Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 1276–1303

1303 questions total · 18pages · All types, answers revealed

Page 17

Page 18 of 18

1276
MCQhard

A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect a possible password spray attack. The rule must trigger when a single source IP address has more than 10 failed logon attempts on different user accounts within a 30-minute window. The analyst writes a KQL query starting with 'SigninLogs | where ResultType == 50057' (failed logon). Which operator should the analyst use to group events by source IP and count distinct user accounts, then filter for counts above 10?

A.summarize
B.where
C.extend
D.project
AnswerA

The 'summarize' operator is the correct answer because it groups rows by specified columns and applies aggregation functions such as dcount() or count() to calculate distinct user counts per IP. It produces a new table with one row per group, enabling the SOC analyst to derive meaningful metrics like unique users per IP address. Without summarize, no grouping or aggregation can be performed in KQL.

Why this answer

The `summarize` operator is required to group events by source IP address and count distinct user accounts using `dcount()` or `count()`. After summarizing, you apply a `where` clause to filter for counts above 10, which meets the rule's threshold. This is the standard pattern for aggregation in KQL.

Exam trap

The trap here is that candidates often confuse `summarize` with `extend` or `project`, thinking they can achieve aggregation without an explicit grouping operator, or they mistakenly use `where` after a simple filter instead of performing the required count and threshold check.

How to eliminate wrong answers

Option B is wrong because `where` filters rows based on conditions but cannot perform grouping or counting; it would only filter individual sign-in events, not aggregate them. Option C is wrong because `extend` adds new calculated columns to each row without any aggregation or grouping, so it cannot count distinct users per IP. Option D is wrong because `project` selects or reorders columns but does not group or count data; it would merely reduce the columns returned.

1277
MCQeasy

Your organization uses Microsoft Defender for Identity. You need to create a role that allows analysts to view security alerts but not modify them. Which built-in role should you assign?

A.Security Administrator
B.Compliance Administrator
C.Global Administrator
D.Security Reader
AnswerD

Security Reader provides read-only access to security alerts and reports across Microsoft 365 services, including Microsoft Defender for Identity. This role allows users to view and investigate identity-based alerts without the ability to modify settings, making it the correct minimum-permission role for this task.

Why this answer

The Security Reader role (D) is the correct choice because it provides read-only access to security-related features in Microsoft 365 Defender, including the ability to view security alerts from Microsoft Defender for Identity without the ability to modify or respond to them. This aligns directly with the requirement to allow analysts to view alerts but not modify them, as the role grants no write permissions to security configurations or alert states.

Exam trap

The trap here is that candidates often confuse Security Reader with Security Administrator, assuming the 'Administrator' suffix implies broader access, but the key distinction is that Security Reader is the only built-in role that provides read-only access to security alerts without modification rights.

How to eliminate wrong answers

Option A is wrong because the Security Administrator role has full write permissions to security policies and alerts, including the ability to modify alert statuses and configurations, which violates the requirement to prevent modifications. Option B is wrong because the Compliance Administrator role is focused on compliance settings (e.g., data classification, DLP, retention policies) and does not grant access to security alerts from Defender for Identity; it is not designed for security operations viewing. Option C is wrong because the Global Administrator role has unrestricted access to all administrative features, including full control over security alerts, which far exceeds the read-only requirement and introduces unnecessary privilege.

1278
MCQeasy

You are configuring Microsoft Defender for Cloud Apps to enhance visibility into your organization's SaaS app usage. You need to ensure that risky user activities are automatically suspended. What should you configure?

A.Set up IP address range policies.
B.Configure app discovery policies.
C.Create a session policy to block or limit activities based on risk.
D.Define file policies to protect sensitive data.
AnswerC

Session policies in Microsoft Defender for Cloud Apps use reverse proxy conditional access app control to intercept user sessions in real time, allowing you to allow or block specific activities such as downloading sensitive files, copying data, or uploading from risky devices. They can enforce restrictions based on user risk, device compliance, and contextual signals, applying controls dynamically during the active session. This granular, per-activity enforcement is exactly what is needed to 'block or limit activities based on risk' in a real-time manner.

Why this answer

Session policies in Microsoft Defender for Cloud Apps allow you to monitor and control user activities in real time based on risk level. By configuring a session policy with the 'block' or 'limit' action triggered by risk factors (e.g., anomalous location, impossible travel), you can automatically suspend risky user activities without disrupting legitimate usage.

Exam trap

The trap here is that candidates often confuse 'session policies' (which control real-time risky activities) with 'app discovery policies' (which only identify shadow IT) or 'file policies' (which protect data, not user behavior), leading them to select a wrong answer that addresses a different security objective.

How to eliminate wrong answers

Option A is wrong because IP address range policies are used to tag or categorize traffic by location (e.g., known corporate IPs) but do not automatically suspend risky activities; they only provide context for other policies. Option B is wrong because app discovery policies identify and analyze shadow IT usage (e.g., discovering unsanctioned SaaS apps) but do not enforce real-time activity suspension. Option D is wrong because file policies focus on detecting and protecting sensitive data (e.g., DLP rules for credit card numbers) rather than suspending risky user behaviors.

1279
MCQhard

A SOC team wants to use Microsoft Sentinel to detect when a user logs in from a new country not previously seen for that user. They have the SigninLogs table. Which KQL function is most appropriate to build this anomaly detection?

A.timechart()
B.make_set() with lookup
C.dcount()
D.startofday()
AnswerB

make_set() creates a dynamic array of distinct values for each user, effectively building a baseline of historically seen countries by grouping on the user column and applying make_set(Country). When a new login occurs, you can use a lookup or join operation to retrieve that user's set and then check whether the current Country exists in the array using array_contains() or the set_has_element operator. This allows you to flag any login from a country not present in the user's set, making make_set() with lookup the correct and direct method for this anomaly detection logic.

Why this answer

The `make_set()` function creates a dynamic array of distinct values (e.g., countries) per user over a specified time window. By using `lookup` to compare the current sign-in's country against the historical set, you can flag logins from countries not previously seen. This directly implements the 'new country' anomaly detection pattern in KQL.

Exam trap

Microsoft often tests the distinction between aggregate functions that return counts (`dcount`) versus those that return the actual set of values (`make_set`), leading candidates to choose `dcount` when they need to compare individual values against a historical list.

How to eliminate wrong answers

Option A is wrong because `timechart()` is a rendering function used to plot time-series data visually; it does not perform set-based anomaly detection or comparison logic. Option C is wrong because `dcount()` returns an approximate distinct count of values, not the actual set of values needed to check if a specific country has been seen before. Option D is wrong because `startofday()` is a datetime function that truncates timestamps to the start of the day; it has no capability to build or compare historical sets of countries.

1280
MCQhard

Wide World Importers uses Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Purview for data loss prevention (DLP). An incident is generated: 'DLP policy violation - sensitive data shared externally.' The incident shows that a user shared a document containing credit card numbers via SharePoint Online with an external guest. The user is a finance department employee. You need to respond to the incident. The organization wants to minimize business disruption while protecting data. Which of the following is the BEST immediate action?

A.Delete the document from SharePoint Online.
B.Modify the DLP policy to block sharing of credit card numbers.
C.Remove the external guest's access to the document in SharePoint Online.
D.Disable the user's account in Microsoft Entra ID and investigate.
AnswerC

Removing the external guest's access to the document in SharePoint Online is the correct containment step because it directly targets the specific sharing permission that caused the incident. This action revokes the guest's ability to view or download the file while preserving the document for investigation and allowing internal users with existing permissions to continue working. It is a granular, least-privilege response that minimizes disruption and aligns with Microsoft incident response guidance for external sharing.

Why this answer

Removing the external guest's access to the document stops data exposure without affecting the user's work. Option A is wrong: disabling the user prevents all work and may be too drastic. Option B is wrong: deleting the document destroys evidence.

Option D is wrong: DLP policy change takes time and does not stop current exposure.

1281
MCQmedium

You are reviewing a PowerShell script used for automated response on a Windows 10 device managed by Microsoft Defender for Endpoint. What is the intended outcome of this script?

A.It removes all Trojan threats from the device.
B.It updates the antimalware signatures and then performs a scan.
C.It triggers a quick scan if any Trojan detection exists.
D.It configures Windows Defender to exclude Trojan files.
AnswerC

The script includes a conditional statement that evaluates whether any Trojan threat detection is present, likely using Get-MpThreatDetection or Get-MpThreat with a filter for the Trojan threat category. When that condition is true, it executes Start-MpScan with the QuickScan parameter. Because the decision to run the quick scan depends directly on the presence of Trojan detections, the correct characterization is that it triggers a quick scan if any Trojan detection exists.

Why this answer

The script checks for Trojan detections using Get-MpThreat with a threat category filter for Trojans. If any Trojan is found, it triggers Start-MpScan -ScanType QuickScan to perform a quick scan. This matches option C exactly.

Exam trap

The trap here is that candidates may assume the script performs remediation (option A) or updates signatures (option B) because those are common steps in response workflows, but the script only triggers a scan based on detection, not removal or update actions.

How to eliminate wrong answers

Option A is wrong because the script does not remove threats; it only triggers a scan, and removal would require additional commands like Remove-MpThreat. Option B is wrong because the script does not update antimalware signatures (which would require Update-MpSignature) before scanning. Option D is wrong because the script does not configure exclusions; it only checks for threats and initiates a scan.

1282
MCQmedium

During an incident investigation in Microsoft 365 Defender, an analyst examines an email that was reported as phishing. The analyst opens the email entity page and looks at the 'Detection details' section. Which piece of information would the analyst find there?

A.The delivery location and whether the email was delivered to Inbox, Junk, or Quarantine.
B.The authentication statuses (SPF, DKIM, DMARC) for the sender domain.
C.The sender IP address and the recipient email address.
D.The detection technology (e.g., Advanced ML, Reputation) and if the email was part of a phish simulation or a campaign.
AnswerD

Correct. The Detection details tab in Microsoft 365 Defender discloses the precise detection technology that flagged the email—such as Advanced ML, Reputation, or a custom allow/block rule—along with whether the email is part of a phishing simulation campaign or a broader campaign. This tab is distinct from Summary (delivery outcome), Authentication details (SPF/DKIM/DMARC), and Message or Internet headers (transport metadata). For incident investigators, it is the authoritative source for understanding why Defender considered the email malicious, enabling quick triage of genuine threats versus simulation traffic.

Why this answer

The 'Detection details' section on the email entity page in Microsoft 365 Defender specifically shows the detection technology used (e.g., Advanced ML, Reputation, Bulk) and whether the email was part of a phishing simulation or a campaign. This information helps analysts understand how the email was identified as malicious and its context within broader threat activity.

Exam trap

The trap here is that candidates confuse the 'Detection details' section with other sections like 'Summary' or 'Authentication', leading them to select options that describe information found elsewhere on the email entity page.

How to eliminate wrong answers

Option A is wrong because the delivery location (Inbox, Junk, Quarantine) is found in the 'Email details' or 'Summary' section, not in 'Detection details'. Option B is wrong because authentication statuses (SPF, DKIM, DMARC) are displayed in the 'Authentication' section of the email entity page, not in 'Detection details'. Option C is wrong because the sender IP address and recipient email address are shown in the 'Summary' or 'Details' sections, not in 'Detection details'.

1283
MCQmedium

A company uses Microsoft Defender for Cloud to protect Azure virtual machines. The security team receives an alert indicating that a VM is communicating with a known malicious IP address. Which Defender for Cloud feature can be used to automatically block outbound traffic to that IP address by adjusting the network security group (NSG)?

A.Adaptive application controls
B.Just-in-time VM access
C.Adaptive network hardening
D.File integrity monitoring
AnswerC

Adaptive network hardening only recommends inbound NSG rules based on traffic patterns and threat intelligence; it does not automatically block outbound malicious traffic.

Why this answer

None of the listed Defender for Cloud features automatically blocks outbound traffic to a known malicious IP address by adjusting the NSG. Adaptive network hardening only analyzes traffic patterns and threat intelligence to recommend inbound NSG hardening rules; it does not automatically apply outbound deny rules. Automatic outbound blocking would typically require Azure Firewall threat intelligence, a Microsoft Sentinel automation playbook, or a manually configured NSG deny rule.

Exam trap

Do not confuse adaptive network hardening with just-in-time VM access. JIT only manages inbound management ports on a schedule. Adaptive network hardening only recommends inbound NSG rules; neither automatically blocks outbound traffic to a known-malicious destination.

How to eliminate wrong answers

Option A is wrong because adaptive application controls are designed to control which applications can run on a VM, not to block network traffic to specific IP addresses. Option B is wrong because just-in-time VM access reduces the attack surface by locking down inbound ports to a VM and opening them only when needed, but it does not block outbound traffic to malicious IPs. Option D is wrong because file integrity monitoring tracks changes to critical files and registry settings, not network traffic or IP-based blocking.

1284
MCQeasy

Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What does it return?

A.Number of high-severity incidents per status.
B.Total count of high-severity incidents in the last 7 days.
C.Top 5 incident owners by number of high-severity incidents in the last 7 days.
D.Top 5 users assigned to high-severity incidents.
AnswerC

This is correct. After filtering incidents to those with `Severity` equal to 'High' and `TimeGenerated` within the last 7 days, the query performs `summarize count() by Owner`, sorts the owner counts in descending order, and applies `take 5`. That yields exactly the top five incident owners ranked by their number of high-severity incidents in that time period.

Why this answer

The KQL query uses `summarize` with `count()` by `Owner`, then `top 5 by count_`, and filters with `where Severity == 'High'` and `TimeGenerated > ago(7d)`. This returns the top 5 incident owners ranked by the number of high-severity incidents they own in the last 7 days, making option C correct.

Exam trap

The trap here is that candidates confuse `Owner` (the incident owner, often a person or automation rule) with `User` (a user entity involved in the incident), leading them to pick option D, which incorrectly assumes the query returns users assigned to incidents rather than owners.

How to eliminate wrong answers

Option A is wrong because the query does not group or summarize by `Status`; it groups by `Owner` and counts incidents, not statuses. Option B is wrong because the query returns a top 5 list of owners with counts, not a single total count of incidents. Option D is wrong because the query filters by `Owner` (the incident owner, typically a security analyst or automation account), not by `User` (which would refer to a user entity or account involved in the incident).

1285
MCQmedium

During a threat hunt, you suspect a user may have exfiltrated data via email. Which Microsoft 365 Defender advanced hunting table should you query to review email attachments and their file hashes?

A.EmailUrlInfo
B.EmailAttachmentInfo
C.EmailEvents
D.EmailPostDeliveryEvents
AnswerB

EmailAttachmentInfo is the correct table because it is specifically designed to store metadata about files attached to emails, including the file name, file size, and crucially the SHA256 hash. In a threat hunt for data exfiltration, this hash lets you pivot to threat intelligence sources or correlate with command-and-control activities. This table is the only one among the options that directly provides a hash value to verify if a file was malicious or sensitive.

Why this answer

EmailAttachmentInfo is the correct table because it specifically contains metadata about email attachments, including the SHA256 hash of each attached file, file name, file type, and size. This table is designed for scenarios where you need to investigate suspicious attachments, such as during a data exfiltration hunt. The other tables focus on URLs, general email events, or post-delivery actions, not attachment details.

Exam trap

SC-200 often tests the distinction between email-related tables in advanced hunting, and candidates frequently confuse EmailAttachmentInfo with EmailEvents or EmailUrlInfo, forgetting that only EmailAttachmentInfo contains file hashes for attachments.

How to eliminate wrong answers

Option A is wrong because EmailUrlInfo stores information about URLs found in emails, such as the URL and its verdict, not attachments or file hashes. Option C is wrong because EmailEvents contains general email metadata like sender, recipient, subject, and delivery action, but does not include attachment hashes. Option D is wrong because EmailPostDeliveryEvents records post-delivery actions like ZAP (Zero-hour Auto Purge) or manual remediation, not attachment details.

1286
Multi-Selecteasy

Which THREE components are part of Microsoft Defender XDR? (Select three.)

Select 3 answers
A.Microsoft Defender for Endpoint
B.Microsoft Entra ID
C.Microsoft Defender for Identity
D.Microsoft Defender for Cloud
E.Microsoft Defender for Office 365
AnswersA, C, E

Microsoft Defender for Endpoint is one of the core workloads that compose Microsoft Defender XDR, feeding endpoint detections and alerts into the unified incident queue. Its signals correlate with the other Defender services, making it a required component of the suite.

Why this answer

Microsoft Defender XDR is the unified extended detection and response suite that correlates signals across Microsoft's first-party security workloads, and its core components include Microsoft Defender for Endpoint (A), which provides endpoint detection and response (EDR) for devices; Microsoft Defender for Identity (C), which monitors on-premises Active Directory Domain Services signals via sensors to detect identity-based attacks; and Microsoft Defender for Office 365 (E), which protects email, collaboration, and Office apps against phishing, malware, and business email compromise. These three services natively share incidents, alerts, and advanced hunting data in the Microsoft 365 Defender portal, which is why they are part of Defender XDR. Microsoft Entra ID (B) is the identity and access management service (formerly Azure AD) and is not itself a Defender XDR workload, though it feeds identity signals into the suite.

Microsoft Defender for Cloud (D) is a cloud security posture management and workload protection offering for Azure, multicloud, and hybrid resources, and it belongs to the Microsoft Defender for Cloud family rather than being one of the Defender XDR components.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID (formerly Azure AD) as a security detection component because it handles identity, but it is not a source of threat alerts within Defender XDR; instead, it is the identity provider that Defender for Identity monitors for malicious activity.

1287
MCQhard

You are a SOC analyst at Contoso Ltd. The company uses Microsoft Sentinel and Microsoft Defender XDR. A high-severity incident is generated from a Sentinel analytics rule that detects multiple failed logins followed by a successful login from a geographically unusual location for a user. The incident includes an alert from Microsoft Defender for Identity indicating a possible brute-force attack. The user's account is a privileged administrator. Your organization has strict compliance requirements: any privileged account compromise must be contained within 15 minutes of detection. You have the following tools available: Microsoft Entra ID with Privileged Identity Management (PIM), Microsoft Defender for Cloud Apps, and Microsoft 365 Defender automation rules. The incident is now 5 minutes old. What should you do to meet the compliance requirement?

A.Create an automation rule in Microsoft 365 Defender to alert the security team.
B.Disable the user account in Microsoft Entra ID immediately.
C.Create a conditional access policy to block the user's sign-ins.
D.Activate PIM and remove the user's role assignments.
AnswerB

Disabling the user account in Microsoft Entra ID is the fastest and most direct containment action. Setting the account's AccountEnabled property to false immediately prevents new token issuance and triggers revocation of the user's existing refresh tokens, effectively cutting off access within seconds. This can be done in the Entra admin center or via Microsoft Graph, and it is the recommended first step for a confirmed account compromise because it stops the attacker regardless of which app or resource they are targeting.

Why this answer

Disabling the account in Microsoft Entra ID immediately is the fastest, most direct containment action for a confirmed privileged-account compromise. It revokes the account's ability to authenticate and blocks all new sign-ins and token issuance at the identity provider level, satisfying the 15-minute containment SLA. Since the incident is only 5 minutes old and involves a privileged admin, immediate account disablement is the correct incident-response action rather than a detective or policy-based control.

Exam trap

SC-200 often tests the difference between detective controls (alerts, automation rules) and true containment actions (disable account, revoke sessions), tricking candidates into choosing policy-based or notification-based options that do not meet a strict time-bound SLA.

How to eliminate wrong answers

Option A is wrong because creating an automation rule to alert the security team is a notification action, not a containment action — it does nothing to stop the attacker and wastes the remaining 10 minutes of the SLA. Option C is wrong because a Conditional Access policy is a preventive control that requires policy design, testing, and propagation time; it also may not immediately revoke existing sessions or tokens, so it cannot guarantee containment within 15 minutes. Option D is wrong because activating PIM and removing role assignments addresses privilege scope but does not disable the underlying account — the attacker could still authenticate and the account remains active, and PIM changes may take time to propagate.

1288
MCQeasy

During a ransomware incident, you need to prevent the encryption of files in SharePoint Online and OneDrive for Business. You have already identified the compromised user account. What should you do?

A.Disable external sharing for SharePoint Online
B.Lock the compromised user account in Microsoft Entra ID
C.Delete the compromised user's OneDrive files
D.Apply a retention policy to all SharePoint sites
AnswerB

Locking the compromised account in Microsoft Entra ID immediately invalidates its refresh tokens, halting further authenticated access to SharePoint Online and OneDrive for Business. This directly satisfies the stem's requirement to stop ongoing file encryption, since ransomware encrypts through the hijacked session's existing permissions rather than exploiting a separate vulnerability.

Why this answer

Locking the compromised user account in Microsoft Entra ID immediately revokes the attacker's access to SharePoint Online and OneDrive for Business, preventing further file encryption. Option A is incorrect because disabling external sharing does not stop an already authenticated user from encrypting files. Option C is incorrect because deleting the user's OneDrive files does not prevent the attacker from encrypting other files.

Option D is incorrect because a retention policy only protects against deletion or modification, not encryption.

1289
MCQhard

You are investigating an incident where a user reported receiving a suspicious email with a malicious attachment. Microsoft Defender for Office 365 did not block it. The email originated from a known malicious sender domain. What configuration should you check first?

A.User-reported message settings
B.SPF record for the sender domain
C.Safe Attachments policy
D.Anti-phishing policy in Microsoft Defender for Office 365
AnswerD

Anti-phishing policy in Microsoft Defender for Office 365 is the correct control because it provides domain impersonation protection and spoof intelligence that can identify and block messages from known malicious domains or those mimicking protected senders. It leverages threat intelligence and real-time reputation to enforce blocking, quarantine, or redirect to Junk before delivery to the user's inbox. This policy is specifically designed to combat phishing and impersonation, which aligns with the reported incident involving a suspicious email.

Why this answer

The anti-phishing policy in Microsoft Defender for Office 365 is the primary configuration that evaluates sender reputation, impersonation attempts, and spoof intelligence. Since the email originated from a known malicious sender domain and was not blocked, the anti-phishing policy's spoof settings or impersonation protection may be misconfigured or not applied to the affected user. This policy directly controls how Defender handles emails from malicious domains, making it the first place to check.

Exam trap

The trap here is that candidates confuse the anti-phishing policy with Safe Attachments or SPF records, but the anti-phishing policy is the correct first check because it directly handles domain-based threats and spoofing, while Safe Attachments focuses on file analysis and SPF is a DNS record not configurable within Defender.

How to eliminate wrong answers

Option A is wrong because user-reported message settings control how users submit emails for analysis (e.g., via the Report Message add-in), not how Defender blocks malicious emails at the transport layer. Option B is wrong because the SPF record for the sender domain is a DNS record that the recipient's mail server checks, but it is not a configuration within Microsoft Defender for Office 365 that you can adjust; you can only configure SPF handling in the anti-phishing policy. Option C is wrong because Safe Attachments policy specifically handles attachments by detonating them in a sandbox, but the question states the email had a malicious attachment that was not blocked, and the primary issue is the sender domain being known malicious, which is addressed by anti-phishing policies, not attachment scanning.

1290
MCQeasy

Refer to the exhibit. You are configuring a Microsoft Sentinel scheduled analytics rule with the above incident creation settings. What is the effect of setting 'groupingConfiguration.enabled' to false?

A.Alerts will be suppressed for 5 minutes
B.The rule will run every 5 minutes
C.No incidents will be created
D.Each alert will generate a separate incident
AnswerD

With groupingConfiguration.enabled set to false, Sentinel disables alert grouping, so each individual alert raised by the rule creates its own incident rather than being merged into a single incident. This satisfies the scenario's requirement for one incident per alert.

Why this answer

When groupingConfiguration.enabled is set to false in a Microsoft Sentinel scheduled analytics rule, the alert-grouping logic is disabled entirely. This means Sentinel will not bundle multiple alerts from a single rule run into one incident; instead, every individual alert generated by the query produces its own distinct incident. This is useful when each alert requires separate triage or when alerts represent unrelated events that should not be merged.

Exam trap

SC-200 often tests the distinction between alert grouping, alert suppression, and rule frequency, causing candidates to confuse groupingConfiguration.enabled with suppression or scheduling settings.

How to eliminate wrong answers

Option A is wrong because alert suppression is controlled by the rule's 'suppression' settings (suppressionEnabled, suppressionDuration), not by groupingConfiguration.enabled; setting grouping to false does not suppress alerts. Option B is wrong because the rule's execution frequency is defined by the 'queryPeriod' and 'queryFrequency' fields in the scheduled rule definition, not by groupingConfiguration. Option C is wrong because disabling grouping does not prevent incident creation — it actually increases incident count by creating one incident per alert rather than merging them.

1291
MCQhard

You are threat hunting in Microsoft Sentinel using KQL. You want to identify potential beaconing activity by looking for regular, periodic network connections from a host. Which KQL operator or function is most appropriate to calculate the time intervals between connections and detect patterns?

A.serialize then use prev() and datetime_diff()
B.make-series count() on TimeGenerated step 1m
C.join kind=inner on RemoteIP
D.summarize count() by bin(TimeGenerated, 1m)
AnswerA

To detect beaconing, you need to calculate the time difference between consecutive connections from the same host. The serialize operator orders the rows, and prev() accesses the previous row's timestamp. datetime_diff() then computes the interval. By analyzing these intervals for regularity (e.g., low standard deviation), you can identify beaconing. This approach is flexible and works with irregular intervals, making it the most appropriate for this scenario.

Why this answer

Detecting beaconing requires analyzing the time intervals between consecutive network connections from a host. The serialize operator orders events, prev() retrieves the previous timestamp, and datetime_diff() calculates the interval. You can then summarize these intervals to find regularity, such as a low standard deviation or a common interval.

This method works even with jitter, making it the most effective for identifying command-and-control beaconing patterns.

Exam trap

The trap here is using aggregation functions like bin or make-series that group events into fixed windows, which can mask the precise intervals needed to detect beaconing with jitter.

1292
MCQeasy

Refer to the exhibit. You are reviewing a custom Azure Policy definition that should block deployments from specific IP addresses. However, the policy does not seem to be evaluating any resources. What is the most likely issue?

A.The 'in' operator cannot be used with an array parameter
B.The policy definition has not been assigned to any scope
C.The policy mode should be 'Indexed' for network policies
D.The 'effect' should be 'audit' instead of 'deny'
AnswerB

A custom policy definition is merely a rule set that remains dormant until it is assigned to a management group, subscription, or resource group. Without an assignment, Azure Policy does not evaluate resources against the definition, so no deny actions or compliance results will appear. In this exhibit, the policy definition has no assigned scope, which is why it has no effect on any resources.

Why this answer

The exhibit shows a custom Azure Policy definition that is syntactically correct, but the policy is not evaluating any resources. The most likely cause is that the policy definition has not been assigned to a scope (e.g., management group, subscription, or resource group). In Azure Policy, a definition alone does nothing; it must be assigned to a scope to take effect and begin evaluating resources.

Exam trap

The trap here is that candidates focus on syntax errors or operator misuse in the policy definition, overlooking the prerequisite that a policy must be assigned to a scope before it can evaluate any resources.

How to eliminate wrong answers

Option A is wrong because the 'in' operator can be used with an array parameter in Azure Policy; the issue is not with the operator but with the missing assignment. Option C is wrong because the policy mode should be 'All' (or 'Microsoft.Network.Data') for network policies that evaluate resource properties, not 'Indexed', which is used for resource provider modes like 'Microsoft.Kubernetes.Data'. Option D is wrong because changing the effect from 'deny' to 'audit' would not cause the policy to fail to evaluate resources; it would only change the enforcement behavior, and the policy would still need to be assigned to a scope.

1293
MCQeasy

A SOC analyst needs to create a custom alert in Microsoft Sentinel that triggers when a specific user logs in from an unusual geographic location, compared to a learned baseline of normal locations. Which type of analytics rule is best suited for this scenario?

A.Scheduled query
B.Near-real-time (NRT) rule
C.Anomaly detection rule (machine learning)
D.Fusion rule
AnswerC

An anomaly detection rule using machine learning is the correct choice because it is purpose-built to learn a baseline of normal sign-in behavior for each user or entity. Using Microsoft Sentinel's ML analytics rules, the rule applies unsupervised learning to historical Azure AD sign-in logs, then triggers when an event deviates significantly from that baseline (e.g., impossible travel or an unusual device). This matches the SOC analyst's need to create a custom alert for sign-in anomalies without manually specifying thresholds.

Why this answer

Anomaly detection rules in Microsoft Sentinel use machine learning to establish a baseline of normal user behavior, such as typical geographic login locations. When a login event deviates significantly from this learned baseline, the rule triggers an alert. This is the only rule type specifically designed for detecting behavioral anomalies without requiring static thresholds or predefined patterns.

Exam trap

The trap here is that candidates often confuse scheduled queries (Option A) with anomaly detection, assuming a KQL query using 'where Location != 'US'' can replace ML-based baseline learning, but scheduled queries cannot dynamically adapt to changing user behavior over time.

How to eliminate wrong answers

Option A is wrong because scheduled queries run on a fixed schedule (e.g., every 5 minutes) and rely on static KQL queries with hardcoded thresholds or lists, not on a learned baseline of normal locations. Option B is wrong because near-real-time (NRT) rules process streaming data with minimal latency but still require explicit query logic and cannot adaptively learn a baseline of normal behavior. Option D is wrong because Fusion rules correlate alerts from multiple security products to detect multi-stage attacks, not to detect single-user geographic anomalies against a learned baseline.

1294
MCQeasy

Your team uses Microsoft Defender XDR to manage incidents. You need to ensure that all incidents with a severity of 'High' are automatically assigned to a specific SOC analyst group. What should you configure?

A.Set up an advanced hunting query to detect high severity incidents and send email.
B.Create an automation rule in Microsoft Defender XDR to automatically assign incidents.
C.Configure a playbook in Microsoft Sentinel triggered by incidents.
D.Use the 'New-MTPIncidentAssignment' cmdlet in a scheduled task.
AnswerB

Automation rules in Microsoft Defender XDR are the built-in mechanism for automatically applying actions—including assigning incidents to a specific owner or team—based on conditions like severity, detection source, or category. When an incident is created or updated, the rule evaluates it in real time and executes the assigned action, eliminating manual triage. This is the correct, supported way to enforce ownership policies centrally.

Why this answer

Microsoft Defender XDR's automation rules allow you to define conditions (e.g., severity equals 'High') and actions (e.g., assign to a specific SOC analyst group) that are executed automatically when incidents are created or updated. This is the native, built-in mechanism for incident assignment without requiring external scripts, playbooks, or email-based workflows.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel playbooks with Defender XDR automation rules, assuming Sentinel's incident orchestration can be applied to Defender XDR incidents, but they are separate platforms with distinct automation mechanisms.

How to eliminate wrong answers

Option A is wrong because advanced hunting queries are read-only and cannot trigger actions like assignment; they only return data for analysis, and sending an email does not automate the assignment of the incident. Option C is wrong because Microsoft Sentinel playbooks are designed for Azure Sentinel incidents, not Microsoft Defender XDR incidents; Defender XDR has its own automation rules and does not natively integrate Sentinel playbooks for incident assignment. Option D is wrong because the 'New-MTPIncidentAssignment' cmdlet does not exist; the correct PowerShell module for Defender XDR is 'Microsoft 365 Defender' and there is no such cmdlet for incident assignment—assignment is done via the API or automation rules, not a scheduled task.

1295
MCQeasy

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to ensure that all incidents from a specific analytics rule are automatically assigned to the 'SOC Tier 1' team. What should you configure in Microsoft Sentinel?

A.Configure alert enrichment in the analytics rule to add the owner.
B.Modify the analytics rule to write the incident to a custom table accessible by the SOC team.
C.Create a playbook that assigns the incident and attach it to the analytics rule.
D.Create an automation rule that triggers when the incident is created and sets the owner.
AnswerD

An automation rule can be configured to trigger when an incident is created, and its 'Set owner' action immediately assigns the incident to a designated user or group. This is the native, lightweight mechanism in Microsoft Sentinel for enforcing assignment policy at incident creation, and it can be scoped to the specific analytics rule. Because it directly updates the incident record's Owner property, it satisfies the requirement.

Why this answer

Automation rules in Microsoft Sentinel allow you to define conditions (such as incident creation) and actions (such as setting the owner) without requiring a playbook or custom code. This provides a lightweight, native way to automatically assign incidents from a specific analytics rule to the 'SOC Tier 1' team by filtering on the rule's name or ID in the automation rule's condition.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, thinking a playbook is always required for any automated action, when in fact automation rules can directly assign ownership without invoking a Logic App.

How to eliminate wrong answers

Option A is wrong because alert enrichment in an analytics rule is used to add custom details (like key-value pairs) to alerts, not to assign ownership or modify incident properties. Option B is wrong because writing an incident to a custom table does not assign ownership; it only stores data for querying, and incidents are already stored in the SecurityIncident table. Option C is wrong because while a playbook can assign an incident, it is an overengineered solution requiring additional Logic Apps cost and complexity; automation rules are the recommended and simpler method for this task.

1296
MCQeasy

You are investigating a low-severity incident in Microsoft Sentinel where a user reported receiving a phishing email. The email was not blocked by the email security solution. The user did not click any links. What should you do first?

A.Delete the phishing email from the user's inbox
B.Report the email for analysis using the Microsoft 365 Defender portal
C.Reset the user's password as a precaution
D.Isolate the user's device from the network
AnswerB

Reporting the email via the Microsoft 365 Defender portal (using the 'Report a message' or admin submission workflow) submits the original email, including its headers and attachments, to Microsoft's automated detonation and analysis systems. This enables the security team to extract actionable IOCs, update tenant-level block and allow lists, and contribute to global filtering improvements—directly addressing the low-severity phishing incident without destroying evidence. It is the correct initial response because it simultaneously preserves the artifact and enhances email security posture.

Why this answer

The first step is to report the email for analysis using the Microsoft 365 Defender portal. Since the email was not blocked and the user did not click any links, the immediate priority is to submit the message to Microsoft for analysis (via the Submissions page or the Report button) so that detections can be tuned and the sender/URLs can be blocked if malicious. This preserves evidence and improves organizational protection before taking remediation actions.

Exam trap

SC-200 often tests the order of operations in incident response — candidates jump to remediation (delete, reset, isolate) instead of the correct first step of analysis/reporting, especially when the user did not click.

How to eliminate wrong answers

Option A is wrong because deleting the email from the inbox is a remediation step that destroys evidence needed for analysis and does not address the root cause (why it bypassed filtering); it should come after analysis, not first. Option C is wrong because resetting the user's password is unnecessary — the user did not click any links, so there is no indication of credential compromise, and password resets are disruptive. Option D is wrong because isolating the device is a containment action for a confirmed endpoint compromise; with no click and no evidence of execution, it is premature and overly disruptive.

1297
Multi-Selecthard

During a security incident, a Microsoft Sentinel analytics rule generated an alert for a suspicious sign-in from an unusual location. The incident involves a user whose account has been compromised. The security team needs to take immediate actions to remediate and prevent further damage. Which THREE actions should the security team prioritize?

Select 3 answers
A.Reset the user's password
B.Revoke the user's session tokens
C.Review audit logs for all users
D.Raise the user's risk level in Identity Protection
E.Disable the user account in Microsoft Entra ID
AnswersA, B, E

Resetting the user's password in Microsoft Entra ID is a direct containment action because it invalidates the previously valid credential. If the attacker gained access via a phished or stolen password, this immediately prevents them from using that secret for interactive sign-in. It is a focused remediation step that should be performed as soon as the user is confirmed as a legitimate account holder, forcing them to create a new password on next sign-in.

Why this answer

Resetting the user's password (A) is a critical immediate step because it invalidates the current compromised credentials, preventing the attacker from using the known password to authenticate again. In Microsoft Entra ID, a password reset forces the user to create a new credential, which the attacker does not possess, effectively cutting off one of the most common attack vectors.

Exam trap

The trap here is that candidates may confuse detection actions (like raising risk level) with containment actions, or mistakenly think reviewing all audit logs is a priority step when the focus should be on immediate remediation of the compromised account.

1298
MCQmedium

You are a security operations analyst for a company that uses Microsoft Sentinel. The SOC manager wants to reduce alert fatigue by automatically closing incidents that are created by a specific analytics rule and contain only low-severity alerts. You need to configure this behavior with the least administrative effort. What should you do?

A.Configure a workbook that filters incidents by severity and analytics rule, and instruct analysts to manually close matching incidents during each shift.
B.Create a playbook that queries the Microsoft Sentinel incidents table with a KQL query for low-severity incidents and then calls the Microsoft Sentinel API to close them on a schedule.
C.Create an automation rule that runs when an incident is created, with a condition on the analytics rule name and severity, and an action to change the incident status to Closed.
D.Modify the analytics rule to set the incident creation setting to Disabled so that no incident is created for low-severity alerts.
AnswerC

Automation rules in Microsoft Sentinel can trigger on incident creation and evaluate conditions such as the analytics rule name and severity. The 'Change status' action can set the incident to Closed. This directly addresses the requirement without custom logic or manual triage, and it is the least-effort native approach.

Why this answer

Microsoft Sentinel automation rules are designed for lightweight incident handling and can trigger when an incident is created. By scoping conditions to the analytics rule name and severity, the rule targets only the intended low-severity incidents and uses the built-in status change action to close them. This avoids custom code, reduces manual triage, and meets the least-effort requirement.

Exam trap

The trap here is assuming that automation rules cannot change incident status and that a playbook is always required for any automated incident action.

1299
MCQmedium

A security analyst is performing threat hunting in Microsoft Sentinel and wants to identify anomalous outbound network traffic from a compromised virtual machine. Which data source should be prioritized for this hunt?

A.Azure Activity Log
B.Azure Network Watcher flow logs
C.Windows Event Logs (Security, System)
D.Microsoft Entra ID sign-in logs
AnswerB

Azure Network Watcher flow logs are the correct source for this hunt because they record IP traffic through network security groups, capturing source/destination IPs, ports, protocols, and whether traffic was allowed or denied. These logs enable security analysts to identify anomalous outbound connections, such as a VM communicating with a known command-and-control (C2) IP on a non-standard port, by analyzing traffic patterns and byte/package counts. However, note that flow logs are aggregate and do not capture packet payloads, so they are best merged with other signals (e.g., threat intelligence) to confirm malicious intent.

Why this answer

Azure Network Watcher flow logs provide detailed information about IP traffic through Azure networks, making them ideal for detecting anomalous outbound traffic patterns. Option A (Azure Activity Log) focuses on control plane events, not network flows. Option C (Windows Event Logs) is for host-level events, not network traffic.

Option D (Azure AD sign-in logs) is for authentication events.

1300
Multi-Selectmedium

Which TWO actions should you take when handling a confirmed ransomware incident in an environment protected by Microsoft Defender for Endpoint?

Select 2 answers
A.Block the ransomware file hash using threat intelligence indicators in Microsoft Defender.
B.Initiate device isolation from the Microsoft Defender for Endpoint console.
C.Disable Windows Defender real-time protection.
D.Submit the ransomware sample to Microsoft for analysis.
E.Reimage all affected servers immediately.
AnswersA, B

Blocking the ransomware executable's SHA-256 hash via Microsoft Defender for Endpoint custom indicators immediately prevents that specific binary from running on any monitored endpoint, independent of signature updates. Because the hash is a known-bad IOC, defining it as a block indicator enforces a deny action at the kernel and network layers, halting execution on already-uninfected devices and stopping the ransomware from propagating through mapped shares.

Why this answer

Blocking the ransomware file hash via threat intelligence indicators in Microsoft Defender for Endpoint (MDE) immediately prevents further execution of that known malicious file across all endpoints in the environment, leveraging the built-in TI indicator feature. Option B is correct because initiating device isolation from the MDE console disconnects the affected device from the network while maintaining connectivity to the MDE service, containing the spread of ransomware without losing visibility or control.

Exam trap

The trap here is that candidates may confuse post-incident actions (like submitting samples or reimaging) with immediate containment actions, or mistakenly think disabling real-time protection is a valid response instead of understanding that isolation and indicator blocking are the primary containment steps in MDE.

1301
MCQeasy

A security operations center (SOC) uses Microsoft Sentinel. The team wants to automatically assign incidents to the appropriate analyst based on the severity level of the alert. Which feature should be configured to achieve this automation?

A.Automation rules
B.Playbooks
C.Analytics rules
D.Watchlists
AnswerA

Automation rules are Sentinel's native mechanism that runs when an incident is created or an alert is generated. For incident creation, they can automatically assign the incident to an analyst or a group based on criteria like severity, product name, or entity type. This built-in action does not require any external services, making it the primary and most efficient way to automate incident ownership and triage.

Why this answer

Automation rules in Microsoft Sentinel allow you to define conditions (such as alert severity) and corresponding actions (like assigning an incident to a specific analyst or group) without requiring custom code. This directly meets the SOC's requirement to automatically route incidents based on severity levels, as automation rules can trigger on incident creation or update and perform assignment actions.

Exam trap

The trap here is that candidates often confuse playbooks with automation rules, thinking playbooks are required for any automated action, but automation rules handle simple, condition-based assignments natively without needing a Logic App.

How to eliminate wrong answers

Option B is wrong because playbooks are automated workflows (often using Azure Logic Apps) that execute complex, multi-step responses, but they are not the primary feature for simple, rule-based assignment; they are typically triggered by automation rules for advanced orchestration. Option C is wrong because analytics rules are used to generate alerts and incidents from data sources (e.g., KQL queries), not to manage incident assignment or routing after creation. Option D is wrong because watchlists are collections of static data (e.g., IP addresses, usernames) used for correlation or enrichment in analytics rules, not for automating incident assignment actions.

1302
MCQeasy

A security analyst is investigating a phishing campaign using Microsoft 365 Defender advanced hunting. The analyst needs to find all emails sent from a specific sender address in the last 7 days. Which table should be queried?

A.EmailEvents
B.EmailAttachmentInfo
C.EmailUrlInfo
D.DeviceEvents
AnswerA

EmailEvents is the correct table because it is the primary Microsoft 365 Defender email metadata store, containing the sender address (SenderFromAddress/SenderDisplayName), recipient (RecipientEmailAddress), subject, and delivery status/actions such as Phish or Junk. In a phishing campaign investigation, you start here to identify which mailboxes received the malicious message and to correlate the sender and delivery outcome. It also fields like ThreatTypes and DetectionMethods, making it the authoritative source for the core message flow. Without querying EmailEvents, you cannot establish the baseline scope of the campaign.

Why this answer

The EmailEvents table in Microsoft 365 Defender advanced hunting stores metadata about email messages, including sender addresses, recipients, timestamps, and delivery actions. To find all emails from a specific sender in the last 7 days, you query EmailEvents because it contains the 'SenderFromAddress' or 'SenderMailFromAddress' fields needed to filter by sender. The other tables focus on attachments, URLs, or device-level events, which are not relevant for identifying emails by sender address.

Exam trap

The trap here is that candidates may confuse the purpose of EmailAttachmentInfo or EmailUrlInfo, thinking they contain sender data, when in fact they only store attachment or URL details and require a join with EmailEvents to correlate back to the sender.

How to eliminate wrong answers

Option B (EmailAttachmentInfo) is wrong because it stores information about email attachments (e.g., file names, hashes) but does not contain the sender address field needed to filter by sender. Option C (EmailUrlInfo) is wrong because it tracks URLs found in email bodies or attachments, not sender metadata. Option D (DeviceEvents) is wrong because it logs endpoint-level activities (e.g., process creation, network connections) and has no email-related data, making it irrelevant for querying email sender addresses.

1303
MCQhard

You run the KQL query above in Microsoft Sentinel. The query returns zero results even though you know some devices have connected to malicious IPs. What is the most likely cause?

A.The externaldata source URL is inaccessible from the Sentinel workspace.
B.The malicious IPs are not in the list.
C.The DeviceNetworkEvents table does not contain the RemoteIP column.
D.The let statement syntax is incorrect.
AnswerA

If the externaldata URL cannot be reached from the workspace, the query returns no rows because the external source yields nothing to join or filter. Connectivity to that URL is the prerequisite the query depends on.

Why this answer

The most likely cause is that the externaldata source URL is inaccessible from the Sentinel workspace. The externaldata operator in KQL retrieves data from an external storage location, such as an Azure Storage blob or a public URL. If the URL is unreachable due to network restrictions, authentication issues, or incorrect permissions, the query will return zero results even if the data exists.

This is a common pitfall when using externaldata in Microsoft Sentinel.

Exam trap

SC-200 often tests the externaldata operator's dependency on external source accessibility, and candidates may overlook network or permission issues, assuming the query logic is correct.

How to eliminate wrong answers

Option B is wrong because if the malicious IPs were not in the list, the query would still return results for other IPs, but the question states zero results, implying a complete failure to retrieve any data. Option C is wrong because the DeviceNetworkEvents table does include a RemoteIP column, so that is not the issue. Option D is wrong because the let statement syntax is correct; the problem is with the externaldata source accessibility, not the query syntax.

Page 17

Page 18 of 18