Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 76–150

1303 questions total · 18pages · All types, answers revealed

Data quality score: 70/100 — Review before indexing

2 errors found across 75 questions. This page is set to noindex until issues are resolved.

Page 1

Page 2 of 18

Page 3
76
MCQeasy

You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different workloads. You need to view all related alerts in a single timeline. What should you use?

A.Incident page
B.Advanced hunting
C.Action center
D.Device timeline
AnswerA

The incident page is the central investigation surface in Microsoft Defender XDR. It automatically aggregates all alerts related to a single attack campaign from across the Microsoft 365 security stack—Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps—into a unified view. Along with alerts, it surfaces the full attack story, affected assets, and evidence, making it the correct place to investigate the full scope of an incident. This page directly answers the need to see all related alerts in one place.

Why this answer

The Incident page in Microsoft Defender XDR aggregates all alerts from different workloads (e.g., Microsoft Defender for Endpoint, Office 365, Identity) into a single, unified timeline view. This allows you to see the sequence of events and alerts related to the incident in chronological order, which is essential for understanding the attack chain and coordinating response actions.

Exam trap

The trap here is that candidates confuse the Incident page's unified alert timeline with Advanced hunting, thinking they need to write a KQL query to see related alerts, when in fact the Incident page automatically provides that consolidated view without any querying.

How to eliminate wrong answers

Option B (Advanced hunting) is wrong because it is a query-based tool for proactively searching raw data across workloads, not a pre-built timeline view for a specific incident. Option C (Action center) is wrong because it lists pending and completed remediation actions (e.g., isolate device, block file) across incidents, not the alerts or their timeline for a single incident. Option D (Device timeline) is wrong because it shows events and alerts for a single device only, not the cross-workload alerts aggregated for an incident.

77
MCQmedium

A company uses Microsoft Defender for Cloud with Defender for Servers enabled. They also run SQL Server on Azure Virtual Machines (IaaS). The security team wants to enable Advanced Threat Protection (ATP) for these SQL Server IaaS instances to detect threats like SQL injection. What is the single most effective action to achieve this?

A.Enable the Defender for SQL plan on the management group or subscription
B.Install the SQL IaaS Agent extension on each VM
C.Configure a vulnerability assessment solution on each SQL Server
D.Enable Azure SQL Database Threat Detection policy
AnswerA

Enabling the Microsoft Defender for SQL plan at the management-group or subscription scope activates the security workload that includes advanced threat protection (ATP) for SQL Server instances running on Azure VMs. This is a subscription-level feature in Defender for Cloud: once enabled, Defender for SQL collects SQL audit logs, detects suspicious activity such as SQL injection and brute-force attacks, and can raise security alerts. It also enables vulnerability assessment without needing separate manual configuration on each VM. Therefore, the plan must be enabled at a central scope to achieve the desired protection across all SQL IaaS workloads.

Why this answer

The Defender for SQL plan in Microsoft Defender for Cloud provides Advanced Threat Protection (ATP) for Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure VMs. Enabling this plan at the management group or subscription level automatically protects all current and future SQL Server IaaS instances within that scope, including threat detection for SQL injection attacks, without requiring per-VM agent installation.

Exam trap

The trap here is that candidates often confuse the SQL IaaS Agent extension (which is needed for VM registration and management) with the actual security configuration required for ATP, leading them to select Option B instead of the subscription-level plan enablement in Option A.

How to eliminate wrong answers

Option B is wrong because installing the SQL IaaS Agent extension is a prerequisite for registering the VM with the SQL IaaS resource provider, but it does not enable ATP by itself; ATP requires the Defender for SQL plan to be enabled. Option C is wrong because configuring a vulnerability assessment solution addresses security misconfigurations and vulnerabilities, not real-time threat detection like SQL injection. Option D is wrong because Azure SQL Database Threat Detection policy applies only to Azure SQL Database, not to SQL Server running on Azure VMs (IaaS).

78
MCQeasy

A SOC analyst needs to create a basic analytics rule in Microsoft Sentinel to detect when an Azure VM is created with an open management port (e.g., SSH or RDP). Which data source should the analyst configure to get the VM creation events?

A.Azure Activity log (AzureActivity)
B.Azure Security Center alerts (SecurityAlert)
C.Microsoft Entra ID Audit logs (AuditLogs)
D.Azure Network Watcher logs (NetworkMonitoring)
AnswerA

The AzureActivity table is populated by the Azure Activity connector and captures control-plane operations, such as Microsoft.Compute/virtualMachines/write for VM creation. A basic analytics rule can query AzureActivity for these operations to detect when a VM is provisioned, which is a common precursor to opening management ports. This makes it the correct and direct data source for detecting the resource creation event itself.

Why this answer

The Azure Activity log (AzureActivity) captures all control-plane operations on Azure resources, including virtual machine creation events (e.g., Microsoft.Compute/virtualMachines/write). When a VM is created with an open management port like SSH (22) or RDP (3389), the activity log records the deployment details, making it the correct data source for triggering a basic analytics rule in Microsoft Sentinel to detect such events.

Exam trap

The trap here is that candidates often confuse Azure Activity logs with Azure Security Center alerts, mistakenly thinking that security alerts will fire on VM creation events, when in fact Activity logs are the only source for raw control-plane operations in Sentinel.

How to eliminate wrong answers

Option B is wrong because Azure Security Center alerts (SecurityAlert) are generated from security findings after resource creation, not from the raw creation event itself, and cannot be used to detect the initial VM creation action. Option C is wrong because Microsoft Entra ID Audit logs (AuditLogs) track identity and authentication activities within Entra ID, not Azure resource creation events like VM deployments. Option D is wrong because Azure Network Watcher logs (NetworkMonitoring) capture network-level traffic and diagnostics (e.g., NSG flow logs, connection monitors), not control-plane operations such as VM provisioning.

79
Multi-Selectmedium

You are a security operations analyst using Microsoft Sentinel. You need to configure a playbook that automatically posts a message to a Microsoft Teams channel when a high-severity incident is created. Which two actions must you perform? (Choose two.)

Select 2 answers
A.Create a playbook that uses the Office 365 Outlook connector and sends an email to the SOC team.
B.Create a playbook that uses the Microsoft Sentinel connector and retrieves incident details.
C.Create an automation rule that triggers when an incident is created and has a condition for severity equals High.
D.Create a playbook that uses the Microsoft Teams connector and posts a message to the desired channel.
E.Create an automation rule that triggers when an incident is updated and has a condition for severity equals High.
AnswersC, D

This is correct because to automatically run a playbook based on incident creation and severity, you need an automation rule. The automation rule can have a condition to check the severity and then an action to run the playbook. This ensures the playbook only runs for high-severity incidents.

Why this answer

To automatically post a message to Microsoft Teams when a high-severity incident is created in Microsoft Sentinel, you need an automation rule that triggers on incident creation, checks the severity, and runs a playbook. The playbook must use the Microsoft Teams connector to post the message to the desired channel. The automation rule provides the trigger and condition, while the playbook performs the action.

Exam trap

The trap here is confusing the trigger condition (incident created vs. updated) or using the wrong connector (Outlook instead of Teams).

80
MCQmedium

You are using Microsoft Defender for Cloud Apps to hunt for suspicious OAuth app permissions. Which activity type should you look for to detect a potentially malicious app that was granted high privileges by a user?

A.Consent to application
B.Add service principal
C.Update application
D.Add app role assignment grant
AnswerA

Consent to application records the OAuth grant event, capturing the user, the application and the scopes requested. This directly satisfies the stem's requirement to detect a malicious app granted high privileges by a user, since the consent activity surfaces the permission grant itself rather than later API usage.

Why this answer

'Consent to application' (Option A). This activity captures when a user grants OAuth permissions to an application, which is the key indicator of high-privilege app consent. Option B, 'Add service principal', relates to creating a service principal object in Azure AD, not user consent.

Option C, 'Update application', involves modifying an app's configuration, not consent. Option D, 'Add app role assignment grant', is about assigning an app role to a user or group, which is a separate permission grant that does not involve user consent directly.

81
MCQmedium

A security analyst in Microsoft 365 Defender is investigating an email-based threat. The analyst needs to find all emails that were initially delivered to user inboxes but were later remediated (e.g., moved to junk, deleted, or quarantined) by Zero-Hour Auto Purge (ZAP). Which advanced hunting tables should the analyst query to get both the original email metadata and the post-delivery remediation events?

A.EmailEvents and EmailPostDeliveryEvents
B.EmailEvents and EmailAttachmentInfo
C.EmailPostDeliveryEvents and EmailUrlInfo
D.EmailEvents and CloudAppEvents
AnswerA

EmailEvents supplies the original delivery metadata, while EmailPostDeliveryEvents records post-delivery actions including ZAP moves to junk, deletion, or quarantine. Querying both satisfies the requirement to correlate initial inbox delivery with later remediation, since ZAP outcomes are logged only in EmailPostDeliveryEvents, not in EmailEvents.

Why this answer

To investigate emails that were initially delivered but later remediated by Zero-Hour Auto Purge (ZAP), you need both the original email metadata (from EmailEvents) and the post-delivery remediation actions (from EmailPostDeliveryEvents). EmailEvents provides details like sender, recipient, subject, and delivery status, while EmailPostDeliveryEvents records ZAP actions such as moving to junk, deleting, or quarantining. Querying these two tables together allows you to correlate the initial delivery with the subsequent remediation event.

Exam trap

The trap here is that candidates may think EmailPostDeliveryEvents alone suffices, but without EmailEvents you cannot confirm the original delivery status (e.g., 'Delivered') which is essential to distinguish ZAP from other post-delivery actions like manual user moves.

How to eliminate wrong answers

Option B is wrong because EmailAttachmentInfo only contains metadata about email attachments (e.g., file name, hash) and does not include post-delivery remediation events or original email delivery metadata needed for ZAP investigation. Option C is wrong because EmailUrlInfo only contains URL-related information from emails (e.g., clicked links) and lacks the original email metadata from EmailEvents, so you cannot see the initial delivery status. Option D is wrong because CloudAppEvents tracks activities in Microsoft cloud apps (e.g., SharePoint, OneDrive) and is not related to email delivery or ZAP remediation events in Exchange Online.

82
MCQhard

As a threat hunter at Contoso, you are investigating a potential advanced persistent threat (APT) that may have compromised multiple Azure subscriptions. You have Microsoft Defender for Cloud enabled and Microsoft Sentinel collecting data from all subscriptions. You suspect the attacker is using Azure Resource Manager operations to create malicious resources. You need to create a hunting query that identifies anomalous Azure management operations, specifically focusing on operations that create new resources (e.g., virtual machines, storage accounts) from unusual IP addresses or at unusual times. Which approach should you take?

A.Use the CommonSecurityLog table to analyze network traffic from management tools.
B.Use the AzureActivity table in Microsoft Sentinel to query for any operation where the OperationNameValue contains 'write' and then manually review each result.
C.Use the AzureActivity table to filter for operations where HttpMethod == 'PUT' (create/update), then summarize by CallerIpAddress and bin(TimeGenerated, 1h) to find spikes or unusual caller IPs.
D.Query the SigninLogs table in Microsoft Sentinel for all interactive sign-ins to the Azure portal, then cross-reference with Azure Activity logs.
AnswerC

The AzureActivity table records control-plane operations, so filtering on HttpMethod == 'PUT' isolates resource creation and update calls. Summarising by CallerIpAddress with bin(TimeGenerated, 1h) surfaces anomalous IP addresses and off-hours spikes, directly satisfying the requirement to hunt suspicious Azure Resource Manager resource-creation activity.

Why this answer

Azure Resource Manager write operations are logged in the AzureActivity table, and create/update operations use HTTP PUT (or sometimes PATCH). Filtering for HttpMethod == 'PUT' isolates resource-creation activity, and summarizing by CallerIpAddress with a time bin (e.g., 1h) surfaces spikes or unusual source IPs that indicate anomalous management-plane activity. This directly targets the APT's resource-creation behavior from unusual IPs or times.

Exam trap

SC-200 often tests table selection — candidates confuse SigninLogs (authentication) with AzureActivity (control-plane operations) or pick CommonSecurityLog (network logs) when the question is about ARM resource creation.

How to eliminate wrong answers

Option A is wrong because CommonSecurityLog contains network/security appliance logs (firewall, proxy, IDS), not Azure control-plane operations — it cannot show ARM resource creation. Option B is wrong because filtering only on OperationNameValue containing 'write' is too broad and lacks the IP/time summarization needed to identify anomalies; manual review of every write is not a scalable hunting approach. Option D is wrong because SigninLogs captures authentication events, not resource-creation operations; cross-referencing sign-ins with activity logs is useful context but does not by itself identify anomalous ARM write operations from unusual IPs.

83
MCQmedium

A security operations center (SOC) uses Microsoft Sentinel. The team wants to detect anomalous behavior for a specific user account that typically logs in only during business hours from a known IP range. They create a scheduled analytics rule that queries the SigninLogs table for logins outside that range or outside business hours. To reduce false positives, which of the following configurations should the analyst apply?

A.Set the alert threshold to 5 occurrences within the query lookback period.
B.Enable entity mapping for the user account to correlate with other data sources.
C.Increase the query scheduling frequency to every 5 minutes from every hour.
D.Group all events into a single alert and set the suppression limit to 1 hour.
AnswerA

Setting the alert threshold to 5 occurrences within the query lookback period directly addresses false positives by requiring a minimum number of matching events before an alert is created. In a Sentinel scheduled query rule, the threshold is evaluated against the number of rows returned by the query each run; lone anomalous but benign logins will fall below the threshold and be ignored. This is the most effective option because it manipulates the rule's triggering criterion, which is exactly what suppresses low-signal events.

Why this answer

Setting an alert threshold (e.g., 5 occurrences within the query lookback period) reduces false positives by requiring the anomalous behavior to be persistent rather than a single outlier. In Microsoft Sentinel, the alert threshold filters out noise from occasional legitimate logins that might accidentally fall outside business hours or the known IP range, ensuring the rule only fires when the pattern is repeated enough to indicate a real threat.

Exam trap

The trap here is that candidates confuse alert suppression (which reduces duplicates) with alert threshold (which reduces false positives by requiring multiple occurrences), leading them to choose options like D that manage alert volume but do not filter out low-confidence events.

How to eliminate wrong answers

Option B is wrong because entity mapping does not reduce false positives; it enriches alerts with additional context (e.g., linking to user entities) for investigation but does not filter out low-confidence events. Option C is wrong because increasing the query scheduling frequency to every 5 minutes would generate more frequent alerts, potentially increasing false positives and noise, not reducing them. Option D is wrong because grouping events into a single alert with a suppression limit of 1 hour only prevents duplicate alerts for the same detected pattern; it does not address the underlying false-positive rate from single anomalous logins.

84
MCQmedium

You are a security analyst investigating a detected phishing campaign targeting users in your organization. The Microsoft Defender for Office 365 alert indicates that several users clicked on a malicious link. Which action should you take first to prevent further compromise?

A.Add the malicious URL to the Microsoft Defender for Endpoint custom threat indicator list.
B.Isolate all affected users' devices from the network.
C.Report the email to Microsoft for analysis.
D.Block the sender email address in the tenant.
AnswerA

Creating a custom threat intelligence indicator for the malicious URL in Microsoft Defender for Endpoint triggers an immediate Alert/Block enforcement action on all onboarded endpoints via the built-in Network Protection component. When any user clicks the link, the endpoint blocks outbound connectivity to that URL before the content loads, regardless of the fact that the phishing email is already sitting in their mailbox. This is the fastest operational control because it addresses the actual click vector across all affected devices, not just the email envelope, and can also generate an alert for incident investigation.

Why this answer

Adding the malicious URL to the Microsoft Defender for Endpoint custom threat indicator list is the correct first action because it immediately blocks future access to that URL across all endpoints protected by Defender for Endpoint, preventing further compromise from users clicking the same link. This leverages the threat intelligence feed to enforce a block action at the network level, stopping the attack vector proactively without disrupting user productivity or requiring device isolation.

Exam trap

The trap here is that candidates often confuse incident response containment steps (like device isolation) with the most immediate preventive action, failing to recognize that blocking the malicious URL at the endpoint level stops the attack vector for all users without the operational impact of isolating devices.

How to eliminate wrong answers

Option B is wrong because isolating all affected users' devices from the network is an extreme containment step that disrupts operations and should only be taken after confirming active compromise or lateral movement, not as the first action when the primary threat is the URL itself. Option C is wrong because reporting the email to Microsoft for analysis is a reactive, long-term feedback action that does not immediately prevent further users from clicking the malicious link. Option D is wrong because blocking the sender email address is ineffective against phishing campaigns that often use spoofed or disposable addresses, and it does not block the malicious URL which could be delivered via other senders or methods.

85
MCQhard

You manage a Microsoft Sentinel workspace that ingests logs from multiple sources. You notice that the workspace is approaching its daily ingestion quota, and some data sources are being dropped. You need to ensure that security-related logs are prioritized and that non-critical logs are not ingested. What should you configure?

A.Create analytic rules with entity mapping to prioritize alerts
B.Use data collection rules (DCRs) to filter log ingestion
C.Set a daily cap on the Log Analytics workspace
D.Configure diagnostic settings to exclude certain logs
AnswerB

Data collection rules (DCRs) provide a pipeline-level mechanism to control what gets ingested into a Log Analytics workspace. By defining a KQL transformation in a DCR, you can filter out unwanted records or fields from specific data sources before they are stored, which directly enables selective ingestion and cost control. Because this processing occurs during the collection phase, it is the correct tool for filtering log ingestion in Sentinel.

Why this answer

Data collection rules (DCRs) allow you to define transformations that filter logs before they are ingested into a Log Analytics workspace. By configuring a DCR with a KQL-based transformation, you can drop non-critical logs while ensuring security-related logs are always ingested, preventing them from being dropped when the daily quota is approached.

Exam trap

The trap here is that candidates often confuse data collection rules (which filter at ingestion) with diagnostic settings (which control log routing) or daily caps (which stop all ingestion), failing to recognize that DCRs provide the granular control needed to prioritize specific log types.

How to eliminate wrong answers

Option A is wrong because analytic rules with entity mapping are used to generate alerts and correlate events, not to control which logs are ingested or to prioritize ingestion. Option C is wrong because setting a daily cap on the Log Analytics workspace stops all ingestion when the cap is reached, including security logs, which does not prioritize critical data. Option D is wrong because diagnostic settings control which logs are sent from Azure resources to destinations like Log Analytics, but they do not provide granular filtering or prioritization within a single workspace; they either include or exclude entire log categories.

86
MCQeasy

Your organization uses Microsoft Defender for Office 365. You detect a phishing email that was delivered to a user's inbox. You want to remove the email from all recipients. What should you do?

A.Submit the email to Microsoft for analysis.
B.Create a mail flow rule to delete similar emails in the future.
C.Block the sender using the Tenant Allow/Block List.
D.Use Threat Explorer to find the email and take action to delete it.
AnswerD

Threat Explorer (part of Microsoft Defender for Office 365) provides a deep, filterable view of email activity, including sender, recipient, subject, and threat signals. You can locate the specific email(s) that match the attack, select them, and use the 'Take action' drop-down to choose 'Delete' (or 'Soft delete/Delete'), which performs a bulk removal of the message from all affected mailboxes and can optionally trigger a remediation action. This is the appropriate tool because it combines search, investigation, and remediation for already-delivered threats.

Why this answer

Threat Explorer in Microsoft Defender for Office 365 allows security analysts to search for specific emails based on attributes like sender, subject, or recipient, and then take bulk remediation actions such as soft-delete (move to Deleted Items) or hard-delete (purge from mailbox). This is the correct tool to remove a phishing email that has already been delivered to users' inboxes, as it provides granular search and remediation capabilities for existing messages.

Exam trap

The trap here is that candidates often confuse proactive blocking (e.g., blocking the sender or creating a rule) with reactive remediation, failing to recognize that Threat Explorer is the only option that can remove already-delivered emails from user mailboxes.

How to eliminate wrong answers

Option A is wrong because submitting the email to Microsoft for analysis (e.g., via the Submissions portal) is used to improve detection algorithms or verify classification, not to remove already-delivered emails from recipients' mailboxes. Option B is wrong because creating a mail flow rule (transport rule) applies to future emails only; it cannot retroactively delete messages already delivered to inboxes. Option C is wrong because blocking the sender via the Tenant Allow/Block List prevents future delivery from that sender but does not remove emails already delivered to users' inboxes.

87
Multi-Selectmedium

Which TWO data sources are most relevant for threat hunting for lateral movement using remote service creation (e.g., WMI, PsExec)?

Select 2 answers
A.DeviceRegistryEvents
B.DeviceEvents
C.DeviceNetworkEvents
D.DeviceFileEvents
E.DeviceProcessEvents
AnswersC, E

DeviceNetworkEvents captures outbound and inbound connection attempts, including connections to TCP port 445, which is used for SMB file sharing to remote admin shares. Lateral movement techniques such as PsExec generate distinctive network connections to hosts on port 445 or any high-order port, making this telemetry among the most relevant for detecting an attacker pivoting across systems. The source IP, destination IP, and port data directly expose the network-level footprint of a move.

Why this answer

Correct options: C and E. DeviceProcessEvents captures process creation on remote machines (e.g., services.exe, cmd.exe) which is indicative of remote service creation via WMI or PsExec. DeviceNetworkEvents captures outbound network connections to high ports (e.g., 135, 445) on remote machines.

Option A (DeviceRegistryEvents) captures registry modifications, not directly relevant. Option B (DeviceEvents) is less specific for this scenario. Option D (DeviceFileEvents) captures file writes, not process execution.

88
MCQmedium

A threat hunter is using Microsoft Defender for Endpoint advanced hunting to find devices that have a specific file hash associated with a known malware variant. The analyst wants to include devices that have the file in any location, including quarantined items. Which table and column should be used?

A.DeviceImageLoadEvents, SHA256
B.DeviceFileEvents, SHA256
C.DeviceNetworkEvents, RemoteIP
D.DeviceProcessEvents, ProcessCommandLine
AnswerB

DeviceFileEvents records file creation and modification activity with SHA256 hashes, including quarantined items, so filtering on the known hash returns every device that encountered the file regardless of location. This satisfies the requirement to include quarantined detections.

Why this answer

DeviceFileEvents tracks file creation, modification, and deletion events, including those that are quarantined, and it includes the SHA256 column for file hashes. Option A (DeviceImageLoadEvents) is for image (DLL) loads, not general file info. Option C (DeviceNetworkEvents) covers network connections, not files.

Option D (DeviceProcessEvents) involves process execution, not file discovery, and its ProcessCommandLine column does not contain file hashes.

89
MCQhard

Your organization uses Microsoft Defender for Identity and Microsoft Defender XDR. You receive an alert about a suspicious LDAP query originating from a domain controller. The alert indicates potential use of the DCSync attack technique. What is the most effective immediate action to contain the attack?

A.Block all LDAP traffic at the firewall.
B.Restart the domain controller to clear any malicious processes.
C.Disable the account that initiated the suspicious replication request.
D.Reset the krbtgt account password twice.
AnswerC

Disabling the account is the correct immediate containment action because DCSync attacks (like Golden Ticket or DCshadow pre-staging) rely on the compromised identity having directory replication permissions, and disabling it blocks that account from authenticating or invoking DRS replication any further. This directly severs the attacker's current access path and halts the unauthorized replication request without requiring a full DC restart or broad network disruption. After disabling, the SID of the account can be added to a honeytoken or monitored for any further attempts during incident response. It is the fastest, least-destructive way to stop the bleeding.

Why this answer

The DCSync attack abuses the Directory Replication Service Remote Protocol (MS-DRSR) to impersonate a domain controller and request replication of credentials. Disabling the compromised account that initiated the suspicious LDAP replication request immediately stops the attacker's ability to request further replication, effectively containing the attack at the source without disrupting the entire domain.

Exam trap

The trap here is that candidates often confuse DCSync with a standard LDAP query and choose to block LDAP traffic, not realizing DCSync uses the DRSR protocol over RPC, and that disabling the offending account is the precise immediate containment step.

How to eliminate wrong answers

Option A is wrong because blocking all LDAP traffic at the firewall would break legitimate domain controller replication and authentication traffic, causing a domain-wide outage, and DCSync uses the DRSR protocol over RPC, not standard LDAP, so it would not even block the attack. Option B is wrong because restarting the domain controller would only clear volatile processes temporarily; the attacker's account or session would still be active, and the malicious replication request could be re-initiated immediately after reboot. Option D is wrong because resetting the krbtgt account password twice is a recovery step to invalidate existing Kerberos tickets after the attack has been contained, not an immediate containment action, and it does not stop the ongoing DCSync replication.

90
MCQhard

You are reviewing an analytics rule in Microsoft Sentinel. The rule is supposed to alert when a Confidential sensitivity label file is accessed. However, no alerts have been generated despite known accesses. What is the most likely reason?

A.The suppression duration is set to 5 hours, which suppresses alerts.
B.The required data connector for Microsoft Purview Information Protection is not connected.
C.The query frequency and period are too short to capture the events.
D.The trigger condition is set to 'GreaterThan' 0, which should fire on any event.
AnswerB

The `SensitivityLabelEvent` table is populated only when the Microsoft Purview Information Protection data connector is connected to Microsoft Sentinel. Without that connector, the table remains empty in the Log Analytics workspace, so the query for this analytics rule returns zero rows even if label consumption events are happening across the organization. This is the root cause because the rule's logic and trigger are sound, but the underlying telemetry is never ingested—so the alert never fires.

Why this answer

The query should reference the MicrosoftPurviewInformationProtection table (populated by the Microsoft Purview Information Protection data connector), not a nonexistent 'SensitivityLabelEvent' table. With the connector disconnected, that table is empty, which is why the rule's query returns zero rows and no alert fires despite the query logic, schedule, and trigger threshold all being otherwise correct.

Exam trap

Microsoft often tests the misconception that a rule's logic or scheduling is the root cause, when in fact the underlying data source is missing or misconfigured — candidates overlook the prerequisite of having the correct data connector enabled.

How to eliminate wrong answers

Option A is wrong because suppression duration only temporarily hides alerts after a match is triggered; it does not prevent the rule from firing in the first place. Option C is wrong because query frequency and period affect how often the rule runs and how far back it looks, but if the events are never ingested, no query will find them. Option D is wrong because 'GreaterThan' 0 is a correct trigger condition that would fire on any positive match; the issue is that no matches exist due to missing data.

91
MCQmedium

You are a threat hunter at Contoso. You suspect that an attacker is using the 'net user' command to create local accounts on compromised machines. You need to write a KQL query in Microsoft Defender XDR advanced hunting to find all instances of 'net user' being executed. Which operator should you use to search for the command line containing 'net user'?

A.has
B.startswith
C.contains
D.endswith
AnswerC

The contains operator checks for a substring anywhere in the string, so it will match command lines that include 'net user' even if there are additional arguments. This is appropriate for detecting the execution of 'net user' because the command may appear with various parameters. However, be aware that contains is case-insensitive and can be slower than has on large datasets.

Why this answer

To detect the 'net user' command, you need to search for the substring within the command line. The contains operator is designed for this purpose and will match any command line that includes 'net user', regardless of position. Other operators like startswith or endswith are too position-specific and would miss common variations.

Exam trap

The trap here is using has, which searches for whole terms and would not match the phrase 'net user' because it contains a space and is not a single term.

92
MCQeasy

Your team uses Microsoft Sentinel workbooks to visualize security data. You want to allow team members to customize a workbook without affecting the original. What should you do?

A.Edit the original workbook to add personalization
B.Assign the team the Microsoft Sentinel Reader role
C.Create a copy of the workbook and save it as a custom workbook
D.Share the workbook directly with the team
AnswerC

Creating a copy of the workbook and saving it as a custom workbook gives each user an independent Azure Workbooks resource that they can personalize without affecting the shared template. In Sentinel, selecting Save As typically prompts you to choose the resource group and name for the new workbook, creating a separate item in Workbooks that only the owner or granted users can edit. This approach satisfies the personalization requirement because modifications are stored in each user's own workbook resource, while the original template remains unchanged.

Why this answer

Creating a copy of the workbook and saving it as a custom workbook allows team members to modify their own version without altering the original. In Microsoft Sentinel, workbooks are based on Azure Monitor Workbooks, and saving a copy creates an independent resource with its own settings and queries. This preserves the original workbook for reference or reuse while enabling customization.

Exam trap

The trap here is that candidates may confuse the Microsoft Sentinel Reader role with the ability to customize workbooks, not realizing that Reader only allows viewing, not editing or saving copies, which requires at least Contributor permissions on the workbook resource.

How to eliminate wrong answers

Option A is wrong because editing the original workbook directly would modify the shared resource, affecting all users who access it, which contradicts the requirement to avoid impacting the original. Option B is wrong because the Microsoft Sentinel Reader role grants read-only access to Sentinel resources, including workbooks, but does not allow any customization or saving of copies. Option D is wrong because sharing the workbook directly with the team provides only read access by default; users cannot customize or save changes unless they have contributor permissions on the workbook resource, which still modifies the original.

93
MCQeasy

A threat hunter wants to use Microsoft Sentinel to hunt for signs of brute-force attacks against Azure AD (now Microsoft Entra ID). Which data connector should be enabled to ingest sign-in logs?

A.Windows Security Events via AMA
B.DNS (Preview)
C.Microsoft Entra ID Audit Logs
D.Microsoft Entra ID
AnswerD

Microsoft Entra ID is correct because this data connector streams both sign-in logs and audit logs into Microsoft Sentinel via diagnostic settings. The sign-in logs include interactive, non-interactive, service principal, and managed identity sign-ins, with rich details like MFA result, Conditional Access policy, and risk level. This comprehensive authentication telemetry is exactly what a threat hunter needs to detect unusual or malicious cloud sign-in behavior.

Why this answer

Microsoft Entra ID (formerly Azure AD) connector. This connector ingests sign-in logs, which contain authentication attempts and can be used to detect brute-force attacks. Option A (Windows Security Events via AMA) captures on-premises Windows security events, not cloud sign-ins.

Option B (DNS Preview) ingests DNS query logs, not sign-in logs. Option C (Microsoft Entra ID Audit Logs) captures audit logs (e.g., user management, configuration changes), not authentication sign-in logs. Therefore, only Option D provides the necessary sign-in log data for hunting brute-force attacks.

94
MCQhard

During a ransomware incident, security team needs to prevent encryption while preserving forensic data. Which action best achieves this balance?

A.Shut down all affected servers immediately.
B.Run a full antivirus scan on all endpoints.
C.Enable network micro-segmentation to isolate affected systems from file servers and take memory snapshots.
D.Disconnect the network but leave systems running.
AnswerC

Network micro-segmentation enforces granular access control at the workload level, so even if a host is compromised, it cannot reach file servers or other critical systems, halting lateral movement and additional encryption. Taking memory snapshots contemporaneously preserves volatile forensic evidence such as encryption keys and process artifacts, which are vital for identifying the ransomware variant and potentially recovering data without paying the ransom. This approach provides both containment and evidence preservation.

Why this answer

Network micro-segmentation (e.g., using Azure Network Security Groups or software-defined networking) isolates affected systems from file servers, halting lateral movement and preventing encryption of shared data, while memory snapshots (e.g., via Azure VM snapshots or live memory acquisition tools like WinPmem) preserve volatile forensic evidence such as encryption keys or process artifacts. This balances containment with forensic preservation, unlike destructive actions like shutdown or disconnection that lose memory data.

Exam trap

The trap here is that candidates confuse 'preserving forensic data' with keeping systems powered on (Option D), failing to realize that memory snapshots require a controlled capture before isolation, and that micro-segmentation specifically targets file server access to stop encryption at the network layer.

How to eliminate wrong answers

Option A is wrong because shutting down servers immediately destroys volatile memory (e.g., encryption keys, running processes) and may trigger anti-forensic mechanisms that delete logs. Option B is wrong because running a full antivirus scan on all endpoints can modify file timestamps, trigger ransomware to encrypt remaining data, and consume I/O that overwrites forensic evidence. Option D is wrong because disconnecting the network but leaving systems running does not prevent ransomware from continuing to encrypt local files and may allow persistence mechanisms to execute, while also failing to isolate from file servers that could be encrypted via cached credentials.

95
MCQmedium

An organization uses Microsoft 365 Defender. A security analyst wants to identify all devices that have been accessed from a compromised device via RDP in the past 24 hours. Which advanced hunting table should the analyst query?

A.DeviceEvents
B.DeviceNetworkEvents
C.DeviceLogonEvents
D.DeviceProcessEvents
AnswerC

DeviceLogonEvents is the authoritative advanced hunting table for authentication events in Microsoft 365 Defender. It provides detailed logon records, including the LogonType field, where LogonType = 10 specifically indicates remote interactive (RDP) logons. This table captures the target device, user account, source IP, and timestamp, making it the only reliable way to determine which devices were successfully accessed via RDP.

Why this answer

DeviceLogonEvents is the correct table because it records authentication events, including remote interactive logons such as RDP (LogonType 10). By filtering for logon type 10 and the compromised device's IP address, the analyst can identify all devices that accepted an RDP connection from that source within the past 24 hours.

Exam trap

The trap here is that candidates often choose DeviceNetworkEvents thinking network connections alone can identify RDP access, but they fail to realize that only DeviceLogonEvents provides the logon type and authentication context necessary to confirm a successful RDP session.

How to eliminate wrong answers

Option A is wrong because DeviceEvents tracks security-related events like antivirus detections and file modifications, not authentication or network connection details. Option B is wrong because DeviceNetworkEvents captures network-level connections (e.g., TCP/UDP flows) but does not include logon type or user authentication context required to confirm RDP access. Option D is wrong because DeviceProcessEvents logs process creation and termination events, which do not directly record RDP logon sessions or authentication outcomes.

96
MCQhard

Refer to the exhibit. A security analyst creates a scheduled analytics rule in Microsoft Sentinel based on the JSON shown. After enabling the rule, the analyst notices that the rule generates alerts every hour for the same user accounts even after the incidents are resolved. What is the most likely cause?

A.The severity is set to High, causing multiple alerts
B.The query period is too short, causing the rule to refetch old data
C.Suppression is disabled, so the rule fires every hour with overlapping results
D.The trigger threshold is too low, causing the rule to fire too often
AnswerC

When suppression is disabled, the scheduled rule has no mechanism to pause or stop additional runs after an alert is created, so it executes every hour exactly as scheduled. Because each hourly run uses a 1-day query period, the same events fall into multiple overlapping lookback windows, causing the rule to generate a new alert each time the query returns results that meet the threshold. Enabling suppression would suspend the rule for a defined period after an alert is generated, preventing overlapping and duplicate alerts from the same activity.

Why this answer

In Microsoft Sentinel, an analytics rule with suppression disabled will fire every time its query period elapses and the query returns results, even if those results overlap with previously generated incidents. Since the rule runs hourly and the query period likely covers a window that includes the same user accounts, it repeatedly generates alerts for the same entities. Enabling suppression (or configuring the rule to group and suppress duplicate alerts) prevents this repetitive firing.

Exam trap

SC-200 often tests the difference between rule scheduling parameters (query period, frequency, threshold) and suppression settings, catching candidates who blame alert frequency on severity or thresholds instead of the missing suppression configuration.

How to eliminate wrong answers

Option A is wrong because severity level (High) affects the incident's priority and labeling, not the frequency of alert generation; a High severity rule does not inherently fire more often. Option B is wrong because a short query period would actually reduce overlap by looking at a smaller time window, not cause repeated alerts for the same data; the issue is the lack of suppression, not the query period length. Option D is wrong because the trigger threshold controls how many results must be returned before an alert is generated, not how often the rule fires; a low threshold might make the rule more sensitive but does not cause hourly repetition of the same alerts.

97
MCQmedium

Your organization uses Microsoft Sentinel. A security incident is generated by a scheduled analytics rule. You need to automatically assign the incident to the SOC team and set its severity. What should you create?

A.An analytics rule
B.An automation rule
C.A workbook
D.A playbook
AnswerB

An automation rule is the correct choice because it executes natively and immediately when an incident is created, and it directly supports simple actions such as 'Assign owner' and 'Set severity' through conditions that evaluate incident properties at that moment. Unlike a playbook, it requires no Logic App or separate trigger, so it provides the fastest, most reliable method to impose mandatory ownership and severity settings during initial incident generation, exactly matching the requirement.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to a specific team (e.g., SOC team) and set their severity based on conditions like analytics rule name or incident properties. Unlike playbooks, automation rules are lightweight, run immediately without a Logic Apps connector, and are designed for simple, no-code incident management tasks such as assignment and severity changes.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, thinking that any automated response requires a playbook, but Microsoft Sentinel specifically uses automation rules for lightweight, built-in incident management actions like assignment and severity changes, reserving playbooks for more complex or multi-step workflows.

How to eliminate wrong answers

Option A is wrong because an analytics rule generates alerts and incidents based on queries, but it cannot automatically assign incidents or change severity after creation; it only defines the initial severity in the rule configuration. Option C is wrong because a workbook provides visualizations and dashboards of Sentinel data, but it cannot perform automated actions like incident assignment or severity modification. Option D is wrong because a playbook is a workflow built on Azure Logic Apps that can automate complex responses, but it is not the simplest or most direct method for simple assignment and severity changes; automation rules are preferred for these straightforward actions and run without the overhead of a playbook.

98
Multi-Selecteasy

You are a security analyst at a company that uses Microsoft Sentinel. You need to create a custom analytics rule that detects failed logon attempts from multiple IP addresses within 5 minutes. Which two KQL operators should you use?

Select 2 answers
A.where
B.project
C.bin
D.join
E.summarize
AnswersC, E

bin (sometimes called floor) rounds numeric values down to the nearest multiple of a specified bin size, creating discrete time buckets such as bin(timestamp, 1h). This function is essential for time-window grouping because it assigns each event to a specific bucket, which can then be used as a grouping key in summarize. By itself, bin does not aggregate; it only produces a grouping value. When combined with summarize, it enables time-series aggregations like count per hour, making it the correct choice for creating time windows.

Why this answer

The `bin` operator is correct because it groups timestamps into fixed-size time buckets (e.g., 5-minute intervals), which is essential for detecting patterns like failed logon attempts from multiple IPs within a specific time window. The `summarize` operator is correct because it aggregates data (e.g., counting distinct IP addresses) per each time bucket, enabling the rule to identify when the count exceeds a threshold.

Exam trap

The trap here is that candidates often confuse `where` or `project` as sufficient for time-window analysis, failing to recognize that only `bin` with `summarize` can group events into fixed intervals and aggregate distinct IPs per interval.

99
MCQhard

A security analyst receives a high-severity incident in Microsoft Sentinel for a user who is suspected of lateral movement. The analyst wants to automatically run a playbook that isolates the user's machine and disables their account when such an incident is created. What is the most efficient way to achieve this?

A.Configure a Logic Apps trigger to poll for new incidents every minute
B.Train analysts to manually run the playbook when they see the incident
C.Create an analytics rule that runs a playbook as part of its alert generation
D.Create an automation rule that triggers the playbook when the incident is created
AnswerD

Creating an automation rule that triggers the playbook when the incident is created is the correct, documented approach in Microsoft Sentinel. Automation rules use a trigger condition (incident creation) to run a playbook automatically, and they provide a simple, event-driven integration with Logic Apps. This ensures the playbook executes immediately and consistently for every matching incident, without the need for manual intervention or custom polling logic.

Why this answer

Automation rules in Microsoft Sentinel are designed to trigger playbooks automatically when an incident is created, based on conditions like severity or rule name. This provides the most efficient, event-driven response without polling or manual intervention, directly addressing the requirement to isolate the machine and disable the account upon incident creation.

Exam trap

The trap here is confusing analytics rules (which generate alerts) with automation rules (which respond to incidents), leading candidates to incorrectly choose option C because they think a playbook must be tied directly to the alert generation process.

How to eliminate wrong answers

Option A is wrong because polling with a Logic Apps trigger every minute introduces latency and unnecessary overhead, and it is less efficient than an event-driven trigger. Option B is wrong because manual execution defeats the purpose of automation, increases response time, and is not efficient for a high-severity incident requiring immediate action. Option C is wrong because analytics rules generate alerts, not incidents; while a playbook can be run as part of alert generation, this approach does not directly respond to incident creation and may not cover all incident creation scenarios (e.g., from other sources).

100
MCQmedium

Refer to the exhibit. A SOC analyst runs the KQL query in Microsoft Sentinel to identify the top 10 alert names by count. They notice the results include alerts with low severity that are not relevant. What should they add to the query to focus on high-severity alerts only?

A.Add 'order by Severity' to the query.
B.Add 'where Severity == "High"' after the summarize clause.
C.Change the time range to last 24 hours.
D.Add 'where Severity == "High"' before the summarize clause.
AnswerD

Adding `where Severity == "High"` before the summarize clause is the correct approach because it pushes the predicate as far upstream as possible in the query pipeline. KQL first restricts the alert stream to only High-severity rows, and then the summarize operator only sees and aggregates those filtered rows, reducing both I/O and aggregation cost. This aligns with Kusto best practice to filter early, and it is particularly important in Microsoft Sentinel where alert tables can contain millions of rows.

Why this answer

In KQL, the `where` clause must be placed before the `summarize` clause to filter raw events before aggregation. Placing `where Severity == "High"` before `summarize` ensures that only high-severity alerts are counted, preventing low-severity alerts from appearing in the top 10 results. This is a fundamental KQL query execution order: filtering first reduces the dataset for aggregation, improving both accuracy and performance.

Exam trap

The trap here is that candidates mistakenly think a `where` clause can be placed after `summarize` to filter aggregated results, but KQL requires filtering on raw columns before aggregation, and the `where` clause after `summarize` only works on aggregated columns (e.g., `count_`) unless the original column is explicitly included in the `summarize` output.

How to eliminate wrong answers

Option A is wrong because `order by Severity` only sorts the results after aggregation, it does not filter out low-severity alerts; the top 10 by count would still include low-severity alerts if they have high counts. Option B is wrong because adding `where Severity == "High"` after the `summarize` clause would attempt to filter aggregated results, but `Severity` is a field from the raw events and is not available after summarization unless explicitly projected; this would cause a query error or no filtering effect. Option C is wrong because changing the time range to last 24 hours does not filter by severity; it only limits the time window, so low-severity alerts within that period would still be included.

101
MCQhard

Your organization uses Microsoft Sentinel and has enabled the Microsoft 365 Defender connector. You want to automatically assign incidents to a specific analyst team based on the incident severity and type. Which component should you configure?

A.Analytics rule in Microsoft Sentinel
B.Workbook in Microsoft Sentinel
C.Automation rule in Microsoft Sentinel
D.Custom playbook in Microsoft Sentinel
AnswerC

Automation rules in Microsoft Sentinel are the native, lightweight mechanism for automating incident management tasks, including assigning an owner, changing status, or applying tags, without requiring a Logic Apps connector or additional code. You can create a rule with a condition like 'When incident is created' and an action 'Assign owner' to set the incident owner to a specific user or group. This is simpler, more performant, and directly integrated into the incident pipeline compared to custom code or playbooks.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific teams based on conditions like severity and type. This is the correct component because it provides a no-code, rule-based engine for incident management tasks, including assignment, without requiring custom logic or external automation.

Exam trap

The SC-200 exam often tests the distinction between automation rules (for incident management) and playbooks (for response actions), leading candidates to choose playbooks when a simpler, built-in rule suffices.

How to eliminate wrong answers

Option A is wrong because analytics rules are used to generate alerts and incidents from data sources, not to manage or assign incidents after creation. Option B is wrong because workbooks are visualization tools for querying and displaying data, not for automating incident assignment. Option D is wrong because custom playbooks (based on Azure Logic Apps) can automate responses but are overkill for simple assignment; automation rules are the native, simpler solution for this task.

102
Matchingmedium

Match each Microsoft Defender for Cloud security alert to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Anomalous process run on a VM

Multiple failed login attempts from an IP

Antimalware scan found a threat

Download of a suspicious file from an external source

Unusual outbound data transfer detected

Why these pairings

Correct matches: SQL Injection detects SQL code injection, Brute Force detects multiple failed logins, Malware Alert detects known malware. Common confusions include swapping definitions between these alerts.

103
MCQmedium

A SOC team uses Microsoft Sentinel and ingests Windows Security Events from domain controllers using the Azure Monitor Agent (AMA). They want to create a scheduled analytics rule that generates an incident when a user account is created in a sensitive Active Directory group (e.g., Domain Admins) outside of approved change windows (e.g., after 9 PM). The required event IDs are 4728 (member added to security-enabled global group) and 4732 (member added to security-enabled local group). Which KQL query should the analyst use to filter for these specific events and the targeted group?

A.SecurityEvent | where EventID in (4728, 4732) | where TargetAccount contains 'Domain Admins'
B.SecurityEvent | where EventID == 4624 | where Account contains 'Admin'
C.SecurityEvent | where EventID == 4738 | where TargetAccount contains 'Domain Admins'
D.SecurityEvent | where EventID == 4670 | where ObjectName contains 'Domain Admins'
AnswerA

Security events 4728 and 4732 are generated specifically when a member is added to a security-enabled global group and a security-enabled local group, respectively. By filtering on TargetAccount containing 'Domain Admins', this query captures modifications to the Domain Admins group, which is a common privilege-escalation target. This is the correct approach because it directly monitors group membership changes rather than logon or object-permission events.

Why this answer

It uses the `SecurityEvent` table with the `EventID` filter for 4728 and 4732, which are the exact event IDs for member additions to security-enabled global and local groups. The `TargetAccount` field contains the name of the group being modified, so filtering for 'Domain Admins' correctly identifies when a user is added to that sensitive group. This query directly matches the requirement to detect account creation in a sensitive AD group outside approved change windows.

Exam trap

The trap here is that candidates often confuse EventID 4738 (user account changed) or 4624 (logon) with group membership events, or they incorrectly assume the TargetAccount field contains the user account being added rather than the group name.

How to eliminate wrong answers

Option B is wrong because EventID 4624 corresponds to a successful logon event, not a group membership change, and filtering for 'Admin' in the Account field is too broad and unrelated to the target group. Option C is wrong because EventID 4738 is for a user account being changed (e.g., password reset or attribute modification), not for adding a member to a group. Option D is wrong because EventID 4670 is for permissions on an object being changed (e.g., ACL modification), not for group membership additions, and the ObjectName field does not reliably capture the group name in this context.

104
MCQhard

Your organization is implementing Microsoft Sentinel in a multi-tenant environment using Azure Lighthouse. The SOC team needs to investigate incidents across all tenants from a single interface. Which configuration is required?

A.Use Azure AD B2B to grant users from other tenants access to the workspace.
B.Create a single workspace and have all tenants send logs to it.
C.Assign custom roles in each tenant's Sentinel workspace.
D.Onboard multiple workspaces to Azure Lighthouse and use a central workspace for investigation.
AnswerD

Onboarding multiple Sentinel workspaces to Azure Lighthouse is the proper approach because it enables delegated resource management across tenant boundaries. Once each tenant's workspace is delegated to the central management tenant, security analysts can use Azure Lighthouse to access all workspaces in a single browser session and leverage Sentinel's built-in multi-workspace views, such as unified incident management and cross-workspace hunting. This preserves each tenant's data ownership and isolation while giving the central SOC operational visibility, and it supports a dedicated central workspace for aggregating alerts and managing investigations across the enterprise.

Why this answer

Azure Lighthouse enables cross-tenant management by allowing the SOC team to delegate access to multiple Sentinel workspaces from a single control plane. This configuration lets investigators view and manage incidents across all tenants without needing separate sign-ins or duplicating data, which is essential for a multi-tenant SOC environment.

Exam trap

The trap here is that candidates often confuse Azure AD B2B (external user access) with Azure Lighthouse (delegated resource management), assuming that granting external identities access to a single workspace is sufficient for multi-tenant incident investigation, when in fact Lighthouse is required to project multiple workspaces into a single management plane.

How to eliminate wrong answers

Option A is wrong because Azure AD B2B provides external user access to a single tenant's resources but does not aggregate incidents from multiple tenants into one interface; each tenant would still require separate workspace access. Option B is wrong because sending logs from all tenants to a single workspace violates data residency and isolation requirements, and Microsoft Sentinel does not support ingesting logs from external tenants into a workspace without proper delegation. Option C is wrong because assigning custom roles in each tenant's Sentinel workspace still requires the SOC team to switch between tenants to investigate incidents, failing to provide a unified investigation interface.

105
MCQhard

You have a Microsoft Sentinel workspace that uses Customer-Managed Keys (CMK). A security audit requires that all data at rest be encrypted with the CMK. You recently onboarded a new data connector that sends logs to a Log Analytics workspace in a different region. You need to ensure the new workspace uses CMK. What should you do?

A.Associate the new Log Analytics workspace with an Azure Key Vault containing the CMK before ingesting data.
B.Update the data connector settings to enable CMK at the source.
C.Use Azure Policy to enforce CMK on the new workspace.
D.Configure CMK on the new workspace's tables individually.
AnswerA

CMK configuration must occur before any data is written because Log Analytics binds the customer-managed key to the workspace's encryption context at provisioning time. After ingestion, the key association cannot be retroactively changed; enabling CMK on a workspace with existing data is not supported. Therefore, you must create the new workspace, associate it with the Key Vault key, and only then connect data sources.

Why this answer

Customer-Managed Keys (CMK) for Log Analytics workspaces must be configured at workspace creation time or before any data is ingested. The CMK is associated with the workspace via an Azure Key Vault, and once data is written, the encryption key cannot be changed. Therefore, to ensure the new workspace in a different region uses CMK, you must associate it with the Key Vault containing the CMK before any logs are ingested.

Exam trap

The trap here is that candidates may think CMK can be applied after data ingestion or per table, but Microsoft Sentinel requires CMK to be configured before any data is written to the workspace.

How to eliminate wrong answers

Option B is wrong because data connectors do not have settings to enable CMK at the source; CMK is a workspace-level encryption configuration, not a connector property. Option C is wrong because Azure Policy can enforce compliance but cannot retroactively apply CMK to a workspace that already has data; the policy must be assigned before data ingestion. Option D is wrong because CMK is applied at the workspace level, not per table; individual table encryption is not supported in Log Analytics.

106
Multi-Selecthard

Your organization uses Microsoft Sentinel and Microsoft Copilot for Security. You want to improve incident response efficiency. Which THREE features should you implement? (Choose three.)

Select 3 answers
A.Enable Microsoft Copilot for Security to assist with incident investigations.
B.Use watchlists to track known malicious IP addresses.
C.Configure workbooks to display real-time incident trends.
D.Develop playbooks to automate response actions for common threats.
E.Create automation rules to automatically assign and triage incidents based on severity.
AnswersA, D, E

Microsoft Copilot for Security, embedded directly in Microsoft Sentinel, uses large language models to generate incident summaries and correlate evidence across alerts, logs, and threat intelligence. This enables analysts to ask natural-language questions about an attack and receive recommended next steps or response actions. By providing context-aware guidance and automating the initial investigative narrative, Copilot reduces the time to understand and act on a security incident.

Why this answer

Microsoft Copilot for Security integrates directly with Microsoft Sentinel to provide AI-driven natural language assistance for incident investigations, enabling analysts to query data, summarize incidents, and generate KQL queries without manual scripting. This directly improves incident response efficiency by reducing investigation time and cognitive load.

Exam trap

The trap here is that candidates confuse passive features (watchlists, workbooks) with active response features (Copilot, automation rules, playbooks), leading them to select options that provide visibility rather than efficiency improvements in incident handling.

107
MCQhard

A global enterprise uses Microsoft 365 Defender across multiple tenants. During an incident, a security analyst needs to search for a specific file hash indicator of compromise (IOC) across all mailboxes and endpoints in all tenants from a single interface. Which feature allows the analyst to run a query across multiple tenants without switching contexts?

A.Cross-tenant advanced hunting
B.Multi-tenant management
C.Unified audit log
D.Microsoft Graph Security API
AnswerA

Cross-tenant advanced hunting in Microsoft 365 Defender provides a native KQL-based query surface that can span multiple tenants at once. A security analyst can search for a specific IOC, such as a SHA256 hash or sender address, across all connected tenants' advanced hunting tables in a single query. This is the only built-in option that supports multi-tenant search on raw telemetry without custom development.

Why this answer

Cross-tenant advanced hunting in Microsoft 365 Defender allows a security analyst to run Kusto Query Language (KQL) queries across multiple tenants from a single interface. This feature is specifically designed for hunting for indicators of compromise (IOCs), such as file hashes, across all mailboxes and endpoints in a multi-tenant environment without requiring the analyst to switch between tenant portals.

Exam trap

The trap here is that candidates often confuse multi-tenant management (a centralized policy and settings tool) with cross-tenant advanced hunting (a query tool), assuming that any 'multi-tenant' feature can run cross-tenant queries, but only cross-tenant advanced hunting supports interactive KQL hunting across tenants.

How to eliminate wrong answers

Option B is wrong because multi-tenant management provides a centralized view for managing settings and policies across tenants, but it does not support running ad-hoc hunting queries for IOCs like file hashes across mailboxes and endpoints. Option C is wrong because the unified audit log aggregates audit records from multiple Microsoft 365 services but is limited to audit events and does not support endpoint data or advanced hunting queries for file hashes. Option D is wrong because the Microsoft Graph Security API enables programmatic access to security alerts and incidents but is not a single interface for running interactive hunting queries across multiple tenants; it requires custom development and does not provide the built-in query experience of advanced hunting.

108
MCQmedium

A security analyst is investigating an incident in Microsoft 365 Defender that involves a user who clicked a phishing link. The analyst wants to find all processes executed on the user's device immediately after the email was opened. Which advanced hunting table should the analyst query to obtain process creation events with timestamps relative to the email event?

A.DeviceProcessEvents
B.EmailEvents
C.DeviceNetworkEvents
D.IdentityLogonEvents
AnswerA

DeviceProcessEvents is the correct table because it captures process creation events on endpoints, including the executable name, command line, parent process, and timestamp. When investigating a phishing click, this table lets you determine exactly which process was spawned (e.g., a script from a downloaded attachment) and whether it initiated further malicious activity. Without this telemetry, there is no direct evidence that a suspicious executable was run on the device.

Why this answer

DeviceProcessEvents is the correct table because it stores process creation events (including image name, command line, and timestamp) for all devices onboarded to Microsoft Defender for Endpoint. By querying this table with a time range starting immediately after the email event (identified from EmailEvents), the analyst can correlate the phishing click with subsequent process executions on the user's device.

Exam trap

The trap here is that candidates confuse the table that stores the email event (EmailEvents) with the table that stores the resulting process activity (DeviceProcessEvents), forgetting that process creation data is only in the endpoint-specific table.

How to eliminate wrong answers

Option B (EmailEvents) is wrong because it contains email delivery and post-delivery events (e.g., sender, recipient, subject, delivery action) but does not include process creation data. Option C (DeviceNetworkEvents) is wrong because it records network connections (source/destination IP, port, protocol) but not process creation events. Option D (IdentityLogonEvents) is wrong because it tracks authentication and logon activities from Azure AD and Active Directory, not process execution on endpoints.

109
MCQhard

You are investigating a Microsoft Defender XDR incident where a user's device is showing signs of compromise. The incident includes alerts from Microsoft Defender for Endpoint and Microsoft Defender for Identity. You need to isolate the device from the network while preserving forensic evidence. Which action should you take?

A.Initiate a full antivirus scan on the device and then reboot it to remove the threat.
B.Use Microsoft Defender for Identity to disable the user account and then isolate the device from the Defender for Identity portal.
C.Run the 'Live response' session and execute the 'isolate' command.
D.Run the 'Isolate device' action in Microsoft Defender for Endpoint, selecting the 'Full isolation' option.
AnswerD

Full isolation in Microsoft Defender for Endpoint disconnects the device from all network traffic except for the Defender for Endpoint cloud service, allowing you to contain the threat while maintaining communication for investigation. It preserves forensic evidence on the device because it does not wipe or modify files. This action is appropriate for a compromised device requiring containment and evidence preservation.

Why this answer

Full isolation in Microsoft Defender for Endpoint is the correct action to contain a compromised device while preserving forensic evidence. It restricts network communication to only the Defender for Endpoint service, preventing lateral movement and C2 traffic, and allows investigators to perform live response and collect evidence. Other options either misstate capabilities or do not achieve isolation.

Disabling a user account does not isolate the device, and antivirus scans do not contain the threat.

Exam trap

The trap here is confusing device isolation capabilities across Microsoft Defender services; only Defender for Endpoint provides device isolation, not Defender for Identity or live response commands.

110
MCQeasy

Your organization has multiple Azure subscriptions and wants to ensure that all of them have Microsoft Defender for Cloud's enhanced security features enabled. What is the minimal step required to achieve this for all subscriptions?

A.Assign an Azure Policy initiative to enable Defender for Cloud on each subscription
B.Enable the required Defender for Cloud plans at the management group level
C.Install the Log Analytics agent on all virtual machines in each subscription
D.Create a security contact email for each subscription
AnswerB

Enabling the required Defender for Cloud plans at the management group level propagates the pricing-tier settings to every subscription nested beneath that management group. Because Defender for Cloud plan configuration is inherited hierarchically, this single action provisions the plans across all subscriptions at once, eliminating the need to navigate to each subscription individually. This is the simplest and most direct method for multi-subscription enablement.

Why this answer

Enabling Microsoft Defender for Cloud plans at the management group level is the minimal step because it applies the configuration to all child subscriptions under that management group in a single action. This leverages Azure's hierarchical management structure, ensuring every subscription inherits the enhanced security features without needing individual subscription-level configuration.

Exam trap

The trap here is that candidates often confuse enabling Defender for Cloud plans with deploying agents or configuring policies, but the minimal step is simply toggling the plans at the management group scope, which applies to all child subscriptions automatically.

How to eliminate wrong answers

Option A is wrong because assigning an Azure Policy initiative to enable Defender for Cloud is not minimal; it requires creating and assigning a policy, which is more complex than directly enabling plans at the management group level. Option C is wrong because installing the Log Analytics agent on virtual machines is not required to enable Defender for Cloud's enhanced security features; the agent is needed for specific features like file integrity monitoring but not for enabling the plans themselves. Option D is wrong because creating a security contact email for each subscription is a separate compliance requirement for incident notification, not a step to enable enhanced security features.

111
MCQmedium

A SOC analyst wants to create a Microsoft Sentinel scheduled analytics rule that alerts when a user from a critical department (e.g., Finance) logs on from an IP address that is not in the company's approved IP address ranges. The analyst has an Azure Sentinel watchlist named 'FinanceApprovedIPs' containing the allowed IP ranges. Which KQL operator should be used in the rule's query to efficiently check if the IP address from SigninLogs falls within any of the watchlist ranges?

A.join kind=inner (watchlist) on $left.IPAddress $right.IPRange with condition using ipv4_is_in_range() or ipv4_lookup()
B.where IPAddress has any (watchlist)
C.where IPAddress in (watchlist)
D.where IPAddress startswith (watchlist)
AnswerA

The join correctly pairs each sign-in event with the watchlist's range entries, then applies ipv4_is_in_range() (or ipv4_lookup()) inside the condition to evaluate whether the sign-in IP falls within the specified CIDR block or address range. This is the only pattern that performs true network-range comparison rather than string or exact-value matching. The inner join also filters to only events that have a matching range, effectively acting as an allowlist check. This approach scales well because the watchlist is loaded into memory and the function runs natively in KQL.

Why this answer

The `ipv4_lookup()` function (or `ipv4_is_in_range()` used with a join) is specifically designed to efficiently check whether an IP address falls within a range defined in a watchlist. In Microsoft Sentinel, watchlists store data as tables, and `ipv4_lookup()` performs a range-based lookup using CIDR notation, which is far more efficient than string-based or exact-match operators. This allows the query to match the `IPAddress` from `SigninLogs` against the `IPRange` column in the `FinanceApprovedIPs` watchlist without iterating over every possible address.

Exam trap

The trap here is that candidates often confuse string-based operators like `has`, `in`, or `startswith` with IP-specific functions, failing to recognize that IP range matching requires subnet-aware logic (CIDR) rather than simple text comparison.

How to eliminate wrong answers

Option B is wrong because the `has` operator performs a substring search, not an IP range match; it would incorrectly match partial strings (e.g., '10.0.0.1' would match '10.0.0.15') and cannot evaluate CIDR ranges. Option C is wrong because the `in` operator performs exact string matching, which cannot handle IP ranges or CIDR notation; it would only match if the IP address literally equals a watchlist entry (e.g., '192.168.1.0/24' would never match '192.168.1.5'). Option D is wrong because `startswith` checks if the IP address string begins with a specified prefix, which is not suitable for range-based matching and would produce false positives (e.g., '10.0.0.1' would match '10.0.0.0/24' but also '10.0.0.100' incorrectly).

112
MCQeasy

You are a security operations analyst at a company that uses Microsoft Sentinel. You need to ensure that when a specific analytics rule generates an incident, a playbook is automatically triggered to post a message in a Microsoft Teams channel. What should you configure?

A.A workflow in Microsoft Teams that monitors the Sentinel incident queue.
B.A playbook that is triggered by the analytics rule directly.
C.An automation rule that triggers the playbook when the incident is created.
D.A scheduled query rule in Azure Monitor that detects the incident and calls the playbook.
AnswerC

Automation rules in Microsoft Sentinel can trigger playbooks based on incident creation. By creating an automation rule that runs when the specific analytics rule generates an incident, you can automatically invoke the playbook that posts to Microsoft Teams. This is the correct method to achieve the required automation.

Why this answer

To automatically trigger a playbook when a specific analytics rule creates an incident, you need an automation rule. Automation rules in Microsoft Sentinel respond to incident creation and can invoke playbooks. The playbook can then use the Microsoft Teams connector to post a message.

This is the standard and supported method for this automation.

Exam trap

The trap here is thinking that an analytics rule can directly trigger a playbook or that a Teams workflow can monitor Sentinel incidents, bypassing the need for an automation rule.

113
Multi-Selecteasy

Which TWO actions can you perform in the Microsoft Defender XDR unified alert queue? (Select TWO.)

Select 2 answers
A.Link the alert to an existing incident
B.Assign an alert to a SOC analyst
C.Create a hunting query from the alert details
D.Edit the analytics rule that generated the alert
E.Run a playbook to automatically remediate the alert
AnswersA, B

In the Microsoft Defender XDR alert queue, you can take an alert and associate it with an existing incident by selecting the 'Link to incident' action. This consolidates related alerts into a single incident, allowing the SOC team to manage and investigate the full scope of an attack from one place. The linkage is stored so that the alert's lifecycle becomes tied to the incident's status, ensuring proper tracking and correlation.

Why this answer

In the Microsoft Defender XDR unified alert queue, you can link an alert to an existing incident to consolidate related alerts into a single investigation. This action is supported directly from the alert queue interface, allowing analysts to manage incident correlation without leaving the queue. Linking alerts helps reduce alert fatigue and streamlines the incident management workflow.

Exam trap

The trap here is that candidates often confuse the unified alert queue with the incident queue, mistakenly thinking that actions like running playbooks or editing rules are available directly from the alert queue, when in fact those actions are tied to incidents or separate configuration interfaces.

114
MCQeasy

You manage Microsoft Sentinel. You need to ensure that an automated response is triggered when a specific type of incident is created. The response should send an email to the on-call security engineer. What should you use?

A.Use a watchlist to map incident types to email addresses and configure a scheduled query.
B.Create an automation rule that runs a playbook when an incident is created.
C.Modify the analytics rule to include an email action in the rule settings.
D.Create a workbook that alerts via email when new incidents appear.
AnswerB

Automation rules are Sentinel's built-in incident orchestration engine; they evaluate triggers like incident creation and can invoke playbooks. A playbook is an Azure Logic Apps workflow that can send email through connectors such as Outlook or Office 365. This design cleanly separates detection from response and supports re-use of the same playbook across multiple rules.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when an incident is created. The playbook can include an action to send an email to the on-call security engineer, providing the automated response required by the scenario.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rule settings or workbooks, mistakenly thinking that email actions can be configured directly in the analytics rule or that workbooks can send alerts, when in fact only automation rules with playbooks provide the necessary automated response capability.

How to eliminate wrong answers

Option A is wrong because watchlists are used for correlation and enrichment of data in queries, not for triggering automated email responses; a scheduled query can generate alerts but does not directly send emails based on incident types. Option C is wrong because analytics rules do not have a built-in email action in their settings; they generate alerts or incidents, but email notifications must be handled by automation rules or playbooks. Option D is wrong because workbooks are visualization tools that do not send alerts via email; they display data but cannot trigger automated responses like email notifications.

115
MCQmedium

A security incident in Microsoft Sentinel has been classified as a true positive and remediated. According to your SOC playbook, the incident should be closed with a classification of 'True Positive' and a sub-classification of 'Confirmed activity'. What is the correct way to close the incident in Microsoft Sentinel?

A.In the Microsoft Sentinel incident, set Status to 'Closed', Classification to 'True Positive', and Sub-classification to 'Confirmed activity'.
B.Close the incident in Microsoft Defender XDR and let it sync to Microsoft Sentinel.
C.Change the incident status to 'Closed' without adding a classification.
D.Use the Microsoft Security Graph API to close the incident with the appropriate classification.
AnswerA

In the Microsoft Sentinel incident pane, set Status to 'Closed', Classification to 'True Positive', and Sub-classification to 'Confirmed activity'. This exact combination satisfies the SOC playbook's closure criteria and writes the triage verdict into the incident metadata for Microsoft Sentinel analytics and reporting. Closing directly in Sentinel ensures that any automation rules triggered by incident closure run with the expected values, preserving the audit trail for compliance.

Why this answer

Using the Microsoft Security Graph API to close the incident is unnecessary and out of scope here: the scenario calls for a single incident to be manually closed per the SOC playbook's exact classification and sub-classification values, which is done directly in the Microsoft Sentinel incident pane. The Graph API is useful for bulk/programmatic incident updates, but that is not what this scenario requires, so it is not the correct choice here.

Exam trap

The trap here is that candidates may assume closing an incident in Microsoft Defender XDR will sync all details to Sentinel, but in reality, Sentinel requires direct closure within its own interface to apply classification and sub-classification fields.

How to eliminate wrong answers

Option B is wrong because closing an incident in Microsoft Defender XDR does not automatically sync the classification and sub-classification to Microsoft Sentinel; Sentinel incidents must be closed within Sentinel to set these fields. Option C is wrong because changing the status to 'Closed' without adding a classification leaves the incident without a proper closure reason, which violates the SOC playbook and hinders accurate reporting and auditing. Option D is wrong because while the Microsoft Security Graph API can be used to close incidents, it is not the correct or recommended method for this scenario; the Sentinel portal provides the direct and intended way to set classification and sub-classification fields.

116
MCQeasy

A Microsoft Defender XDR incident shows a malicious email delivered to a user, and the analyst confirms the message contains a credential-harvesting link. Before the user clicks, you need to remove the message from all mailboxes in the tenant and block the sender and URL for the future. Which Microsoft Defender for Office 365 capability should you use from the incident?

A.Threat Explorer with a message trace filter to identify and delete matching messages.
B.The email entity page action to soft delete, hard delete, or move to junk, plus submitting the sender and URL for blocking.
C.Automated investigation and response with the soft delete action on the email entity.
D.A mail flow transport rule in the Exchange admin center that rejects messages from the sender domain.
AnswerB

Microsoft Defender for Office 365 exposes email entity actions in the incident that include soft delete, hard delete, and move to junk, letting you purge the message across all mailboxes. Submitting the sender and URL through the same workflow lets the service add them to tenant-level block entries. This directly removes the active threat and prevents recurrence, matching both requirements in the scenario.

Why this answer

When a malicious email is confirmed, Microsoft Defender for Office 365 provides email entity remediation actions that purge the message tenant-wide and let you block the associated sender and URL. This combines cleanup of the delivered threat with prevention of recurrence. Tools that only investigate, or controls that only affect future mail, leave the delivered message reachable and do not satisfy both halves of the requirement.

Exam trap

The trap here is confusing investigation tooling, such as Threat Explorer, with remediation actions that actually remove and block content.

117
MCQmedium

A security analyst is investigating a Microsoft Defender for Cloud Apps alert about a suspicious OAuth app that has high permissions. The analyst needs to disable the app immediately. What is the correct action?

A.Revoke all tokens for the app in Microsoft Entra ID.
B.Generate a new client secret for the app.
C.From the Microsoft Defender for Cloud Apps alert, select 'Disable app'.
D.Go to Microsoft Entra ID admin center and delete the app registration.
AnswerC

This is the recommended remediation because Defender for Cloud Apps provides a built-in governance action that disables the OAuth app directly from the alert. Disabling the app denies the app's service principal from acquiring new tokens and revokes existing grants, effectively cutting off access to Microsoft 365 resources. This action is integrated with the investigation workflow, ensuring immediate and consistent enforcement across the organization.

Why this answer

Microsoft Defender for Cloud Apps provides a built-in 'Disable app' action directly from the alert, which immediately revokes the OAuth app's permissions and prevents further access without deleting the app registration. This is the fastest way to mitigate the threat while preserving the app for potential forensic analysis.

Exam trap

The trap here is that candidates often assume revoking tokens (Option A) or deleting the app registration (Option D) is the correct immediate response, but the exam tests the specific 'Disable app' action available within the Defender for Cloud Apps alert workflow, which is the designed incident response step for OAuth app compromise.

How to eliminate wrong answers

Option A is wrong because revoking all tokens for the app in Microsoft Entra ID would invalidate current sessions but does not disable the app itself; the app could still request new tokens and regain access. Option B is wrong because generating a new client secret only rotates credentials; the app retains its high permissions and can continue to use the old secret until it is updated, which does not stop the immediate threat. Option D is wrong because deleting the app registration in Microsoft Entra ID is a permanent action that removes the app entirely, which may be too destructive and could disrupt legitimate use; it also bypasses the Defender for Cloud Apps alert's purpose-built disablement workflow.

118
MCQmedium

An analyst is investigating a potential data exfiltration incident involving a user who accessed sensitive files from a personal device. The analyst wants to gather evidence about the device's compliance status and recent activity. Which Microsoft Intune feature should the analyst use?

A.Exchange Online message trace
B.Microsoft Intune device inventory and compliance reports
C.Azure Activity Log
D.Microsoft 365 Defender's service health dashboard
AnswerB

Microsoft Intune device inventory and compliance reports give a centralized view of every enrolled device, including its operation system, ownership type, enrollment date, and compliance status against assigned policies. These reports also surface recent device activity, such as check-ins and policy evaluation results, which allows an analyst to pinpoint non-compliant or unmanaged devices that might be involved in data exfiltration. This is the correct tool because it directly supports identifying which devices lack the required security controls.

Why this answer

Microsoft Intune device inventory and compliance reports provide detailed information about a device's compliance status, including whether it meets security policies, has required updates, and is managed correctly. This is essential for investigating potential data exfiltration from a personal device, as it allows the analyst to verify if the device was compliant and review recent activity logs within Intune.

Exam trap

The trap here is that candidates may confuse Azure Activity Log (which covers Azure resource operations) with Intune's device management logs, or mistakenly think Exchange message trace can reveal device compliance status.

How to eliminate wrong answers

Option A is wrong because Exchange Online message trace is used for tracking email delivery and routing, not for device compliance or activity monitoring. Option C is wrong because Azure Activity Log records subscription-level events (e.g., resource creation, RBAC changes) and does not include device compliance or user activity on a personal device. Option D is wrong because Microsoft 365 Defender's service health dashboard shows the operational status of Microsoft services, not device-specific compliance or activity data.

119
MCQhard

Refer to the exhibit. You are using a hunting query in Microsoft Defender XDR to find devices generating excessive DNS queries. The query returns many results, but you want to exclude legitimate DNS servers. What is the best approach to refine the query?

A.Add a `where` clause to exclude known internal DNS server IPs.
B.Join with DeviceInfo to filter by device type.
C.Change the RemotePort filter to UDP 53 only instead of all DNS.
D.Increase the count threshold to 5000.
AnswerA

Excluding known DNS servers reduces noise from legitimate traffic.

Why this answer

Correct answer: A. Adding a `where` clause to exclude known internal DNS server IPs reduces false positives by filtering out legitimate DNS traffic from your own DNS servers, which generate high DNS query volumes by design. Options B, C, and D are incorrect: B – Changing the RemotePort filter to UDP 53 only is already implied in a DNS query hunt and does not exclude internal servers; C – Joining with DeviceInfo may not effectively filter out DNS servers and could add complexity; D – Increasing the threshold risks missing true excessive queries that are still below the new threshold but above normal.

120
MCQeasy

A company wants to enable Microsoft Defender for Cloud's enhanced security features for all Azure virtual machines in a subscription. What is the first action they should take in the Defender for Cloud pricing & settings page?

A.Turn on the 'Servers' plan for the subscription
B.Install the Log Analytics agent on each VM
C.Enable vulnerability assessment
D.Assign a regulatory compliance policy
AnswerA

Enabling the 'Servers' plan at the subscription level is the authoritative first step that activates Microsoft Defender for Cloud's enhanced security features (formerly Azure Defender) for every supported VM in that subscription. This plan turns on capabilities such as threat detection, just-in-time VM access, and integrated vulnerability assessment, making it the required prerequisite before any other configuration or agent deployment can deliver full value. Without this plan enabled, other settings remain dormant or incomplete.

Why this answer

To enable Microsoft Defender for Cloud's enhanced security features for Azure VMs, the first step is to turn on the 'Servers' plan at the subscription level in the Defender for Cloud pricing & settings page. This activates Defender for Servers, which provides threat detection, vulnerability assessment, and just-in-time access. Without enabling this plan, no enhanced security features are available, regardless of other configurations.

Exam trap

The trap here is that candidates often confuse the order of operations, thinking that installing the Log Analytics agent or enabling vulnerability assessment is the first step, when in fact the subscription-level plan toggle must be enabled to unlock all enhanced security features.

How to eliminate wrong answers

Option B is wrong because installing the Log Analytics agent (now the Azure Monitor Agent) is a prerequisite for data collection but is not the first action; the 'Servers' plan must be enabled first to authorize the use of enhanced features. Option C is wrong because enabling vulnerability assessment (e.g., via Qualys or Microsoft Defender Vulnerability Management) is a feature within the 'Servers' plan and cannot be activated until the plan itself is turned on. Option D is wrong because assigning a regulatory compliance policy (e.g., Azure Policy for compliance standards) is a separate governance action that does not enable the underlying threat detection capabilities; it only maps resources to compliance frameworks after the plan is active.

121
MCQeasy

A security administrator wants to see the overall security posture of all their Azure subscriptions in a single numerical score. Which dashboard in Microsoft Defender for Cloud provides this score based on implemented security controls?

A.Regulatory Compliance
B.Secure Score
C.Inventory
D.Recommendations
AnswerB

Secure Score is the central metric in Defender for Cloud that aggregates all security recommendations into a single numeric value. Each security control groups related recommendations and contributes a maximum score, and the score reflects the percentage of healthy resources relative to total resources. Remediating recommendations increases the score, giving a direct, overall measure of security posture that continuously updates as resources change. It is explicitly designed to answer the question of overall security posture.

Why this answer

The Secure Score dashboard in Microsoft Defender for Cloud aggregates the security posture across all Azure subscriptions into a single numerical score. This score is calculated based on the implementation of security controls and recommendations, reflecting the percentage of completed security measures. The administrator needs this consolidated view, which is exactly what Secure Score provides.

Exam trap

The trap here is that candidates confuse the Secure Score with the Regulatory Compliance score, thinking both provide a general security posture, but Regulatory Compliance is specifically tied to compliance frameworks, not the overall security control implementation.

How to eliminate wrong answers

Option A is wrong because Regulatory Compliance provides a score based on compliance with specific standards (e.g., CIS, NIST), not a general security posture score. Option C is wrong because Inventory lists resources and their security configurations but does not calculate a numerical score. Option D is wrong because Recommendations shows individual security suggestions and their status, but does not aggregate them into a single overall score.

122
Multi-Selecthard

Which THREE capabilities are provided by Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) plan? (Select THREE.)

Select 3 answers
A.Compliance dashboard that shows your posture against regulatory standards.
B.Continuous assessment of your cloud resources against security best practices.
C.Endpoint detection and response for on-premises machines.
D.Secure score calculation based on implemented security controls.
E.Integrated vulnerability assessment for virtual machines.
AnswersA, B, D

The compliance dashboard in Microsoft Defender for Cloud provides a continuous view of your regulatory compliance posture, mapping security assessments to standards such as CIS Controls, NIST SP 800-53, and Azure CIS. It tracks compliance against these frameworks over time, shows which controls are failing, and lets you download evidence for audits. This is a core Cloud Security Posture Management (CSPM) capability, distinct from individual workload protections.

Why this answer

Microsoft Defender for Cloud's CSPM plan includes a compliance dashboard that continuously assesses your cloud resources against regulatory standards such as SOC 2, ISO 27001, and PCI DSS. This dashboard provides a real-time view of your compliance posture, mapping security controls to specific regulatory requirements and highlighting non-compliant resources.

Exam trap

The trap here is that candidates often confuse the CSPM plan's compliance and secure score capabilities with workload protection features like vulnerability assessment or EDR, which belong to separate Defender plans (e.g., Defender for Servers or Defender for Endpoint).

123
MCQmedium

Your organization has Microsoft Defender for Cloud Apps (MDA) connected to Microsoft Sentinel. The SOC team wants to receive alerts when a user accesses a sanctioned cloud app from an anonymous IP address. What should you configure?

A.Create a file policy in Defender for Cloud Apps.
B.Create an activity policy in Defender for Cloud Apps and connect it to Sentinel.
C.Enable the Defender for Cloud Apps connector in Sentinel without additional configuration.
D.Create a session policy in Defender for Cloud Apps.
AnswerB

Anonymised IP access is a user activity signal, not a Microsoft Sentinel analytics rule condition. Defender for Cloud Apps activity policies evaluate app sessions against risk factors such as anonymous proxy usage, then forward matching alerts into Microsoft Sentinel through the connected data connector, satisfying the SOC's alerting requirement.

Why this answer

An activity policy in Defender for Cloud Apps can be configured to trigger alerts on specific user activities, such as accessing a sanctioned app from an anonymous IP address. This policy can then be connected to Microsoft Sentinel via the Defender for Cloud Apps data connector, which ingests alerts as incidents for SOC review. File policies (A) focus on file-level actions like sharing or malware detection, not user access events, while session policies (D) control real-time access but do not generate alerts for historical or post-access monitoring.

Exam trap

The trap here is that candidates confuse file policies with activity policies, assuming any policy in Defender for Cloud Apps can detect access events, but only activity policies are designed to monitor user sign-in and access behaviors against IP-based conditions.

How to eliminate wrong answers

Option A is wrong because file policies monitor file-related activities (e.g., sharing, upload, download) and cannot detect user access events like logging into an app from an anonymous IP. Option C is wrong because simply enabling the Defender for Cloud Apps connector in Sentinel without additional configuration only ingests default alerts (e.g., from anomaly detection policies), not custom activity-based alerts for anonymous IP access. Option D is wrong because session policies are designed for real-time access control and monitoring during a user session (e.g., blocking downloads), not for generating alerts on access events that have already occurred.

124
MCQmedium

You are configuring automated responses in Microsoft Sentinel. You have created an automation rule that runs a playbook when an incident is created. The playbook performs actions in Microsoft Entra ID and Microsoft Defender for Cloud. However, the playbook fails with a permissions error. What should you do?

A.Assign the managed identity of the playbook the required roles in Microsoft Entra ID and Defender for Cloud.
B.Enable 'Allow playbooks to use managed identity' in the Sentinel settings.
C.Configure the Microsoft Entra ID connector in Sentinel with delegated permissions.
D.Grant the security analyst's account Contributor permissions on the automation rule.
AnswerA

The playbook runs under its own system-assigned managed identity in Microsoft Entra ID rather than under a user account. For automated responses to succeed, that identity must be explicitly assigned Azure RBAC roles—such as Security Reader or Security Admin on the relevant subscriptions/resource groups—and matching roles in Defender for Cloud. Without these assignments, the Logic App's API calls to fetch alerts or trigger actions are denied, causing the automation rule to fail.

Why this answer

The playbook fails with a permissions error because it uses a managed identity to authenticate to Microsoft Entra ID and Microsoft Defender for Cloud, but that identity has not been granted the necessary Azure RBAC roles (e.g., Security Reader, Security Admin) on the target resources. Assigning the required roles to the managed identity directly resolves the authorization failure.

Exam trap

The trap here is that candidates often confuse enabling the managed identity feature (Option B) with actually assigning the necessary RBAC roles to that identity, assuming the setting alone grants permissions.

How to eliminate wrong answers

Option B is wrong because 'Allow playbooks to use managed identity' is a setting that enables the use of managed identities for authentication, but it does not grant the actual permissions needed to perform actions in Entra ID or Defender for Cloud; permissions must be assigned separately via RBAC. Option C is wrong because configuring the Microsoft Entra ID connector with delegated permissions is used for user-based authentication (OAuth 2.0 authorization code flow), not for a playbook’s managed identity; the playbook uses a system-assigned or user-assigned managed identity, not delegated permissions. Option D is wrong because granting the security analyst's account Contributor permissions on the automation rule does not affect the permissions of the playbook’s managed identity; the playbook runs under its own identity, not the analyst’s account.

125
MCQeasy

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel during an investigation. The analyst expects to see alerts related to malware from IP 10.0.0.5 but receives no results. The SecurityAlert table contains data from the last 24 hours. What is the most likely reason for no results?

A.The ExtendedProperties column does not contain a key named 'IPAddress' for these alerts.
B.The 'contains' operator is case-sensitive.
C.The time filter 'ago(1d)' is too restrictive; should use 'ago(7d)'.
D.The 'project' statement drops the necessary columns.
AnswerA

The query filters on ExtendedProperties parsing a key named IPAddress. If the alerts store the address under a different key or format, the dynamic field access returns null and every row is filtered out, so no results appear despite matching data existing in the table.

Why this answer

The most likely reason for no results is that the ExtendedProperties column does not contain a key named 'IPAddress' for these alerts. In Microsoft Sentinel, the SecurityAlert table stores additional alert details in the ExtendedProperties column as a dynamic (JSON) field, and the specific key name varies by alert provider — if the key is not 'IPAddress', the query filter returns nothing.

Exam trap

SC-200 often tests the assumption that column names and JSON keys are consistent across all alert providers — candidates assume 'IPAddress' is a standard key in ExtendedProperties, when in reality the schema is provider-dependent and must be verified.

How to eliminate wrong answers

Option B is wrong because the 'contains' operator in KQL is case-insensitive by default (unlike 'has_cs' or 'contains_cs'), so case sensitivity would not cause zero results. Option C is wrong because the SecurityAlert table only contains data from the last 24 hours per the scenario, so extending the time filter to 7 days would not help — the data simply is not there. Option D is wrong because the 'project' statement only selects columns for output; it does not filter rows, so it cannot be the cause of zero results.

126
MCQmedium

You are a SOC analyst using Microsoft Defender XDR. An incident named "Multi-stage intrusion on FIN-PC01" contains alerts for a malicious PowerShell script, a suspicious outbound connection to a known C2 IP, and credential dumping activity. You need to perform an investigation that automatically shows the full attack story, including related entities, alerts, and timeline, without manually correlating each alert. What should you use?

A.The Microsoft Sentinel incident investigation graph
B.The incident's attack story timeline in the Microsoft Defender XDR portal
C.Automated investigation and response (AIR) investigation details page
D.Advanced hunting with a custom KQL query across DeviceProcessEvents and DeviceNetworkEvents
AnswerB

The attack story timeline automatically aggregates all alerts, entities, and events related to the incident into a single visual timeline. It shows the full chain of events, including process execution, network connections, and user actions, enabling rapid correlation without manual effort. This is the primary investigation view for incidents in Microsoft Defender XDR.

Why this answer

The attack story timeline in Microsoft Defender XDR is designed to automatically correlate all alerts, entities, and events from an incident into a single, interactive timeline. It eliminates manual correlation and provides a comprehensive view of the attack, which is exactly what the analyst needs to understand the full scope quickly.

Exam trap

The trap here is assuming that advanced hunting or Sentinel's investigation graph provides the same automated incident correlation as the Defender XDR attack story timeline.

127
Multi-Selectmedium

Which TWO actions are appropriate when handling a confirmed ransomware incident in Microsoft 365?

Select 2 answers
A.Run a full antivirus scan on all devices.
B.Restore encrypted files from backup immediately without investigation.
C.Pay the ransom to regain access.
D.Isolate affected devices from the network.
E.Change passwords for all potentially compromised accounts.
AnswersD, E

Isolating affected devices from the network is the correct containment measure because it immediately severs the ransomware's ability to propagate laterally via SMB, RDP, or other network protocols. This should be performed at the endpoint level (disconnecting the NIC or blocking in the switch/firewall) and ideally include domain controllers and backup servers to prevent mass encryption and credential theft. The goal is to preserve evidence and stop the incident from becoming a full-domain compromise while allowing responders to analyze the threat safely.

Why this answer

Option D is correct because isolating affected devices from the network is a standard containment step that prevents the ransomware from spreading laterally to other endpoints and limits further encryption or exfiltration within the Microsoft 365 environment. Option E is correct because changing passwords for all potentially compromised accounts revokes the attackers' access, invalidates stolen credentials, and is essential when identity compromise (e.g., via phishing or token theft) is a common ransomware entry vector in Microsoft 365. Option A is not appropriate as a primary incident response action because a full antivirus scan is a remediation/detection step that does not contain an active ransomware incident and may be ineffective against fileless or cloud-based attacks.

Option B is wrong because restoring from backup immediately without investigation can reintroduce the threat or restore already-compromised data, and the root cause must be identified first. Option C is wrong because paying the ransom is discouraged by Microsoft and law enforcement, does not guarantee data recovery, and may fund further criminal activity.

Exam trap

SC-200 often tests the misconception that immediate restoration or antivirus scanning is the first response to ransomware, when in fact containment and identity remediation are the priority.

128
Multi-Selectmedium

Which TWO actions should you take when responding to a confirmed ransomware incident in Microsoft Defender XDR?

Select 2 answers
A.Run a full antivirus scan
B.Reset the user's password
C.Restore files from backup
D.Disable the user account
E.Isolate the affected devices
AnswersA, E

Running a full antivirus scan is a critical eradication step that identifies and removes malware from the affected system, including worms, trojans, and ransomware. The scan should be performed after the device is isolated to prevent the infection from spreading while the scan is in progress. It also provides valuable indicators of compromise (IOCs) that can be used for further threat hunting and to ensure the system is clean before recovery.

Why this answer

Running a full antivirus scan (Option A) is a critical containment and remediation step in a confirmed ransomware incident because it detects and removes malicious files, including ransomware binaries and associated artifacts, from affected devices. In Microsoft Defender XDR, a full scan leverages the Microsoft Defender Antivirus engine to inspect all files and running processes, ensuring that the ransomware payload is eliminated from the system. This action helps prevent further encryption or lateral movement by the malware.

Exam trap

The trap here is that candidates often confuse recovery actions (like restoring from backup) with immediate containment actions, leading them to select Option C instead of recognizing that isolation and scanning are the correct first steps in the incident response playbook.

129
MCQmedium

Your security team uses Microsoft Defender for Cloud to assess the security posture of Azure resources. You need to ensure that all virtual machines have endpoint protection enabled. Which policy initiative should you assign?

A.Enable encryption on Azure VMs
B.Deploy Microsoft Defender for Endpoint
C.Deploy Windows Defender Exploit Guard
D.Azure Security Benchmark
AnswerB

Deploy Microsoft Defender for Endpoint is a built-in policy initiative in Microsoft Defender for Cloud that contains definitions such as 'Configure machines to automatically onboard to Microsoft Defender for Endpoint' and 'Endpoint protection solution should be installed on virtual machines.' This initiative actually installs and deploys the Defender for Endpoint agent to Azure VMs, enabling EDR, real-time antimalware protection, and vulnerability management. Because it directly fulfills the regulatory goal of deploying endpoint protection, it is the correct initiative to assign for this requirement.

Why this answer

The 'Deploy Microsoft Defender for Endpoint' policy initiative is specifically designed to ensure that all Azure VMs have endpoint protection enabled. This initiative deploys the Microsoft Defender for Endpoint agent to VMs that are missing it, directly addressing the requirement for endpoint protection. Other options focus on encryption, exploit guard configuration, or general security benchmarks, not the deployment of endpoint protection.

Exam trap

The trap here is that candidates often confuse 'deploying endpoint protection' with 'configuring security features' (like Exploit Guard) or 'applying broad benchmarks' (like Azure Security Benchmark), rather than recognizing that only the specific 'Deploy Microsoft Defender for Endpoint' initiative installs the endpoint protection agent.

How to eliminate wrong answers

Option A is wrong because 'Enable encryption on Azure VMs' addresses disk encryption (e.g., Azure Disk Encryption), not endpoint protection. Option C is wrong because 'Deploy Windows Defender Exploit Guard' configures attack surface reduction rules and exploit protection settings, but it does not deploy the endpoint protection agent itself. Option D is wrong because 'Azure Security Benchmark' is a broad set of security recommendations and compliance controls, not a policy initiative that deploys endpoint protection agents.

130
Multi-Selecthard

You are building a threat hunting query in Microsoft Sentinel to detect potential lateral movement via Windows Management Instrumentation (WMI). You want to identify processes that were created remotely using WMI, which often indicates an attacker moving laterally. Which two data sources or fields should you use in your query to detect this activity? (Choose two.)

Select 2 answers
A.DeviceEvents with ActionType == 'WmiProcessCreate'
B.DeviceProcessEvents with InitiatingProcessFileName == 'wmiprvse.exe'
C.DeviceRegistryEvents with RegistryKey contains 'WMI'
D.DeviceNetworkEvents with RemotePort == 135
E.DeviceLogonEvents with LogonType == 3
AnswersA, B

DeviceEvents includes various event types, and the ActionType 'WmiProcessCreate' specifically logs process creation via WMI. This is a direct signal of WMI-based process execution, which is exactly what you need to detect lateral movement. Querying DeviceEvents for this action type will surface relevant events without relying on parent process inference.

Why this answer

To detect WMI-based lateral movement, you need process creation events where the parent is wmiprvse.exe (indicating WMI spawned the process) or events explicitly logged as WmiProcessCreate. DeviceProcessEvents with InitiatingProcessFileName 'wmiprvse.exe' and DeviceEvents with ActionType 'WmiProcessCreate' both directly capture this behavior. Other sources like network events or logon events are too generic and do not confirm WMI process execution.

Exam trap

The trap here is assuming that network connections to port 135 or generic network logons are sufficient to detect WMI lateral movement, when only process-level events tied to WMI can confirm remote process creation.

131
MCQmedium

Your organization is using Microsoft Sentinel and you are responsible for managing the security operations environment. You need to ensure that a new security analyst can triage incidents but cannot modify analytics rules. Which role should you assign?

A.Microsoft Sentinel Responder
B.Microsoft Sentinel Reader
C.Microsoft Sentinel Contributor
D.Microsoft Sentinel Contributor with a custom role denying rule modification
AnswerA

Microsoft Sentinel Responder is the correct choice because it grants the ability to triage incidents directly—changing their status, assigning ownership, and adding comments—without any write permissions to analytics rules. This precisely matches the requirement to act on incidents while being prohibited from modifying detection rules. The Responder role is a built-in Azure RBAC role designed exactly for this job, providing least privilege and avoiding any unnecessary Sentinel management capabilities.

Why this answer

The Microsoft Sentinel Responder role provides the necessary permissions to triage incidents (view, investigate, respond) while explicitly excluding write access to analytics rules. This matches the requirement for a security analyst who needs to handle incidents but cannot modify detection logic.

Exam trap

The trap here is that candidates often confuse 'Responder' with 'Reader' or assume 'Contributor' is needed for any interactive work, but Microsoft specifically designed the Responder role for incident triage without rule modification permissions.

How to eliminate wrong answers

Option B (Microsoft Sentinel Reader) is wrong because it only allows read access to all Sentinel data, including incidents, but does not permit any response actions like changing incident status or assigning ownership. Option C (Microsoft Sentinel Contributor) is wrong because it grants full write access to all Sentinel resources, including the ability to create, modify, or delete analytics rules, which exceeds the required permissions. Option D (Microsoft Sentinel Contributor with a custom role denying rule modification) is wrong because it is unnecessarily complex and not a built-in role; the Responder role already provides the exact permissions needed without custom role creation.

132
MCQeasy

Your team uses Microsoft Sentinel to monitor multiple Azure subscriptions. You need to grant a junior analyst the ability to view incidents and run playbooks, but not modify analytics rules or data connectors. Which built-in role should you assign?

A.Microsoft Sentinel Contributor
B.Automation Contributor
C.Microsoft Sentinel Reader
D.Microsoft Sentinel Responder
AnswerD

Microsoft Sentinel Responder is the built-in incident-response role that can view, triage, and manage incidents while also being able to execute playbooks directly from those incidents. Its permission set includes Microsoft.SecurityInsights/incidents/read, /write, and /playbooks/execute, allowing a responder to run the playbook and update the incident without granting broader SIEM configuration rights like altering analytics rules or connectors. This role is the correct least-privilege assignment because it specifically enables the requested playbook execution while still maintaining separation of duties from administrative Sentinel tasks.

Why this answer

Microsoft Sentinel Responder is the correct built-in role because it grants the junior analyst the ability to view incidents and run playbooks, while explicitly preventing modifications to analytics rules or data connectors. This role provides the exact permissions needed for incident response tasks without allowing changes to the security configuration.

Exam trap

The trap here is that candidates often confuse 'Responder' with 'Reader' or 'Contributor', assuming that running playbooks requires Contributor-level access, when in fact the Responder role is specifically designed for incident response actions without broader management rights.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel Contributor has full write access to Sentinel resources, including the ability to modify analytics rules and data connectors, which exceeds the required permissions. Option B is wrong because Automation Contributor only allows management of Azure Automation resources (like runbooks and jobs) but does not grant any permissions to view or manage Sentinel incidents. Option C is wrong because Microsoft Sentinel Reader is read-only and cannot run playbooks, which requires the 'Microsoft.SecurityInsights/incidents/runPlaybook/action' permission.

133
Multi-Selecteasy

Which TWO are supported data sources for Microsoft Sentinel?

Select 2 answers
A.Google Cloud VPC Flow Logs
B.Windows Server 2008 event logs
C.Microsoft Entra ID audit logs
D.AWS CloudTrail
E.On-premises syslog-ng
AnswersC, D

Microsoft Entra ID audit logs are a correct, natively supported data source for Microsoft Sentinel. Sentinel's Microsoft Entra ID connector (formerly Azure AD) ingests sign-in logs, audit logs, and provisioning logs into the workspace for identity-based detection and investigation. This connector is first-party and uses the Microsoft Graph API or diagnostic settings, making it a standard supported source.

Why this answer

Microsoft Entra ID audit logs (Option C) are a native data source for Microsoft Sentinel because Sentinel is built on Azure Monitor Logs and directly ingests Entra ID (formerly Azure AD) diagnostic settings via the Azure portal or API. This integration requires no additional connectors or agents, as Entra ID audit logs are automatically forwarded to a Log Analytics workspace when configured under 'Diagnostic settings' in the Entra ID blade.

Exam trap

The trap here is that candidates often assume any syslog source (like syslog-ng) is directly supported, but Microsoft Sentinel only supports syslog via the Linux agent or AMA, not the syslog-ng daemon itself as a distinct data source.

134
MCQmedium

Your organization uses Microsoft Sentinel and has enabled UEBA. You notice that many low-severity incidents are being created from high-volume informational alerts. You want to reduce noise without disabling data connectors. What should you do?

A.Create an automation rule that closes low-severity incidents immediately.
B.Increase the incident creation threshold in the analytics rule.
C.Modify the analytics rule query to exclude the high-volume informational events using KQL.
D.Disable the Microsoft 365 Defender connector for those data sources.
AnswerC

Modify the KQL query behind the analytics rule to exclude the high-volume informational events, e.g., by filtering out event IDs, specific log sources, or task categories with a `where` clause. This stops those events from ever being selected for alert generation, reducing incident noise and storage/ingestion costs at the source. It preserves detection coverage for all other event types and is the recommended approach for tuning noisy analytics rules.

Why this answer

Modifying the analytics rule query to exclude high-volume informational events using KQL directly addresses the root cause: the rule is generating low-severity incidents from noisy informational data. This approach preserves the data connectors and UEBA functionality while filtering out the specific events that cause alert fatigue. Unlike automation rules that close incidents after creation, query modification prevents the incidents from being generated in the first place.

Exam trap

The trap here is that candidates often choose automation rules (Option A) because they seem like a quick fix to close incidents, but they fail to realize that the incidents are still created and consume resources, whereas modifying the query prevents generation entirely.

How to eliminate wrong answers

Option A is wrong because closing incidents immediately with an automation rule still generates the incident, consuming storage and processing resources, and does not address the underlying issue of noisy analytics rules; it also bypasses proper triage. Option B is wrong because increasing the incident creation threshold in the analytics rule would suppress all low-severity incidents, potentially missing legitimate threats that match the same severity level, and it does not differentiate between high-volume informational events and other low-severity events. Option D is wrong because disabling the Microsoft 365 Defender connector would stop all data ingestion from that source, including critical security signals, and is an overly aggressive measure that violates the requirement to not disable data connectors.

135
MCQmedium

An organization uses Microsoft Defender for Cloud and has enabled enhanced security features. They want to receive alerts when a user attempts to connect to an Azure VM via RDP from a public IP address that is not in a predefined list of trusted IP ranges. Which Defender for Cloud plan or feature provides this capability?

A.Adaptive network hardening
B.Network security groups (NSG) flow logs
C.Just-In-Time (JIT) VM access
D.File Integrity Monitoring (FIM)
AnswerC

Just-In-Time (JIT) VM access is correct because it directly addresses the requirement to alert on unauthorized connection attempts. JIT locks down management ports (such as RDP and SSH) by creating NSG rules that deny all traffic except from approved source IPs and for a limited time window. When an unapproved IP attempts to establish a connection to a protected port, Microsoft Defender for Cloud immediately raises a security alert, satisfying the organization's requirement.

Why this answer

Just-In-Time (JIT) VM access in Microsoft Defender for Cloud allows you to lock down inbound traffic to Azure VMs, reducing exposure to attacks while providing easy access when needed. When enabled, JIT creates rules in the network security group (NSG) that permit RDP (TCP 3389) or SSH (TCP 22) traffic only from specific IP addresses or ranges that you define, and only during a requested time window. If a user attempts an RDP connection from a public IP not in the trusted list, Defender for Cloud generates an alert, as the traffic is blocked by the JIT policy.

Exam trap

The trap here is that candidates often confuse Adaptive network hardening (which also adjusts NSG rules) with JIT VM access, but Adaptive network hardening does not enforce a predefined trusted IP list or generate alerts for unauthorized RDP attempts—it only recommends rule changes based on traffic patterns.

How to eliminate wrong answers

Option A is wrong because Adaptive network hardening is a feature that dynamically adjusts NSG rules based on observed traffic patterns to reduce the attack surface, but it does not provide the ability to define a trusted IP list for RDP access or generate alerts for unauthorized connection attempts from specific IPs. Option B is wrong because NSG flow logs capture information about IP traffic flowing through an NSG for network monitoring and analysis, but they do not enforce access control or generate real-time alerts for RDP connection attempts from untrusted IPs. Option D is wrong because File Integrity Monitoring (FIM) monitors changes to critical files, registries, and software on VMs, not network-level access attempts like RDP connections from public IPs.

136
Drag & Dropmedium

Arrange the steps to enable and configure Microsoft Defender for Identity (MDI) sensor on a domain controller.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

MDI sensors are installed on domain controllers to capture and analyze authentication events.

137
MCQeasy

A security administrator wants to view the overall security posture of all Azure subscriptions in a single numerical score. Which dashboard in Microsoft Defender for Cloud provides this score based on implemented security controls?

A.Regulatory compliance dashboard
B.Secure Score dashboard
C.Inventory dashboard
D.Recommendations dashboard
AnswerB

Secure Score is the primary dashboard for viewing overall security posture across all Azure subscriptions, presenting a single numerical score from 0 to 100. Each recommendation in Defender for Cloud contributes a potential score increase, and the current score reflects the percentage of those security controls you have remediated. The score aggregates data from all subscriptions in the selected scope, making it the intended tool for a unified posture assessment.

Why this answer

The Secure Score dashboard in Microsoft Defender for Cloud aggregates the security posture across all Azure subscriptions into a single numerical score. This score is calculated based on the implementation of security controls and recommendations, providing a quantifiable measure of your overall security hygiene.

Exam trap

The trap here is that candidates often confuse the Secure Score dashboard with the Recommendations dashboard, thinking that viewing individual recommendations provides the same aggregated score, but the Secure Score dashboard is the only place where the single numerical score is displayed.

How to eliminate wrong answers

Option A is wrong because the Regulatory compliance dashboard shows compliance with specific standards (e.g., ISO 27001, NIST) but does not produce a single numerical score for overall security posture. Option C is wrong because the Inventory dashboard lists all monitored resources and their security configurations, but it does not aggregate them into a single score. Option D is wrong because the Recommendations dashboard lists individual security recommendations and their status, but it does not calculate or display a unified numerical score.

138
Multi-Selectmedium

Your Microsoft Sentinel workspace ingests logs from Microsoft Defender for Cloud and Microsoft 365 Defender. You need to create an incident response playbook that automatically responds to high-severity incidents. Which THREE components are required? (Choose three.)

Select 3 answers
A.A workbook to visualize the incident data
B.An analytics rule that generates the incident
C.An automation rule in Microsoft Sentinel
D.A hunting query to search for similar activity
E.A Logic Apps workflow with Microsoft Sentinel trigger
AnswersB, C, E

An analytics rule is the foundational component that uses a KQL query to detect a specific security pattern and, when matched, creates an incident in Microsoft Sentinel. Because automated responses (such as playbooks or automation rules) only operate on incidents, an analytics rule is strictly required to generate the incident in the first place. Without this rule, there is no incident object to act upon, regardless of any downstream automation.

Why this answer

Option B is required because an analytics rule is what detects the activity and generates the incident in Microsoft Sentinel; without an incident, there is nothing for the playbook to respond to. Option C is required because an automation rule in Microsoft Sentinel is the mechanism that triggers a playbook automatically when an incident is created, matching conditions such as high severity. Option E is required because the playbook itself is implemented as an Azure Logic Apps workflow that uses the Microsoft Sentinel incident trigger to run the response actions.

Option A is not required because a workbook is only a visualization/reporting tool and plays no role in automated incident response. Option D is not required because a hunting query is used for proactive threat hunting, not for automatically triggering a playbook.

Exam trap

SC-200 often tests whether candidates confuse visualization (workbooks) and hunting (queries) with the actual automation chain — analytics rule, automation rule, and Logic Apps playbook — that is required for automated response.

139
MCQmedium

A security analyst receives a high-severity alert for a suspicious login from an unusual location. The alert was generated by Microsoft Sentinel from Microsoft Entra ID sign-in logs. The analyst needs to determine if the login was successful and if any data exfiltration occurred. What is the MOST efficient first step?

A.Run a KQL query in Microsoft Sentinel to review the SigninLogs table for the user within the alert time range.
B.Use Microsoft Defender XDR to check the user's device timeline for suspicious activity.
C.Run a KQL query in Microsoft Sentinel to check Microsoft Defender for Cloud Apps alerts for the user.
D.Check the firewall logs in Azure Firewall for outbound connections from the user's IP.
AnswerA

The SigninLogs table in Microsoft Sentinel stores authentication events from Microsoft Entra ID, including interactive and non-interactive sign-ins. Querying this table within the alert time range for the affected user reveals the login success/failure status, source IP, location, MFA result, and conditional access policies applied. This is the authoritative source for validating whether the suspicious sign-in succeeded and assessing the blast radius.

Why this answer

The most efficient first step is to run a KQL query in Microsoft Sentinel against the SigninLogs table for the specific user within the alert time range. This directly confirms whether the suspicious login was successful by checking the 'ResultType' and 'ResultDescription' fields, which is the fastest way to validate the alert's core claim before investigating data exfiltration.

Exam trap

The trap here is that candidates often jump to investigating data exfiltration (e.g., checking firewall logs or Defender for Cloud Apps) without first confirming the login was successful, which wastes time and resources if the login actually failed.

How to eliminate wrong answers

Option B is wrong because checking the user's device timeline in Microsoft Defender XDR is a secondary step that assumes the login was successful and the device was involved, but it does not first confirm the login status. Option C is wrong because querying Microsoft Defender for Cloud Apps alerts for the user is premature; those alerts would only be generated after the login is successful and suspicious activity is detected, so it is not the most efficient first step. Option D is wrong because checking Azure Firewall logs for outbound connections from the user's IP is a deep investigation step for data exfiltration that should only be performed after confirming the login was successful, making it inefficient as a first step.

140
MCQhard

An analyst is investigating a data exfiltration incident. They suspect that a user downloaded sensitive files from a SharePoint site and then uploaded them to a non-corporate cloud storage service (e.g., Dropbox) using the same device. Which combination of Advanced Hunting tables should the analyst query to correlate the SharePoint download activity with network connections to external IPs?

A.CloudAppEvents and DeviceNetworkEvents
B.EmailEvents and DeviceNetworkEvents
C.DeviceFileEvents and DeviceNetworkEvents
D.CloudAppEvents and IdentityLogonEvents
AnswerA

CloudAppEvents is the authoritative cloud-side audit source for SharePoint and OneDrive activity, recording file download events with user, file, and timestamp; DeviceNetworkEvents supplies endpoint-level outbound connection details such as destination IP, port, and protocol. Joining these two tables on the device ID and a narrow time window lets the analyst correlate the SharePoint fetch to the subsequent network egress, proving both the data source and the exfiltration path.

Why this answer

CloudAppEvents logs user activities in cloud apps like SharePoint, including file downloads. DeviceNetworkEvents logs network connections from devices, including connections to external IPs. Combining these tables allows the analyst to correlate the SharePoint download event (from CloudAppEvents) with subsequent network connections to non-corporate cloud storage IPs (from DeviceNetworkEvents) on the same device, directly mapping the exfiltration path.

Exam trap

The trap here is that candidates often pick DeviceFileEvents (Option C) thinking it logs the SharePoint download locally, but SharePoint downloads are cloud events logged in CloudAppEvents, not local file events.

How to eliminate wrong answers

Option B is wrong because EmailEvents logs email-related activities (send, receive, phishing), not SharePoint file downloads or network connections to external IPs, so it cannot correlate the download with network activity. Option C is wrong because DeviceFileEvents logs local file operations (create, modify, delete) on the device, but SharePoint downloads are cloud-side events not captured locally unless the file is saved to disk; it does not log the cloud download action itself. Option D is wrong because IdentityLogonEvents logs authentication events (logons, logoffs), not SharePoint file activities or network connections, so it cannot correlate the download with external IP connections.

141
MCQhard

During a security incident, you need to isolate a compromised Windows device from the network while allowing communication with Microsoft Defender for Endpoint services. Which Microsoft Defender for Endpoint action should you use?

A.Run antivirus scan
B.Isolate device
C.Collect investigation package
D.Restrict app execution
AnswerB

Device isolation in Defender for Endpoint places the machine in a state where all inbound and outbound network traffic is blocked, except for traffic to the Defender for Endpoint cloud service. This preserves the management channel, allowing security operations to issue further commands, receive telemetry, and complete remediation while the host is quarantined from the network. It directly prevents the attacker from continuing their C2 and lateral movement, making it the correct containment action.

Why this answer

The correct action is 'Isolate device' because it disconnects the compromised Windows device from the network while maintaining a dedicated communication channel to Microsoft Defender for Endpoint (MDE) services. This ensures the device cannot be used to spread laterally or exfiltrate data, yet MDE can still receive telemetry and apply remediation commands. The isolation is enforced via a Windows Filtering Platform (WFP) firewall rule that blocks all inbound and outbound traffic except for MDE-related endpoints (e.g., *.events.data.microsoft.com).

Exam trap

The trap here is that candidates confuse 'Restrict app execution' with network isolation, not realizing that restricting apps only controls what software can run locally, not the device's ability to communicate over the network.

How to eliminate wrong answers

Option A is wrong because 'Run antivirus scan' only performs a local malware scan and does not alter network connectivity, leaving the device able to communicate with other network hosts and potentially spread the threat. Option C is wrong because 'Collect investigation package' gathers forensic data (e.g., registry, memory, event logs) for analysis but does not isolate the device from the network, so lateral movement remains possible. Option D is wrong because 'Restrict app execution' uses Windows Defender Application Control (WDAC) to block untrusted software from running, but it does not block network traffic, so the device can still communicate with other systems and MDE services are not specifically preserved.

142
MCQeasy

An organization uses Microsoft 365 Defender. A security analyst is investigating a malware incident on a user's device. The automated investigation and response (AIR) has already isolated the device from the network. The analyst now needs to collect a copy of a specific suspicious file from the device for further analysis. Which action should the analyst initiate from the device's entity page?

A.Collect investigation package
B.Run antivirus scan
C.Restrict app execution
D.Initiate a live response session
AnswerA

The collect investigation package action builds a comprehensive forensic archive from the device, gathering the specific file along with associated processes, registry keys, and memory artifacts into a single downloadable bundle for offline analysis. This is the appropriate choice when the goal is to retrieve and preserve a suspicious file for deep inspection without requiring an interactive session, aligning with the analyst's need to collect and examine the file.

Why this answer

The 'Collect investigation package' action on the device entity page in Microsoft 365 Defender gathers a ZIP file containing the device's forensic data, including specific suspicious files, registry keys, and memory dumps. This is the designed method for retrieving a copy of a file for offline analysis without requiring interactive access, and it works even after AIR has isolated the device.

Exam trap

The trap here is that candidates often confuse 'Initiate a live response session' as the go-to for file collection, but fail to remember that live response requires an active network connection to the device, which is blocked when AIR has isolated the device from the network.

How to eliminate wrong answers

Option B is wrong because 'Run antivirus scan' only triggers a Microsoft Defender Antivirus scan on the device; it does not collect a copy of a specific file for export. Option C is wrong because 'Restrict app execution' applies a Windows Defender Application Control policy to block untrusted apps, which is a containment action, not a file collection method. Option D is wrong because 'Initiate a live response session' provides real-time remote shell access to the device, but it is not available when the device is isolated by AIR (isolation blocks all incoming connections, including live response), and the question specifically asks for an action from the entity page that works under isolation.

143
MCQmedium

Your organization uses Microsoft Defender for Identity. The security team wants to monitor for suspected DCSync attacks. Which Windows Event ID should you monitor to detect DCSync activity?

A.Event ID 4776: The domain controller attempted to validate the credentials for an account.
B.Event ID 4662: An operation was performed on an object.
C.Event ID 4648: A logon was attempted using explicit credentials.
D.Event ID 4624: An account was successfully logged on.
AnswerB

Event ID 4662 logs when an operation is performed on an Active Directory object, including directory replication operations. In the context of DCSync, you would look for 4662 events where the operation includes control access rights like DS-Replication-Get-Changes or DS-Replication-Get-Changes-All. These rights are required to perform replication and, when requested from a non-domain-controller source, are a strong indicator of a DCSync attempt. This makes 4662 the correct event to monitor for this attack.

Why this answer

Event ID 4662 logs any operation performed on an Active Directory object, including the directory service access control entry for the DS-Replication-Get-Changes-All extended right (control access right 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2). A DCSync attack uses this right to replicate domain credentials from a domain controller, so monitoring 4662 with the specific object type and access mask for replication is the correct detection method.

Exam trap

The trap here is that candidates confuse authentication events (4776, 4624) or credential use events (4648) with the directory replication operation that DCSync actually performs, leading them to choose a logon-related event ID instead of the object access event that captures the replication request.

How to eliminate wrong answers

Option A is wrong because Event ID 4776 logs credential validation attempts by the domain controller, which is a normal authentication event and does not indicate the replication of directory data required for DCSync. Option C is wrong because Event ID 4648 logs logons using explicit credentials (e.g., RunAs), which is unrelated to the directory replication process that DCSync exploits. Option D is wrong because Event ID 4624 logs successful logon events, which are too generic and do not capture the specific directory service access or replication operations that characterize a DCSync attack.

144
Multi-Selecthard

A SOC analyst needs to create a custom watchlist in Microsoft Sentinel to use in an analytics rule. Order the following steps from first to last to correctly create and use the watchlist (Choose 4.)

Select 4 answers
A.1. Create a new watchlist in Microsoft Sentinel (e.g., from Sentinel > Watchlists > Add new).
B.2. Import a CSV file containing the data (e.g., IP addresses or domains) into the watchlist.
C.3. Write the KQL query for the analytics rule that uses the `_GetWatchlist('WatchlistAlias')` function to reference the watchlist.
D.4. Create a scheduled analytics rule, paste the KQL query, and configure the alert details (e.g., severity, entity mapping).
AnswersA, B, C, D

Creating the watchlist in Microsoft Sentinel is the foundational and correct first action because it defines the watchlist's metadata, including a unique alias, name, and optional description, as well as the schema for the data that will be imported. Without this explicit creation step, there is no object for the CSV data to bind to, and the alias cannot be referenced in any later KQL query. In the Sentinel blade, 'Add new' initializes the watchlist resource, and the alias set here is precisely what the _GetWatchlist() function will expect in detection rules.

Why this answer

Creating a new watchlist in Microsoft Sentinel is the initial step to define a custom data source for threat intelligence or reference data. This is done via Sentinel > Watchlists > Add new, where you specify the alias, description, and other metadata before uploading data. Without this step, there is no container to import the CSV file into, making it the logical first action.

Exam trap

The trap here is that candidates might think the KQL query must be written before importing the CSV, but the watchlist alias must already exist in Sentinel for the _GetWatchlist function to reference it correctly, making the import step second.

How to eliminate wrong answers

All options A, B, C, and D are correct steps in the correct order, so there are no wrong options to eliminate. The question asks to order the steps from first to last, and the provided sequence (A → B → C → D) is accurate: create the watchlist, import the CSV, write the KQL query using _GetWatchlist, then create the scheduled analytics rule with that query.

145
MCQmedium

Your SOC team uses Microsoft Defender XDR. You want to ensure that all incidents are automatically classified and determined by the built-in AI before any manual review. What should you configure?

A.Create a custom detection rule in Microsoft Defender XDR.
B.Enable the incident summarization and classification feature in Microsoft Defender XDR.
C.Enable automation rules in Microsoft Sentinel to classify incidents.
D.Configure a workbook in Microsoft Sentinel to analyze incidents.
AnswerB

The incident summarization and classification feature in Microsoft Defender XDR is a built-in AI capability that automatically analyzes the alert and incident evidence, generates a natural-language summary, and assigns a classification (e.g., true positive, false positive, informational) and determination to each incident. Enabling this feature meets the stated objective because it activates the platform's native machine learning reasoning to pre-classify incidents before human review, significantly reducing analyst workload.

Why this answer

Microsoft Defender XDR includes a built-in AI-driven incident summarization and classification feature that automatically assigns a classification (e.g., true positive, false positive) and determination (e.g., malicious, clean) to each incident before manual review. This feature leverages machine learning models trained on Microsoft's global threat intelligence to reduce alert fatigue and streamline SOC workflows.

Exam trap

The trap here is that candidates may confuse the AI-driven incident classification in Defender XDR with automation rules in Microsoft Sentinel, which are for response actions, not for the built-in AI classification and determination of incidents.

How to eliminate wrong answers

Option A is wrong because custom detection rules in Microsoft Defender XDR are used to create custom alerts based on specific query logic, not to automatically classify or determine incidents via AI. Option C is wrong because automation rules in Microsoft Sentinel are designed for automated incident response and orchestration (e.g., assigning ownership, changing status), not for the built-in AI classification and determination of incidents within Defender XDR. Option D is wrong because workbooks in Microsoft Sentinel are visualization tools for analyzing data and metrics, not a configuration that enables automatic AI-driven incident classification.

146
MCQeasy

You are configuring a Microsoft Sentinel analytics rule to detect failed logons from multiple IP addresses. The rule should trigger an incident only when the same user account has failed logons from more than three distinct IP addresses within 5 minutes. Which rule setting should you configure?

A.Set the 'Alert threshold' to 'Custom' and define a condition on distinct IP count.
B.Set the 'Group by' field to 'Account' and 'IP address'.
C.Set the 'Event grouping' to 'Group all events into a single alert'.
D.Set the 'Suppression' to '5 minutes' after an alert is generated.
AnswerA

Setting the Alert threshold to Custom lets you specify an aggregation condition on the query results, such as dcount(IP_Address) greater than a numeric value. This matches the required detection of a single account being accessed from many distinct IPs, which indicates distributed brute-force activity. The rule will fire only when the distinct IP count crosses the defined threshold.

Why this answer

The requirement is to trigger an incident only when the same user account has failed logons from more than three distinct IP addresses within 5 minutes. In Microsoft Sentinel analytics rules, the 'Alert threshold' set to 'Custom' allows you to define a condition on the count of distinct values (e.g., distinct IP addresses) aggregated over the rule's query window, which directly matches the scenario.

Exam trap

The trap here is that candidates often confuse 'Group by' (which splits alerts by field values) with the ability to count distinct values across those groups, leading them to select Option B instead of recognizing that a custom threshold on distinct count is required.

How to eliminate wrong answers

Option B is wrong because setting 'Group by' to 'Account' and 'IP address' would create separate alerts for each combination of account and IP address, not aggregate distinct IPs per account. Option C is wrong because 'Group all events into a single alert' would combine all failed logon events into one alert regardless of distinct IP count, failing to enforce the 'more than three distinct IPs' threshold. Option D is wrong because 'Suppression' pauses alert generation after an alert fires, but does not control the condition for triggering the alert based on distinct IP count within a time window.

147
MCQhard

Your organization uses Microsoft Sentinel and has multiple workspaces for different regions. The security team wants to use a single workbook to display data from all workspaces. What is the correct approach?

A.Create a workbook with cross-workspace queries using the workspace() expression
B.Export data from all workspaces to a single Azure Data Lake
C.Create a workbook in one workspace and configure it to use Azure Lighthouse
D.Create a workbook in each workspace and merge them manually
AnswerA

The workspace() expression lets a single workbook query tables in other Microsoft Sentinel workspaces, satisfying the requirement to display data from all regional workspaces in one view. It bypasses the default single-workspace scope without duplicating workbooks or exporting data.

Why this answer

Microsoft Sentinel workbooks support cross-workspace queries using the `workspace()` expression in Kusto Query Language (KQL). This allows a single workbook to aggregate and display data from multiple Sentinel workspaces without moving or duplicating the data, meeting the security team's requirement efficiently.

Exam trap

The trap here is that candidates may confuse Azure Lighthouse (which is for cross-tenant management) with cross-workspace querying, or assume that data must be centralized (e.g., via Data Lake) before it can be visualized in a single workbook.

How to eliminate wrong answers

Option B is wrong because exporting data to Azure Data Lake requires additional services (e.g., Azure Data Factory or Event Hubs) and does not provide a native way to query the data in a Sentinel workbook; it also incurs extra cost and latency. Option C is wrong because Azure Lighthouse enables cross-tenant management but does not allow a single workbook to query multiple workspaces within the same tenant; workbooks still need explicit cross-workspace queries. Option D is wrong because creating separate workbooks in each workspace and manually merging them is not a scalable or automated solution, and it defeats the purpose of a single unified view.

148
MCQhard

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector. During a hunt, you notice that some alerts from Microsoft Defender for Identity are not appearing in Sentinel. You have verified the connector is enabled and data is flowing for other Defender products. What is the most likely cause?

A.The Microsoft Sentinel pricing tier is set to Free, which limits data ingestion.
B.The 'IdentityLogonEvents' data type is disabled in the Microsoft Sentinel connector configuration.
C.The Microsoft Sentinel workspace is in a different region than Microsoft Defender for Identity.
D.Your tenant does not have the required Microsoft Entra ID P2 license for Microsoft Defender for Identity alerts.
AnswerD

Microsoft Defender for Identity alerts only flow to Microsoft Sentinel when the tenant has the appropriate license, such as Microsoft Entra ID P2 (or a Microsoft 365 E5 license) that includes the MDI service plan. Without this license, the connector may show a healthy status but will not forward MDI alerts to the SecurityAlert table. This is a well-known licensing prerequisite and the most likely reason for the symptom.

Why this answer

Microsoft Defender for Identity alerts require a premium Azure AD P2 license to be ingested via the connector. Option A is wrong because the connector is enabled. Option B is wrong because data ingestion is working for other products.

Option C is wrong because the data types are not disabled.

149
MCQeasy

You are setting up Microsoft Sentinel for the first time. You need to ingest Windows security events from on-premises servers using the Azure Monitor Agent. Which data connector should you enable in Microsoft Sentinel?

A.Common Event Format (CEF) via AMA
B.Windows Security Events via AMA
C.Syslog via AMA
D.DNS via AMA
AnswerB

Windows Security Events via AMA is the correct connector because it uses the Azure Monitor Agent to collect security-relevant events directly from the Windows Event Log (Security, System, Application). This connector gives you the audit trail needed for detection rules, UEBA, and incident investigation—covering events like 4624 logon successes, 4625 failures, and 4688 process creation. As AMA is the supported replacement for the legacy Log Analytics agent, this is the standard, first-party choice for Windows security telemetry in Sentinel.

Why this answer

The Windows Security Events via AMA data connector is specifically designed to collect Windows security events (e.g., Event ID 4625, 4688) from on-premises servers using the Azure Monitor Agent (AMA). This connector leverages the AMA's Data Collection Rules (DCRs) to filter and ingest security-relevant logs directly into Microsoft Sentinel, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse 'Syslog via AMA' with Windows event collection, but Syslog is a Linux-centric protocol (UDP/TCP 514) and cannot natively read Windows Event Log files.

How to eliminate wrong answers

Option A is wrong because Common Event Format (CEF) via AMA is used for ingesting logs from security appliances (e.g., firewalls, IDS/IPS) that output CEF-formatted syslog messages, not native Windows security events. Option C is wrong because Syslog via AMA is designed for Linux-based syslog data (RFC 3164/5424) and does not natively collect Windows Event Log data. Option D is wrong because DNS via AMA is a specialized connector for collecting DNS query/response logs from Windows DNS servers, not general Windows security events.

150
MCQeasy

Your organization uses Microsoft Defender XDR. You need to ensure that all cloud app alerts are forwarded to Microsoft Sentinel for correlation. What should you configure?

A.Create an analytics rule in Sentinel that queries Defender for Cloud Apps API.
B.Configure Microsoft Defender for Cloud Apps to export alerts to Azure Event Hubs.
C.In Microsoft Sentinel, enable the data connector for Microsoft Defender for Cloud Apps.
D.In Microsoft Sentinel, enable the data connector for Microsoft Defender for Endpoint.
AnswerC

Enabling the Defender for Cloud Apps data connector in Microsoft Sentinel establishes a native, one-click ingestion pipeline that automatically imports alerts and incidents from the cloud app security service into Log Analytics. This connector uses Microsoft Graph Security API to synchronize alert data, allowing security analysts to investigate cloud application threats alongside other signals in Sentinel. Once enabled, alerts become available in the SecurityAlert table, and you can then build analytics rules or workbooks on top of them.

Why this answer

The Microsoft Defender for Cloud Apps data connector in Microsoft Sentinel is specifically designed to ingest alerts and cloud discovery logs from Defender for Cloud Apps. Enabling this connector ensures that all cloud app alerts are automatically forwarded to Sentinel for correlation without requiring custom API queries or external export pipelines.

Exam trap

The trap here is that candidates may confuse the purpose of data connectors for different Microsoft Defender products, mistakenly selecting the Defender for Endpoint connector when the question specifically targets cloud app alerts.

How to eliminate wrong answers

Option A is wrong because creating an analytics rule that queries the Defender for Cloud Apps API would require custom logic and does not provide automated, continuous ingestion of alerts; analytics rules are for detection, not data ingestion. Option B is wrong because exporting alerts to Azure Event Hubs is an alternative method for custom integration, but it is not the standard or recommended configuration for forwarding all cloud app alerts to Sentinel; the built-in data connector is simpler and directly supported. Option D is wrong because the Microsoft Defender for Endpoint data connector ingests endpoint detection and response alerts, not cloud app alerts; it addresses a different security domain.

Page 1

Page 2 of 18

Page 3