Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 1201–1275

1303 questions total · 18pages · All types, answers revealed

Page 16

Page 17 of 18

Page 18
1201
MCQeasy

Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the purpose of the query?

A.To list all incidents in the last 7 days
B.To count alerts by severity over the last week
C.To find the most recent high-severity alert
D.To identify hunting results
AnswerB

The query filters SecurityAlert records to the last seven days using the TimeGenerated field and then uses summarize to count rows grouped by AlertSeverity, returning one row per severity value with a count. This directly answers how many low, medium, high, and informational alerts occurred in that window. It is the intended purpose of this KQL statement.

Why this answer

The KQL query uses the `SecurityAlert` table and summarizes alerts by `AlertSeverity` using the `count()` aggregation function. The `where TimeGenerated > ago(7d)` filter restricts results to the last 7 days, and the `project` clause outputs only the severity and count columns. This directly produces a count of alerts grouped by severity over the last week, matching option B.

Exam trap

The SC-200 exam often tests the distinction between the `SecurityAlert` table (alerts) and the `SecurityIncident` table (incidents), and candidates mistakenly interpret any time-filtered count query as 'listing incidents' or 'finding the most recent alert' without recognizing the aggregation and projection logic.

How to eliminate wrong answers

Option A is wrong because the query queries the `SecurityAlert` table (alerts), not the `SecurityIncident` table (incidents), and it counts alerts rather than listing incidents. Option C is wrong because the query summarizes counts by severity, not filtering for the single most recent high-severity alert; there is no `top 1` or `sort by TimeGenerated` to isolate the latest alert. Option D is wrong because hunting results are stored in the `HuntingBookmark` table or generated via custom hunting queries, not the `SecurityAlert` table, and the query performs a simple aggregation, not a hunting operation.

1202
MCQhard

You are handling an incident where a user's account was used to access sensitive data from an unusual location. Microsoft Entra ID Identity Protection flagged the sign-in as risky. You need to determine if the account is compromised. Which investigation step should you perform first?

A.Block the user from signing in
B.Force a password reset for the user
C.Check if the device used is managed by Intune
D.Review the sign-in details and compare with the user's typical behavior
AnswerD

Reviewing the sign-in details and comparing them with the user's typical behavior is the correct initial triage action because Entra ID sign-in logs contain rich data—client IP, latitude/longitude, user agent, authentication method, device ID, and risk labels (e.g., impossible travel, unfamiliar sign-in properties, anonymized IP)—that can be correlated against the user's historical baseline. This behavioral analytics approach validates whether the sign-in is truly anomalous before any containment steps are taken, which is consistent with the 'identify-scope-contain' incident response lifecycle. Without this evidence-based review, actions like resetting credentials or blocking the account would be premature and potentially misguided, either disrupting a legitimate sign-in or failing to address a real compromise.

Why this answer

Before taking any remediation action, you should first review the sign-in details and compare them with the user's typical behavior to determine if the account is actually compromised. This investigation step provides context and helps avoid unnecessary disruptions. Only after confirming a compromise should you proceed with actions like blocking or password reset.

Exam trap

The trap is jumping to remediation actions (block, reset password) before completing the investigation; candidates may think immediate action is best, but the question asks for the first step in determining if the account is compromised.

How to eliminate wrong answers

Option A is wrong because blocking the user from signing in is a remediation step that should be taken only after confirming a compromise; doing it first could disrupt legitimate user access. Option B is wrong because forcing a password reset is also a remediation action that may be premature without investigation. Option C is wrong because checking if the device is managed by Intune is a useful data point but not the first step; it is part of the broader investigation into sign-in details and behavior.

1203
MCQeasy

Your team uses Microsoft Defender for Endpoint to hunt for signs of credential theft. You want to query for events where a process accesses the LSASS process memory. Which event type should you look for?

A.Process access (Event 4656)
B.Network connection (Event 5156)
C.Registry modification (Event 4657)
D.Process creation (Event 4688)
AnswerA

Process access events, recorded as Event 4656, capture when one process opens a handle to another with specific access rights. LSASS credential dumping appears here because tools request read access to lsass.exe memory, matching the hunting requirement.

Why this answer

Credential theft via LSASS memory access is captured by Windows Security Event ID 4656 (and its companion 4663), which logs handle requests to objects including processes. Defender for Endpoint surfaces this as 'Process access' events, making it the correct event type to query for LSASS access.

Exam trap

The trap is confusing process access (4656) with process creation (4688) — candidates often pick 4688 because they think 'process' is the key word, but the question asks about memory access, which is a handle/object access event.

How to eliminate wrong answers

Option B is wrong because Event 5156 logs Windows Filtering Platform network connections, which is unrelated to process memory access. Option C is wrong because Event 4657 logs registry value modifications, not process handle requests. Option D is wrong because Event 4688 logs process creation, which would show a tool like Mimikatz launching but not the actual LSASS memory access.

1204
Multi-Selecteasy

You are managing Microsoft Defender for Cloud Apps. Which TWO actions can be performed using the Microsoft Defender XDR integration?

Select 2 answers
A.Quarantine malicious emails.
B.Investigate user activities across cloud apps.
C.Govern discovered apps with access policies.
D.Manage device compliance policies in Microsoft Intune.
E.Onboard devices to Microsoft Defender for Endpoint.
AnswersB, C

Defender for Cloud Apps collects activity log from connected cloud apps, such as Office 365, AWS, and Google Workspace, and presents them in a unified investigation experience. Analysts can search a user's activity timeline, cross-correlate with alerts from Microsoft Defender XDR, and trace the scope of a compromise across multiple SaaS services. This investigation capability directly addresses security incidents that span cloud applications, making it a core function of a CASB.

Why this answer

Microsoft Defender XDR integration with Defender for Cloud Apps enables cross-domain investigation of user activities across cloud apps, leveraging signals from Microsoft 365 Defender to correlate events like sign-ins, file downloads, and admin actions. This allows security analysts to trace a user's behavior across SaaS applications (e.g., SharePoint, OneDrive, Teams) without switching consoles, using the unified incidents and alerts in the Microsoft 365 Defender portal.

Exam trap

The trap here is that candidates confuse the scope of Defender for Cloud Apps with broader Microsoft 365 security features, assuming it can perform email quarantine (A) or endpoint management (D, E) when those actions belong to separate products like Defender for Office 365 and Intune.

1205
Multi-Selectmedium

Your organization uses Microsoft Sentinel with the Azure Activity connector. Which TWO actions should you take to ensure that all subscription-level activity logs are being ingested into Sentinel?

Select 2 answers
A.Install the Azure Activity solution from the content hub.
B.Enable diagnostic settings on each subscription to stream logs to the Sentinel Log Analytics workspace.
C.Assign the 'Reader' role to the Sentinel managed identity on each subscription.
D.Configure the Azure Activity data connector to include all subscriptions.
E.Use the Azure Policy initiative to deploy the connector.
AnswersC, D

The Sentinel workspace's managed identity must be assigned the Reader role on each subscription that will contribute activity logs. This role allows the Azure Activity data connector to call the Azure Monitor Activity Log API and retrieve subscription-level audit events. Without this permission grant, the connector will show success but collect zero records, or will fail authentication when polling for new activity.

Why this answer

The Azure Activity data connector uses a managed identity to read subscription-level activity logs. Assigning the 'Reader' role to that managed identity on each subscription grants it the necessary permissions to access and ingest the logs into Sentinel. Without this role assignment, the connector cannot retrieve the activity data, even if the connector is configured.

Exam trap

The trap here is that candidates often confuse the Azure Activity connector's requirement for a managed identity role assignment with the diagnostic settings method used by other data connectors, leading them to incorrectly select option B.

1206
MCQeasy

A security analyst is investigating a malware incident on an endpoint using Microsoft 365 Defender. The analyst wants to see all processes that were created on the device in the last hour, including the command line arguments. Which advanced hunting table should they query?

A.DeviceProcessEvents
B.DeviceNetworkEvents
C.DeviceFileEvents
D.DeviceRegistryEvents
AnswerA

DeviceProcessEvents records process creation on endpoints, capturing the initiating and created process names, account, timestamp, and full command line arguments. Querying it filtered by Timestamp over the last hour returns exactly the process lineage the analyst needs, satisfying the requirement to inspect command line arguments for recent process creations.

Why this answer

The DeviceProcessEvents table in Microsoft 365 Defender's advanced hunting schema captures process creation events, including the command line arguments used to start each process. This directly meets the analyst's need to see all processes created in the last hour with their command-line details, making it the correct table for investigating malware that spawns processes.

Exam trap

The trap here is that candidates often confuse process creation events with network or file events, mistakenly choosing DeviceNetworkEvents or DeviceFileEvents because they associate malware with network traffic or file drops, rather than recognizing that command-line arguments are exclusively stored in DeviceProcessEvents.

How to eliminate wrong answers

Option B (DeviceNetworkEvents) is wrong because it records network connections (e.g., IP addresses, ports, protocols) and not process creation or command-line arguments. Option C (DeviceFileEvents) is wrong because it logs file creation, modification, and deletion events, not process creation or command-line data. Option D (DeviceRegistryEvents) is wrong because it tracks registry key modifications, not process creation or command-line arguments.

1207
MCQhard

Your organization is using Microsoft Defender for Cloud to protect Azure workloads. A critical vulnerability was discovered in a virtual machine that is part of a production application. The vulnerability has a high severity score and is actively being exploited in the wild. You need to respond quickly to mitigate the risk. What is the most effective immediate action?

A.Apply the vendor patch immediately during business hours.
B.Enable just-in-time (JIT) VM access in Microsoft Defender for Cloud to lock down inbound traffic.
C.Modify the network security group (NSG) to block all inbound traffic to the VM.
D.Use the 'Remediate' option in Defender for Cloud to automatically apply the patch.
AnswerB

Enabling just-in-time (JIT) VM access in Microsoft Defender for Cloud immediately reduces the attack surface by creating temporary NSG rules that only allow specified source IPs and ports during defined schedules. This blocks inbound traffic from the internet or other high-risk sources while preserving legitimate administrative access, unlike a full inbound block. JIT is a fast, reversible, and targeted network-level control that buys time for a safe patch deployment without taking the VM offline.

Why this answer

Enabling just-in-time (JIT) VM access in Microsoft Defender for Cloud immediately reduces the attack surface by locking down inbound traffic to the VM, except for approved connections from specific IP addresses and ports. This is the most effective immediate action when a critical, actively exploited vulnerability exists, as it buys time to apply a patch without exposing the VM to further exploitation. Unlike patching, which may require a reboot or cause downtime, JIT access can be enabled in minutes and does not disrupt production traffic for authorized users.

Exam trap

The trap here is that candidates often choose the 'Remediate' option (D) thinking it automatically patches the vulnerability, but in reality, the patch may not be available or may require a reboot, making JIT access the faster and safer immediate containment action.

How to eliminate wrong answers

Option A is wrong because applying a vendor patch immediately during business hours risks causing unplanned downtime or application instability, and the patch may not be available or tested for the specific vulnerability. Option C is wrong because modifying the NSG to block all inbound traffic would completely deny access to the VM, including legitimate production traffic, effectively taking the application offline. Option D is wrong because the 'Remediate' option in Defender for Cloud applies the vendor patch automatically, which may not be immediately available, could require a reboot, and does not provide the same rapid, non-disruptive containment as JIT access.

1208
MCQhard

Your SOC uses Microsoft Sentinel with multiple workspaces for different business units. You want to create a single dashboard that shows key performance indicators (KPIs) across all workspaces. Which approach minimizes complexity and query latency?

A.Export data to Azure Data Explorer and build the dashboard there.
B.Ingest all logs into a single workspace and create the dashboard there.
C.Use Power BI to query each workspace separately and combine data.
D.Use cross-workspace queries in a single dashboard that references all workspaces.
AnswerD

Cross-workspace queries let a single Sentinel dashboard use KQL to query multiple Log Analytics workspaces in real time by referencing each workspace with the workspace() expression, such as union workspace("WS-A").SecurityEvent, workspace("WS-B").SecurityEvent. This approach avoids moving or duplicating data, provides immediate visibility, and is the minimal-effort design intended by Microsoft. It also requires proper read permissions on all referenced workspaces, but no additional infrastructure or data pipelines.

Why this answer

Cross-workspace queries in Microsoft Sentinel allow you to query multiple workspaces in a single KQL query using the `workspace()` expression, enabling a unified dashboard without data duplication or additional infrastructure. This minimizes complexity by avoiding data movement and reduces query latency by leveraging the existing indexing and caching within each workspace.

Exam trap

The trap here is that candidates may assume a single workspace is simpler (Option B) or that external tools like Power BI are required for cross-source aggregation, missing the native cross-workspace query capability in Sentinel that is designed exactly for this multi-workspace scenario.

How to eliminate wrong answers

Option A is wrong because exporting data to Azure Data Explorer introduces additional latency and complexity from data export, transformation, and storage, and is unnecessary when Sentinel already supports cross-workspace queries. Option B is wrong because ingesting all logs into a single workspace violates the requirement of separate workspaces for different business units and creates a single point of failure, increased ingestion costs, and potential data sovereignty issues. Option C is wrong because using Power BI to query each workspace separately requires multiple connections and data merging on the client side, which increases query latency and complexity compared to native cross-workspace queries that run server-side in Sentinel.

1209
MCQmedium

You are a threat hunter in a Microsoft Sentinel workspace. You hypothesize that an attacker is using the legitimate tool PsExec to move laterally, but you want to detect it without relying on process names that are easily renamed. Which hunting approach using KQL best identifies PsExec-like lateral movement by examining named pipes?

A.Search DeviceNetworkEvents for connections to TCP port 445 where InitiatingProcessFileName is "psexec.exe".
B.Search SecurityEvent for EventID 4624 with LogonType 3 and a SubjectUserName ending with "$".
C.Search SecurityEvent for EventID 4688 where NewProcessName ends with "psexec.exe" or "psexesvc.exe".
D.Search SecurityEvent for EventID 5145 where ShareName contains "IPC$" and RelativeTargetName matches "*psexesvc*".
AnswerD

This is correct because PsExec creates a named pipe called 'psexesvc' on the target host when it executes. Event ID 5145 (A network share object was checked to see whether client can be granted desired access) with ShareName IPC$ and RelativeTargetName containing psexesvc is a reliable indicator of PsExec lateral movement. Hunting this named pipe artifact avoids dependence on the process name, which attackers can rename.

Why this answer

PsExec creates a named pipe called 'psexesvc' on the target system during execution. Hunting for Event ID 5145 with ShareName IPC$ and RelativeTargetName containing 'psexesvc' detects this behavior regardless of the source binary name, making it a reliable method for identifying lateral movement with PsExec-like tools. Other options either rely on easily changed process names or produce high false positives.

Exam trap

The trap here is focusing on process names like psexec.exe or psexesvc.exe, which attackers can rename, instead of the named pipe artifact that PsExec inherently creates.

1210
Multi-Selectmedium

Your organization uses Microsoft Sentinel and wants to reduce alert fatigue. Which TWO actions should you take to improve the quality of incidents?

Select 2 answers
A.Create separate incidents for each alert.
B.Create automation rules to close all low-severity incidents automatically.
C.Configure alert grouping in analytics rules to combine related alerts into one incident.
D.Use suppression and tuning rules to filter out known benign activity.
E.Increase the severity of all low-severity alerts to high.
AnswersC, D

Alert grouping in an analytics rule, configured under 'Incident settings,' consolidates alerts that share the same group key—commonly entity mappings like account, host, or IP—into a single incident. This reduces alert volume while preserving the correlation between related events, enabling the analyst to see the full attack narrative in one place. Grouping also lets you set a display name and alert severity for the aggregated incident, which improves triage prioritization and reduces the operational overhead of handling many separate incident objects.

Why this answer

Configuring alert grouping in analytics rules consolidates multiple related alerts into a single incident, reducing noise and helping analysts focus on the root cause rather than triaging individual alerts. This directly improves incident quality by providing a richer context and reducing alert fatigue.

Exam trap

The trap here is that candidates often confuse 'reducing alert fatigue' with simply deleting or ignoring low-severity alerts, rather than understanding that intelligent grouping and suppression of known benign activity preserves detection fidelity while reducing noise.

1211
MCQhard

An organization needs to meet PCI DSS compliance requirements and also enforce a custom policy requiring that encryption keys be stored in a specific Azure Key Vault. The security administrator wants to view a unified compliance score that includes both the built-in PCI DSS standard and the custom policy. What should the administrator do in Microsoft Defender for Cloud?

A.Assign the built-in PCI DSS regulatory compliance standard and add a custom policy through Azure Policy
B.Create a custom initiative that includes the PCI DSS built-in policy set and the custom key vault policy, then assign it to the scope
C.Use Azure Blueprints to deploy the PCI DSS standard and custom policies
D.Enable the Secure Score dashboard to measure compliance
AnswerB

Creating a custom initiative lets you combine the built-in PCI DSS policy set with a custom Key Vault policy definition into one assignable Azure Policy object, which overcomes the read-only nature of built-in regulatory standards. After assignment to the management group, subscription, or resource group, this initiative appears under Defender for Cloud's Regulatory Compliance dashboard because custom initiatives are supported there and are evaluated against the corresponding compliance controls. This is the only option that both enforces the custom Key Vault requirement and surfaces the result as part of the PCI DSS compliance view.

Why this answer

Microsoft Defender for Cloud's regulatory compliance dashboard can only display a unified compliance score when all relevant standards and custom policies are grouped into a single initiative. By creating a custom initiative that includes both the built-in PCI DSS policy set and the custom Key Vault policy, then assigning that initiative to the scope, the administrator ensures the compliance score reflects both requirements in one view.

Exam trap

The trap here is that candidates assume simply assigning the built-in standard and adding a custom policy separately will merge their scores, but Defender for Cloud requires all policies to be part of the same initiative for a unified compliance score.

How to eliminate wrong answers

Option A is wrong because simply assigning the built-in PCI DSS standard and adding a custom policy through Azure Policy does not merge them into a single compliance score; the custom policy would appear separately and not contribute to the unified score. Option C is wrong because Azure Blueprints is a deployment and orchestration tool, not a compliance scoring mechanism; it cannot aggregate compliance data into Defender for Cloud's regulatory compliance dashboard. Option D is wrong because the Secure Score dashboard measures security posture based on security controls, not regulatory or custom policy compliance; it does not include PCI DSS or custom key vault policies.

1212
Multi-Selecthard

Which TWO steps are necessary to configure Microsoft Sentinel to automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created?

Select 2 answers
A.Create a playbook that uses the Microsoft Entra ID 'Disable user' action.
B.Create an automation rule that triggers the playbook when a high-severity incident is created.
C.Enable the Microsoft Defender XDR connector.
D.Enable the Microsoft Entra ID Protection data connector.
E.Create an analytics rule that detects compromised user accounts.
AnswersA, B

The playbook is the core remediation component because it contains the executable logic that calls the Microsoft Entra ID 'Disable user' action. This action, available via the Microsoft Entra ID connector in Azure Logic Apps, directly disables the targeted user account, effectively neutralizing the compromised identity. Without this action, the playbook would have no ability to apply a security control, so it is a mandatory piece of the automated response.

Why this answer

A playbook is an automated workflow that can contain the 'Disable user' action from Microsoft Entra ID, which directly disables a compromised user account. This action leverages the Microsoft Graph API to update the user's accountEnabled property to false, effectively blocking sign-ins. Without this playbook, there is no mechanism to execute the disablement action when an incident is created.

Exam trap

The trap here is that candidates often confuse data connectors (which only ingest data) with playbooks (which perform actions), leading them to select options like the Microsoft Entra ID Protection data connector instead of the playbook and automation rule combination.

1213
Multi-Selecteasy

Which TWO are supported methods to ingest syslog data into Microsoft Sentinel?

Select 2 answers
A.Common Event Format (CEF) connector
B.Logstash output plugin
C.Azure Event Hubs
D.Syslog connector using Azure Monitor Agent (AMA)
E.Direct Azure Monitor Agent ingestion without connector
AnswersA, D

The Common Event Format (CEF) connector is a supported syslog ingestion method because it uses a dedicated syslog forwarder (typically a Linux VM running the CEF collector) that listens for syslog messages formatted as CEF, normalizes them, and sends them to the CommonSecurityLog table in Microsoft Sentinel. This connector natively parses the key/value pairs in CEF and maps them to standard fields, making it a first-class, documented integration for security devices that emit syslog in CEF format.

Why this answer

The Common Event Format (CEF) connector is a supported method because it uses a syslog daemon on a Linux log collector to receive CEF-formatted syslog messages over UDP/TCP (port 514 or 25226) and forwards them to the Log Analytics workspace via the Log Analytics agent. This connector specifically parses CEF headers and maps fields to Sentinel's schema, making it a native ingestion path for security appliances like Palo Alto Networks or Fortinet.

Exam trap

The trap here is that candidates confuse Azure Event Hubs as a direct ingestion method for syslog data, when it is actually a transport layer that requires additional components (like a syslog collector or Logstash) to forward data to Sentinel.

1214
MCQeasy

Refer to the exhibit. You are deploying this analytics rule in Microsoft Sentinel. Which activity will trigger an alert?

A.cmd.exe launching winword.exe
B.Any process creation event
C.Winword.exe execution
D.Any cmd.exe execution
E.Word launching cmd.exe
AnswerE

The query conditions—ParentImage equals 'winword.exe' and CommandLine contains 'cmd.exe'—precisely describe a Microsoft Word process creating a child command prompt. This is a classic indicator of a document with an embedded macro executing a shell command, a common technique for lateral movement or payload delivery. Therefore, this option correctly interprets the rule's intent and logic.

Why this answer

The analytics rule is configured to trigger an alert when a process creation event (Event ID 4688) has a parent process of 'winword.exe' and a child process of 'cmd.exe'. This specific parent-child relationship indicates that Microsoft Word is launching a command prompt, which is a common technique used in malicious documents to execute commands. The rule's query filters for 'ParentImage' containing 'winword.exe' and 'Image' containing 'cmd.exe', so only when Word launches cmd.exe will the alert fire.

Exam trap

The trap here is that candidates often confuse the parent-child process direction, assuming any execution of cmd.exe or winword.exe will trigger the alert, but the rule explicitly requires winword.exe as the parent and cmd.exe as the child, not the reverse.

How to eliminate wrong answers

Option A is wrong because it describes the reverse relationship (cmd.exe launching winword.exe), which does not match the rule's filter for ParentImage being winword.exe and Image being cmd.exe. Option B is wrong because the rule does not trigger on any process creation event; it specifically requires the parent process to be winword.exe and the child process to be cmd.exe. Option C is wrong because the rule requires both the parent (winword.exe) and child (cmd.exe) to be present; a standalone winword.exe execution without launching cmd.exe will not trigger the alert.

Option D is wrong because the rule requires the parent process to be winword.exe, not any cmd.exe execution; a cmd.exe launched by another process (e.g., explorer.exe) will not match the rule's conditions.

1215
MCQhard

During a ransomware incident, a security analyst needs to isolate an affected Windows 10 device managed by Microsoft Intune. The device is currently online and connected to the corporate network. Which remediation action should be taken from Microsoft Defender XDR to achieve this?

A.Block the device in Microsoft Intune
B.Initiate device isolation from the Microsoft Defender for Endpoint console
C.Disable the Windows Firewall via Intune
D.Run a full antivirus scan from Microsoft Defender for Endpoint
AnswerB

Device isolation from the Microsoft Defender for Endpoint console severs network connectivity while preserving the Defender sensor channel, blocking lateral movement and ransomware spread on the online Intune-managed device. This is the supported remediation action within Microsoft Defender XDR.

Why this answer

Device isolation from the Microsoft Defender for Endpoint console (accessible via Microsoft Defender XDR) immediately cuts the device off from the network while preserving the Defender communication channel, allowing the analyst to investigate and remediate without losing contact with the endpoint. This is the purpose-built ransomware containment action.

Exam trap

SC-200 often tests the confusion between Intune device actions (block, wipe, retire) and Defender for Endpoint remediation actions (isolate, restrict app execution, live response) — candidates pick Intune block thinking it isolates the device, when only Defender isolation actually severs network connectivity.

How to eliminate wrong answers

Option A is wrong because blocking a device in Intune marks it as non-compliant and can trigger conditional access restrictions, but it does not sever the device's existing network connections — the ransomware can continue lateral movement. Option C is wrong because disabling Windows Firewall removes a defensive layer and does not isolate the device; it actually increases exposure. Option D is wrong because running a full antivirus scan is a detection/remediation step, not containment — the device remains network-connected and the ransomware continues to spread during the scan.

1216
MCQeasy

A company wants to be alerted when a virtual machine is exposed to the internet through a permissive network security group rule. Which Microsoft Defender for Cloud feature provides recommendations and alerts for such misconfigurations?

A.Adaptive network hardening
B.Just-in-time VM access
C.File integrity monitoring
D.Application controls
AnswerA

Adaptive network hardening is a Microsoft Defender for Cloud feature that uses machine learning to analyze historical traffic patterns against current network security group (NSG) rules. When it identifies rules that are overly permissive—such as allowing inbound traffic from the internet on management ports—it generates a security alert and provides a recommendation to restrict the rule. This directly surfaces VMs that are inadvertently exposed to the internet due to flawed NSG configurations.

Why this answer

Adaptive network hardening (ANH) in Microsoft Defender for Cloud analyzes actual traffic patterns, NSG rules, and internet-facing endpoints to identify overly permissive rules that expose VMs to the internet. It then provides actionable recommendations to tighten those rules and can generate security alerts when such misconfigurations are detected. This directly matches the requirement for alerts on internet exposure via permissive NSG rules.

Exam trap

The trap here is confusing a feature that actively controls access (like JIT VM access) with one that detects and alerts on existing misconfigurations (adaptive network hardening), leading candidates to choose JIT because it also deals with internet exposure, but it does not generate alerts for permissive NSG rules.

How to eliminate wrong answers

Option B (Just-in-time VM access) is wrong because it controls inbound access by temporarily opening ports only when needed, but it does not analyze existing NSG rules for permissive internet exposure or generate alerts for misconfigurations. Option C (File integrity monitoring) is wrong because it monitors changes to critical files, registry keys, and system files for compliance and forensic purposes, not network security group rules or internet exposure. Option D (Application controls) is wrong because it uses allow/deny lists to control which applications can run on VMs, focusing on executable and script control, not network security group rule analysis or internet exposure alerts.

1217
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Entra ID. You need to implement a solution that automatically disables a user account in Microsoft Entra ID when a high-severity incident involving that user is created in Sentinel. The solution must also send a notification to the security team. You have a playbook that disables the user and sends an email. What should you configure to trigger the playbook?

A.Configure the playbook to run on a schedule and query incidents.
B.Create a workbook that triggers the playbook when a high-severity incident appears.
C.Create an automation rule that runs when an incident is created with severity High and triggers the playbook.
D.Configure the playbook as a response action in the analytics rule that generates the incident.
AnswerC

Automation rules are Sentinel's native mechanism for triggering playbooks in response to incident creation, and they support severity-based conditions. Matching severity High ensures the playbook runs only for the relevant incidents, satisfying the automatic disablement and notification requirement.

Why this answer

To automatically trigger a playbook when a high-severity incident is created in Microsoft Sentinel, you should create an automation rule. Automation rules in Microsoft Sentinel allow you to define conditions (such as incident severity) and actions (such as running a playbook). This is the native, no-code way to trigger playbooks based on incident creation.

Exam trap

SC-200 often tests the difference between automation rules and analytics rule response actions, confusing candidates about which to use for triggering playbooks on incident creation.

How to eliminate wrong answers

Option A is wrong because running a playbook on a schedule would not be event-driven and would not trigger immediately upon incident creation; it would also require the playbook to query incidents, which is inefficient. Option B is wrong because workbooks are for visualization and reporting, not for triggering playbooks. Option D is wrong because while you can configure a playbook as a response action in an analytics rule, that is only for incidents generated by that specific rule, and it is not the most flexible or recommended approach for triggering on any high-severity incident; automation rules are designed for this purpose.

1218
MCQmedium

Your Microsoft Sentinel environment is not generating incidents from a custom KQL detection rule. The rule runs successfully in the Log Analytics query editor but no incidents appear. What is the most likely cause?

A.The rule's alert grouping settings are misconfigured
B.The rule is set to create alerts but not incidents
C.The rule's query schedule is too long
D.The rule does not have entity mapping configured
AnswerB

Sentinel analytics rules have separate toggles for generating alerts and creating incidents. If incident creation is disabled, the rule fires and logs alerts but no incidents appear, matching the symptom of a query that runs successfully yet produces nothing.

Why this answer

The most likely cause is that the rule is set to create alerts but not incidents. In Microsoft Sentinel, analytics rules have a toggle to 'Create incidents' from alerts. If this toggle is disabled, alerts are generated but not grouped into incidents.

The query running successfully in Log Analytics confirms the rule logic works, but incidents will not appear unless the incident creation toggle is enabled. Entity mapping is not required for incident creation; it enhances correlation but is not a prerequisite.

Exam trap

The trap is that candidates often assume entity mapping is necessary for incident creation, but in reality the key setting is the 'Create incident' toggle. They may overlook this simple configuration.

How to eliminate wrong answers

Option A is wrong because alert grouping settings control how alerts are grouped into a single incident (e.g., by entity or time window), but they do not prevent incidents from being created entirely; if incidents are enabled, misconfigured grouping might cause unexpected grouping, not a total absence of incidents. Option B is wrong because this is the correct description of the issue—the rule is set to create alerts but not incidents, which directly explains why no incidents appear despite successful query execution. Option C is wrong because a long query schedule (e.g., running every 24 hours) would delay incident creation but not prevent it; incidents would still appear after the scheduled run if the rule is configured to create them.

1219
Matchingmedium

Match each Microsoft Sentinel feature to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Define conditions that generate incidents

Visualize data using custom dashboards

Proactively search for threats

Automate responses using Azure Logic Apps

Detect anomalous behavior based on entity analytics

Why these pairings

Analytics rules generate incidents, Workbooks visualize data, Hunting queries search for threats, and Playbooks automate response. Common confusions include mixing visualization with rule generation and automation with proactive search.

1220
MCQeasy

During an incident response, your team identifies a suspicious PowerShell command executed on multiple devices. Which Microsoft Defender XDR feature should you use to block the command across all endpoints immediately?

A.Potentially Unwanted Application (PUA) protection
B.Indicators of compromise (IoC)
C.Attack Surface Reduction (ASR) rules
D.Device Control policies
AnswerB

Indicators of compromise in Microsoft Defender XDR let you define file hashes, IPs, URLs or commands that block or remediate across onboarded endpoints. Creating a command indicator enforces immediate blocking fleet-wide, satisfying the requirement to stop the PowerShell command on all devices.

Why this answer

Microsoft Defender XDR's Indicators of compromise (IoC) allow creating custom indicators to block file hashes, IPs, URLs, or commands across endpoints. Option A is wrong because Potentially Unwanted Application (PUA) protection targets unwanted software, not specific commands. Option C is wrong because Attack Surface Reduction (ASR) rules are designed to block common attack patterns, not ad-hoc commands.

Option D is wrong because Device Control policies manage peripheral devices like USB drives.

1221
MCQmedium

Your organization uses Microsoft Defender for Identity. You need to receive alerts when suspicious LDAP queries are detected. What should you configure?

A.Set up an anomaly detection policy in Microsoft Defender for Cloud Apps.
B.Configure alert rules in Microsoft Defender for Identity.
C.Assign the Security Administrator role in Microsoft Entra ID.
D.Create a custom sensitivity label in Microsoft Purview.
AnswerB

Defender for Identity's alert rules are the correct mechanism to detect suspicious LDAP queries because its lightweight sensor, installed on domain controllers, AD FS, and AD CS servers, monitors incoming LDAP traffic. The service includes a built-in alert rule named "LDAP reconnaissance" that compares query patterns to known reconnaissance techniques such as account enumeration, group membership queries, or unauthenticated LDAP searches. By configuring this alert rule—adjusting thresholds and enabling it to trigger—you directly satisfy the requirement to detect suspicious LDAP queries.

Why this answer

Microsoft Defender for Identity (MDI) detects suspicious LDAP queries, such as LDAP reconnaissance or directory traversal attacks, by analyzing domain controller traffic. To receive alerts for these detections, you must configure alert rules directly within the MDI portal, which allows you to set thresholds and notification preferences for specific LDAP-related activities. Option B is correct because MDI's built-in alert rules are the mechanism for generating and delivering these security alerts.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Cloud Apps' anomaly detection policies with MDI's alert rules, not realizing that LDAP query monitoring is a core MDI function tied to on-premises Active Directory traffic, not cloud app behavior.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps (MCAS) focuses on cloud application usage and shadow IT, not on-premises LDAP traffic; anomaly detection policies in MCAS are for cloud app behavior, not domain controller LDAP queries. Option C is wrong because assigning the Security Administrator role in Microsoft Entra ID grants permissions to manage security settings across Microsoft 365 but does not directly configure alert rules for LDAP queries in MDI; it is an administrative role, not a configuration setting. Option D is wrong because custom sensitivity labels in Microsoft Purview are used for data classification and protection (e.g., labeling documents or emails), not for detecting or alerting on suspicious LDAP queries.

1222
MCQmedium

Your organization has Microsoft Defender for Cloud Apps and Microsoft Sentinel integrated. The security team wants to receive alerts when a user's activity from an anonymous IP address exceeds a certain risk score. What should you configure in Defender for Cloud Apps?

A.Anomaly detection policy
B.File policy
C.Activity policy
D.App discovery policy
AnswerC

Activity policies are the correct choice because they allow you to define custom, rule-based conditions on tens of thousands of user operations, including sign-in events, admin actions, and file accesses. These policies support granular filters like IP category (including Anonymous), user risk level, and device tags, so you can trigger an immediate alert when a user logs in from an anonymous IP. Unlike anomaly detection, this is deterministic and provides precise, actionable results with low noise.

Why this answer

Activity policies in Microsoft Defender for Cloud Apps allow you to monitor and respond to specific user activities based on conditions such as IP address categories (e.g., anonymous proxy) and risk scores. This policy type can trigger alerts when a user's activity from an anonymous IP address exceeds a defined risk score threshold, meeting the security team's requirement.

Exam trap

The trap here is that candidates often confuse anomaly detection policies (which detect behavioral anomalies) with activity policies (which allow explicit condition-based filtering), leading them to select Option A incorrectly.

How to eliminate wrong answers

Option A is wrong because anomaly detection policies focus on identifying unusual patterns of behavior (e.g., impossible travel, unusual mass download) rather than filtering activities based on a specific IP category like anonymous IP addresses combined with a risk score. Option B is wrong because file policies are designed to monitor and control data sharing and file access (e.g., sharing sensitive files externally), not user activities from specific IP types. Option D is wrong because app discovery policies are used to identify and analyze shadow IT usage (i.e., unsanctioned cloud apps), not to alert on user activities from anonymous IP addresses.

1223
MCQhard

You are reviewing the ARM template snippet shown in the exhibit. What is the purpose of this template?

A.Create a workbook in Azure Monitor
B.Create an analytics rule in Microsoft Sentinel
C.Create a saved search in a Log Analytics workspace
D.Create a data connector in Microsoft Sentinel
AnswerC

The resource type 'Microsoft.OperationalInsights/workspaces/savedSearches' is specifically used to create a saved search in a Log Analytics workspace. The 'properties' object includes 'category' and 'query', where the query is the KQL statement to be saved. This saved search can be reused in workbooks or pinned to dashboards, and it is the correct interpretation of this ARM template snippet.

Why this answer

The ARM template snippet defines a saved search resource of type 'Microsoft.OperationalInsights/workspaces/savedSearches'. This resource type is specifically used to create a saved query within a Log Analytics workspace, which can then be used for log queries, alert rules, or workbooks. Option C correctly identifies this purpose.

Exam trap

The trap here is that candidates may confuse saved searches with other Log Analytics features like workbooks or analytics rules, but the resource type 'Microsoft.OperationalInsights/workspaces/savedSearches' is uniquely tied to saved queries, not visualizations or alerting logic.

How to eliminate wrong answers

Option A is wrong because creating a workbook in Azure Monitor uses the resource type 'Microsoft.Insights/workbooks', not 'Microsoft.OperationalInsights/workspaces/savedSearches'. Option B is wrong because creating an analytics rule in Microsoft Sentinel uses the resource type 'Microsoft.SecurityInsights/alertRules', not a saved search. Option D is wrong because creating a data connector in Microsoft Sentinel uses resource types like 'Microsoft.SecurityInsights/dataConnectors' or 'Microsoft.OperationalInsights/workspaces/dataSources', not a saved search.

1224
MCQeasy

Refer to the exhibit. You deploy this ARM template to your subscription. After deployment, you cannot find the saved search 'Test Search' in the Microsoft Sentinel workspace. What is the most likely reason?

A.The resource type should be for analytics rules, not saved searches.
B.The query 'Heartbeat | summarize Count() by Computer' is invalid.
C.The apiVersion is incorrect.
D.The name concatenation is missing a parameter.
AnswerA

The core issue in this template is the resource type. Microsoft Sentinel analytics rules must be declared as `Microsoft.SecurityInsights/alertRules` (or under a Sentinel-compatible solution), not as `Microsoft.OperationalInsights/workspaces/savedSearches`. A savedSearches resource only creates a Log Analytics saved query, which will not appear in the Sentinel Analytics blade or generate alerts. Therefore, the deployment succeeds but the intended detection rule does not function.

Why this answer

The ARM template deploys a resource of type 'Microsoft.OperationsManagement/solutions' with a saved search, but Microsoft Sentinel does not use saved searches for analytics rules. In Sentinel, detection rules are created as 'Microsoft.SecurityInsights/alertRules', not as saved searches under a Log Analytics workspace. The template's resource type is mismatched for the intended functionality, so the saved search 'Test Search' will not appear as a Sentinel analytics rule.

Exam trap

The trap here is that candidates assume any KQL query deployed via ARM template in a Log Analytics workspace will automatically appear as a Sentinel analytics rule, but Microsoft requires the correct resource provider and type for Sentinel-specific features.

How to eliminate wrong answers

Option B is wrong because the query 'Heartbeat | summarize Count() by Computer' is syntactically valid KQL and would execute successfully in Log Analytics; it is not the reason the saved search is missing. Option C is wrong because the apiVersion '2015-11-01-preview' is a valid and supported version for Log Analytics saved searches and solutions; an incorrect apiVersion would cause a deployment error, not a silent failure to find the search. Option D is wrong because the name concatenation '[concat(parameters('workspaceName'), '/', variables('savedSearchName'))]' is correctly formatted and includes all required parameters; missing a parameter would cause a deployment failure, not a missing search.

1225
MCQhard

You are the security operations lead for a multinational company that uses Microsoft Sentinel in a single workspace. You have recently onboarded 10 new business units, each with their own analytics rules and automation. The security team is overwhelmed by the number of low-fidelity incidents generated. You need to reduce noise without disabling critical detections. You must ensure that each business unit retains ownership of their incidents and can customize their own suppression rules. You also need centralized reporting on incident trends across all business units. You have identified that many low-fidelity alerts come from a common set of data sources. What should you do?

A.Disable the data connectors that produce the most noise.
B.Create an automation rule that automatically closes low-severity incidents.
C.Create a separate analytics rule for low-fidelity alerts that uses alert suppression to group similar alerts.
D.Create a workbook that filters out low-severity incidents from the dashboard.
AnswerC

Alert suppression in a dedicated analytics rule groups similar low-fidelity alerts into a single incident, reducing the incident queue while retaining signal awareness. Because it is a separate rule, its suppression settings can be tuned independently without impacting high-fidelity detection rules. This balances detection capability with operational efficiency, making it the only option that actually lowers incident volume without losing data.

Why this answer

Creating a separate analytics rule for low-fidelity alerts with alert suppression enabled allows you to group similar alerts into a single incident, reducing noise without disabling the underlying data connectors or critical detections. This approach preserves each business unit's ownership of their incidents and enables them to customize suppression rules via automation rules or analytics rule settings, while centralized reporting on incident trends remains intact because the workspace still ingests all alerts.

Exam trap

The trap here is that candidates often confuse reducing noise with simply hiding or closing incidents after they are generated, rather than preventing the noise at the analytics rule level through alert suppression, which is the only option that reduces incident volume while preserving data fidelity and per-unit customization.

How to eliminate wrong answers

Option A is wrong because disabling data connectors that produce noise would also remove all alerts from those sources, potentially disabling critical detections that rely on the same data, and it does not allow per-business-unit customization. Option B is wrong because automatically closing low-severity incidents via an automation rule does not reduce the number of incidents generated; it only closes them after creation, still overwhelming the queue and potentially hiding legitimate low-severity incidents that require investigation. Option D is wrong because creating a workbook that filters out low-severity incidents only changes the dashboard view, not the actual incident generation or noise reduction, and it does not address the root cause of excessive low-fidelity alerts.

1226
MCQhard

The KQL query above is used in a threat hunt. What is the most likely scenario this query is designed to detect?

A.Identification of lateral movement using PsExec
B.Discovery of data exfiltration using FTP
C.Hunting for code execution via rundll32.exe loading JavaScript
D.Detection of regsvr32.exe being used to execute scriptlet files
AnswerC

This query is correctly hunting for a known LOLBin technique where an attacker uses rundll32.exe to execute JavaScript code by placing 'javascript:' in the command line. When PowerShell (or another process) launches rundll32 with that argument, it triggers the JScript engine to evaluate the supplied script, allowing arbitrary code execution while masquerading as a legitimate Windows binary. This pattern is documented in MITRE ATT&CK as Signed Binary Proxy Execution (T1218.011), and the combination of the parent-child process relationship and the 'javascript:' string makes it a strong hunting indicator.

Why this answer

The query specifically looks for rundll32.exe loading JavaScript files, which is a known technique for executing malicious code while evading detection. This aligns with option C, as it directly describes the behavior the query is designed to hunt for. The query likely includes process creation events where rundll32.exe is the parent or child process and the command line contains .js or .jse extensions, indicating JavaScript execution.

Exam trap

SC-200 often tests the ability to distinguish between different LOLBin techniques, such as confusing rundll32.exe with regsvr32.exe or misidentifying the specific script type being executed.

How to eliminate wrong answers

Option A is wrong because PsExec lateral movement typically involves the creation of services or named pipes, not rundll32.exe loading JavaScript files. Option B is wrong because FTP data exfiltration would involve network connections to FTP servers and file transfers, not rundll32.exe executing scripts. Option D is wrong because regsvr32.exe executing scriptlet files (e.g., .sct) is a different LOLBin technique; the query specifically targets rundll32.exe and JavaScript, not regsvr32.exe and scriptlets.

1227
MCQhard

A SOC team uses Microsoft Sentinel. They receive a large volume of low-severity incidents from a specific analytics rule that causes alert fatigue. They want to automatically close incidents that match certain criteria (e.g., originating from a known test IP). Which feature should they configure?

A.Automation rules with a condition to close incidents
B.Playbook with a timer trigger
C.Watchlist integration
D.Fusion rule
AnswerA

Automation rules are native Sentinel orchestration objects that trigger synchronously on incident creation or update. Under a condition such as an entity matching a watchlist or a low severity classification, the rule can execute the 'Close incident' action with a chosen classification and comment, requiring no external logic app and no analyst intervention. This is the correct low-code way to suppress noisy alerts.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically close incidents based on specific conditions, such as a known test IP address. This directly addresses alert fatigue by suppressing low-severity incidents without manual intervention. Unlike playbooks, automation rules are lightweight and run natively within Sentinel without requiring a Logic Apps instance.

Exam trap

Microsoft often tests the distinction between automation rules (native, condition-based actions) and playbooks (external Logic Apps workflows), leading candidates to incorrectly choose a playbook when a simpler automation rule suffices.

How to eliminate wrong answers

Option B is wrong because a playbook with a timer trigger runs on a schedule, not in response to an incident being created; it cannot automatically close incidents based on real-time criteria like source IP. Option C is wrong because a watchlist is a data reference object used for enrichment or correlation in queries and rules, not a mechanism to automatically close incidents. Option D is wrong because a Fusion rule is a correlation-based analytics rule that reduces alert fatigue by combining alerts into high-fidelity incidents, but it does not close existing incidents based on custom criteria like a test IP.

1228
MCQmedium

Your threat hunt involves correlating alerts from Microsoft Defender for Cloud Apps with Microsoft Defender for Endpoint. Which Microsoft Sentinel integration should you use to unify these alerts for hunting?

A.Microsoft Sentinel's unified analytics rules and incident creation
B.Power Automate flows to merge alerts
C.Microsoft Graph API to pull alerts into a custom database
D.Azure Monitor Workbooks to display alerts side by side
AnswerA

Unified analytics rules in Microsoft Sentinel correlate alerts from multiple sources, including Microsoft Defender for Cloud Apps and Microsoft Defender for Endpoint, and group them into a single incident. This satisfies the requirement to unify cross-product alerts for hunting rather than viewing them separately.

Why this answer

Microsoft Sentinel provides built-in connectors and analytics rules to correlate alerts across Microsoft Defender XDR, including Defender for Cloud Apps and Defender for Endpoint. Option B (Power Automate) can automate workflows but does not provide a unified hunting experience or correlation. Option C (Microsoft Graph API) is programmatic and can retrieve alerts, but it is not a unified correlation tool.

Option D (Azure Monitor Workbooks) visualizes data but does not correlate or unify alerts for hunting.

1229
MCQmedium

A company uses Microsoft Defender for Cloud with Defender for Containers enabled. The security team wants to view security alerts generated for their Azure Kubernetes Service (AKS) clusters. Where should they navigate to see these alerts?

A.In the Microsoft Defender for Cloud 'Security alerts' page.
B.In Microsoft Sentinel incidents.
C.In the Microsoft 365 Defender portal.
D.In Azure Monitor alerts.
AnswerA

All Defender for Cloud security alerts—whether they originate from Azure, hybrid, multicloud, or container workloads—are aggregated in the unified Security alerts page. This page is the default and authoritative console for viewing, filtering, and triaging alerts generated by Defender for Cloud's plans, including Defender for Containers. Container-specific findings appear here with the relevant resource, severity, and associated MITRE ATT&CK tactics, making it the correct location for this scenario.

Why this answer

Microsoft Defender for Cloud is the central console for security alerts generated by Defender for Containers, including those for AKS clusters. The 'Security alerts' page within Defender for Cloud aggregates all cloud workload protection alerts, making it the correct location to view AKS-specific alerts. Alerts from Defender for Containers are automatically surfaced here without additional configuration.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender portal (unified for Microsoft 365 security) with Defender for Cloud (for cloud workloads), leading them to choose Option C instead of the correct Azure-native security alerts page.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel incidents require a separate SIEM integration and are not the native location for Defender for Cloud alerts; alerts must be forwarded via connector to appear there. Option C is wrong because the Microsoft 365 Defender portal focuses on endpoint, email, and identity threats, not cloud workload alerts from AKS. Option D is wrong because Azure Monitor alerts are designed for infrastructure metrics and logs, not the security-specific, contextual alerts generated by Defender for Cloud's threat detection engines.

1230
MCQmedium

A security analyst is building a custom detection rule in Microsoft 365 Defender to identify ransomware activity. The rule should trigger when files with specific extensions (e.g., .encrypted, .locked) are created on multiple devices within a short time frame, suggesting a widespread attack. Which combination of advanced hunting tables should be used to obtain both file creation events and device information?

A.DeviceFileEvents and DeviceInfo
B.DeviceProcessEvents and DeviceInfo
C.DeviceFileEvents and DeviceNetworkEvents
D.DeviceFileEvents and DeviceLogonEvents
AnswerA

DeviceFileEvents supplies the file creation records, including the extension and timestamp, while DeviceInfo supplies the device metadata needed to correlate activity across machines. Joining them on DeviceId satisfies the stem's requirement to detect widespread ransomware file encryption across multiple devices.

Why this answer

DeviceFileEvents captures file creation events, including the specific extensions like .encrypted and .locked, while DeviceInfo provides device metadata such as device name, OS platform, and device group. Joining these tables on DeviceId allows the analyst to correlate file creation events across multiple devices, enabling detection of widespread ransomware activity within a short time frame.

Exam trap

The trap here is that candidates may confuse file creation events with process creation events (DeviceProcessEvents) or network events (DeviceNetworkEvents), overlooking that only DeviceFileEvents directly captures the file extension data needed for ransomware detection.

How to eliminate wrong answers

Option B is wrong because DeviceProcessEvents logs process creation events (e.g., command-line executions), not file creation events; it cannot directly identify files with specific extensions being created. Option C is wrong because DeviceNetworkEvents captures network connections and DNS queries, not file creation events; it provides no visibility into local file system changes. Option D is wrong because DeviceLogonEvents records authentication events (logon/logoff), not file creation events; it cannot detect the creation of encrypted or locked files.

1231
MCQhard

Refer to the exhibit. An automation rule in Microsoft Sentinel is configured as shown. When a high-severity incident is created, what is the expected behavior?

A.All actions execute successfully: task created, playbook runs, incident owner set to SOC-Tier1.
B.The rule fails to run because the actions are not in valid JSON format.
C.The task is created, then the playbook runs, but the incident modification fails because the owner is incorrectly formatted.
D.The playbook runs first, then the task is created, then the incident is modified.
AnswerC

The automation rule successfully creates the task and triggers the playbook as configured. However, Microsoft Sentinel requires incident owners to be valid Microsoft Entra ID user principal names or object IDs. If the automation rule's configuration for setting the incident owner specifies an incorrectly formatted value, such as an arbitrary string that does not correspond to a recognised identity, the attempt to modify the incident's owner property will fail. This specific constraint on owner format causes the modification failure, even if other actions succeed.

Why this answer

The automation rule in Microsoft Sentinel executes actions sequentially. The task creation and playbook run succeed, but the incident modification fails because the owner field is incorrectly formatted. Sentinel expects the incident owner to be specified as a user principal name (UPN) or object ID, not a plain text string like 'SOC-Tier1'.

Exam trap

The trap here is that candidates assume all actions in an automation rule execute independently and ignore the specific formatting requirements for the incident owner field, leading them to select Option A or D.

How to eliminate wrong answers

Option A is wrong because the incident modification action fails due to the invalid owner format, so not all actions execute successfully. Option B is wrong because the rule actions are defined in the Sentinel UI as structured JSON, which is valid; the failure is due to runtime validation of the owner value, not JSON syntax. Option D is wrong because the actions execute in the order listed in the rule: task creation first, then playbook, then incident modification; the playbook does not run first.

1232
MCQeasy

A security operations analyst is reviewing recommendations in Microsoft Defender for Cloud. For a virtual machine that is missing critical security updates, which recommendation category will highlight this issue?

A.Secure score
B.Regulatory compliance
C.Workload protections
D.Inventory
AnswerA

Secure score is the correct answer because it aggregates all security recommendations from Microsoft Defender for Cloud, including the specific recommendation 'System updates should be installed on your machines.' Each recommendation contributes to the overall secure score percentage, and the feature directly lists missing critical updates with remediation steps and affected resources, making it the primary location for a security operations analyst to address patch gaps.

Why this answer

In Microsoft Defender for Cloud, the Secure score category directly reflects the security posture of your resources by tracking the implementation of security recommendations. Missing critical security updates on a virtual machine are flagged as a recommendation within this category, and resolving them improves your secure score percentage. This is because secure score is calculated based on the compliance status of each recommendation, with missing updates being a key control for vulnerability management.

Exam trap

The trap here is that candidates often confuse the 'Regulatory compliance' category with security update tracking, but regulatory compliance only shows compliance with specific standards, not the operational status of missing patches.

How to eliminate wrong answers

Option B is wrong because Regulatory compliance focuses on aligning your environment with specific compliance standards (e.g., ISO 27001, SOC 2) and does not directly surface missing security updates as a standalone recommendation category. Option C is wrong because Workload protections is a category for enabling and managing advanced threat protection plans (e.g., Defender for Servers, Defender for SQL) and does not list individual missing update recommendations. Option D is wrong because Inventory provides a list of all resources and their metadata, but it does not categorize or prioritize missing security updates as a recommendation; it is a resource discovery tool, not a recommendation category.

1233
Multi-Selecthard

Which TWO of the following are valid approaches to perform threat hunting using Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Using Fusion analytics rule
B.Using the Hunting blade and Livestream
C.Using Automation rules to trigger playbooks
D.Using KQL queries in the Logs blade
E.Using Azure Policy to enforce compliance
AnswersB, D

The Hunting blade in Microsoft Sentinel provides a centralized interface containing built-in hunting queries mapped to MITRE ATT&CK techniques, allowing analysts to run predefined KQL searches and pivot on suspicious results. Livestream is a complementary feature that creates an ongoing KQL query session over live ingested data, presenting real-time results that update as logs flow in, with optional alerts on each result. This combination is a valid hunting approach because it directly supports proactive, iterative, and continuous investigation of workspace data.

Why this answer

The Hunting blade in Microsoft Sentinel provides a dedicated interface for proactive threat hunting, allowing analysts to run KQL queries and pivot through results. Livestream extends this by enabling continuous, real-time query execution against incoming data, which is essential for detecting patterns that evolve over minutes or hours. Both features are explicitly designed for iterative, hypothesis-driven threat hunting rather than automated detection.

Exam trap

The trap here is that candidates confuse automated detection rules (like Fusion) or response automation (like playbooks) with the manual, iterative process of threat hunting, which requires interactive querying and live monitoring rather than passive alerting.

1234
MCQmedium

You are investigating a potential malicious PowerShell execution in Microsoft Defender for Endpoint using this KQL query in Advanced Hunting. The query returns no results. What is the most likely cause?

A.The column names are incorrect; 'InitiatingProcessFileName' should be 'ParentProcessFileName'.
B.The table name should be 'DeviceProcessEvents' instead of 'DeviceEvents'.
C.The 'take 100' operator limits results to only 100, but the query may return results if more data exists.
D.The query uses 'ago(7d)' which may be too short for historical data.
AnswerB

The root cause is that the query queries the DeviceEvents table, which does not contain process creation events. Process creation events are stored in the DeviceProcessEvents table, part of the Advanced Hunting schema. Querying DeviceEvents will not return process creation data, even if the rest of the query is correct. Changing the table to DeviceProcessEvents resolves the issue.

Why this answer

The query uses the table 'DeviceEvents', which is incorrect for hunting process execution events. The correct table for process creation events in Microsoft Defender for Endpoint Advanced Hunting is 'DeviceProcessEvents'. 'DeviceEvents' contains other types of events (e.g., registry, file, network) but not process creation data, so the query returns no results.

Exam trap

The trap here is that candidates may focus on column names or time ranges, overlooking the fundamental table mismatch between 'DeviceEvents' and 'DeviceProcessEvents' in Microsoft Defender for Endpoint Advanced Hunting.

How to eliminate wrong answers

Option A is wrong because 'InitiatingProcessFileName' is a valid column in 'DeviceProcessEvents' and correctly refers to the parent process file name; renaming it to 'ParentProcessFileName' would not fix the table issue. Option C is wrong because 'take 100' limits output but does not prevent results from being returned if the query matches data; the issue is that no matching data exists due to the wrong table. Option D is wrong because 'ago(7d)' is a reasonable time range for investigating recent malicious activity; extending it would not help if the table itself is incorrect.

1235
MCQmedium

Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). During an incident investigation, you identify that a user account has been exhibiting anomalous behavior, such as logging in from multiple countries within a short time. You need to determine if the account is compromised and take appropriate action. What should you do first?

A.Disable the user account in Microsoft Entra ID.
B.Review the UEBA insights for the user to understand the anomaly.
C.Create a custom automation rule in Sentinel to disable the account on similar alerts.
D.Reset the user's password immediately.
AnswerB

Reviewing the user's UEBA insights is the initial investigative step because Sentinel's UEBA engine has already modeled that user's historical behavior and established a baseline. These insights reveal what made the activity anomalous—for example, unexpected geo-location, new device, unusual hour, or abnormal access frequency—and provide a context-rich timeline for triage. This assessment lets the analyst validate the alert and decide on containment versus false positive before any corrective action is taken.

Why this answer

Before taking any disruptive action like disabling an account or resetting a password, the analyst must review the UEBA insights to validate whether the anomaly is a true compromise or a false positive (e.g., VPN usage, travel, or shared credentials). UEBA in Microsoft Sentinel correlates sign-in logs, Azure Activity, and other sources to surface risk scores and anomalous entities, giving the context needed for an informed decision.

Exam trap

SC-200 often tests the investigate-before-remediate principle, luring candidates into picking immediate containment actions (disable, reset) instead of first validating the anomaly with UEBA context.

How to eliminate wrong answers

Option A is wrong because disabling the account before validating the anomaly could disrupt legitimate business operations and destroy forensic evidence if the account is not actually compromised. Option C is wrong because creating an automation rule is a preventive/detection-engineering task, not the first investigative step during an active incident. Option D is wrong because resetting the password immediately is a remediation action that should follow confirmation of compromise, not precede it, and it may lock out a legitimate user.

1236
MCQeasy

Your SOC team receives a high-priority incident related to a potential malware outbreak. You need to quickly identify all affected devices and users across the environment. What Microsoft Defender XDR feature should you use?

A.Advanced hunting
B.Action center
C.Incident graph
D.Microsoft Sentinel workbook
AnswerC

Incident graph maps the relationships between alerts, devices, users and mailboxes into a single visual topology, letting analysts pivot from the incident to every affected entity. This directly satisfies the need to identify all impacted devices and users across the environment quickly.

Why this answer

The incident graph in Microsoft Defender XDR visually maps the relationships between alerts, devices, users, IP addresses, and other entities involved in an incident, letting analysts quickly see the full scope of an outbreak. It aggregates related alerts into a single incident and shows lateral movement, affected users, and affected devices in one view. This is the fastest way to identify all impacted assets and accounts during a high-priority malware incident.

Exam trap

SC-200 often tests the difference between hunting (Advanced hunting), remediation tracking (Action center), and incident visualization (Incident graph), so candidates who pick Advanced hunting miss that the question asks for quick identification of all affected entities, not a custom query.

How to eliminate wrong answers

Option A is wrong because Advanced hunting is a query-based tool (KQL) for proactive threat hunting and custom detection, not the visual incident-scoping feature that shows all affected devices and users at a glance. Option B is wrong because Action center tracks remediation actions taken on devices and users, not the relationship map of an incident's affected entities. Option D is wrong because Microsoft Sentinel workbooks are dashboards for log analytics and reporting, not the Defender XDR incident graph that correlates entities within an incident.

1237
MCQmedium

You are a security analyst. You notice that Microsoft Sentinel is not receiving logs from Microsoft 365 Defender incidents. The diagnostic settings in Microsoft 365 Defender are configured to send data to the Sentinel workspace. What should you check first?

A.Check if the Microsoft Sentinel solution is installed.
B.Verify that the Log Analytics workspace is in the same region as the Sentinel workspace.
C.Ensure the Microsoft 365 Defender data connector in Microsoft Sentinel is enabled.
D.Check the 'SecurityIncident' table schema for missing columns.
AnswerC

Ensure the Microsoft 365 Defender data connector is enabled because this connector is the only ingestion path by which incidents generated in Microsoft 365 Defender are pulled into Microsoft Sentinel. When disabled, no SecurityIncident records from Defender are written, and the connector must show a 'Connected' status in the Data connectors blade. The connector uses delegated API permissions to subscribe to Defender incidents; without this enabled configuration, all other workspace and solution settings are irrelevant to the missing data.

Why this answer

The diagnostic settings in Microsoft 365 Defender send raw data to the Log Analytics workspace, but Microsoft Sentinel must have the Microsoft 365 Defender data connector enabled to parse and ingest that data into the correct tables (e.g., SecurityIncident, AlertInfo). Without the connector enabled, the logs arrive in the workspace but are not processed by Sentinel, so incidents won't appear. This is the first and most common check because the connector acts as the ingestion pipeline.

Exam trap

The trap here is that candidates assume diagnostic settings alone are sufficient for data ingestion, but they overlook that the Sentinel data connector is the required bridge to parse and normalize the data into Sentinel-specific tables.

How to eliminate wrong answers

Option A is wrong because the Microsoft Sentinel solution must be installed on the workspace for Sentinel to function at all, but the question states Sentinel is already present and only missing M365 Defender incidents, so the solution is likely installed. Option B is wrong because Log Analytics workspaces do not have a region constraint with Sentinel; Sentinel is a service that runs on top of the workspace, and they must be in the same region, but this is a prerequisite that would prevent all data ingestion, not just M365 Defender incidents. Option D is wrong because the 'SecurityIncident' table schema is fixed and cannot be modified; missing columns would indicate a schema change or corruption, which is extremely rare and not the first troubleshooting step for missing data.

1238
MCQmedium

You are a security analyst for a company that uses Microsoft Defender XDR. You receive a high-severity incident indicating that a user's device has been compromised with a remote access trojan (RAT). The incident is automatically generated by Microsoft Defender XDR. You need to contain the threat immediately while preserving forensic data. You also need to ensure that the user can continue working with minimal disruption. What should you do?

A.Initiate device isolation from Microsoft Defender XDR.
B.Restore the device from a recent backup.
C.Run a full antivirus scan on the device.
D.Reset the user's password and force a sign-out.
AnswerA

Initiating device isolation in Microsoft Defender XDR severs the endpoint's network connections while preserving its communication path to the Defender service, effectively halting the RAT's command-and-control (C2) channel and preventing lateral movement or data exfiltration. This containment action also preserves the in-memory and on-disk artifacts needed for forensic analysis, since the device remains powered on and untouched. Isolation is the immediate, containment-focused response that limits the attacker's ability to operate while allowing the IR team to investigate and remediate safely.

Why this answer

Initiating device isolation from Microsoft Defender XDR immediately disconnects the device from the network while preserving forensic data on the device. This contains the RAT's command-and-control communication without disrupting the user's ability to work offline, and it allows the security team to investigate the compromised device without risk of lateral movement or data exfiltration.

Exam trap

The trap here is that candidates may choose a reactive remediation step like running a scan or resetting credentials, failing to recognize that immediate containment via network isolation is the priority to stop active compromise while preserving evidence.

How to eliminate wrong answers

Option B is wrong because restoring from a recent backup would overwrite existing forensic data, potentially destroying evidence of the RAT's installation and persistence mechanisms, and it does not contain the active threat in real time. Option C is wrong because running a full antivirus scan is a reactive, time-consuming step that does not immediately stop the RAT from communicating or spreading; the threat remains active during the scan. Option D is wrong because resetting the user's password and forcing a sign-out does not address the device-level compromise; the RAT would still be present on the device and could re-establish access or capture new credentials.

1239
MCQmedium

Your organization has deployed Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that all Defender XDR incidents are automatically synchronized into Microsoft Sentinel for a single pane of glass. What should you configure?

A.Enable the Microsoft Sentinel data connector for Microsoft Defender XDR
B.Use Microsoft Graph API to sync incidents daily
C.Create an automation rule in Microsoft Sentinel to create incidents from Defender XDR alerts
D.Configure Microsoft Defender XDR to forward incidents to Sentinel using a webhook
AnswerA

The Microsoft Sentinel data connector for Microsoft Defender XDR is the native, supported integration that continuously streams incidents and alerts from Defender XDR into Sentinel using the Microsoft Graph API. Once enabled, incident properties, status, and severity are automatically synchronized bi-directionally, enabling SOC analysts to manage the full incident lifecycle from a single pane. This requires no custom coding, uses built-in authentication, and provides near real-time ingestion, making it the only correct solution for this scenario.

Why this answer

The Microsoft Sentinel data connector for Microsoft Defender XDR is the native integration that automatically synchronizes all Defender XDR incidents into Sentinel. This connector ingests incidents, alerts, and evidence from Defender XDR into the Sentinel workspace, enabling a single pane of glass without requiring custom scripting or manual workflows.

Exam trap

The trap here is that candidates often confuse alert-based connectors (like the Microsoft Defender for Endpoint connector) with the incident-level Microsoft Defender XDR connector, or they assume that automation rules or webhooks are the correct method for incident synchronization, when the native connector is the only supported and recommended approach.

How to eliminate wrong answers

Option B is wrong because using Microsoft Graph API to sync incidents daily would require custom development, polling logic, and manual scheduling, which is not a built-in or supported method for automatic incident synchronization; the native connector handles this in real time. Option C is wrong because creating an automation rule in Sentinel to create incidents from Defender XDR alerts would only process individual alerts, not the correlated incidents that Defender XDR generates, and would bypass the incident-level synchronization provided by the connector. Option D is wrong because configuring Defender XDR to forward incidents to Sentinel using a webhook is not a supported feature; Defender XDR does not have a native webhook export for incidents, and even if implemented via Logic Apps, it would be a custom, non-standard approach compared to the official connector.

1240
MCQmedium

Your threat hunt identifies a process that is making outbound connections to an unknown IP address. Which Microsoft Defender for Endpoint action can you take to immediately isolate the device?

A.Isolate device
B.Collect investigation package
C.Block file
D.Run antivirus scan
AnswerA

Isolate device — Immediately disconnects the device from the network via Microsoft Defender for Endpoint's containment action, severing all inbound and outbound traffic while keeping the device powered on for forensic preservation. This is the correct first response to a process making outbound connections because it stops active data exfiltration and lateral movement without rebooting or losing volatile evidence, and it can be applied selectively if needed.

Why this answer

The 'Isolate device' action in Microsoft Defender for Endpoint immediately cuts off a device from all network communication except for the Defender for Endpoint service itself, preventing the malicious process from exfiltrating data or communicating with command-and-control servers. This is the only action that provides immediate network isolation while preserving the ability to remotely investigate and remediate the device. Other actions like collecting an investigation package or running an antivirus scan do not stop active outbound connections.

Exam trap

SC-200 often tests the distinction between actions that contain a threat (like isolation) versus those that only gather data or remediate files, so candidates must recognize that only 'Isolate device' immediately stops network communication.

How to eliminate wrong answers

Option B is wrong because 'Collect investigation package' gathers forensic data (running processes, network connections, etc.) but does not block network traffic, so the malicious process continues its outbound connections. Option C is wrong because 'Block file' prevents a specific file from executing on devices, but it does not isolate an already-running process or stop its network activity. Option D is wrong because 'Run antivirus scan' initiates a scan for malware but does not immediately sever network connections, allowing the threat to remain active during the scan.

1241
MCQmedium

A security analyst wants to configure a playbook in Microsoft Sentinel that runs automatically when a specific alert is generated. Which trigger concept is used to invoke the playbook?

A.Azure Logic Apps trigger
B.Sentinel trigger
C.Alert trigger
D.Automation rule trigger
AnswerA

This is the correct answer because Microsoft Sentinel playbooks are built on Azure Logic Apps, and the playbook workflow itself begins with a built-in Logic Apps trigger—specifically the 'When a response to a Microsoft Sentinel alert is triggered' trigger. This trigger receives the alert payload via the Sentinel connector and initiates the Logic App. The term 'Azure Logic Apps trigger' accurately reflects the underlying technology and distinguishes it from other trigger types in Sentinel.

Why this answer

In Microsoft Sentinel, playbooks are built on Azure Logic Apps, and the correct trigger to invoke a playbook automatically when an alert is generated is the Azure Logic Apps trigger. This trigger listens for the Sentinel alert creation event and initiates the playbook workflow. The other options are not valid trigger concepts within Sentinel's architecture.

Exam trap

The trap here is that candidates may confuse the automation rule (which invokes the playbook) with the actual trigger mechanism, leading them to choose 'Automation rule trigger' instead of recognizing that the playbook itself is triggered by an Azure Logic Apps trigger.

How to eliminate wrong answers

Option B is wrong because 'Sentinel trigger' is not a defined trigger type; the actual trigger is an Azure Logic Apps trigger that uses the Sentinel connector. Option C is wrong because 'Alert trigger' is a generic term and not the specific trigger concept used in Sentinel; the trigger is implemented via Logic Apps. Option D is wrong because 'Automation rule trigger' is a misnomer; automation rules can invoke playbooks, but the trigger itself is the Azure Logic Apps trigger, not an automation rule trigger.

1242
MCQeasy

You are configuring a Microsoft Sentinel automation rule to automatically assign incidents to a specific owner based on a custom property. Which action type should you use?

A.Run playbook
B.Assign owner
C.Change status
D.Create ticket (preview)
AnswerB

The Assign owner action changes an incident's owner to a specified user or group, satisfying the requirement to route incidents based on a custom property. Automation rules evaluate trigger conditions, then execute this action to set ownership automatically.

Why this answer

The 'Assign owner' action type is specifically designed to change the owner of an incident in Microsoft Sentinel. When you need to automatically assign incidents to a specific owner based on a custom property (e.g., a tag or custom field), this action directly modifies the incident's 'Owner' property. Other action types serve different purposes: 'Run playbook' executes a logic app, 'Change status' updates the incident's status (e.g., New, Active, Closed), and 'Create ticket (preview)' creates an external ticket in a connected ticketing system.

Exam trap

The trap here is that candidates often confuse 'Assign owner' with 'Run playbook', thinking a playbook is required to change the owner, but Sentinel provides a native action for this simple property change without needing a Logic App.

How to eliminate wrong answers

Option A is wrong because 'Run playbook' triggers a Logic App workflow, which can include complex logic but is not a direct action to set the incident owner; it is used for automation beyond simple property changes. Option C is wrong because 'Change status' modifies the incident's status (e.g., from New to Active), not the owner assignment. Option D is wrong because 'Create ticket (preview)' generates a ticket in an external system (e.g., ServiceNow) and does not modify the Sentinel incident's owner field.

1243
MCQmedium

Your organization uses Microsoft Sentinel. You are responsible for responding to incidents. A new 'MFA Denied' incident is created from Microsoft Entra ID sign-in logs, indicating that a user in your organization had multiple MFA denials from a suspicious IP address (203.0.113.5). The user is a sales representative who frequently travels. The incident severity is Medium. The incident contains entities: user 'jsmith@contoso.com', IP address 203.0.113.5, and a device running Windows 11. You need to investigate and determine if this is a true positive. The user is currently on a business trip in Europe, but the sign-in attempts originated from an IP address in a different region. What should you do first?

A.Immediately reset the user's password and revoke sessions.
B.Contact the user to confirm if they attempted to sign in at the time of the alerts.
C.Block the suspicious IP address in the Conditional Access policy.
D.Isolate the user's device using Microsoft Defender for Endpoint.
AnswerB

Contacting the user to confirm if they attempted to sign in is the correct initial triage step. In Microsoft Sentinel, sign-in logs and failed attempts are often false positives triggered by user behavior, such as using a personal device or mistyping a password. This direct verification helps the analyst correlate the alert with the user's actual activity, geographic location, and device, enabling a risk-based decision without causing unnecessary disruption. It aligns with standard incident response procedures that emphasize validation before containment.

Why this answer

The first step in investigating a potential true positive is to contact the user to confirm if they attempted to sign in. This helps determine if the MFA denials were legitimate (e.g., user error) or malicious. It is a non-destructive action that gathers critical context.

Exam trap

SC-200 often tests incident response order; candidates may jump to containment actions without first verifying the incident, leading to unnecessary disruption.

How to eliminate wrong answers

Option A is wrong because immediately resetting the password and revoking sessions is a containment action that should be taken only after confirming a compromise; it could disrupt the user unnecessarily. Option C is wrong because blocking the IP in Conditional Access is a mitigation that might affect other users and should be done after investigation. Option D is wrong because isolating the device is a response action that is premature without evidence of compromise on the device.

1244
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. An incident is triggered: 'Lateral movement detected - pass-the-hash attack.' The incident includes alerts from Microsoft Defender for Identity (MDI) showing anomalous NTLM authentication attempts from a compromised workstation to multiple servers. The compromised workstation is a Windows 10 device. You need to contain the incident. Which of the following actions should you take FIRST?

A.Reset the krbtgt account password twice.
B.Isolate the compromised workstation using Microsoft Defender for Endpoint.
C.Disable NTLM authentication across the domain.
D.Reset passwords on all servers that received anomalous authentication attempts.
AnswerB

Isolating the compromised Windows 10 workstation via Microsoft Defender for Endpoint immediately severs the attacker's NTLM authentication path to the target servers, halting lateral movement. Containment precedes investigation, and endpoint isolation is the fastest action that stops pass-the-hash propagation.

Why this answer

The compromised Windows 10 workstation is the source of the pass-the-hash authentication attempts, so isolating it via Microsoft Defender for Endpoint immediately cuts off the attacker's ability to pivot to additional servers. This is the fastest containment action and preserves forensic evidence on the endpoint. Only after containment should the team proceed with credential resets and broader remediation.

Exam trap

SC-200 often tests the order of containment versus eradication — candidates pick disruptive domain-wide actions like krbtgt resets or NTLM disabling instead of the targeted, reversible endpoint isolation that stops the immediate threat.

How to eliminate wrong answers

Option A is wrong because resetting krbtgt twice is a Kerberos Golden Ticket remediation step, not the first response to pass-the-hash NTLM abuse, and it is highly disruptive. Option C is wrong because disabling NTLM domain-wide would break countless legacy applications and is not a proportionate first containment action. Option D is wrong because resetting passwords on all target servers is premature — the attacker's foothold is the workstation, and resetting server passwords without containing the source may not stop ongoing attacks and could cause widespread outages.

1245
MCQmedium

Your organization uses Microsoft Sentinel with the Microsoft 365 Defender connector. You receive an incident indicating that a user's account was used to sign in from an unusual location (Russia) while the user is in the United States. The sign-in was successful and no MFA challenge was prompted because the user had a valid session. The incident severity is High. You need to respond immediately. What should you do first?

A.Block the IP address in the Conditional Access policy.
B.Revoke the user's session in Microsoft Entra ID.
C.Investigate the sign-in logs to determine if there are other compromised accounts.
D.Reset the user's password.
AnswerB

Revoking the user's session in Microsoft Entra ID immediately invalidates all refresh tokens for that user and forces re-authentication across all applications, terminating the attacker's active session without waiting for token expiry. This is the correct initial response in a Sentinel incident because it stops ongoing unauthorized access at the session layer, which is faster and more comprehensive than network-level or credential-based actions. It is a precise containment step that precedes password reset and further investigation.

Why this answer

Revoking the user's session in Microsoft Entra ID immediately terminates all active tokens and sessions, preventing the attacker from continuing to use the authenticated session. This is the fastest way to stop the ongoing compromise because the sign-in succeeded without MFA due to a valid session, and the attacker is already inside. Other actions like blocking IP or resetting password are slower or less direct in this scenario.

Exam trap

The trap here is that candidates often choose 'Reset the user's password' thinking it kills all sessions, but in Microsoft Entra ID, password reset does not revoke existing tokens or sessions unless combined with explicit token revocation or a 'Sign out everywhere' action.

How to eliminate wrong answers

Option A is wrong because blocking the IP address in a Conditional Access policy would only affect future sign-in attempts from that IP, not the currently active session that is already authenticated; the attacker could still use the existing session. Option C is wrong because investigating sign-in logs for other compromised accounts is a secondary step that does not immediately stop the current active compromise; it delays containment. Option D is wrong because resetting the user's password does not invalidate existing session tokens or refresh tokens in Microsoft Entra ID unless the user's tokens are explicitly revoked; the attacker could still use the active session until it expires.

1246
MCQmedium

Refer to the exhibit. You are deploying a Microsoft Sentinel workspace using an ARM template. After deployment, you notice the workspace is in a disabled state for ingesting data. Which parameter is most likely causing this?

A.The location parameter is set to 'eastus' but Sentinel is not available in that region
B.The dailyQuotaInGB parameter sets a daily cap that may have been exceeded
C.The retentionInDays parameter is set to 90, which is less than the default 30 days
D.The workspaceName parameter is set to 'SentinelWorkspace' but the name must be globally unique
AnswerB

The dailyQuotaInGB parameter is the correct culprit: it configures the workspace's daily ingest cap in the Log Analytics workspace backing your Sentinel deployment. When that cap is reached, Log Analytics pauses data ingestion for the remainder of the day, so Sentinel appears to be 'disabled' because it stops receiving security logs and alerts. This is a well-known operational state that is incorrectly diagnosed as an outage, and it persists until the next day or until the quota is raised.

Why this answer

The dailyQuotaInGB parameter sets a daily ingestion cap for the Log Analytics workspace. If this cap is reached, data ingestion is disabled until the next day, causing the workspace to appear in a disabled state for ingesting data. This is the most likely cause because the question explicitly states the workspace is disabled for data ingestion, which aligns with the behavior of the daily cap being exceeded.

Exam trap

The SC-200 exam often tests the misconception that workspace names must be globally unique (like storage accounts) or that Sentinel availability varies by region, when in fact the daily cap is the direct cause of a disabled ingestion state.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is available in the East US region, so setting the location to 'eastus' would not cause the workspace to be disabled for data ingestion. Option C is wrong because the retentionInDays parameter set to 90 is greater than the default of 30 days, and retention settings do not affect the ingestion state of the workspace. Option D is wrong because workspace names in Log Analytics do not need to be globally unique; they only need to be unique within a resource group, so 'SentinelWorkspace' is a valid name.

1247
MCQmedium

You are a threat hunter using Microsoft Sentinel. You have ingested syslog data from a Palo Alto firewall. You want to create a scheduled query rule that alerts when more than 10 outbound connections to a known bad IP address occur within 5 minutes. Which KQL function should you use to summarize the count?

A.project SourceIp, DestinationIp
B.extend Count = 1
C.summarize count() by SourceIp, DestinationIp
D.join kind=inner (Syslog)
AnswerC

`summarize count() by SourceIp, DestinationIp` aggregates events into per-source and per-destination groups, satisfying the stem's requirement to count outbound connections to a known bad IP. Grouping by DestinationIp lets you filter or threshold on that specific address, while the 5-minute window is applied by the scheduled query rule's frequency and lookback settings.

Why this answer

The `summarize` operator is the KQL aggregation function that groups rows by one or more columns and computes aggregate values such as `count()`, `sum()`, `avg()`, etc. In this scenario, `summarize count() by SourceIp, DestinationIp` produces a row per unique SourceIp/DestinationIp pair with the number of outbound connection events, which can then be filtered with a `where` clause (e.g., `where Count > 10`) to trigger the Sentinel scheduled query rule. This directly satisfies the requirement to count connections within the 5-minute rule window.

Exam trap

SC-200 often tests the difference between row-level operations (project, extend) and aggregation operations (summarize), so candidates may incorrectly choose extend or project when asked to count events.

How to eliminate wrong answers

Option A is wrong because `project` only selects or renames columns and does not perform any aggregation or counting. Option B is wrong because `extend Count = 1` merely adds a constant column with value 1 to every row; it does not group or sum events, so no meaningful count per source/destination is produced. Option D is wrong because `join kind=inner (Syslog)` is used to correlate two datasets on a matching key, not to aggregate or count events; it would not summarize connection counts.

1248
MCQmedium

An organization ingests its Palo Alto firewall logs into a custom table named 'PaloAlto_CL' in Microsoft Sentinel. A security analyst wants to create a scheduled analytics rule that triggers an incident when a single source IP is involved in more than 100 outbound connections to different destinations in 1 minute. Which KQL query and configuration would trigger the alert correctly?

A.summarize count() by SourceIP, bin(TimeGenerated,1m) and set threshold >100
B.summarize dcount(DestinationIP) by SourceIP, bin(TimeGenerated,1m) and set threshold >100
C.summarize count() by DestinationIP and threshold >100
D.summarize dcount(SourceIP) by DestinationIP, bin(TimeGenerated,1m) and threshold >100
AnswerB

Using dcount(DestinationIP) is the correct measure because it approximates the number of unique destination IP addresses contacted by each source in each one-minute window. Grouping by SourceIP and bin(TimeGenerated,1m) isolates per-source scanning bursts, and threshold >100 accurately flags a single host that attempts more than 100 distinct destinations in a minute, which is the classic signature of network scanning or worm propagation. The dcount operator uses HyperLogLog estimation, which is memory-efficient and sufficiently precise for alerting at this scale.

Why this answer

The requirement is to count distinct destination IPs per source IP per minute, not total connections. Using `dcount(DestinationIP)` with `bin(TimeGenerated,1m)` ensures we count unique destinations, and setting the threshold to >100 triggers when a single source IP connects to more than 100 different destinations in one minute, exactly matching the alert condition.

Exam trap

The trap here is confusing `count()` (total events) with `dcount()` (distinct values), leading candidates to select Option A, which would trigger on repeated connections to the same destination rather than the specified condition of different destinations.

How to eliminate wrong answers

Option A is wrong because `count()` counts all outbound connections, including repeated connections to the same destination, which would overcount and could trigger false positives. Option C is wrong because it groups by DestinationIP only, missing the per-source-IP requirement and the 1-minute time window, and uses a threshold without proper aggregation. Option D is wrong because it uses `dcount(SourceIP)` by DestinationIP, which counts distinct source IPs per destination, the inverse of what is needed, and the threshold >100 would incorrectly trigger on destinations receiving connections from many sources.

1249
MCQeasy

An analyst wants to find all devices that have run a specific process named 'malware.exe' in the last 24 hours using Microsoft 365 Defender Advanced Hunting. Which table should be the primary source for this query?

A.DeviceProcessEvents
B.DeviceEvents
C.DeviceFileEvents
D.DeviceNetworkEvents
AnswerA

DeviceProcessEvents is the correct table because it is the dedicated Advanced Hunting schema for process creation events. Filtering on FileName directly yields every device on which that executable was launched, along with exact timestamps and command-line arguments. This table provides the most complete and reliable evidence of process execution, making it the standard resource for hunting a specific binary across the fleet.

Why this answer

The DeviceProcessEvents table in Microsoft 365 Defender Advanced Hunting is the primary source for querying process creation events, including the execution of a specific process name like 'malware.exe'. This table captures process creation and termination events, making it the correct choice for finding devices that have run a specific process within a given time frame.

Exam trap

The trap here is that candidates may confuse DeviceProcessEvents with DeviceEvents, assuming the latter covers all events, but DeviceEvents is limited to security alerts and audit events, not process creation.

How to eliminate wrong answers

Option B (DeviceEvents) is wrong because it primarily captures system-level events such as security alerts, Windows Defender AV detections, and other audit events, not process creation events. Option C (DeviceFileEvents) is wrong because it tracks file creation, modification, and deletion events, not process execution. Option D (DeviceNetworkEvents) is wrong because it records network connections and related events, not process execution.

1250
MCQhard

Refer to the exhibit. You are analyzing a KQL query used in a custom detection rule in Microsoft Defender XDR. The rule is supposed to detect devices where a parent process launched more than 10 instances of PowerShell or cmd.exe in the last 7 days. However, the query returns no results even though you know such activity exists. What is the most likely reason?

A.The 'extend' line creates a new column that is not used in the subsequent summarize, causing the query to not group by parent process as intended.
B.The 'summarize' operator cannot be used with 'count()' in this context.
C.The 'where' clause filters out all events because the FileName list is incorrect.
D.The 'extend' line uses a column that does not exist in the DeviceProcessEvents schema.
AnswerD

According to the Microsoft 365 Defender DeviceProcessEvents schema, there is no valid column named 'InitiatingProcessParentFileName'; the correct field for the parent process executable is 'InitiatingProcessFileName'. An 'extend' expression that references a non-existent column causes a Kusto semantic error, because schema validation rejects the unrecognized identifier. As a result, the entire query fails or returns an empty result set, rather than creating a new column. This schema mismatch is the direct cause of the issue.

Why this answer

The 'extend' line references a column named 'ParentProcessFileName' that does not exist in the DeviceProcessEvents schema. The actual column is 'InitiatingProcessFileName' (or 'ParentProcessName' in some schemas). Since the column doesn't exist, the 'extend' operation fails silently or produces null values, causing the subsequent 'summarize' to group by null and return no results.

Exam trap

The trap here is that candidates assume the column name 'ParentProcessFileName' is correct based on intuition or generic naming conventions, without verifying the actual schema of the DeviceProcessEvents table in Microsoft Defender XDR.

How to eliminate wrong answers

Option A is wrong because the 'extend' line creates a new column that is indeed used in the 'summarize' operator (the 'by' clause references 'ParentProcessFileName'), so the grouping is not broken by an unused column. Option B is wrong because 'summarize' with 'count()' is perfectly valid in KQL and commonly used to count rows per group. Option C is wrong because the 'where' clause filters on 'FileName' with 'has' operators, which is syntactically correct; the issue is not with the filter logic but with a missing column upstream.

1251
MCQmedium

A security analyst is configuring a Microsoft Sentinel playbook to automate the response to phishing incidents. When an incident is created based on a phishing analytics rule, the playbook needs to execute an action in Microsoft 365 Defender, such as blocking the sender email address. Which connector should the analyst add to the playbook to interact with Microsoft 365 Defender?

A.Microsoft 365 Defender connector
B.Microsoft Entra ID connector
C.Azure DevOps connector
D.Teams connector
AnswerA

The Microsoft 365 Defender connector is the correct choice because it is purpose-built for security response actions in Microsoft 365 Defender, including blocking email senders, isolating compromised devices, and running advanced hunting queries. It is implemented as a Logic Apps managed connector that uses the Microsoft 365 Defender APIs, allowing playbooks to initiate remediation directly from Sentinel incidents.

Why this answer

The Microsoft 365 Defender connector is the correct choice because it provides the necessary actions to interact directly with Microsoft 365 Defender components, such as blocking a sender email address via the Advanced Hunting or action APIs. This connector enables the playbook to trigger remediation actions like email quarantine or sender block within the Microsoft 365 Defender portal, which is essential for automating responses to phishing incidents in Microsoft Sentinel.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender connector with the Microsoft Entra ID connector, assuming identity actions can block email senders, but Entra ID lacks the email security APIs required for such remediation.

How to eliminate wrong answers

Option B is wrong because the Microsoft Entra ID connector is designed for identity and access management actions (e.g., revoking user sessions, disabling accounts), not for email security actions like blocking a sender in Microsoft 365 Defender. Option C is wrong because the Azure DevOps connector is used for managing work items, pipelines, and repositories in Azure DevOps, not for security response actions in Microsoft 365 Defender. Option D is wrong because the Teams connector is used for sending messages or notifications to Microsoft Teams channels, not for executing remediation actions like blocking a sender email address.

1252
Multi-Selectmedium

Which TWO are valid sources of evidence in a Microsoft Sentinel incident? (Choose two.)

Select 2 answers
A.Playbooks
B.Watchlists
C.Alerts
D.Bookmarks
E.Hunting queries
AnswersC, D

Alerts are generated by built-in analytics rules, Microsoft Defender services, or custom detections and represent a single security detection with associated entities, timestamps, and severity. When an incident is created, related alerts are automatically linked, and you can explicitly add alerts from the Evidence tab to support the investigation. Each alert carries rich metadata such as rule ID, tactic, technique, and triggered logic, making it a primary evidence source. Alerts are valid evidence because they capture the exact detection that initiated or expanded the incident response.

Why this answer

Alerts are a core evidence type in Microsoft Sentinel incidents because they represent the raw security findings that trigger an incident. When an alert is generated from a detection rule (e.g., analytics rule, fusion, or scheduled query), it is automatically linked to the incident as evidence, providing the initial context and supporting data for investigation.

Exam trap

The trap here is that candidates confuse 'sources of evidence' with 'tools used during investigation'—playbooks and hunting queries are actions or workflows, not static evidence records stored within the incident.

1253
MCQmedium

A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect anomalous Microsoft Entra ID sign-ins. The rule runs every 5 minutes and queries the SigninLogs table for sign-ins from IP addresses outside the organization's known country codes. To avoid duplicates, the rule should generate an incident only once for a particular user-IP combination until the combination is not seen for 60 minutes. Which configuration should the analyst use in the analytics rule wizard?

A.Alert details section
B.Query scheduling section
C.Incident settings tab - Grouping configuration
D.Entity mapping section
AnswerC

The Incident settings tab contains the grouping configuration, which allows you to enable incident grouping and set a grouping window during which alerts triggered by the same rule are automatically merged into a single incident. Crucially, you can enable 'Reset grouping' to restart the grouping window whenever certain properties change, such as a new entity being found, thereby preventing duplicate incidents by beginning a fresh aggregation period. This is the exact mechanism that addresses the creation of duplicate incidents for repeated events within a short timeframe.

Why this answer

The Incident settings tab's Grouping configuration allows you to group alerts into a single incident based on specific criteria, such as user-IP combination, and to suppress re-creation of an incident for a defined time window (e.g., 60 minutes) after the last occurrence. This directly addresses the requirement to avoid duplicate incidents for the same user-IP pair until it is not seen for 60 minutes.

Exam trap

The trap here is that candidates often confuse the Query scheduling section's 'Run query every' and 'Lookup data from the last' settings with deduplication, not realizing that those control query frequency and data range, not incident grouping or suppression based on entity combinations.

How to eliminate wrong answers

Option A is wrong because the Alert details section is used to configure the alert's name, description, severity, and tactics, not to control incident grouping or deduplication logic. Option B is wrong because the Query scheduling section defines how often the rule runs and the query lookback period, but it does not provide settings to group alerts or suppress duplicates based on entity combinations. Option D is wrong because Entity mapping section maps query results to entities (e.g., user, IP) for correlation and investigation, but it does not include any grouping or deduplication configuration.

1254
Multi-Selecthard

Your Microsoft Defender XDR environment has an advanced hunting query that returns devices potentially affected by a known vulnerability. You want to create a custom detection rule that triggers an alert when more than 10 devices are affected. Which THREE steps are required?

Select 3 answers
A.Set the rule frequency and threshold to trigger when the query returns more than 10 results.
B.Configure the rule action to generate an alert in Microsoft Defender XDR.
C.Assign the rule to a severity level.
D.Create a Power Automate flow to send an email when the rule triggers.
E.Save the advanced hunting query as a custom detection rule.
AnswersA, B, E

In Microsoft Defender XDR custom detection rules, you must set both the rule frequency (how often the query runs, such as every hour) and the threshold (the number of results that triggers the rule) in the rule's settings. For this scenario, configuring the threshold to fire when the query returns more than 10 results ensures that only significant matches generate alerts, reducing false positives. This step is essential because without a defined frequency and threshold, the rule has no scheduling or triggering condition to act on.

Why this answer

Setting the rule frequency and threshold to trigger when the query returns more than 10 results directly implements the requirement to alert when more than 10 devices are affected. In Microsoft Defender XDR custom detection rules, the threshold condition is configured in the rule settings to evaluate the number of query results against a specified count, enabling precise alert triggering based on result volume.

Exam trap

The trap here is that candidates often confuse optional post-alert actions (like Power Automate flows or severity assignment) with the mandatory steps required to create a functional custom detection rule, leading them to select options C or D instead of focusing on the core rule creation steps (save query, set frequency/threshold, configure alert action).

1255
MCQeasy

A security analyst needs to contain a compromised device that is spreading malware in the network. The device is enrolled in Microsoft Intune and managed by Microsoft Defender for Endpoint. What is the fastest way to isolate the device from the network?

A.Disable the device in Microsoft Intune.
B.Use Microsoft Defender for Endpoint to initiate device isolation.
C.Perform a remote wipe of the device from Microsoft Intune.
D.Block the user's account in Microsoft Entra ID.
AnswerB

Device isolation in Microsoft Defender for Endpoint is a response action that blocks all inbound and outbound network traffic on the endpoint, except for communication with Defender for Endpoint cloud services. It preserves the sensor's ability to send telemetry and receive additional commands while effectively cutting off lateral movement and data exfiltration. This is the intended containment mechanism for a compromised device during incident response.

Why this answer

Microsoft Defender for Endpoint provides a dedicated 'Device isolation' action that immediately blocks all network traffic to and from the device while maintaining connectivity to the Defender service for management and monitoring. This is the fastest containment method as it can be triggered directly from the Defender portal without requiring additional configuration or user interaction.

Exam trap

The trap here is that candidates often confuse device isolation with account blocking or device wipe, not realizing that isolation is a network-level containment action that preserves the device's ability to communicate with the security management plane.

How to eliminate wrong answers

Option A is wrong because disabling a device in Microsoft Intune only prevents it from receiving new policies or apps; it does not cut existing network connections or stop active malware spread. Option C is wrong because a remote wipe deletes all data from the device, which is a destructive and slower process that does not instantly isolate the device from the network. Option D is wrong because blocking the user's account in Microsoft Entra ID prevents authentication but does not block the device's existing network traffic or stop malware already running on the device.

1256
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. A security analyst reports that incidents related to ransomware are not being automatically triaged by the SOC automation playbook. You confirm that the playbook is enabled and connected to the analytics rule. What is the most likely cause of the issue?

A.The Microsoft Sentinel workspace is in a different region than Microsoft Defender XDR.
B.The incident is not being created by the analytics rule.
C.The playbook is not associated with the correct analytics rule in the automation rule.
D.The automation rule that triggers the playbook is set to run only when the incident is created by a specific provider (e.g., Microsoft Defender XDR), but the incident is created by Microsoft Sentinel.
AnswerD

If the automation rule includes a condition using the 'Provider' property — such as requiring it to equal 'Microsoft Defender XDR' — then an incident created by a Microsoft Sentinel analytics rule will not match. Analytics rule incidents have their Provider field set to 'Microsoft Sentinel' by default, regardless of the source data source, so the rule's condition evaluates to false and the playbook never triggers. To fix this, remove the provider filter or change it to 'Microsoft Sentinel' (or set it to 'Other' depending on the version), ensuring the automation rule runs for incidents generated by the desired analytics rule.

Why this answer

The automation rule that triggers the playbook is configured with a condition that restricts it to incidents created by a specific provider, such as Microsoft Defender XDR. However, the ransomware incident is being created by Microsoft Sentinel (e.g., via an analytics rule), not by Microsoft Defender XDR. This provider mismatch prevents the automation rule from firing, so the playbook never runs, even though the playbook itself is enabled and connected to the analytics rule.

Exam trap

The trap here is that candidates assume the playbook or analytics rule association is the problem, when in fact the automation rule's provider condition silently filters out the incident, causing the playbook to never trigger despite all other connections being correct.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel and Microsoft Defender XDR can be integrated across regions; region mismatch does not prevent automation rules from triggering playbooks. Option B is wrong because the question states that incidents related to ransomware are not being automatically triaged, implying that incidents are indeed being created (the analyst sees them), but the playbook is not running. Option C is wrong because the playbook is confirmed to be enabled and connected to the analytics rule; the issue lies in the automation rule's provider filter, not in the playbook-to-rule association.

1257
MCQhard

A global organization has Azure subscriptions organized under a single management group. The security team wants to ensure that the Azure Security Benchmark initiative is assigned once to cover all current and future subscriptions within that management group, without needing to assign it individually. They also want to see compliance results aggregated at the management group level. In Microsoft Defender for Cloud, what is the correct approach to achieve this?

A.Assign the Azure Security Benchmark initiative directly to the management group via Azure Policy, and use the Defender for Cloud's Regulatory Compliance dashboard.
B.Enable Defender for Cloud's enhanced security features on each subscription, and the benchmark will be automatically applied.
C.Create a custom assessment in Defender for Cloud that queries the management group scope.
D.Assign the initiative to the root management group using Azure Policy, then configure Defender for Cloud to ignore individual subscription assignments.
AnswerA

Assigning the Azure Security Benchmark initiative at the management group scope via Azure Policy applies the policy definitions to every subscription within that group through inheritance. Defender for Cloud's Regulatory Compliance dashboard then evaluates those assigned initiatives and aggregates the compliance results for the whole management group, providing a single-pane view of security controls. This is the intended method for centralized, organization-wide compliance monitoring because it avoids the need to assign the initiative separately to each subscription.

Why this answer

Assigning the Azure Security Benchmark initiative directly to the management group via Azure Policy ensures that the policy initiative is inherited by all current and future subscriptions under that management group. Defender for Cloud's Regulatory Compliance dashboard then aggregates compliance results at the management group level, providing a single view of compliance across the entire hierarchy without requiring individual assignments.

Exam trap

The trap here is that candidates may think enabling enhanced security features in Defender for Cloud automatically applies the Azure Security Benchmark, but in reality, the benchmark must be explicitly assigned as a policy initiative, and the management group scope is the correct way to cover all subscriptions.

How to eliminate wrong answers

Option B is wrong because enabling Defender for Cloud's enhanced security features on each subscription does not automatically assign the Azure Security Benchmark initiative; the benchmark must be explicitly assigned via Azure Policy. Option C is wrong because creating a custom assessment in Defender for Cloud that queries the management group scope does not enforce the Azure Security Benchmark initiative across subscriptions; it only provides a custom query without policy-driven compliance evaluation. Option D is wrong because assigning the initiative to the root management group would cover all subscriptions, but configuring Defender for Cloud to ignore individual subscription assignments is unnecessary and not a supported configuration; the correct approach is to assign directly to the target management group.

1258
MCQhard

A security analyst is hunting for a targeted phishing attack in Microsoft 365 Defender. They have identified a phishing email delivered to a user and want to find all devices where the user clicked the link in the email, and any processes that were spawned from the browser on those devices. Which advanced hunting strategy is most effective to correlate the email, network, and process data?

A.Query EmailEvents for the email, then DeviceLogonEvents for user logons, then DeviceProcessEvents for process creations after logon.
B.Query EmailUrlInfo for the URL, then DeviceNetworkEvents for devices that connected to that URL, then DeviceProcessEvents for processes on those devices that started shortly after the connection.
C.Query EmailAttachmentInfo, then DeviceFileEvents for files dropped.
D.Query IdentityLogonEvents, then DeviceEvents from the device where the logon occurred.
AnswerB

This is the correct hunting path because EmailUrlInfo directly reveals the malicious URL from the email, DeviceNetworkEvents captures the outbound connection made by the endpoint when the user clicks that URL, and DeviceProcessEvents can then be filtered by a short time window around that network event to identify the payload process. Joining these tables on device ID and timestamp gives a precise, evidence-backed chain from email to network connection to execution. This approach works for link-based phishing even when the user is already logged on and no new authentication event occurs.

Why this answer

It directly correlates the malicious URL from the email (via EmailUrlInfo) with devices that connected to that URL (via DeviceNetworkEvents), then identifies any processes spawned on those devices shortly after the connection (via DeviceProcessEvents). This sequence maps the attack chain from email delivery to network connection to post-click process execution, which is exactly what the analyst needs to find devices where the link was clicked and any resulting processes.

Exam trap

The trap here is that candidates often choose Option A, mistakenly thinking that user logon events are a reliable proxy for link clicks, but logons do not indicate that the user actually clicked the URL or that any malicious process was spawned from the browser.

How to eliminate wrong answers

Option A is wrong because DeviceLogonEvents captures user authentication events, not the specific act of clicking a link in a browser; correlating logons with process creations is too broad and misses the direct network connection to the phishing URL. Option C is wrong because it focuses on email attachments and file drops, but the question specifies a phishing email with a link, not an attachment; DeviceFileEvents would not capture browser network connections or spawned processes from clicking a URL. Option D is wrong because IdentityLogonEvents tracks identity-based logon events, not email or network activity; it cannot correlate the specific phishing email or URL with device processes.

1259
Multi-Selecteasy

Which TWO actions should a SOC analyst take immediately after confirming a ransomware incident in Microsoft Defender XDR?

Select 2 answers
A.Isolate affected devices from the network.
B.Begin restoring data from backups.
C.Disable all mailboxes in the organization.
D.Reset passwords for compromised accounts and enforce MFA.
E.Collect a full memory dump from each affected device.
AnswersA, D

Isolating affected devices at the switch or via VLAN segmentation immediately stops the ransomware's lateral movement over SMB, RDP, or WinRM, while keeping the device powered on so volatile data remains intact for later forensic acquisition. This containment measure is the top priority because a single connected endpoint can encrypt an entire network in minutes, including backups that are mounted as network drives.

Why this answer

Option A is correct because isolating affected devices in Microsoft Defender XDR (via the device isolation action) immediately stops lateral movement, command-and-control communication, and further encryption by cutting the host off from the network while preserving the ability to investigate remotely. Option D is correct because ransomware actors commonly obtain and reuse compromised credentials, so resetting passwords for affected accounts and enforcing MFA revokes the attacker's access and prevents re-entry or persistence through valid accounts. Option B is not an immediate containment action; restoring from backups should occur only after the threat is contained and the environment is verified clean, otherwise restored data can be re-encrypted.

Option C is too broad and destructive — disabling all mailboxes organization-wide is not a proportionate or standard ransomware response and would disrupt business without addressing the root compromise. Option E, collecting a full memory dump, is a forensic step that may be valuable later but is not one of the two immediate containment and credential-remediation actions required upon confirmation.

Exam trap

SC-200 often tests the confusion between containment actions and recovery or forensic actions, tempting candidates to choose backup restoration or memory collection as 'immediate' steps when they are actually later-phase activities.

1260
MCQmedium

A company has several Azure virtual machines running SQL Server (IaaS). The security team wants to enable Advanced Threat Protection for these SQL Server instances to detect threats like SQL injection. What should they do?

A.Deploy the SQL Server IaaS Agent extension on each VM and enable Azure Defender for SQL in Microsoft Defender for Cloud.
B.Enable Azure Defender for Servers on the subscription; it automatically protects SQL Server workloads.
C.Enable Azure Defender for SQL on the Log Analytics workspace used by the VMs.
D.Configure the Microsoft Sentinel SQL connector to ingest SQL audit logs.
AnswerA

Correct. The SQL IaaS Agent extension registers the VM with the SQL resource provider. After that, enabling Azure Defender for SQL (under Defender for Cloud plans) provides Advanced Threat Protection and vulnerability assessment for the SQL Server instances.

Why this answer

To enable Advanced Threat Protection for SQL Server IaaS, you must deploy the SQL Server IaaS Agent extension on each VM, which allows the VM to register with the SQL IaaS platform. Then, you enable Azure Defender for SQL in Microsoft Defender for Cloud, which provides threat detection for SQL injection and other anomalous activities. This combination ensures the SQL Server instances are monitored by Defender for Cloud's SQL-specific protections.

Exam trap

The trap here is that candidates often confuse Azure Defender for Servers with Azure Defender for SQL, assuming server-level protection automatically covers SQL workloads, but SQL-specific threat detection requires the dedicated SQL Defender plan and the IaaS Agent extension.

How to eliminate wrong answers

Option B is wrong because Azure Defender for Servers protects the VM's operating system and network, but it does not automatically enable SQL-specific threat detection like SQL injection; you need Azure Defender for SQL for that. Option C is wrong because Azure Defender for SQL is enabled at the subscription or workspace level for PaaS SQL databases, not for SQL Server IaaS VMs, which require the IaaS Agent extension. Option D is wrong because the Microsoft Sentinel SQL connector ingests audit logs for analysis in Sentinel, but it does not enable Advanced Threat Protection or real-time threat detection for SQL Server IaaS; that requires Defender for SQL.

1261
MCQeasy

A security analyst is reviewing phishing emails in Microsoft 365 Defender and wants to identify all messages that were blocked by an anti-phish policy before delivery. The analyst plans to use advanced hunting. Which table column indicates whether an email was blocked as phishing?

A.EmailEvents table, the 'DeliveryAction' column
B.EmailPostDeliveryEvents table, the 'Action' column
C.EmailAttachmentInfo table, the 'FileType' column
D.EmailUrlInfo table, the 'Url' column
AnswerA

The EmailEvents table in Microsoft 365 Defender (Threat Explorer) records the system-level disposition for each message during the mail flow pipeline, and the DeliveryAction column stores the final verdict (e.g., Delivered, Blocked, Junked) determined by Exchange Online Protection policies such as anti-phishing and anti-spam. Since the question specifically asks about the initial delivery decision for phishing emails, this column is the authoritative source for whether a message was blocked at the edge or reached the inbox. Other columns in EmailEvents (e.g., ThreatName, Policy) can further filter the results, making it the correct place to start.

Why this answer

The EmailEvents table records actions taken on emails before delivery, including whether a message was blocked by anti-phish policies. The 'DeliveryAction' column specifically indicates the final disposition, such as 'Blocked' for phishing. This makes it the correct source for identifying pre-delivery phishing blocks in advanced hunting.

Exam trap

The trap here is that candidates confuse the EmailPostDeliveryEvents table (which shows post-delivery remediation actions like 'Move to Junk' or 'Soft Delete') with pre-delivery blocking, but the correct table for pre-delivery phishing blocks is EmailEvents with the 'DeliveryAction' column.

How to eliminate wrong answers

Option B is wrong because the EmailPostDeliveryEvents table captures actions taken after delivery (e.g., Zero-Hour Auto Purge), not pre-delivery blocks. Option C is wrong because the EmailAttachmentInfo table stores metadata about attachments (e.g., file type), not the delivery action or phishing disposition. Option D is wrong because the EmailUrlInfo table contains URLs found in emails, not the action taken on the email itself.

1262
MCQhard

Your organization's Microsoft Sentinel workspace ingests logs from multiple regions. During an incident, you need to search for a specific user's activity across all workspaces in a single query. What is the most efficient way to accomplish this?

A.Use a cross-workspace query with the workspace() expression.
B.Run separate queries in each workspace and combine results manually.
C.Create a new analytics rule that queries all workspaces.
D.Use the Microsoft Sentinel search feature with the workspace filter.
AnswerA

Cross-workspace queries using the workspace() expression allow you to reference multiple Log Analytics workspaces in a single KQL query, typically with the union operator. This is the most efficient way to search for threats across Microsoft Sentinel workspaces because it avoids data duplication and runs in one query request, returning merged results that can be further processed with KQL operators like project, where, or summarize.

Why this answer

The workspace() expression in Kusto Query Language (KQL) allows you to include data from multiple Log Analytics workspaces in a single query. By specifying the workspace ID or name within the expression, you can search across all relevant workspaces without needing to run separate queries or manually combine results. This is the most efficient method because it executes as a single query against the underlying Azure Data Explorer clusters, minimizing latency and administrative overhead.

Exam trap

The trap here is that candidates may confuse the workspace filter in the Sentinel search UI with the KQL workspace() expression, assuming the filter can query multiple workspaces when it actually only filters data within the currently selected workspace.

How to eliminate wrong answers

Option B is wrong because running separate queries in each workspace and manually combining results is inefficient, error-prone, and does not scale; it also prevents using unified KQL operators like union or join across workspaces. Option C is wrong because creating a new analytics rule is designed for ongoing detection and alerting, not for ad-hoc incident investigation; it would also require defining logic and scheduling, which is not suitable for a one-time search. Option D is wrong because the Microsoft Sentinel search feature with the workspace filter only queries the current workspace; it does not support cross-workspace queries natively, and the filter merely narrows results within that single workspace.

1263
MCQeasy

A company enables Microsoft Defender for Cloud on its Azure subscription. The security team wants to ensure that all existing and future Azure VMs have Just-In-Time (JIT) VM access configured. Which of the following actions must the team take first to enable JIT for VMs?

A.Enable the 'Just-In-Time VM access' plan in Microsoft Defender for Cloud's environment settings
B.Configure a network security group (NSG) to allow RDP traffic from a specific IP range
C.Create a security policy assignment to block all inbound RDP traffic
D.Install the Log Analytics agent on all VMs
AnswerA

Enabling the Just-In-Time VM access plan in Microsoft Defender for Cloud's environment settings is the prerequisite step that activates the JIT feature for the subscription. Before any VM can be protected or any request processed, the plan must be turned on; after that, you configure individual VMs by selecting ports, allowed source IPs, and the maximum time window for access. Once configured, a user's access request causes Defender for Cloud to dynamically create temporary NSG allow rules, and those rules are automatically removed when the window expires.

Why this answer

Enabling the 'Just-In-Time VM access' plan in Microsoft Defender for Cloud's environment settings is the prerequisite step that activates the JIT feature for the subscription. Without this plan enabled, Defender for Cloud cannot enforce JIT policies on any VMs, regardless of NSG or agent configurations.

Exam trap

The trap here is that candidates often think JIT requires an agent or manual NSG configuration, but the first step is always enabling the plan in Defender for Cloud's environment settings, as JIT is a cloud-level policy feature, not a VM-level agent-based one.

How to eliminate wrong answers

Option B is wrong because configuring an NSG to allow RDP from a specific IP range is a manual access control method, not the first step to enable JIT; JIT itself dynamically manages NSG rules. Option C is wrong because creating a security policy to block all inbound RDP traffic would prevent JIT from opening ports on demand, as JIT requires the ability to temporarily allow traffic. Option D is wrong because the Log Analytics agent is not required for JIT VM access; JIT works through Azure Resource Manager and NSG rules, not agent-based monitoring.

1264
MCQhard

You are a security operations analyst for Contoso Ltd. The company uses Microsoft Sentinel as its SIEM and Microsoft Defender for Cloud Apps for SaaS security. You are tasked with threat hunting for potential data exfiltration via Microsoft SharePoint Online. You need to create a hunting query that identifies users who have downloaded an unusually high number of files from SharePoint within a short time window compared to their historical baseline. The query should be run in Microsoft Sentinel using the OfficeActivity table. Which of the following approaches should you take?

A.Use the HuntingBookmark table to search for user activity
B.Query the CommonSecurityLog table for SharePoint events and look for high volumes of outbound traffic
C.Query the OfficeActivity table, filter for Operation=='FileDownloaded', summarize by UserId and bin(TimeGenerated, 1h), then use a join with a historical baseline table to detect deviations
D.Query the SecurityAlert table for alerts related to data exfiltration
AnswerC

Filtering OfficeActivity for Operation=='FileDownloaded' and summarising with bin(TimeGenerated, 1h) aggregates download counts per user per hour, satisfying the short-window requirement. Joining against a historical baseline table then surfaces deviations from each user's normal behaviour, which is precisely the anomaly detection the stem demands for SharePoint exfiltration hunting.

Why this answer

The OfficeActivity table in Microsoft Sentinel contains audit logs for Microsoft 365 services, including SharePoint Online. Filtering for Operation=='FileDownloaded' and summarizing by UserId and time bin allows you to count downloads per user per hour. Joining with a historical baseline table (e.g., created via a separate query or using the 'summarize' operator over a longer period) enables detection of anomalies compared to each user's normal behavior.

Exam trap

SC-200 often tests the correct table for a given data source; candidates may mistakenly choose CommonSecurityLog or SecurityAlert instead of OfficeActivity for SharePoint activity.

How to eliminate wrong answers

Option A is wrong because the HuntingBookmark table stores bookmarks created by analysts, not raw SharePoint activity events. Option B is wrong because CommonSecurityLog is for network security devices (e.g., firewalls, proxies), not SharePoint audit logs. Option D is wrong because SecurityAlert contains generated alerts, not raw activity data needed for proactive hunting.

1265
MCQmedium

You are investigating a Microsoft Sentinel incident involving a user who clicked a phishing link. The incident includes alerts from Microsoft Defender for Office 365. You need to identify if any other users received the same phishing email. What should you do?

A.Check the incident timeline for related alerts
B.Review the incident graph in Microsoft Sentinel
C.Run a KQL query in Advanced Hunting
D.Use the Threat Explorer in Microsoft Defender for Office 365
AnswerD

Threat Explorer (also known as Explorer) in Microsoft Defender for Office 365 is purpose-built for investigating email threats across all mailboxes. It allows searching by message ID, subject, sender, recipient, and delivery status, and can filter by detection technology, threat type, and campaign ID. This enables the analyst to quickly locate every copy of the phishing email, assess the blast radius, and take remediation actions directly.

Why this answer

Threat Explorer in Microsoft Defender for Office 365 is the purpose-built tool for investigating email threats at scale — it lets you pivot on the phishing campaign's sender, URL, or message ID and see every recipient who received the same message. This is exactly the 'who else got this email' question. Sentinel's incident graph and timeline show correlated alerts but do not provide the email-centric recipient enumeration that Threat Explorer does.

Exam trap

SC-200 often tests whether candidates pick the generic Sentinel tool (incident graph, timeline, or Advanced Hunting) when the scenario specifically requires email-centric recipient enumeration, which only Threat Explorer provides.

How to eliminate wrong answers

Option A is wrong because the incident timeline shows chronological alert and entity activity for the incident, not a list of all recipients of a specific phishing email. Option B is wrong because the incident graph visualizes relationships between entities (users, hosts, IPs) in the incident, but it does not enumerate email recipients across the tenant. Option C is wrong because a KQL query in Advanced Hunting could theoretically find related email events, but it is a generic hunting tool, not the purpose-built email investigation interface; Threat Explorer is the direct, intended answer for this scenario.

1266
MCQmedium

An analyst runs this PowerShell script to query Microsoft Sentinel data. The query returns no results. What is the most likely reason?

A.The timestamp filter is invalid; it should use TimeGenerated instead of Timestamp
B.The query syntax is incorrect; summarize cannot be used after where
C.No events matched the specific combination of process name and command line in the last 7 days
D.The API endpoint URL is incorrect; it should be /v2/workspaces
AnswerC

The script likely used a query such as DeviceProcessEvents | where ProcessCommandLine contains 'javascript:' combined with a filter for rundll32.exe as the process name. In most environments, rundll32.exe executing a JavaScript URI (e.g., JScript or VBScript) is an uncommon attack pattern that rarely occurs, so the query returned an empty table even though the syntax and endpoint are correct. The absence of matching records, not an API error or schema mistake, explains why no data was returned.

Why this answer

The query syntax is valid (e.g., using where and summarize appropriately), the API endpoint and timestamp filter are standard for Microsoft Sentinel queries. The most probable reason for no results is that no events with rundll32.exe and javascript in the command line occurred within the specified 7-day window. Options A, B, and D describe issues that would typically cause errors, not just empty results, making C the most likely explanation.

1267
MCQhard

Your organization uses Microsoft Defender for Office 365. You need to configure a policy that automatically moves emails detected as 'Bulk' to the user's Junk Email folder. However, users must be able to override this by adding the sender to their Safe Senders list. What should you configure?

A.Anti-spam policy with Bulk email threshold set to a value that triggers junk action
B.Anti-phishing policy
C.Malware filter policy
D.Connection filter policy
AnswerA

This is the correct control because sender complaint data produces a Bulk Complaint Level (BCL) from 0 to 9 for each inbound message, and the anti-spam policy's bulk email threshold routes messages that exceed that BCL to the Junk Email folder. A lower threshold value, such as 6, classifies more senders as bulk and makes the action increasingly aggressive. Safe Senders and Safe Lists can override this action for trusted senders, but no other policy in Microsoft Defender for Office 365 applies BCL thresholds.

Why this answer

The Bulk email threshold setting in an anti-spam policy allows you to specify a Bulk Complaint Level (BCL) value that, when exceeded, triggers a specific action such as moving the email to the Junk Email folder. This action respects the user's Safe Senders list, meaning if the sender is added to that list, the email will bypass the junk folder and be delivered to the inbox. Other policy types like anti-phishing, malware filter, or connection filter do not provide this granular control over bulk email classification and user override behavior.

Exam trap

The trap here is that candidates often confuse anti-spam policies with anti-phishing policies, assuming phishing protection handles bulk email, but only anti-spam policies contain the Bulk email threshold setting that interacts with the user's Safe Senders list.

How to eliminate wrong answers

Option B is wrong because anti-phishing policies are designed to protect against impersonation and phishing attempts, not to handle bulk email classification or junk folder actions based on BCL thresholds. Option C is wrong because malware filter policies focus on detecting and removing malicious attachments or links, not on categorizing or acting on bulk email. Option D is wrong because connection filter policies control email flow based on sender IP reputation (e.g., allow or block lists), not on the content-based bulk email detection or user Safe Senders override.

1268
MCQeasy

During an incident response, you need to collect a forensic image of a Windows 10 device managed by Microsoft Intune. Which Microsoft Defender XDR feature should you use?

A.Microsoft Defender for Cloud Apps
B.Microsoft Purview eDiscovery
C.Microsoft Defender for Endpoint Live Response
D.Microsoft Sentinel
AnswerC

Microsoft Defender for Endpoint Live Response provides an interactive, remote shell on an onboarded endpoint, enabling incident responders to run built-in, PowerShell, or Python commands. It supports collecting files (collectfile), viewing processes and network connections, and running forensic scripts to extract memory, registry, or disk artifacts. This is the correct tool for live forensic data collection directly from the machine, using the Defender for Endpoint sensor as the transport.

Why this answer

Microsoft Defender for Endpoint Live Response (Option C) is the correct feature because it provides a remote shell connection to a Windows 10 device, allowing an incident responder to collect a forensic image by running commands such as `getfile` or `putfile` to acquire disk or memory artifacts. This capability is specifically designed for live incident response on Intune-managed endpoints, enabling acquisition of forensic data without requiring physical access or pre-staged imaging tools.

Exam trap

The trap here is that candidates confuse the forensic imaging requirement with a general log collection or eDiscovery tool, overlooking that Live Response is the only option that provides direct, interactive remote access to a managed endpoint for acquiring disk or memory artifacts during an active incident.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on shadow IT discovery and SaaS app governance, not on collecting forensic images from managed Windows 10 endpoints. Option B is wrong because Microsoft Purview eDiscovery is designed for legal discovery of content in Microsoft 365 (e.g., Exchange, SharePoint, Teams), not for live forensic imaging of a device's disk or memory. Option D is wrong because Microsoft Sentinel is a SIEM/SOAR platform that ingests and analyzes security logs from various sources, but it does not have native capabilities to remotely execute forensic image collection commands on a Windows 10 endpoint.

1269
MCQmedium

A security administrator wants to enable vulnerability assessment for all existing and future Azure virtual machines using the integrated Microsoft Defender Vulnerability Management solution. Which action should they take in Microsoft Defender for Cloud?

A.Enable 'Microsoft Defender for Servers' plan and check the 'Vulnerability assessment' option in the environment settings
B.Install the Log Analytics agent and configure the Qualys connector on each VM
C.Create a policy assignment from the built-in initiative 'Enable Azure Monitor for VMs'
D.Enable 'Servers' workload protection in Defender for Cloud and then manually deploy the VA agent to each existing VM using Azure Policy
AnswerA

Enabling the Microsoft Defender for Servers plan at the subscription level activates the integrated Microsoft Defender Vulnerability Management (MDVM) solution, which is the default vulnerability assessment engine in Defender for Cloud. Checking the 'Vulnerability assessment' option in the environment settings auto-provisions this integrated scanner across every current and future VM without requiring manual agent installation. This ensures continuous coverage and management of vulnerabilities through Defender for Cloud's dashboards and recommendations.

Why this answer

To enable vulnerability assessment for all existing and future Azure VMs using the integrated Microsoft Defender Vulnerability Management solution, you must enable the 'Microsoft Defender for Servers' plan in Defender for Cloud and then check the 'Vulnerability assessment' option within the environment settings. This action activates the built-in, agentless vulnerability assessment engine that is part of Defender for Cloud, automatically scanning VMs without requiring additional agents or manual deployment.

Exam trap

The trap here is that candidates often confuse enabling 'Microsoft Defender for Servers' (which provides general threat protection) with the separate 'Vulnerability assessment' toggle that must be explicitly checked to activate the integrated vulnerability scanning, leading them to select option D which only mentions enabling workload protection.

How to eliminate wrong answers

Option B is wrong because installing the Log Analytics agent and configuring the Qualys connector is a legacy approach for vulnerability assessment that requires a third-party solution and manual per-VM configuration, not the integrated Microsoft Defender Vulnerability Management solution. Option C is wrong because creating a policy assignment from 'Enable Azure Monitor for VMs' enables VM insights and Log Analytics agent deployment, not vulnerability assessment via Defender for Cloud. Option D is wrong because enabling 'Servers' workload protection alone does not automatically enable vulnerability assessment; you must also check the 'Vulnerability assessment' option, and manually deploying the VA agent is unnecessary when the integrated solution is agentless.

1270
MCQeasy

Your team uses Microsoft Sentinel to manage incidents. You want to automatically assign incidents with a severity of 'High' to the Tier 2 security team. Which feature should you configure?

A.Playbook
B.Analytics rule
C.Automation rule
D.Workbook
AnswerC

Automation rules in Microsoft Sentinel trigger on incident creation and can set owner, status and severity automatically. Configuring a rule that matches severity equals High and assigns the Tier 2 team satisfies the automatic assignment requirement without manual triage.

Why this answer

Automation rules in Microsoft Sentinel are designed to perform lightweight incident-level orchestration such as assigning owners, changing severity, adding tags, or closing incidents based on conditions. To auto-assign High-severity incidents to Tier 2, you create an automation rule with a condition on severity and an action to assign the owner. This is exactly the native, no-code mechanism for incident triage routing.

Exam trap

SC-200 often tests the confusion between automation rules (incident orchestration: assign, tag, close) and playbooks (multi-step remediation workflows), so candidates pick Playbook when the task is simple incident assignment.

How to eliminate wrong answers

Option A is wrong because a playbook is a Logic Apps workflow triggered by an automation rule or manually, used for complex multi-step remediation (enrichment, ticketing, containment) — it is not the primary mechanism for simple owner assignment. Option B is wrong because an analytics rule generates alerts and incidents from log queries; it detects threats but does not perform post-creation incident management like assignment. Option D is wrong because a workbook is a visualization/reporting canvas for querying and displaying data, with no incident-handling capability.

1271
Multi-Selecthard

A security analyst is investigating a potential data exfiltration incident in Microsoft Sentinel. The analyst needs to identify which users may have been compromised. Which THREE data sources should be queried to gather the most relevant evidence?

Select 3 answers
A.WindowsEvent from Microsoft Defender for Endpoint.
B.AzureActivity from Azure Monitor.
C.SigninLogs and AuditLogs from Microsoft Entra ID.
D.OfficeActivity from Microsoft 365.
E.CloudAppEvents from Microsoft Defender for Cloud Apps.
AnswersC, D, E

SigninLogs records authentication events and AuditLogs captures directory changes such as role assignments, consent grants and credential additions. Together they reveal anomalous sign-ins and privilege escalation tied to compromised accounts, satisfying the need to identify which users were affected.

Why this answer

SigninLogs and AuditLogs from Microsoft Entra ID (C) are essential because SigninLogs reveal authentication anomalies such as impossible-travel or risky sign-ins tied to compromised accounts, while AuditLogs capture directory changes like new credentials or permission grants made by an attacker. OfficeActivity from Microsoft 365 (D) is correct because it records user and admin actions across Exchange, SharePoint, OneDrive, and Teams, exposing mail-forwarding rules, mass downloads, or file-sharing activity typical of exfiltration. CloudAppEvents from Microsoft Defender for Cloud Apps (E) is correct because it provides granular SaaS activity, including file downloads, uploads, and sharing events across connected cloud apps that reveal data movement.

WindowsEvent from Defender for Endpoint (A) is endpoint telemetry focused on device-level process and file events, not user identity or cloud-service activity, so it is less directly relevant to identifying compromised users. AzureActivity from Azure Monitor (B) logs control-plane operations on Azure resources (e.g., role assignments, resource deployments) and does not capture the identity, mail, or SaaS activity needed here.

1272
Multi-Selecteasy

Which THREE steps are part of the incident response process when using Microsoft Sentinel?

Select 3 answers
A.Identify the incident by creating an analytics rule.
B.Investigate the incident using hunting queries and entity timelines.
C.Remediate the incident by running playbooks or manual actions.
D.Report the incident to the security team via email.
E.Triage the incident to determine severity.
AnswersB, C, E

Investigation is the phase where the analyst uses threat hunting queries, entity timelines, and the investigation graph to reconstruct the attack chain and determine the full scope of compromise. This step involves correlating alerts, user sign-in data, and network artifacts to identify the root cause, affected assets, and potential data loss. In Microsoft Sentinel, a KQL query might pivot on a compromised entity to reveal lateral movement, while the entity timeline provides a chronological view of activities that contextualizes each alert.

Why this answer

Investigating an incident using hunting queries and entity timelines is a core step in the Microsoft Sentinel incident response process. After an incident is created, analysts use KQL-based hunting queries to proactively search for related threats and leverage entity timelines to visualize the sequence of events and entity interactions, which is essential for understanding the scope and impact of the incident.

Exam trap

The trap here is that candidates confuse the proactive detection step of creating analytics rules (which generates incidents) with the reactive incident response step of triaging and investigating those incidents, leading them to incorrectly select Option A as part of the response process.

1273
MCQhard

You are a security administrator for a multinational company using Microsoft Sentinel. You need to ensure that critical incidents are automatically escalated to the on-call team via email and SMS. The on-call schedule uses Microsoft Teams channel. What is the most efficient way to achieve this?

A.Create an automation rule that sends email directly to the on-call team.
B.Build a playbook using Microsoft Teams connector to post a message in the on-call channel with an adaptive card that allows acknowledge and escalate.
C.Configure the analytics rule to send an email when the incident is created.
D.Use a workbook to display critical incidents and expect the team to monitor it.
AnswerB

This is the correct approach because a playbook—built on Azure Logic Apps—can be triggered by an automation rule when an incident is created. The playbook uses the Microsoft Teams connector to post an adaptive card to the on-call channel, and the card's buttons (Acknowledge/Escalate) invoke further logic, such as updating the incident status or notifying a second-tier team. This provides a closed-loop, interactive notification workflow rather than a one-way message.

Why this answer

It uses a Microsoft Teams connector playbook triggered by an automation rule to post an adaptive card in the on-call channel. This allows the on-call team to acknowledge or escalate the incident directly from Teams, fulfilling the requirement for email and SMS escalation through the Teams channel schedule. Automation rules in Sentinel can trigger playbooks based on incident creation or update, making this the most efficient integrated approach.

Exam trap

The trap here is that candidates assume automation rules can natively send emails or SMS, but they can only trigger playbooks or modify incident properties, requiring a Logic App for actual notification delivery.

How to eliminate wrong answers

Option A is wrong because sending email directly via an automation rule does not support SMS or integrate with the Microsoft Teams on-call schedule; automation rules can only trigger playbooks or change incident properties, not send emails natively. Option C is wrong because analytics rules cannot send emails directly; they can only generate alerts or incidents, and email notification would require a separate playbook or logic app. Option D is wrong because a workbook is a passive monitoring tool that requires manual review and does not provide automatic escalation via email or SMS, failing the requirement for automated notification.

1274
Multi-Selecthard

Which TWO actions are effective when threat hunting for lateral movement using remote desktop protocol (RDP) in Microsoft Defender XDR?

Select 2 answers
A.Query DeviceNetworkEvents for inbound connections on port 3389
B.Review CloudAppEvents for access to cloud apps from multiple IPs
C.Correlate RDP connections with successful logon events (Event ID 4624) with LogonType 10
D.Check for unusual email forwarding rules
E.Search for SMB file share connections
AnswersA, C

Querying DeviceNetworkEvents for inbound connections on TCP port 3389 is effective because this is the default port for Remote Desktop Protocol (RDP). Inbound RDP connections from unusual sources or to high-value hosts can indicate an attacker establishing a foothold or performing lateral movement. To refine the hunt, you would look for new or unexpected source IPs, repeated connection attempts, and combine these network observations with authentication logs.

Why this answer

Option A is correct because RDP uses TCP port 3389, so querying DeviceNetworkEvents for inbound connections on port 3389 in Microsoft Defender XDR surfaces potential RDP sessions initiated by an attacker moving laterally to a target device. Option C is correct because a successful RDP logon generates Windows Security Event ID 4624 with LogonType 10 (RemoteInteractive), so correlating those logon events with RDP network connections confirms actual interactive remote sessions rather than mere port scans or blocked attempts. Option B is not relevant because CloudAppEvents covers cloud application activity, not on-premises RDP lateral movement.

Option D is unrelated since unusual email forwarding rules indicate mailbox exfiltration or persistence, not RDP lateral movement. Option E is incorrect because SMB file share connections use ports 445/139 and represent a different lateral movement technique than RDP.

Exam trap

SC-200 often tests the distinction between network-level indicators (port 3389) and host-level logon types (LogonType 10 for RDP), and candidates may incorrectly select cloud app events or SMB connections as relevant to RDP lateral movement.

1275
Multi-Selecteasy

Which THREE are valid incident classification options in Microsoft Sentinel?

Select 3 answers
A.Informational
B.Benign Positive
C.Malicious
D.False Positive
E.True Positive
AnswersB, D, E

Benign Positive is a valid top-level classification in Microsoft Sentinel for activity that is confirmed to be real and potentially interesting but not malicious. Examples include a security tool triggered by an authorized penetration test, a misconfigured internal application, or a user performing an unusual but permitted action. Analysts select this classification to document harmless-but-noteworthy alerts separately from actual threats and false alarms.

Why this answer

(Benign Positive) is correct because Microsoft Sentinel uses incident classification to categorize the outcome of an investigation. A Benign Positive indicates that an alert is triggered by legitimate activity that is expected or acceptable, such as a security tool scanning the network or a user performing an authorized administrative task. This classification helps analysts distinguish between true threats and harmless events without marking them as false positives.

Exam trap

The trap here is that candidates often confuse alert severity levels (like Informational, Low, Medium, High) with incident classification options, leading them to incorrectly select 'Informational' as a valid classification when it is actually a severity label for alerts, not a post-investigation classification for incidents.

Page 16

Page 17 of 18

Page 18