.Run a full antivirus scan on the server.
C.Restore the encrypted files from backup.
D.Isolate the server from the network using Microsoft Defender for Endpoint's device isolation.
AnswerD

Microsoft Defender for Endpoint's device isolation applies an OS-level network security policy at the client that blocks all inbound and outbound traffic other than the Defender service itself, effectively severing the ransomware's command-and-control channel and preventing further server-side or lateral encryption. This is the immediately effective containment action because it does not rely on terminating the process or cleaning files first. The SOC can then inspect processes, stop the malicious binary, and later restore data from backup in a clean state.

Why this answer

The immediate priority in a ransomware incident is containment to prevent lateral movement and further encryption. Microsoft Defender for Endpoint's device isolation feature disconnects the compromised server from the network while allowing communication with the Defender for Cloud backend, stopping the ransomware from spreading to other shares. This aligns with the NIST incident response framework's containment phase, which must occur before eradication or recovery actions.

Exam trap

The trap here is that candidates confuse containment actions with recovery or eradication steps, mistakenly choosing to restore files or run a scan first, when the correct first action is to isolate the compromised device to stop the spread.

How to eliminate wrong answers

Option A is wrong because revoking the user's access does not stop the ransomware process already running on the server from encrypting additional shares or spreading via other accounts or system-level privileges. Option B is wrong because running a full antivirus scan is a detection and eradication step that should follow containment; the ransomware may continue to spread during the scan, and the scan itself may be disrupted by the active malware. Option C is wrong because restoring encrypted files from backup is a recovery action that should only be performed after the threat is contained and eradicated; attempting restoration first could allow the ransomware to immediately re-encrypt the restored files.

1163
MCQmedium

A company runs its critical workloads on Azure Kubernetes Service (AKS). The security team wants to use Microsoft Defender for Cloud to protect the AKS clusters. After enabling Defender for Cloud on the subscription, they also need to enable the Defender for Containers plan. Which of the following capabilities becomes available specifically after enabling the Defender for Containers plan (with the plan turned on)?

A.Azure Policy for Kubernetes add-on installation to enforce pod security policies.
B.Kubernetes audit logs are automatically streamed to the Log Analytics workspace.
C.Security alerts for container runtime threats, such as privilege escalation in a container.
D.Integration with Microsoft Sentinel for monitoring AKS logs.
AnswerC

Defender for Containers provides advanced runtime threat detection that analyzes Kubernetes audit logs and container activity using behavioral analytics. It specifically identifies container runtime threats such as privilege escalation inside a container, container breakouts, and suspicious process execution. This capability to generate actionable, security alerts is the core value of the plan and distinguishes it from static policy enforcement or raw log ingestion.

Why this answer

Enabling the Defender for Containers plan in Microsoft Defender for Cloud activates host-level and cluster-level threat detection for AKS, including runtime threat protection. This allows Defender for Cloud to generate security alerts for container-specific threats such as privilege escalation, container breakout, and suspicious process execution within containers, which are not available with just the basic Defender for Cloud enabled on the subscription.

Exam trap

The trap here is that candidates often confuse the general security monitoring capabilities of Defender for Cloud (like audit log streaming or policy enforcement) with the specific runtime threat detection that only the Defender for Containers plan enables, leading them to select options that are available without the plan or require separate configuration.

How to eliminate wrong answers

Option A is wrong because Azure Policy for Kubernetes add-on installation is a feature of Azure Policy itself, not of the Defender for Containers plan; it can be used to enforce pod security policies (e.g., via built-in initiatives) regardless of whether the Defender for Containers plan is enabled. Option B is wrong because Kubernetes audit logs are automatically streamed to the Log Analytics workspace only if you configure diagnostic settings on the AKS cluster to send them to a Log Analytics workspace; this is not an automatic behavior triggered by enabling the Defender for Containers plan. Option D is wrong because integration with Microsoft Sentinel for monitoring AKS logs is a feature of Sentinel's data connectors, not a capability that becomes available specifically after enabling the Defender for Containers plan; Sentinel can ingest AKS logs via diagnostic settings regardless of the Defender for Containers plan status.

1164
MCQmedium

A security analyst in Microsoft Defender for Cloud receives an alert that an Azure VM has a vulnerability with a high severity. The analyst wants to see the detailed finding, including the steps to remediate. Which blade or page should the analyst open?

A.Vulnerability Assessment findings
B.Secure Score
C.Regulatory Compliance
D.Workload protections alerts
AnswerA

The Vulnerability Assessment findings blade in Microsoft Defender for Cloud is the dedicated destination for aggregated scan results from integrated vulnerability assessment solutions, such as Microsoft Defender Vulnerability Management or Qualys, across Azure VMs, hybrid machines, and container images. It lists each discovered CVE with its severity, affected resource, and step-by-step remediation guidance, so an analyst investigating a specific vulnerability finding would open this blade to view and act on the detailed results.

Why this answer

The Vulnerability Assessment findings blade in Microsoft Defender for Cloud displays detailed results from integrated vulnerability scanners (such as Qualys or Microsoft Defender Vulnerability Management), including the specific vulnerability ID, severity, description, and remediation steps. This is the correct location to view the detailed finding and remediation guidance for a high-severity vulnerability on an Azure VM.

Exam trap

The trap here is that candidates confuse the 'Workload protections alerts' blade (which shows active threat detections) with the 'Vulnerability Assessment findings' blade (which shows scan results), leading them to select D instead of A.

How to eliminate wrong answers

Option B (Secure Score) is wrong because Secure Score provides an overall security posture rating based on control recommendations, not the detailed vulnerability findings or remediation steps for a specific alert. Option C (Regulatory Compliance) is wrong because Regulatory Compliance shows compliance status against standards like ISO 27001 or SOC 2, not the technical details of a vulnerability finding. Option D (Workload protections alerts) is wrong because that blade lists security alerts (e.g., detected threats), not vulnerability assessment findings; alerts are generated from detections, whereas vulnerability findings come from scanning.

1165
Multi-Selectmedium

Which TWO actions should you take when responding to a confirmed data exfiltration incident involving Microsoft 365? (Choose two.)

Select 2 answers
A.Reset passwords for all users
B.Revoke user sessions in Microsoft Entra ID
C.Review audit logs in Microsoft Purview compliance portal
D.Disable all external sharing in SharePoint
E.Block all access to the tenant
AnswersB, C

Revoking sessions in Microsoft Entra ID invalidates refresh and access tokens immediately, cutting off the compromised account's continued access. This satisfies the stem's requirement to contain a confirmed exfiltration, since password resets alone leave existing tokens valid until expiry.

Why this answer

Options B and C are correct. When responding to a confirmed data exfiltration incident involving Microsoft 365, you should contain the threat by revoking user sessions in Microsoft Entra ID (option B) to prevent further unauthorized access, and investigate by reviewing audit logs in the Microsoft Purview compliance portal (option C) to determine the scope and impact of the exfiltration. Option A (resetting passwords for all users) is excessive and disruptive; instead, focus on resetting passwords for compromised accounts only.

Option D (disabling all external sharing in SharePoint) is too broad and may disrupt legitimate business operations. Option E (blocking all access to the tenant) is premature and would cause significant operational disruption.

1166
MCQeasy

Your Microsoft Sentinel workspace is ingesting data from multiple sources. You need to ensure that data from a specific source is retained for 2 years while other data remains at the default retention. What should you do?

A.Create a custom table for that source and set its retention to 2 years.
B.Adjust the data ingestion settings for that source.
C.Set the workspace retention to 2 years.
D.Configure archiving for that source's data.
AnswerA

Create a custom table for that source and set its retention to 2 years. This is correct because Microsoft Sentinel/Log Analytics supports per-table retention policies. By routing this source's data into its own custom table, you can configure that table's retention to 2 years without changing the workspace default. That gives you precisely the granularity needed for a single source.

Why this answer

In Microsoft Sentinel, retention is set at the table level. By creating a custom table for the specific data source and configuring its retention period to 2 years, you can override the default workspace retention for that table only. This allows other tables to retain the default retention setting while the custom table retains data for the required duration.

Exam trap

The trap here is that candidates often assume retention is set globally at the workspace level, but Microsoft Sentinel allows per-table retention, which is the correct method for applying different retention policies to different data sources.

How to eliminate wrong answers

Option B is wrong because data ingestion settings (like data source connectors or diagnostic settings) control what data is collected, not how long it is retained. Option C is wrong because setting the workspace retention to 2 years would apply to all tables in the workspace, not just the specific source. Option D is wrong because archiving is a separate tier for older data (e.g., after the interactive retention period ends) and does not set a specific retention duration for a source; it complements retention but does not replace the need for table-level retention configuration.

1167
Multi-Selecthard

Which THREE are valid data connectors in Microsoft Sentinel for ingesting security events from Microsoft 365 services? (Choose three.)

Select 3 answers
A.Microsoft 365 Defender
B.Microsoft Purview
C.Microsoft Intune
D.Microsoft Entra ID
E.Office 365
AnswersA, D, E

Microsoft 365 Defender is a native Sentinel data connector that ingests high-fidelity alerts and incidents from the Microsoft Defender XDR suite, including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. This connector enables cross-domain correlation and automates incident response by bringing unified XDR telemetry directly into Sentinel, making it a core component for modern security operations.

Why this answer

Microsoft 365 Defender is a valid data connector in Microsoft Sentinel that ingests alerts and incidents from Microsoft 365 Defender components (Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps). It uses the Microsoft 365 Defender API to pull correlated security events, enabling centralized investigation of advanced threats across the M365 ecosystem.

Exam trap

The trap here is that candidates may confuse Microsoft Purview (a compliance tool) with a security event source, or think Intune's device management logs qualify as 'security events from Microsoft 365 services' when Sentinel's Intune connector is actually for device compliance data, not security events.

1168
MCQmedium

In Microsoft 365 Defender, an analyst is investigating an incident involving a malicious script. The analyst wants to see the command-line arguments executed by the script on a specific device. Which Advanced Hunting table should the analyst query?

A.DeviceProcessEvents
B.DeviceNetworkEvents
C.DeviceFileEvents
D.DeviceEvents
AnswerA

DeviceProcessEvents is the advanced hunting table that records process creation events, and it includes the ProcessCommandLine field, which captures the full command-line string passed to the newly created process. When investigating suspicious execution, this table lets an analyst see exact arguments such as encoded PowerShell commands or unusual flags, providing direct evidence of the process's intended behavior. It is the authoritative source for command-line telemetry in Microsoft 365 Defender.

Why this answer

The DeviceProcessEvents table in Advanced Hunting captures process creation events, including the command-line arguments used to execute a process. Since the analyst needs to see the command-line arguments executed by a malicious script on a specific device, querying DeviceProcessEvents is the correct approach because it records the ProcessCommandLine column for each process creation event.

Exam trap

The trap here is that candidates often confuse DeviceProcessEvents with DeviceEvents, assuming the latter includes all process-related data, but DeviceEvents is a catch-all for miscellaneous events and does not contain the ProcessCommandLine column.

How to eliminate wrong answers

Option B is wrong because DeviceNetworkEvents logs network connections (e.g., source/destination IPs, ports, protocols) and does not contain command-line arguments. Option C is wrong because DeviceFileEvents records file creation, modification, and deletion events, but does not capture process command-line arguments. Option D is wrong because DeviceEvents is a generic table that includes various system-level events (e.g., security alerts, sensor events) but does not specifically store process command-line arguments; that data is in DeviceProcessEvents.

1169
MCQmedium

Your organization uses Microsoft Defender for Office 365. You need to create a custom alert that triggers when users receive external emails with attachments from untrusted domains. What should you configure?

A.Create an alert policy in Microsoft 365 Defender.
B.Create a mail flow rule in Exchange admin center.
C.Set up a conditional access policy in Microsoft Entra ID.
D.Configure a data sensitivity label in Microsoft Purview.
AnswerA

Creating an alert policy in Microsoft 365 Defender is correct because alert policies are specifically designed to monitor email activities and generate alerts when conditions are met. For instance, a policy can detect user-reported phishing, suspected malware, or unusual email forwarding patterns, producing an alert that appears in the Defender portal. These alerts can then be assigned severity, include custom notifications, and integrate with incident response queues.

Why this answer

A custom alert policy in Microsoft 365 Defender can be configured to detect when users receive external emails with attachments from untrusted domains. This leverages the built-in threat detection capabilities of Defender for Office 365, allowing you to define conditions such as sender domain reputation and attachment presence, and trigger an alert when the criteria are met.

Exam trap

The trap here is that candidates often confuse alert policies (which detect and notify) with mail flow rules (which enforce actions like blocking or quarantining), leading them to choose Option B when the question specifically asks for creating a custom alert.

How to eliminate wrong answers

Option B is wrong because a mail flow rule (transport rule) in Exchange admin center can block or modify messages based on sender domain or attachment presence, but it cannot generate a custom alert in the Microsoft 365 Defender portal; it only applies actions during message transport. Option C is wrong because a conditional access policy in Microsoft Entra ID controls access to cloud apps based on user, device, or location signals, not email content or attachments from untrusted domains. Option D is wrong because a data sensitivity label in Microsoft Purview is used to classify and protect sensitive data (e.g., via encryption or visual markings), not to detect or alert on external emails with attachments from untrusted domains.

1170
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to use a Microsoft Copilot for Security to summarize an incident in Microsoft Defender XDR. What is the minimum role required?

A.Security Administrator
B.Reader
C.Security Reader
D.Global Administrator
AnswerC

Security Reader is an Entra ID role that grants read-only visibility into security settings, alerts, incidents, and threat intelligence across Microsoft 365 Defender and Microsoft Sentinel. Because Microsoft Copilot for Security only needs to retrieve and summarize security information, this read-only access is sufficient and adheres to least privilege. It is the only option from the list that correctly maps to the required permissions for a Copilot summarization task.

Why this answer

The minimum role required to use Microsoft Copilot for Security to summarize an incident in Microsoft Defender XDR is Security Reader. This role grants read-only access to security data, including incidents and alerts, which is sufficient for Copilot to retrieve and summarize incident details without requiring write permissions. Higher-privileged roles like Security Administrator or Global Administrator are unnecessary for this read-only operation.

Exam trap

The trap here is that candidates often confuse the general Azure Reader role with the security-specific Security Reader role, assuming any read-level access is sufficient, but only Security Reader has the precise permissions to access Defender XDR incident data via Copilot.

How to eliminate wrong answers

Option A is wrong because Security Administrator has write permissions to modify security settings and policies, which exceeds the minimum read-only access needed for summarizing incidents. Option B is wrong because the built-in Reader role does not have the specific permissions to access security incident data in Defender XDR; it is a general Azure role that lacks the necessary scope for security-specific resources. Option D is wrong because Global Administrator is a highly privileged role with full access to all Azure AD and security settings, far beyond the minimum required for read-only incident summarization.

1171
MCQhard

You are managing Microsoft Defender XDR. The security team reports that some automated investigations are closing prematurely without sufficient evidence. You need to ensure that investigations only close when a minimum confidence level is reached. What should you modify?

A.Change the action center settings to require manual approval.
B.Modify the tenant-level advanced features in Microsoft Defender XDR.
C.Create a custom detection rule to override default behavior.
D.Adjust the automation level in the Microsoft 365 Defender security settings.
AnswerD

Adjusting the automation level in the Microsoft 365 Defender security settings is the correct action because this setting includes the confidence level required for automatic investigation closure. The automation level can be set to 'Full – Automatically remediate threats,' which allows Defender to act on alerts with a high confidence verdict, or set to 'Semi – require additional confirmation,' which raises the bar for automatic closure. Changing this setting directly controls whether the system closes an investigation without human review, thereby addressing the team's requirement to modify that confidence threshold.

Why this answer

The automation level in Microsoft 365 Defender security settings controls how automated investigations behave, including the confidence level required for actions to be taken or for investigations to close. By adjusting the automation level (e.g., from 'Full – remediate threats automatically' to a higher threshold like 'Semi – require approval for any remediation'), you can ensure that investigations do not close prematurely without sufficient evidence. This setting directly addresses the requirement to enforce a minimum confidence level before closure.

Exam trap

The trap here is that candidates often confuse the 'automation level' setting with 'action center settings' or 'advanced features', leading them to select Option A or B, when in fact the automation level directly controls the confidence threshold for investigation closure.

How to eliminate wrong answers

Option A is wrong because the action center settings for manual approval control whether remediation actions require human approval, not the confidence level threshold for closing investigations. Option B is wrong because tenant-level advanced features in Microsoft Defender XDR (e.g., preview features, data retention) do not include settings for automation confidence levels or investigation closure criteria. Option C is wrong because custom detection rules are used to create custom alerts or detections, not to override the default behavior of automated investigation closure based on confidence levels.

1172
Multi-Selecthard

Which THREE actions are appropriate when investigating a potential data exfiltration incident in Microsoft Defender for Cloud Apps?

Select 3 answers
A.Check the device inventory for suspicious applications
B.Use the app dashboard to view unusual behavior alerts
C.Suspend the user's account immediately
D.Check the file policy matches for the user
E.Review the user's activity log in Defender for Cloud Apps
AnswersB, D, E

The app dashboard in Defender for Cloud Apps surfaces anomaly detection alerts, such as impossible travel, mass download, or activity from a previously unseen IP. These alerts are produced by user and entity behavior analytics and serve as the initial signal that an exfiltration attempt may be in progress. Reviewing this dashboard is a valid investigative step because it helps you prioritize which users and files warrant deeper log analysis, rather than assuming any single event is malicious.

Why this answer

Options B, D, and E are correct. Option B: Using the app dashboard to view unusual behavior alerts provides context about potential exfiltration. Option D: Checking file policy matches helps identify which files were flagged as suspicious.

Option E: Reviewing the user's activity log in Defender for Cloud Apps helps determine the scope of the exfiltration. Option A is incorrect because checking device inventory is not a cloud app investigation action—it applies to endpoint devices. Option C is incorrect because suspending the user's account is a containment action, not an investigative step.

Exam trap

Candidates may confuse containment actions (e.g., suspending the user) with investigative steps, or mistakenly think device inventory is relevant in cloud app investigations.

1173
MCQmedium

Your organization uses Microsoft Sentinel. A new incident is created from a fusion alert that combines multiple low-severity alerts. The analyst needs to determine the entities involved. What should the analyst review?

A.The Sentinel Overview workbook.
B.The incident's entities tab.
C.The analytics rule that generated the incident.
D.The incident's timeline.
AnswerB

In Microsoft Sentinel, the incident's Entities tab displays the normalized entity objects—such as user accounts, hostnames, IP addresses, URLs, and file hashes—that were extracted and mapped during incident creation. These entities are directly linked to the incident and enriched with context for pivoting, allowing analysts to see and investigate all related resources from a single, authoritative view. This is the correct place to find all related entities for the incident.

Why this answer

The incident's entities tab in Microsoft Sentinel provides a consolidated view of all entities (such as users, hosts, IP addresses, and processes) that were identified by the fusion alert. Since fusion alerts combine multiple low-severity alerts, the entities tab is the direct place to see the aggregated entities involved in the incident, enabling the analyst to understand the scope and pivot for investigation.

Exam trap

The trap here is that candidates confuse the incident's timeline (which shows events) with the entities tab (which shows the involved objects), or they mistakenly think the analytics rule's configuration reveals the actual entities, when in fact entities are dynamically extracted from alert data.

How to eliminate wrong answers

Option A is wrong because the Sentinel Overview workbook provides high-level metrics and trends (e.g., incident counts, data ingestion) but does not show the specific entities for a single incident. Option C is wrong because the analytics rule that generated the incident defines the detection logic and configuration, not the dynamic entities extracted from the alert data. Option D is wrong because the incident's timeline shows the chronological sequence of events and activities related to the incident, but it does not present a structured list of entities; entities are explicitly available only in the entities tab.

1174
MCQhard

A security team is investigating a ransomware incident that encrypted files on several Windows servers. Microsoft Defender for Endpoint detected the ransomware but the initial infection vector is unknown. Which KQL query in Microsoft Sentinel would BEST identify the initial process that executed the ransomware?

A.DeviceNetworkEvents | where RemoteUrl contains 'malicious' | project DeviceName, RemoteIP, Timestamp
B.DeviceFileEvents | where FileName contains 'ransomware.exe' | project DeviceName, ActionType, Timestamp
C.DeviceProcessEvents | where FileName contains 'ransomware.exe' | project DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, Timestamp
D.DeviceEvents | where ActionType == 'RansomwareDetection' | project DeviceName, Timestamp
AnswerC

The DeviceProcessEvents table records actual process creation events on the endpoint, and this query filters for any process whose file name is 'ransomware.exe' while projecting the initiating process file name and its command line. That parent relationship is the critical forensic evidence: it shows which executable (for example msiexec.exe, rundll32.exe, or a malicious PowerShell) launched the ransomware, enabling the security team to trace back to the initial access vector. Including the timestamp supports chronological reconstruction of the infection, which is the core goal of the incident response investigation.

Why this answer

DeviceProcessEvents captures process creation events, and by filtering for the ransomware executable and projecting the InitiatingProcessFileName and InitiatingProcessCommandLine, you can trace back to the parent process that launched the ransomware. This directly identifies the initial infection vector, which is the core goal of the investigation.

Exam trap

The trap here is that candidates often choose Option D (DeviceEvents with RansomwareDetection) because it directly shows the detection event, but it lacks the parent process information needed to identify the initial infection vector, which is the specific requirement of the question.

How to eliminate wrong answers

Option A is wrong because DeviceNetworkEvents focuses on network connections, not process creation; filtering by a URL containing 'malicious' is speculative and does not identify the initial process that executed the ransomware. Option B is wrong because DeviceFileEvents logs file creation, modification, or deletion events, not process execution; while it shows the ransomware file, it cannot reveal the parent process that launched it. Option D is wrong because DeviceEvents with ActionType 'RansomwareDetection' only indicates that Defender for Endpoint detected ransomware activity, but it does not provide the initiating process details needed to trace the infection vector.

1175
MCQeasy

A security analyst needs to identify incidents in Microsoft Sentinel that are related to IP addresses known to be associated with a specific threat actor. The analyst has a CSV file containing a list of these IP addresses. Which feature should the analyst use to make this list available for queries in Sentinel?

A.Custom Log
B.Watchlist
C.Threat Intelligence indicator
D.Bookmark
AnswerB

In Microsoft Sentinel, a watchlist is a metadata-stored, queryable table that lets you upload a CSV of IP addresses and reference it in KQL via _GetWatchlist(), allowing you to match incident entities or enrich analytics rules without redeploying detections. Watchlists support aliases, search keys, validity dates, and are natively integrated into Alert Rules and hunting, making them the simplest and most appropriate mechanism for a custom IP list that must be joined against incoming events. Unlike raw data ingestion, watchlist data is retained in a structured reference table optimized for lookups.

Why this answer

A Watchlist in Microsoft Sentinel allows you to import a CSV file containing IP addresses and use it directly in KQL queries via the _GetWatchlist() function. This is the correct feature because it is specifically designed for storing and querying static reference data, such as known threat actor IPs, without requiring custom ingestion or transformation.

Exam trap

The trap here is that candidates often confuse Threat Intelligence indicators with a simple CSV import, but TI indicators require a structured format and integration with a TI platform, whereas a Watchlist is the direct, low-friction solution for static reference data.

How to eliminate wrong answers

Option A is wrong because a Custom Log is used to ingest raw data from a custom source into a Log Analytics workspace, requiring a defined schema and ingestion pipeline; it is not designed for quick, queryable reference lists from a CSV file. Option C is wrong because Threat Intelligence indicators are structured objects (e.g., STIX format) that integrate with threat intelligence platforms and are used for correlation with Sentinel's TI analytics rules, not for importing a simple CSV list of IPs. Option D is wrong because a Bookmark is used to save specific search results or hunting queries for later investigation, not to store or make a static list of IP addresses available for queries.

1176
MCQmedium

Contoso uses Microsoft Sentinel with Microsoft Defender XDR connector. You receive an incident titled 'Malware detected on endpoint' from Microsoft Defender for Endpoint. The incident includes a detailed timeline showing that the malware was downloaded from a malicious URL. You need to respond to the incident using Microsoft Sentinel and Microsoft Defender XDR capabilities. The affected device is a Windows 10 workstation used by a standard user. You have been asked to contain the threat and prevent recurrence. The organization has a policy to preserve evidence for 90 days. Which action should you take FIRST?

A.Reset the user's password and revoke sessions in Microsoft Entra ID.
B.Create a custom detection rule in Microsoft Sentinel for the malicious URL.
C.Block the malicious URL at the firewall using Microsoft Defender for Cloud Apps.
D.Isolate the device using Microsoft Defender for Endpoint device isolation.
AnswerD

Device isolation via Microsoft Defender for Endpoint immediately cuts the workstation's network connections while preserving the live system and its forensic artefacts, containing lateral movement and further payload downloads. Remediation and evidence collection follow safely afterwards, satisfying the 90-day preservation policy.

Why this answer

Isolating the device using Microsoft Defender for Endpoint immediately contains the threat by disconnecting the device from the network, preventing the malware from spreading or communicating with command-and-control servers. This is the priority first step in incident response. Option A is incorrect because resetting the password does not remove malware from the device.

Option B is incorrect creating a custom detection rule is a proactive step but not an immediate containment action. Option C is incorrect because blocking the URL at the firewall prevents further downloads but does not contain the already infected device.

1177
MCQmedium

During a threat hunt, you discover that a PowerShell script executed on multiple servers and established outbound connections to an external IP address. Which data source should you query in Microsoft Defender XDR to identify the specific command-line arguments used?

A.DeviceEvents
B.DeviceImageLoadEvents
C.DeviceProcessEvents
D.DeviceNetworkEvents
AnswerC

DeviceProcessEvents stores process creation telemetry, including the full command line and arguments for each executed process, so querying it reveals the exact PowerShell parameters used. Network connection tables record destination IPs but not the command-line arguments that launched the script.

Why this answer

DeviceProcessEvents in Microsoft Defender XDR contains detailed information about process creation, including the command-line arguments used when a process was started. Querying this table will reveal the specific arguments passed to the PowerShell script. This is the correct data source for command-line details.

Exam trap

The trap is confusing process events with network events. Candidates might pick DeviceNetworkEvents because the question mentions outbound connections, but the question asks for command-line arguments, which are in process events. DeviceEvents is a distractor because it's a general table.

How to eliminate wrong answers

Option A is wrong because DeviceEvents is a general table for various event types, but it does not specifically focus on process creation with command-line arguments; it may contain some process-related events but not as comprehensive as DeviceProcessEvents. Option B is wrong because DeviceImageLoadEvents records image (DLL) load events, not process command lines. Option D is wrong because DeviceNetworkEvents records network connections, which would show the outbound connections but not the command-line arguments of the process that initiated them.

1178
MCQhard

Your organization uses Microsoft Defender XDR for threat hunting. You suspect a threat actor is using scheduled tasks for persistence. Which hunting query would you use in Microsoft 365 Defender advanced hunting to find newly created scheduled tasks?

A.DeviceEvents | where ActionType == 'ScheduledTaskCreated'
B.DeviceRegistryEvents | where RegistryKey contains 'Tasks'
C.DeviceProcessEvents | where FileName == 'schtasks.exe'
D.DeviceFileEvents | where FolderPath contains 'Tasks'
AnswerA

DeviceEvents records endpoint telemetry from Defender for Endpoint, and its ActionType field captures ScheduledTaskCreated when a new scheduled task is registered. Filtering on that value surfaces persistence activity directly, which is exactly what the hunting scenario requires.

Why this answer

Advanced hunting uses the DeviceEvents table to capture various security events, including scheduled task creation via the 'ScheduledTaskCreated' action type. Option A is correct because DeviceEvents with ActionType 'ScheduledTaskCreated' directly identifies newly created scheduled tasks. Option B (DeviceRegistryEvents) is incorrect because it captures registry modifications, and while scheduled tasks are stored in the registry, querying for 'Tasks' in the registry key is too broad and not specific to creation.

Option C (DeviceProcessEvents) is incorrect because 'schtasks.exe' is the command-line tool used to create scheduled tasks, but querying for process events would capture executions rather than the actual creation of tasks, and it may miss tasks created via other methods. Option D (DeviceFileEvents) is incorrect because it tracks file operations, and scheduled tasks are not typically represented as files in a folder; the 'Tasks' folder path might refer to the Windows Task Scheduler library, but file events for task files (like .job files) are not the primary way to detect creation.

1179
MCQhard

You are configuring Microsoft Sentinel to ingest logs from a third-party firewall via Syslog. The data connector shows 'Connected' but no events are being received. You have verified network connectivity and firewall configuration. What should you check next?

A.Validate that the Data Collection Rule (DCR) is properly configured to ingest the Syslog facility and severity.
B.Verify that the connector has the necessary OAuth permissions in Microsoft Entra ID.
C.Check that the user who configured the connector has the Microsoft Sentinel Contributor role.
D.Ensure the firewall is registered in Azure Policy as a compliant resource.
AnswerA

The Data Collection Rule (DCR) is the authoritative configuration that maps Syslog facility and severity filters to the Log Analytics workspace table. If the DCR's filters are too restrictive, omit the expected facility, or the DCR isn't correctly linked to the Azure Monitor Agent (AMA) and Data Collection Endpoint (DCE), events will be silently dropped. Validating the DCR is the first diagnostic step because misconfigurations here are the most common cause of missing Syslog ingestion.

Why this answer

When a Syslog data connector shows 'Connected' but no events are received, the most common cause is a misconfigured Data Collection Rule (DCR). The DCR defines which Syslog facilities and severities to collect; if it does not match the firewall's actual Syslog output (e.g., facility 'local0' with severity 'informational'), events will be filtered out before ingestion. Network connectivity and firewall configuration are already verified, so the DCR is the next logical check.

Exam trap

The trap here is that candidates assume 'Connected' means data is flowing, but in Syslog connectors, 'Connected' only indicates the agent can reach the Log Analytics workspace—the DCR's filtering logic is the hidden gate that stops events from being ingested.

How to eliminate wrong answers

Option B is wrong because Syslog data connectors do not use OAuth permissions; they rely on the Log Analytics agent or Azure Monitor Agent (AMA) and a DCR, not Microsoft Entra ID authentication. Option C is wrong because the connector configuration does not require the user to have the Microsoft Sentinel Contributor role; the connector setup uses the Log Analytics workspace permissions, and the role is irrelevant to event ingestion. Option D is wrong because Azure Policy compliance is unrelated to Syslog ingestion; firewalls are not registered in Azure Policy as resources, and policy compliance does not affect data flow from on-premises or third-party devices.

1180
MCQmedium

A company has enabled Microsoft Defender for Cloud on multiple Azure subscriptions. The security team wants to view a unified security score that aggregates the scores from all subscriptions. Which feature should they use?

A.Azure Policy compliance dashboard
B.Secure Score dashboard
C.Security alerts dashboard
D.Workload protection dashboard
AnswerB

The Secure Score dashboard in Microsoft Defender for Cloud is the correct place to view an aggregated security score because it consolidates the results of security recommendations and calculates a normalized score across all your subscriptions. It shows your current score, the maximum possible score, and the potential score increase if you remediate all recommended actions. This dashboard provides a single, unified metric that reflects your overall security posture, making it the ideal tool for the stated requirement.

Why this answer

The Secure Score dashboard in Microsoft Defender for Cloud aggregates the security scores from all selected subscriptions into a single, unified score. This allows the security team to view the overall security posture across multiple Azure subscriptions at a glance, based on the compliance status of security recommendations.

Exam trap

The trap here is that candidates often confuse the Secure Score dashboard with the Security alerts dashboard, thinking alerts contribute to the score, but the Secure Score is purely based on recommendation compliance, not active threats.

How to eliminate wrong answers

Option A is wrong because the Azure Policy compliance dashboard shows the compliance state of resources against assigned policies, not a unified security score. Option C is wrong because the Security alerts dashboard lists active security alerts and incidents, not aggregated security scores. Option D is wrong because the Workload protection dashboard focuses on the coverage and status of workload protection plans (e.g., Defender for Servers, Defender for SQL), not a consolidated security score.

1181
MCQhard

An analyst is investigating a sophisticated attack involving a compromised device. The analyst has identified a malicious process that spawned multiple child processes. The analyst wants to create a custom detection rule in Microsoft 365 Defender that alerts when a specific parent process creates a child process that makes an outbound network connection to any IP not in the organization's internal range. Which KQL query and rule type should the analyst use?

A.Create a custom detection rule (Advanced Hunting rule) with a query that joins DeviceProcessEvents and DeviceNetworkEvents, filtering for the parent process and external IP addresses
B.Create a scheduled rule in Sentinel and export the data from M365 Defender
C.Use a custom detection rule with DeviceEvents only
D.Use a Microsoft Defender for Endpoint custom detection rule (built-in) that already detects child process connections
AnswerA

A custom detection rule in Microsoft 365 Defender is the correct choice because it is built on the Advanced Hunting schema, where you can join DeviceProcessEvents and DeviceNetworkEvents on DeviceId and Timestamp. By filtering for the specific parent process and external IP addresses, the query captures child processes making outbound connections, and the scheduled rule can generate alerts and trigger automated response actions.

Why this answer

The analyst needs to correlate process creation events with network connection events across two separate tables (DeviceProcessEvents and DeviceNetworkEvents) in Advanced Hunting. A custom detection rule (Advanced Hunting rule) in Microsoft 365 Defender allows joining these tables to identify when a specific parent process spawns a child that makes an outbound connection to an external IP address, which is exactly the required detection logic.

Exam trap

The trap here is that candidates may think DeviceEvents contains all necessary telemetry or that a built-in rule already covers this specific scenario, but they must recognize that joining two distinct tables (DeviceProcessEvents and DeviceNetworkEvents) in an Advanced Hunting custom detection rule is required to correlate process creation with outbound network connections.

How to eliminate wrong answers

Option B is wrong because creating a scheduled rule in Sentinel and exporting data from M365 Defender is unnecessary and inefficient; the detection can be built natively within Microsoft 365 Defender using Advanced Hunting rules without exporting data. Option C is wrong because DeviceEvents alone do not contain network connection details (like destination IP addresses) needed to filter for external IPs; DeviceNetworkEvents is required for that data. Option D is wrong because there is no built-in custom detection rule in Microsoft Defender for Endpoint that specifically detects child process connections to external IPs; the analyst must create a custom rule.

1182
MCQmedium

Your organization uses Microsoft Defender for Cloud. You need to recommend a solution to automatically remediate misconfigurations in Azure VMs without manual intervention. What should you use?

A.Use Azure Advisor recommendations
B.Configure Azure Backup
C.Set up Update Management in Azure Automation
D.Enable 'Remediate' option in Defender for Cloud recommendations
AnswerD

The 'Remediate' option in Microsoft Defender for Cloud recommendations is the only choice that directly applies automated corrective actions to non-compliant resources. When you trigger it, Defender for Cloud often deploys an Azure Policy assignment with the DeployIfNotExists effect, which automatically reconfigures the resource to meet the security recommendation. This one-click operation fixes the misconfiguration at scale without requiring manual edits, which is exactly what the organization needs.

Why this answer

Microsoft Defender for Cloud provides a 'Remediate' button on security recommendations that can automatically apply the necessary configuration changes to Azure resources, such as VMs, without manual intervention. This feature leverages Azure Policy's 'deployIfNotExists' effect to enforce compliance by running remediation tasks at scale, directly addressing misconfigurations like open management ports or missing disk encryption.

Exam trap

The trap here is that candidates often confuse Azure Advisor's recommendations with Defender for Cloud's recommendations, not realizing that only Defender for Cloud offers the 'Remediate' button for automatic enforcement, while Advisor merely provides advisory guidance without automated action.

How to eliminate wrong answers

Option A is wrong because Azure Advisor provides best-practice recommendations for cost, performance, reliability, and security, but it does not offer an automatic remediation capability for misconfigurations; it only suggests changes that must be applied manually. Option B is wrong because Azure Backup is a data protection service for creating and managing backup copies of VMs, files, and workloads; it has no role in remediating security misconfigurations. Option C is wrong because Update Management in Azure Automation is specifically designed to manage OS updates and patches, not to fix broader security misconfigurations like network security group rules or encryption settings.

1183
MCQeasy

Your organization has recently deployed Microsoft Sentinel and Microsoft Defender XDR. You are tasked with configuring the environment to ensure that incidents created by Microsoft Defender for Cloud Apps are automatically synchronized to Microsoft Sentinel. The security operations team wants to manage all incidents from within Sentinel. You have already connected the Microsoft Defender XDR connector to Sentinel. However, you notice that incidents from Defender for Cloud Apps are not appearing in Sentinel. You verify that the Defender for Cloud Apps connector is not listed in the data connectors blade. What should you do to resolve this issue?

A.Enable the Microsoft Sentinel integration in the Defender for Cloud Apps portal.
B.Configure a data collection rule in Microsoft Purview to forward alerts to Sentinel.
C.Install the Microsoft Defender for Cloud Apps connector from Sentinel data connectors.
D.Ensure the Microsoft Defender XDR connector is configured to include Defender for Cloud Apps incidents.
AnswerD

The proper way to ingest Defender for Cloud Apps incidents is to ensure the Microsoft Defender XDR data connector is enabled in Sentinel and that the 'Microsoft Defender for Cloud Apps' incident table is checked in its configuration. This connector automatically synchronizes incidents from Defender XDR—which include alerts and incidents generated by Defender for Cloud Apps—into Sentinel without any additional setup. As long as the connector shows a connected status and the correct product is selected, Cloud Apps incidents will flow directly to Sentinel's 'Incidents' blade.

Why this answer

When Microsoft Defender XDR connector is enabled in Sentinel, it can ingest incidents from all Microsoft Defender products, including Defender for Cloud Apps, provided the connector's configuration includes the option to synchronize those incidents. Since the Defender for Cloud Apps connector is not listed separately, the correct approach is to verify and adjust the Microsoft Defender XDR connector's settings to include Defender for Cloud Apps incidents. Option D directly addresses this by ensuring the existing connector is configured to forward those incidents.

Exam trap

The trap here is that candidates assume each Microsoft Defender product requires its own dedicated data connector in Sentinel, when in fact the Microsoft Defender XDR connector serves as the unified ingestion point for all Defender incidents, including those from Defender for Cloud Apps.

How to eliminate wrong answers

Option A is wrong because enabling the Sentinel integration in the Defender for Cloud Apps portal is used to send alerts from Defender for Cloud Apps to Sentinel via a legacy method, but when the Microsoft Defender XDR connector is already connected, incidents flow through the unified Microsoft 365 Defender pipeline, not through a separate portal toggle. Option B is wrong because data collection rules in Microsoft Purview are used for managing data lifecycle and compliance, not for forwarding security alerts or incidents to Sentinel. Option C is wrong because the Defender for Cloud Apps connector is not listed in the data connectors blade; this indicates that incidents from Defender for Cloud Apps are ingested through the Microsoft Defender XDR connector, not through a standalone connector.

1184
MCQeasy

In Microsoft Defender for Cloud, what does the Secure Score represent?

A.The number of currently active security alerts.
B.The percentage of compliance with the Azure Security Benchmark.
C.The overall security posture of your resources, based on implemented security controls and recommendations.
D.The number of VMs that have been assessed for vulnerabilities.
AnswerC

The Secure Score is a percentage (0-100%) that quantifies how well your subscriptions and resources have implemented Microsoft's security best practices as recommendations. Each recommendation contributes points based on its associated security control and risk weight, so the score reflects your aggregate posture and helps prioritize remediation actions across all resource types.

Why this answer

The Secure Score in Microsoft Defender for Cloud is a numeric representation of your overall security posture, calculated based on the implementation of security controls and the remediation of recommendations. It aggregates the status of all assessed resources against security best practices, providing a single score that reflects how well you are protecting your workloads. This score helps prioritize actions to improve security, as each recommendation contributes a specific number of points toward the total possible score.

Exam trap

The trap here is that candidates often confuse the Secure Score with a simple compliance percentage or a count of alerts, but Microsoft specifically designed it as a posture metric that reflects the implementation of security controls, not just compliance with a single benchmark or the number of threats detected.

How to eliminate wrong answers

Option A is wrong because the Secure Score does not represent the number of active security alerts; active alerts are tracked separately in the Security Alerts dashboard and do not directly influence the score calculation. Option B is wrong because while the Secure Score is aligned with the Azure Security Benchmark, it is not a percentage of compliance with that benchmark; instead, it is a weighted score based on the implementation of security controls and recommendations across multiple benchmarks and standards. Option D is wrong because the Secure Score is not limited to VM vulnerability assessments; it encompasses all supported resource types (e.g., storage accounts, SQL servers, containers) and their associated security controls.

1185
MCQeasy

A SOC analyst wants to create a visual dashboard in Microsoft Sentinel to monitor sign-in activity trends over the past 30 days. Which feature should the analyst use?

A.Analytics rules
B.Workbooks
C.Playbooks
D.Threat Intelligence
AnswerB

Sentinel workbooks are interactive reporting canvases built on Azure Monitor Workbooks, designed specifically to visualize log data with KQL-backed tiles, charts, grids, and step groups. They support parameters, custom time ranges, and automatic refresh, making them the appropriate choice for assembling a SOC dashboard from ingested signals. A workbook can even query the Sentinel Analytics, Alert, and ThreatIntelligenceIndicator tables and render them in a unified view.

Why this answer

Workbooks in Microsoft Sentinel provide a flexible canvas for creating custom visual dashboards using Azure Monitor Workbooks. They allow the analyst to query Log Analytics workspaces (e.g., SigninLogs table) and render time-series charts, trend lines, and other visualizations to monitor sign-in activity over the past 30 days. This is the correct feature for building a visual dashboard.

Exam trap

The trap here is that candidates often confuse Workbooks with Analytics rules, thinking that detection rules can also produce visual dashboards, but Analytics rules are solely for alert generation, not visualization.

How to eliminate wrong answers

Option A is wrong because Analytics rules are used to generate alerts and incidents based on threat detection logic, not to create visual dashboards or trend charts. Option C is wrong because Playbooks are automated response workflows (based on Azure Logic Apps) triggered by alerts or incidents, not a dashboarding or visualization tool. Option D is wrong because Threat Intelligence is a data source and management feature for ingesting and correlating threat indicators, not a feature for building visual dashboards.

1186
MCQmedium

A security analyst is investigating a phishing campaign targeting multiple users. The analyst has identified a malicious attachment with a known SHA256 hash. The analyst needs to find all email messages that were delivered to any user and contained this specific attachment. Which advanced hunting table should the analyst query in Microsoft 365 Defender to obtain the message IDs of emails containing the attachment?

A.EmailEvents
B.EmailAttachmentInfo
C.EmailPostDeliveryEvents
D.DeviceFileEvents
AnswerB

EmailAttachmentInfo is correct because it stores each attachment's file name, size, and SHA256 hash, along with the parent email's NetworkMessageId in Microsoft 365 Defender's advanced hunting schema. Querying this table with a known malicious SHA256 returns all NetworkMessageIds for messages that contained that exact file, allowing you to identify every recipient in the phishing campaign. You can then join EmailEvents to gather sender, subject, and delivery status details for further analysis.

Why this answer

The EmailAttachmentInfo table in Microsoft 365 Defender advanced hunting contains metadata about attachments on email messages, including the SHA256 hash of each attachment. By querying this table with the known malicious SHA256 hash, the analyst can retrieve the NetworkMessageId values for all emails that contained that specific attachment, regardless of whether the email was delivered or blocked.

Exam trap

The trap here is that candidates often confuse EmailAttachmentInfo with EmailEvents, mistakenly thinking that EmailEvents contains attachment details, when in fact EmailEvents only provides delivery-level metadata and requires a join to access attachment-specific information.

How to eliminate wrong answers

Option A is wrong because EmailEvents contains information about email delivery events (e.g., send, receive, deliver, fail) but does not include attachment metadata such as SHA256 hashes; it only provides the NetworkMessageId, which can then be joined with EmailAttachmentInfo. Option C is wrong because EmailPostDeliveryEvents records actions taken after delivery (e.g., user clicks, ZAP actions) and does not contain attachment hash information. Option D is wrong because DeviceFileEvents tracks file events on endpoints (e.g., file creation, modification) and is not related to email attachments in transit; it would only show files after they have been saved to a device.

1187
MCQmedium

Your organization uses Microsoft Defender XDR. You need to ensure that when a user reports a phishing email in Outlook, it automatically triggers an investigation in Microsoft Defender XDR. What should you configure?

A.Enable user-reported message settings in Microsoft Defender for Office 365 and configure automated investigation.
B.Create a playbook in Microsoft Sentinel triggered by a custom connector.
C.Configure a data loss prevention policy in Microsoft Purview.
D.Set up a session policy in Microsoft Defender for Cloud Apps.
AnswerA

Enabling user-reported message settings in Microsoft Defender for Office 365 ingests reports from the Outlook Report button into the system. When configured with automated investigation, each reported message automatically triggers an AIR (Automated Investigation and Response) workflow that runs detonation, threat hunting, and recommended actions. This is the only option that directly connects the user report to a native investigation in Microsoft Defender XDR, matching the requirement.

Why this answer

Enabling user-reported message settings in Microsoft Defender for Office 365 allows users to report phishing emails directly from Outlook. When combined with automated investigation and response (AIR) policies, this triggers an automatic investigation in Microsoft Defender XDR, leveraging the unified incident and alerting pipeline to analyze the reported message and associated threats.

Exam trap

The trap here is that candidates may confuse the native Defender for Office 365 user-reported message settings with a custom Sentinel playbook, overlooking that the question specifically requires automatic investigation in Defender XDR, not a separate SIEM orchestration.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel is a SIEM for broader security analytics, not the native tool for triggering automated investigations from Outlook user reports; a custom connector and playbook would be an overly complex, non-native workaround. Option C is wrong because Data Loss Prevention (DLP) policies in Microsoft Purview are designed to prevent data exfiltration, not to initiate phishing investigations. Option D is wrong because session policies in Microsoft Defender for Cloud Apps control app access and session-level controls (e.g., conditional access app control), not the ingestion of user-reported emails into Defender XDR investigations.

1188
Multi-Selecthard

Which THREE of the following are valid incident management capabilities in Microsoft Sentinel? (Choose three.)

Select 3 answers
A.Assign incidents to analysts or teams
B.Classify incidents as true positive, false positive, or benign positive
C.Merge related incidents into a single incident
D.Create playbooks to automate incident response
E.Create workbooks to visualize incident trends
AnswersA, B, C

Assigning incidents to analysts or teams is a core incident management capability in Microsoft Sentinel. Through the Incident blade, an analyst can set the Owner and assign the incident to a specific person or group, establishing accountability and routing for follow-up actions. Assignment does not change incident state by itself but ensures each case has a clear point of contact.

Why this answer

A is correct because Microsoft Sentinel allows incident owners to be assigned directly to an analyst or a team via the 'Owner' field in the incident details pane. This assignment is used for tracking responsibility, SLA enforcement, and escalation workflows within the Security Operations (SecOps) lifecycle.

Exam trap

The trap here is that candidates confuse automation (playbooks) and reporting (workbooks) with direct incident management actions, but Microsoft Sentinel explicitly separates incident management capabilities (assignment, classification, merging) from automation and visualization features in the exam blueprint.

1189
MCQmedium

A company uses Microsoft Defender for Cloud to protect their Azure resources. They have enabled the enhanced security features on a subscription that contains several Azure SQL databases. They want to be alerted if a user attempts to perform SQL injection attacks against these databases. Which Defender for Cloud plan specifically enables SQL injection detection alerts?

A.Defender for Servers
B.Defender for SQL
C.Defender for App Service
D.Defender for Storage
AnswerB

Defender for SQL is the dedicated plan that protects Azure SQL Database, SQL Managed Instance, and SQL on Azure VMs by surfacing database-level threats. It analyzes SQL audit logs and query activity to detect SQL injection attempts, anomalous access patterns, brute-force attacks, and other database-specific vulnerabilities. This plan also provides vulnerability assessment and data discovery/classification, making it the only option here that directly addresses the requirement for SQL security alerts.

Why this answer

Defender for SQL is the specific Microsoft Defender for Cloud plan that provides SQL-specific threat detection, including alerts for SQL injection attacks. This plan monitors SQL databases for anomalous activities such as SQL injection attempts, brute-force attacks, and unusual access patterns by analyzing query logs and audit records. Enabling Defender for SQL on the subscription activates these detection capabilities for Azure SQL databases, making it the correct choice for the scenario.

Exam trap

The trap here is that candidates may confuse Defender for App Service with SQL injection detection because App Service can host web applications that are vulnerable to SQL injection, but the question specifically asks for the plan that enables detection alerts against the SQL databases themselves, not the web layer.

How to eliminate wrong answers

Option A is wrong because Defender for Servers focuses on protecting virtual machines and servers, not Azure SQL databases, and does not include SQL injection detection. Option C is wrong because Defender for App Service is designed to protect web applications and APIs running on Azure App Service, not SQL databases, and its threat detection centers on web application attacks like DDoS or cross-site scripting. Option D is wrong because Defender for Storage protects Azure Blob Storage, Azure Files, and Azure Data Lake Storage from threats like malware uploads or anonymous access, but it does not monitor SQL databases or detect SQL injection attacks.

1190
MCQeasy

In Microsoft 365 Defender, after an automated investigation completes, where can an analyst review the specific remediation actions that were taken (e.g., file quarantine, device isolation)?

A.Incident timeline
B.Action center
C.Threat analytics
D.Device inventory
AnswerB

The Action center is the centralized, cross-tenant hub in Microsoft 365 Defender that records every remediation action generated by automated investigations (AIR) as well as manual response activities. It shows the action's status (pending, approved, or rejected), the entity it targets (file, device, email, URL, etc.), and the investigation it belongs to, making it the definitive location to review, approve, or reject actions after an automated investigation finishes.

Why this answer

The Action center in Microsoft 365 Defender is the centralized location where all manual and automated remediation actions (such as file quarantine, device isolation, and process termination) are tracked and can be reviewed or approved. After an automated investigation completes, the specific actions taken are recorded in the Action center's history tab, allowing analysts to see exactly what was executed and the outcome. This is distinct from the Incident timeline, which shows alerts and events but not the detailed remediation action records.

Exam trap

The trap here is that candidates confuse the Incident timeline (which shows investigation steps and alerts) with the Action center (which is the sole location for reviewing and managing remediation actions), leading them to select the Incident timeline instead of the correct Action center.

How to eliminate wrong answers

Option A is wrong because the Incident timeline displays alerts, events, and investigation steps in chronological order, but it does not provide a dedicated view of remediation actions taken; those actions are logged in the Action center. Option C is wrong because Threat analytics provides threat intelligence, vulnerability reports, and mitigation guidance, not a record of specific remediation actions performed on endpoints. Option D is wrong because Device inventory lists managed devices and their properties (e.g., OS, health status) but does not show remediation actions like file quarantine or device isolation.

1191
Multi-Selecteasy

Which TWO data sources in Microsoft Sentinel are most valuable for hunting for command-and-control (C2) communications? (Choose two.)

Select 2 answers
A.Windows Event Logs (e.g., Security, System)
B.Azure Activity log
C.DNS logs (e.g., from DNS servers or Azure DNS Analytics)
D.Syslog from Linux servers
E.Network traffic logs (e.g., from firewalls or network security groups)
AnswersC, E

DNS logs, whether collected from internal DNS servers or via Azure DNS Analytics, are a top-tier C2 data source because malware frequently uses DNS to resolve the domain name of its command-and-control server. Every query name, client IP, and timestamp is captured, allowing defenders to correlate against threat intelligence feeds for known malicious domains or detect domain-generation-algorithm (DGA) patterns. This visibility into the resolution process is essential because C2 often leverages a legitimate-looking domain rather than a hard-coded IP address.

Why this answer

DNS logs (C) are highly valuable for C2 hunting because malware frequently uses DNS for domain generation algorithms (DGA), DNS tunneling, and resolving C2 domains, and Sentinel can ingest DNS server logs or Azure DNS Analytics to detect anomalous queries. Network traffic logs (E) from firewalls or NSGs are equally valuable because they reveal outbound connections to known malicious IPs, beaconing patterns, unusual ports, and data exfiltration flows that characterize C2 channels. Windows Event Logs (A) focus on host-level authentication, process, and service activity rather than the network communication patterns central to C2 detection.

Azure Activity log (B) records control-plane operations on Azure resources, not C2 traffic. Syslog from Linux servers (D) provides host and application events but does not directly expose the DNS or network connection metadata most useful for identifying C2.

Exam trap

SC-200 often tests whether candidates confuse control-plane logs (Azure Activity) with data-plane network telemetry — the trap is selecting Azure Activity log thinking it captures outbound traffic, when it only records resource management operations.

1192
MCQeasy

A company uses Microsoft Defender for Cloud to secure its Azure environment. The security team wants to receive notifications via email whenever a high-severity security alert is generated. What should they configure in Defender for Cloud?

A.Enable the 'Continuous Export' feature to send alerts to a Log Analytics workspace.
B.Configure an alert rule in Azure Monitor.
C.Set up email notifications for high-severity alerts in the Defender for Cloud environment settings.
D.Create an automation rule in Microsoft Sentinel.
AnswerC

In Microsoft Defender for Cloud, the correct way to receive email notifications for high-severity alerts is to navigate to the environment settings, select the subscription's settings, and then configure the email notifications pane. There you can specify security contact email addresses and choose the severity levels (e.g., high severity) for which notifications should be sent. This native feature is purpose-built for directly alerting security teams via email when critical vulnerabilities are detected, ensuring timely awareness without relying on external workflows.

Why this answer

Defender for Cloud provides a built-in email notification configuration specifically for security alerts. By navigating to the 'Environment settings' for the subscription or management group, then selecting 'Email notifications', you can enable and configure alerts to be sent to specified recipients when high-severity alerts are generated. This is the direct, purpose-built method for email notification of Defender for Cloud alerts without requiring additional services.

Exam trap

The trap here is that candidates often confuse the purpose of 'Continuous Export' (which is for data export, not direct notification) or assume that Azure Monitor alert rules are the universal mechanism for all Azure alerts, overlooking Defender for Cloud's dedicated email notification settings.

How to eliminate wrong answers

Option A is wrong because 'Continuous Export' streams security alerts and recommendations to a Log Analytics workspace or Event Hubs for integration with other tools (e.g., SIEM), but it does not directly send email notifications; it requires additional logic (e.g., Azure Monitor alerts or Logic Apps) to trigger emails. Option B is wrong because Azure Monitor alert rules are designed for metrics, logs, and activity logs, not for Defender for Cloud security alerts; while you can create a custom alert rule using Log Analytics data if Continuous Export is enabled, this is an indirect, extra-step approach, not the native configuration for Defender for Cloud email notifications. Option D is wrong because automation rules in Microsoft Sentinel are used to automate incident management and response within Sentinel, not to configure email notifications for Defender for Cloud alerts; Sentinel can ingest Defender for Cloud alerts, but the email notification setting is a Defender for Cloud feature, not a Sentinel one.

1193
Multi-Selecteasy

Which TWO tables in Microsoft Defender XDR advanced hunting are most useful for detecting data exfiltration attempts? (Select two.)

Select 2 answers
A.DeviceProcessEvents
B.DeviceNetworkEvents
C.CloudAppEvents
D.EmailEvents
E.DeviceInfo
AnswersB, C

DeviceNetworkEvents records outbound connections with remote IP, port and initiating process, exposing transfers to unfamiliar destinations or large uploads. That network-layer visibility is what reveals exfiltration traffic leaving endpoints, complementing cloud-side logging rather than duplicating it.

Why this answer

DeviceNetworkEvents (B) is correct because it records outbound network connections from endpoints, including RemoteIP, RemotePort, RemoteUrl, and bytes sent/received, which lets you spot anomalous transfers to external or untrusted destinations indicative of exfiltration. CloudAppEvents (C) is correct because it captures activity in cloud applications and services (for example file downloads, sharing, and uploads via Microsoft 365 and other connected apps), which is where data is commonly staged and moved out. DeviceProcessEvents (A) shows process creation and command lines, which may reveal staging or archiving tools but not the actual data transfer, so it is less directly useful.

EmailEvents (D) covers mail flow and delivery metadata, which is relevant to phishing or email-based leaks but not general exfiltration channels. DeviceInfo (E) is only static asset and configuration inventory, so it contains no transfer activity to detect.

Exam trap

SC-200 often tests whether candidates can map a threat scenario to the correct telemetry table — the trap is choosing process or email tables because they are familiar, when exfiltration is best evidenced by network and cloud activity.

1194
MCQhard

An analyst runs this advanced hunting query to investigate suspicious command-line activity. Which type of activity is this query most likely detecting?

A.Execution of obfuscated scripts via encoded commands
B.Data exfiltration to external IPs
C.Privilege escalation attempts
D.Port scanning activity
AnswerA

Encoded commands, typically Base64 strings passed to PowerShell or command shells, are the signature this hunting query targets. Decoding and inspecting those command lines reveals obfuscated script execution, matching the query's focus on suspicious command-line activity.

Why this answer

The query likely searches for command lines containing encoded or obfuscated script indicators, such as 'powershell -enc' or Base64-encoded commands, which are common in malicious script execution. Advanced hunting in Microsoft 365 Defender uses Kusto Query Language (KQL) to query device process events. Detecting encoded commands is a typical technique to identify obfuscated scripts that evade detection.

Exam trap

SC-200 often tests the ability to interpret KQL queries and map them to attack techniques, so candidates might confuse encoded command execution with other attack types like exfiltration or privilege escalation.

How to eliminate wrong answers

Option B is wrong because data exfiltration queries typically look for network connections to external IPs or large data transfers, not command-line encoding. Option C is wrong because privilege escalation queries focus on processes like 'runas' or token manipulation, not encoded commands. Option D is wrong because port scanning queries involve network events like multiple connection attempts to different ports, not command-line arguments.

1195
MCQhard

A SOC analyst creates a scheduled analytics rule in Microsoft Sentinel that uses the following KQL query to detect impossible travel: SigninLogs | where TimeGenerated > ago(1d) | summarize Countries = make_set(Location) by UserPrincipalName | where array_length(Countries) > 1 However, the analyst notices that the rule generates too many false positives for users who travel legitimately. What is the best way to refine the rule to reduce false positives without missing actual impossible travel?

A.Add a condition to filter out VPN IP addresses from the Log Analytics workspace.
B.Instead of using make_set, use the dcount() function to estimate distinct countries.
C.Use the time series anomaly detection function series_decompose() on the signin data.
D.Modify the query to include a time difference condition using the partition operator or a join to find sign-ins from different countries within a short time window.
AnswerD

This is correct because it introduces the missing temporal constraint: by partitioning sign-ins by user (or self-joining the sign-in table), the query can sort events by timestamp and compute the time difference between consecutive sign-ins where the country changes. A threshold, for example less than 60 minutes for countries that are thousands of miles apart, makes the rule detect actual impossible travel rather than merely multiple countries in a day. The partition operator or join with a time-diff filter enables the scheduled analytics rule to alert only on geographically inconsistent rapid transitions.

Why this answer

Impossible travel detection requires correlating sign-ins from different geographic locations within a time window that is too short for physical travel. By using the partition operator or a join to compare timestamps between sign-ins from different countries, the query can distinguish between legitimate sequential travel (e.g., a user flying from New York to London over 8 hours) and truly impossible simultaneous sign-ins (e.g., sign-ins from New York and London within 30 minutes). This reduces false positives while still catching actual impossible travel.

Exam trap

The trap here is that candidates may think filtering by VPN or using aggregation functions like make_set or dcount() is sufficient, but they fail to recognize that impossible travel detection fundamentally requires a time-based correlation between geographically distinct sign-in events.

How to eliminate wrong answers

Option A is wrong because filtering out VPN IP addresses does not address the core issue of legitimate travel; VPNs may be used for remote access and do not inherently indicate impossible travel, and this approach could miss actual threats where an attacker uses a VPN to mask their location. Option B is wrong because using dcount() instead of make_set only changes how distinct countries are counted (approximate vs. exact) and does not add any time-based logic to differentiate between sequential and simultaneous sign-ins. Option C is wrong because series_decompose() is designed for time series anomaly detection on numeric metrics (e.g., count of sign-ins over time), not for correlating geographic locations across user sign-in events to detect impossible travel.

1196
Multi-Selecteasy

Which TWO are common techniques used during threat hunting to identify suspicious behavior in Microsoft Defender XDR?

Select 2 answers
A.Updating antivirus signatures.
B.Searching for known indicators of compromise (IOCs).
C.Applying anomaly detection models to user behavior.
D.Configuring mail flow rules in Exchange Online.
E.Performing vulnerability scans on endpoints.
AnswersB, C

Matching known IOCs — file hashes, domains, IP addresses — against telemetry quickly flags artefacts already tied to confirmed campaigns. It is a core hunting technique because it converts threat intelligence into concrete queries across Defender XDR tables, surfacing compromised hosts without waiting for alerts.

Why this answer

Option B is correct because threat hunting in Microsoft Defender XDR commonly begins with searching for known indicators of compromise (IOCs) such as malicious file hashes, IP addresses, domains, or URLs using advanced hunting queries (KQL) against tables like DeviceNetworkEvents and DeviceFileEvents. Option C is correct because applying anomaly detection models to user behavior — for example, identifying unusual sign-in patterns or atypical activity via Microsoft Defender for Identity and Microsoft Sentinel UEBA — is a core proactive hunting technique for uncovering threats that signature-based detection misses. Option A is not a hunting technique; updating antivirus signatures is a routine preventive maintenance task performed by Defender Antivirus, not an investigative method.

Option D is incorrect because configuring mail flow rules in Exchange Online is an administrative mail-handling action, not a threat-hunting technique. Option E is incorrect because vulnerability scans identify unpatched weaknesses rather than actively hunting for suspicious or malicious behavior in Defender XDR telemetry.

Exam trap

The trap is confusing threat hunting with other security operations like vulnerability scanning or antivirus updates; candidates must recognize that threat hunting is proactive and intelligence-driven, not routine maintenance.

1197
Multi-Selectmedium

Which of the following resource types are supported by Microsoft Defender for Cloud's workload protection plans? (Select all that apply.) (Choose 3.)

Select 3 answers
A.Azure virtual machines
B.Azure SQL databases
C.On-premises servers connected via Azure Arc
D.Azure Logic Apps
AnswersA, B, C

Microsoft Defender for Cloud's Defender for Servers plan natively integrates with Azure virtual machines, offering a comprehensive suite of protections that include file integrity monitoring, just-in-time VM access, adaptive application controls, and integrated threat detection powered by Microsoft Defender for Endpoint. The plan also facilitates vulnerability assessment by continuously scanning VM operating systems for missing patches and misconfigurations, making Azure VMs a primary and fully supported workload type.

Why this answer

Microsoft Defender for Cloud's workload protection plans support Azure virtual machines by providing integrated threat detection and advanced security features like just-in-time VM access, file integrity monitoring, and vulnerability assessments. These capabilities leverage the Microsoft Monitoring Agent or Azure Monitor Agent to analyze security events and detect suspicious activities within the VM's operating system and network traffic.

Exam trap

The trap here is that candidates often assume all Azure resource types are covered by the same workload protection plan, but Microsoft specifically scopes these plans to compute, data, and hybrid workloads, excluding serverless or integration services like Logic Apps which require separate Defender plans.

1198
MCQeasy

You are a security analyst at a company that uses Microsoft Defender for Cloud Apps. You receive an alert that an anomalous activity was detected from a user's device. You need to investigate the activity to determine if it is a true positive. What should you do first?

A.Use Microsoft Power BI to analyze user activity data.
B.In the Microsoft Defender for Cloud Apps portal, open the alert and then click 'View activity' to see the detailed activity log.
C.Open the user's page in Microsoft Entra ID to review sign-in logs.
D.Create an IP address range policy to block the user's IP.
AnswerB

In Microsoft Defender for Cloud Apps, alerts are backed by discrete activity records captured via API connectors and conditional access app control. Opening the alert and clicking 'View activity' takes you to the Activity log with a filter pre-applied to that exact event, showing user, IP address, user agent, device, cloud app, action, and result. This is the native investigation path designed for alert triage, allowing you to pivot to adjacent activities, related alerts, or governance actions without leaving the portal. It directly answers who did what, from where, when, and with what outcome, which is exactly what an analyst needs for this alert.

Why this answer

The first step in investigating an anomalous activity alert in Microsoft Defender for Cloud Apps is to open the alert and click 'View activity' to examine the detailed activity log. This log provides the raw telemetry—such as IP address, user agent, timestamp, and activity type—needed to determine if the behavior is malicious or benign. Without reviewing this evidence, you cannot make an informed judgment about the alert's validity.

Exam trap

The trap here is that candidates confuse the investigation phase with the remediation phase, incorrectly choosing to block the IP (Option D) or review sign-in logs (Option C) before examining the actual activity details that confirm the threat.

How to eliminate wrong answers

Option A is wrong because Microsoft Power BI is a business analytics tool for visualizing data, not a security investigation interface; it cannot directly access the granular activity logs within Defender for Cloud Apps alerts. Option C is wrong because reviewing sign-in logs in Microsoft Entra ID only shows authentication events, not the full activity context (e.g., file downloads, app permissions) that Defender for Cloud Apps captures for anomaly detection. Option D is wrong because creating an IP address range policy to block the user's IP is a reactive remediation step, not a first investigative action; you must first confirm the activity is malicious before applying blocking policies.

1199
MCQmedium

Your organization has deployed Microsoft Sentinel and configured a workspace with data connectors for Microsoft 365 Defender, Azure Activity, and Office 365. You need to ensure that security incidents are automatically assigned to the appropriate analyst based on the incident type. What should you configure?

A.Create a playbook triggered by incident creation that assigns the incident to a user based on the incident title.
B.Add a watchlist that maps incident types to analyst email addresses and configure a scheduled analytics rule.
C.Create an automation rule that runs when an incident is created, with conditions on the incident title, and an action to assign the incident to a specific owner.
D.Configure a Microsoft 365 Defender incident assignment rule in the Microsoft 365 Defender portal.
AnswerC

Automation rules are the built-in incident orchestration mechanism in Microsoft Sentinel, and one can be configured to trigger whenever an incident is created. The rule can evaluate a condition on the incident's title, such as 'title contains phishing,' and then execute the 'Assign incident to owner' action, specifying an Azure AD user or group as the owner. This happens natively without invoking external workflows, providing instant, deterministic assignment that matches the requirement exactly.

Why this answer

Automation rules in Microsoft Sentinel allow you to define conditions (e.g., incident title containing specific keywords) and actions (e.g., assign incident to a specific owner) that run automatically when an incident is created. This directly meets the requirement to assign incidents to the appropriate analyst based on incident type without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks or think that Microsoft 365 Defender incident assignment rules can manage all Sentinel incidents, but automation rules are the correct native mechanism for incident assignment within Sentinel across all data connectors.

How to eliminate wrong answers

Option A is wrong because playbooks triggered by incident creation can assign incidents, but they require custom logic and are more complex than necessary; automation rules provide a simpler, native way to assign incidents based on conditions. Option B is wrong because watchlists are used for correlation and enrichment in analytics rules, not for assigning incidents; scheduled analytics rules generate alerts, not incidents, and cannot assign ownership. Option D is wrong because Microsoft 365 Defender incident assignment rules apply only to incidents generated within the Microsoft 365 Defender portal, not to incidents ingested into Microsoft Sentinel from other connectors like Azure Activity or Office 365.

1200
Multi-Selectmedium

Which TWO actions should an analyst take when a confirmed ransomware incident is detected on multiple endpoints? (Choose TWO.)

Select 2 answers
A.Run a full antivirus scan on all endpoints.
B.Isolate affected endpoints using Microsoft Defender for Endpoint.
C.Block known malicious IP addresses and domains in the firewall.
D.Disconnect network cables but leave endpoints powered on.
E.Shut down all affected endpoints to prevent data loss.
AnswersB, C

Immediately contains the threat by isolating devices.

Why this answer

Microsoft Defender for Endpoint's device isolation feature immediately severs all network communication (both inbound and outbound) from the affected endpoint while keeping the device powered on for forensic analysis. This containment action prevents lateral movement and further encryption of data across the network, which is critical during a ransomware incident.

Exam trap

The trap here is that candidates often confuse 'isolation' with 'shutdown' or 'disconnect', not realizing that isolation preserves forensic data and allows remote management, while shutdown destroys volatile evidence and may accelerate data loss.

Page 15

Page 16 of 18

Page 17