Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 151–225

1303 questions total · 18pages · All types, answers revealed

Page 2

Page 3 of 18

Page 4
151
MCQmedium

An organization uses Microsoft Defender for Office 365. The security team wants to automatically remove from all user mailboxes any messages that were already delivered but are later identified as malicious. Which feature should they enable?

A.Automated investigation and response (AIR)
B.Zero-hour auto purge (ZAP)
C.Safe Attachments
D.Safe Links
AnswerB

Zero-hour auto purge (ZAP) is a Defender for Office 365 feature that retroactively identifies and acts on messages already delivered to a user's mailbox when they are later found to be phishing, malware, or spam. It automatically moves those messages to quarantine or the junk email folder, or deletes them, depending on the configured policy, effectively closing the gap when detection occurs post-delivery.

Why this answer

Zero-hour auto purge (ZAP) is the correct feature because it automatically detects and removes malicious messages that have already been delivered to user mailboxes, including messages retroactively identified as threats after delivery. ZAP acts on phishing, malware, and spam verdicts by querying the mailbox for the original message and moving it to the Junk Email folder or deleting it, based on the configured policy. This directly meets the requirement to remove already-delivered malicious messages without manual intervention.

Exam trap

The trap here is that candidates confuse ZAP with Safe Attachments or Safe Links, mistakenly thinking those features can retroactively remove delivered messages, when in fact they only protect at the time of delivery or click, respectively.

How to eliminate wrong answers

Option A is wrong because Automated investigation and response (AIR) is a broader incident response capability that orchestrates playbooks across multiple workloads, but it does not automatically remove already-delivered messages from mailboxes; it focuses on investigating and remediating threats at the mailbox or device level after an alert is triggered. Option C is wrong because Safe Attachments is a time-of-delivery protection feature that detonates email attachments in a sandbox before delivery, but it does not retroactively remove messages that were already delivered and later found malicious. Option D is wrong because Safe Links is a time-of-click protection feature that scans URLs in messages and Office documents at the moment a user clicks, but it does not remove already-delivered messages from mailboxes.

152
Multi-Selectmedium

Which TWO actions are valid ways to integrate on-premises firewall logs into Microsoft Sentinel for analysis?

Select 2 answers
A.Enable the Office 365 connector.
B.Configure the firewall to send Common Event Format (CEF) logs to a syslog server running Azure Monitor Agent.
C.Install the Windows DNS Server connector.
D.Connect the Azure Activity log connector.
E.Use the Microsoft Sentinel Data Collector API to send custom logs.
AnswersB, E

This is a standard, supported integration path for firewall appliances that emit Common Event Format (CEF) messages over syslog. The firewall sends CEF to a log collector/forwarder that has the Azure Monitor Agent installed; AMA forwards the events to a Log Analytics workspace using a data collection rule, populating the CommonSecurityLog table in Microsoft Sentinel. This method preserves normalized fields such as source/destination IP, port, and action, making it directly usable by analytics rules.

Why this answer

On-premises firewall logs can be forwarded in Common Event Format (CEF) over syslog to a server running the Azure Monitor Agent (AMA), which then ingests them into Microsoft Sentinel. CEF is a standard log format supported by many security appliances, and the AMA replaces the older Log Analytics Agent for this purpose. This setup allows Sentinel to parse and analyze the firewall events for security monitoring.

Exam trap

The trap here is that candidates often confuse the Azure Activity log connector (which only covers Azure resource operations) with a general-purpose log ingestion method, or they mistakenly think the Office 365 connector can handle any external log source.

153
MCQmedium

Your organization uses Microsoft Defender XDR. You need to investigate a potential ransomware incident that has affected multiple devices. The security team wants to identify the initial access vector. Which advanced hunting table should you query to find the process that initiated the encryption?

A.DeviceRegistryEvents
B.DeviceFileEvents
C.DeviceNetworkEvents
D.DeviceProcessEvents
AnswerD

DeviceProcessEvents captures every process creation, along with the file name, command line, and parent process PID, enabling analysts to build a process tree from the initial point of execution. This table is the authoritative source for tracking the initial process — such as a malicious binary launched from an Office macro — because it records the moment the process became active. By querying DeviceProcessEvents, incident responders can trace the parent process chain and determine exactly which executable initiated the encryption.

Why this answer

DeviceProcessEvents logs process creation events, including the command line and parent process details. To identify the initial access vector in a ransomware incident, you need to trace the process tree back to the executable that launched the encryption process, which is precisely what this table captures.

Exam trap

The trap here is that candidates confuse the artifact of encryption (file changes in DeviceFileEvents) with the action that caused it (process creation in DeviceProcessEvents), leading them to choose DeviceFileEvents instead of the correct table for tracing the initial access vector.

How to eliminate wrong answers

Option A is wrong because DeviceRegistryEvents logs registry modifications, not process creation or execution details, so it cannot show which process initiated encryption. Option B is wrong because DeviceFileEvents logs file creation, modification, and deletion events, but does not capture the parent-child process relationships needed to trace the initial access vector. Option C is wrong because DeviceNetworkEvents logs network connections and traffic, which can show C2 communication but not the local process that started the encryption.

154
Multi-Selectmedium

Your organization uses Microsoft Sentinel. You have been asked to configure automated responses to security incidents. Which TWO of the following can be used to automate responses in Microsoft Sentinel?

Select 2 answers
A.Workbooks
B.Power Automate flows
C.Playbooks (Azure Logic Apps)
D.Custom connectors
E.Automation rules
AnswersC, E

Playbooks are cloud workflows built on Azure Logic Apps that you can invoke from Microsoft Sentinel to automate a security response. They can be triggered by an analytics rule (automatically on alert creation) or by an automation rule on an incident, and they support actions such as isolating a compromised host, resetting credentials, opening a ticket, or sending a Teams notification. Because they run with the Sentinel connector's context, playbooks are the native mechanism for incident-triggered orchestration and satisfy the requirement for automated responses.

Why this answer

Playbooks in Microsoft Sentinel are built on Azure Logic Apps, allowing you to automate complex, multi-step response workflows triggered by security incidents. They can execute actions like blocking IPs, resetting passwords, or enriching alerts with threat intelligence, making them a core automation tool for incident response.

Exam trap

The trap here is that candidates confuse 'automation' with 'visualization' or 'integration', incorrectly selecting Workbooks (which only display data) or Custom connectors (which are infrastructure for APIs, not response actions) instead of recognizing that only Playbooks and Automation rules directly execute automated responses.

155
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to ensure that suspicious email messages are automatically moved to quarantine and an incident is raised in Microsoft Sentinel. What should you configure?

A.Configure the Microsoft Defender for Office 365 data connector in Sentinel.
B.Configure the Microsoft Defender for Cloud data connector in Sentinel.
C.Use the Microsoft Defender for Identity data connector.
D.Enable the Microsoft Defender for Endpoint data connector.
AnswerA

The Microsoft Defender for Office 365 data connector in Sentinel is the appropriate choice because it directly ingests rich Office 365 security signals, including alerts for phishing, malware, malicious URLs, and user-reported email threats, as well as unified incidents. This connector enables you to automatically collect these alerts and correlate them with other analytics in Sentinel, providing complete visibility into email, Teams, and compliance-related threats. No other connector provides native, purpose-built ingestion of Office 365 protection data.

Why this answer

The Microsoft Defender for Office 365 data connector in Microsoft Sentinel ingests email-related alerts and events (e.g., phishing, malware, spam) from Defender for Office 365. When you configure automated investigation and response (AIR) policies in Defender for Office 365 to move suspicious emails to quarantine, and enable the connector in Sentinel, those quarantine actions trigger corresponding incidents in Sentinel. This integration ensures that email threats are both remediated (quarantined) and tracked as security incidents for further analysis.

Exam trap

The trap here is that candidates often confuse the purpose of data connectors—thinking any 'Defender' connector (e.g., Defender for Cloud or Defender for Endpoint) can ingest email security events, when in fact only the specific Office 365 connector handles email quarantine and incident generation for Defender for Office 365.

How to eliminate wrong answers

Option B is wrong because the Microsoft Defender for Cloud data connector focuses on security alerts from cloud workloads (e.g., VMs, containers, SQL) and does not ingest email-related events from Defender for Office 365. Option C is wrong because the Microsoft Defender for Identity data connector ingests alerts related to on-premises Active Directory identity threats (e.g., pass-the-hash, lateral movement) and has no capability to process email quarantine actions. Option D is wrong because the Microsoft Defender for Endpoint data connector ingests endpoint detection and response (EDR) alerts from devices (e.g., malware detections, suspicious processes) and cannot handle email quarantine events from Defender for Office 365.

156
MCQmedium

You have a Microsoft Sentinel analytical rule with the above configuration. During a security incident, multiple high-severity alerts are generated within a 5-minute window. How does the rule handle these alerts?

A.Only the first alert creates an incident; subsequent alerts are ignored.
B.Each alert creates a separate incident.
C.Alerts with the same entities are grouped into a single incident.
D.Alerts are suppressed for 5 minutes after the first alert.
AnswerC

This is the correct behavior for the rule's grouping settings. Microsoft Sentinel uses the entity matching method of 'All' to require that alerts share the exact same set of entities for grouping into one incident. When the rule fires, the incident creation engine evaluates each alert against the defined entities and groups those with matching values, providing a unified incident for triage and investigation.

Why this answer

The analytical rule is configured with 'Group alerts into incidents by: Grouping alerts into a single incident based on matching entities.' This means that when multiple high-severity alerts are generated within a 5-minute window, the rule evaluates the entities (e.g., IP addresses, user accounts) in each alert. If the alerts share the same entities, they are grouped into a single incident, preventing alert flooding and consolidating related security events.

Exam trap

The trap here is that candidates often confuse 'alert grouping' with 'alert suppression' or assume that multiple alerts always create multiple incidents, failing to notice the specific entity-based grouping configuration in the rule settings.

How to eliminate wrong answers

Option A is wrong because the rule does not ignore subsequent alerts; instead, it groups them based on entity matching, not a first-alert-only behavior. Option B is wrong because the rule is explicitly configured to group alerts into a single incident when entities match, not to create separate incidents for each alert. Option D is wrong because alert suppression is a separate configuration (e.g., 'Suppression query' or 'Suppression duration') not shown in the provided configuration; the rule groups alerts but does not suppress them for a fixed 5-minute window.

157
Multi-Selectmedium

Which TWO Microsoft 365 Defender advanced hunting tables would you use together to investigate a potential data exfiltration via email?

Select 2 answers
A.EmailEvents
B.EmailAttachmentInfo
C.DeviceNetworkEvents
D.CloudAppEvents
E.DeviceProcessEvents
AnswersA, B

The EmailEvents table in Microsoft 365 Defender Advanced Hunting is the primary source for email metadata, including the sender, recipient, subject, and message ID (NetworkMessageId). It also records delivery status (Delivered, Blocked, Failed) and detection verdicts for malware, phishing, and spam. This table is essential for hunting email-borne threats because it allows you to filter by specific senders or recipients, inspect message disposition, and correlate with other email and identity tables.

Why this answer

EmailEvents is correct because it is the advanced hunting table that records email message-level metadata and delivery/security verdicts (sender, recipient, subject, timestamps, delivery action, and threat types), which is essential to identify suspicious outbound messages tied to exfiltration. EmailAttachmentInfo is correct because it provides per-attachment details for those messages (file name, SHA-256 hash, file type, and size), letting you pivot from an EmailEvents record via NetworkMessageId to inspect what data was actually attached and sent. Together they correlate the message context with the payload, which is the core of an email-based exfiltration investigation.

DeviceNetworkEvents, CloudAppEvents, and DeviceProcessEvents are not the right pairing here: they cover endpoint network connections, cloud app/service activity, and process execution respectively, none of which directly expose email message and attachment metadata for an email exfiltration scenario.

Exam trap

The trap is confusing email-layer tables (EmailEvents, EmailAttachmentInfo) with endpoint or cloud-app tables — candidates pick DeviceNetworkEvents or CloudAppEvents because they sound like they cover 'exfiltration' broadly.

158
MCQmedium

You are a threat hunter in Microsoft Sentinel. You suspect an attacker is using the Windows utility certutil.exe to download malicious payloads from an external URL. You want to write a hunting query that detects command lines where certutil.exe is used with the -urlcache or -verifyctl arguments. Which KQL query should you use?

A.DeviceNetworkEvents | where InitiatingProcessFileName == "certutil.exe" | where RemoteUrl contains "http"
B.DeviceEvents | where ActionType == "CertUtilDownload" | where AdditionalFields contains "urlcache"
C.DeviceFileEvents | where FileName == "certutil.exe" | where FolderPath contains "urlcache"
D.DeviceProcessEvents | where FileName == "certutil.exe" | where ProcessCommandLine has_any ("-urlcache", "-verifyctl")
AnswerD

This query correctly targets the DeviceProcessEvents table in Microsoft Defender XDR advanced hunting, filters for the process name certutil.exe, and uses has_any to match either of the suspicious arguments. Because DeviceProcessEvents captures process creation events with full command lines, it is the appropriate table for detecting this behavior. The has_any operator efficiently checks for multiple substrings in the command line, making it ideal for this scenario.

Why this answer

The correct query uses DeviceProcessEvents to capture process creation events and filters for certutil.exe with the suspicious arguments -urlcache or -verifyctl. This directly matches the hunting hypothesis. Other tables either lack command-line data or use incorrect fields.

DeviceProcessEvents is the authoritative source for process command lines in Microsoft Defender XDR, making it the right choice for detecting this living-off-the-land binary abuse.

Exam trap

The trap here is assuming that network or file events will reveal command-line arguments, when only process creation events capture the full command line used to launch a binary.

159
MCQmedium

Your organization uses Microsoft Sentinel. A security analyst reports that an incident was automatically created for a sign-in from an unfamiliar location, but after investigation, it was determined to be a false positive. You need to reduce similar false positives in the future without affecting legitimate detections. What should you do?

A.Disable the analytics rule that created the incident.
B.Add the location to a watchlist and reference it in the analytics rule.
C.Create an automation rule to close similar incidents automatically.
D.Modify the analytics rule query to exclude sign-ins from the specific location.
AnswerD

Modifying the analytics rule query to exclude sign-ins from the specific location is the precise fix because it filters out false positives at the source while preserving detection for all other events. In KQL, you would add a clause such as `| where Location != 'Country'` or filter by IP address, ensuring the rule's logic specifically ignores the unwanted sign-in origin. This keeps the rule active and focused on real anomalies, reducing alert noise without losing coverage for other suspicious activities.

Why this answer

Modifying the analytics rule query to exclude sign-ins from the specific location directly addresses the false positive at the detection logic level. This ensures that only sign-ins from that location are ignored, while all other unfamiliar location detections remain active, preserving legitimate detections.

Exam trap

The trap here is that candidates may confuse automation rules (which handle post-detection actions) with analytics rule modifications (which prevent detection at the source), leading them to choose option C instead of D.

How to eliminate wrong answers

Option A is wrong because disabling the analytics rule would stop all detections from that rule, not just the false positive, which would miss legitimate threats. Option B is wrong because adding the location to a watchlist and referencing it in the analytics rule would require complex query modifications and does not inherently exclude the location; watchlists are typically used for inclusion or enrichment, not exclusion, and would still trigger the incident if not properly referenced. Option C is wrong because creating an automation rule to close similar incidents automatically would only suppress the incident after creation, not prevent it, and could inadvertently close legitimate incidents if the criteria are too broad.

160
MCQmedium

In Microsoft 365 Defender, an analyst is investigating an incident where a user's credentials were used to sign in from an unusual geo-location. The analyst wants to find all other sign-in events from the same IP address in the last 7 days. Which Advanced Hunting table should be used?

A.AADSignInEventsBeta
B.IdentityLogonEvents
C.CloudAppEvents
D.DeviceLogonEvents
AnswerA

AADSignInEventsBeta is the correct table because it resides in the Microsoft 365 Defender advanced hunting schema and contains Microsoft Entra ID (Azure AD) sign-in records. Each row represents an authentication attempt, providing the timestamp, source IP address, user principal name (UPN), application, client app, and sign-in result (success or failure). Critically, it includes both interactive and non-interactive sign-ins, so an analyst can pivot on a user's specific IP or timestamp to reconstruct their cloud sign-in activity.

Why this answer

A is correct because the AADSignInEventsBeta table in Advanced Hunting captures Azure Active Directory sign-in logs, including details like IP address, geo-location, and user principal name. This table is specifically designed for investigating interactive and non-interactive sign-in events from Azure AD, making it the appropriate source to query for all sign-ins from a given IP address over the last 7 days.

Exam trap

The trap here is that candidates often confuse IdentityLogonEvents (on-premises AD) with AADSignInEventsBeta (Azure AD cloud), because both deal with 'logon' events, but the question specifically mentions 'geo-location' and 'Microsoft 365 Defender' context, which points to cloud-based Azure AD sign-ins.

How to eliminate wrong answers

Option B is wrong because IdentityLogonEvents captures on-premises Active Directory sign-in events (via Microsoft Defender for Identity), not Azure AD cloud sign-ins, and does not include the geo-location or IP address details needed for this cloud-based investigation. Option C is wrong because CloudAppEvents focuses on activities within Microsoft Cloud App Security (e.g., file downloads, admin actions) and does not contain raw sign-in authentication events with IP and geo-location. Option D is wrong because DeviceLogonEvents records local device logon events (Windows security events like 4624) on endpoints, not Azure AD cloud sign-ins from an unusual geo-location.

161
MCQeasy

Your organization uses Microsoft Sentinel. You need to ensure that incident investigation is efficient by automatically grouping related alerts into incidents. Which configuration should you use?

A.Create an automation rule to group alerts
B.Configure alert grouping in the analytics rule wizard
C.Use a playbook to merge incidents
D.Define a watchlist to consolidate alerts
AnswerB

The analytics rule wizard includes a dedicated 'Incident settings' tab where you can enable alert grouping, making it the correct and native mechanism for consolidating alerts into incidents. When enabled, you can configure grouping based on entity matching (e.g., same account, host, or IP address) and set a time window for how far back to look for matching alerts. You can also choose to limit grouping to specific entities or include custom details to refine the grouping logic. This configuration is applied automatically during incident creation, so no additional automation or manual steps are needed.

Why this answer

Microsoft Sentinel's analytics rule wizard includes a dedicated 'Alert grouping' configuration that allows you to specify how alerts from the same analytics rule are automatically combined into a single incident. This setting is essential for efficient incident investigation, as it reduces alert noise by grouping related alerts based on criteria such as matching entities, time windows, or custom alert details, ensuring that security analysts work with consolidated incidents rather than individual alerts.

Exam trap

The trap here is that candidates often confuse automation rules (which operate on existing incidents) with the alert grouping feature (which operates during incident creation), leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because automation rules in Microsoft Sentinel are used to trigger automated responses (e.g., changing incident status, assigning owners) after an incident is created, not to group alerts into incidents during the creation process. Option C is wrong because playbooks are automated workflows (often using Azure Logic Apps) that respond to incidents or alerts after they exist; they cannot merge incidents or group alerts at the point of incident creation. Option D is wrong because watchlists are collections of data (e.g., IP addresses, hostnames) used for correlation, enrichment, or filtering within analytics rules, not for consolidating alerts into incidents.

162
MCQeasy

Your team is conducting a threat hunt for data exfiltration using Microsoft Defender for Cloud Apps. Which activity is most suspicious and should be included in the hunting query?

A.A user viewing files in OneDrive for Business.
B.A user downloading a single file from SharePoint Online.
C.A user sharing a file with an internal colleague.
D.A user downloading hundreds of files from SharePoint Online in a short time.
AnswerD

Downloading hundreds of files from SharePoint Online in a short period matches mass-download behaviour that Defender for Cloud Apps flags as potential exfiltration. The volume and compressed timeframe satisfy the suspicious-activity constraint in the stem, unlike routine single-file access, making it the strongest hunting query candidate.

Why this answer

Mass download of hundreds of files from SharePoint Online in a short time is a classic indicator of data exfiltration. Option D is correct. Option A is incorrect because viewing files is normal user activity and not indicative of exfiltration.

Option B is incorrect because downloading a single file is routine and not suspicious. Option C is incorrect because sharing a file with an internal colleague is typical collaboration and less likely to be exfiltration than mass downloads or external sharing.

163
MCQeasy

A SOC analyst is investigating an incident where a user's credentials were compromised. The analyst uses Microsoft Sentinel to find all activities performed by the user in the last 24 hours. Which data source should the analyst query FIRST to get the most comprehensive view of the user's actions across Microsoft 365?

A.DeviceEvents
B.OfficeActivity
C.AzureActivity
D.SigninLogs
AnswerB

OfficeActivity represents the unified audit log for Microsoft 365, pulling records from Exchange, SharePoint, OneDrive, Teams, and other workloads. It captures user-level events such as email actions, file accesses, and messages sent after authentication, making it the appropriate table to investigate a user's activities in M365. This table is the primary source for reconstructing user behavior in the M365 environment.

Why this answer

OfficeActivity (Option B) is the correct first query because it captures user actions across Exchange Online, SharePoint Online, OneDrive for Business, Teams, and other Microsoft 365 workloads via the unified audit log. This provides the most comprehensive view of a user's activities—including email sends, file accesses, and Teams messages—within the last 24 hours, which is essential for investigating compromised credentials.

Exam trap

The trap here is that candidates often choose SigninLogs (Option D) thinking it covers all user actions, but it only shows authentication events, not the actual activities performed after sign-in, which is a common misconception tested in SC-200.

How to eliminate wrong answers

Option A is wrong because DeviceEvents (from Microsoft Defender for Endpoint) focuses on endpoint-level events (process creation, file modifications) and does not cover cloud-based Microsoft 365 activities like email or SharePoint access. Option C is wrong because AzureActivity logs only Azure resource management operations (e.g., VM creation, RBAC changes) and excludes user-level productivity actions in Microsoft 365. Option D is wrong because SigninLogs captures only authentication events (successful/failed logins) and not the subsequent actions the user performed after signing in.

164
MCQmedium

Your organization uses Microsoft Sentinel. You receive an incident that involves a potential lateral movement detected by Microsoft Defender for Identity. You need to investigate the timeline of the attack. Which Microsoft Sentinel feature should you use?

A.Workbooks
B.Automation rules
C.Investigation graph
D.Analytics rules
AnswerC

The investigation graph visualises related entities, alerts and activities on a timeline, letting you trace the lateral movement path across accounts and hosts. It surfaces the attack chronology that a raw incident list or hunting query alone would not present as clearly.

Why this answer

The Investigation graph in Microsoft Sentinel is specifically designed to explore the scope and timeline of an attack by visually mapping entities (e.g., users, devices, IPs) and their connections. For a lateral movement incident detected by Defender for Identity, the graph automatically surfaces related alerts, entities, and activities in a chronological view, enabling you to trace the attacker's path across resources. This makes it the correct tool for investigating the attack timeline.

Exam trap

The trap here is that candidates confuse the Investigation graph with Workbooks, assuming any visual tool for analysis is a Workbook, but Workbooks are for aggregated reporting, not for per-incident entity timeline exploration.

How to eliminate wrong answers

Option A is wrong because Workbooks are used for creating custom dashboards and reports from pre-defined queries, not for interactive, entity-based timeline investigation of a specific incident. Option B is wrong because Automation rules are designed to trigger automated responses (e.g., closing incidents, assigning tasks) based on conditions, not to explore the historical sequence of an attack. Option D is wrong because Analytics rules define detection logic to generate alerts from data sources, but they do not provide a visual, entity-centric timeline for investigating an already-triggered incident.

165
Multi-Selecthard

Which THREE are essential components of a threat hunting hypothesis in Microsoft Sentinel? (Choose three.)

Select 3 answers
A.Adversary goal or objective
B.Alert severity level
C.Data sources to query
D.Automated response plan
E.Expected indicators of compromise (IOCs)
AnswersA, C, E

A hypothesis must state what the adversary is trying to achieve, since the goal directs which behaviours, telemetry and queries the hunter pursues. Without an objective, hunting lacks a testable premise and becomes unfocused data review.

Why this answer

A threat hunting hypothesis in Microsoft Sentinel must be structured around what the adversary is trying to achieve, so option A (Adversary goal or objective) is correct because it defines the behavior or intent being tested, such as credential theft or lateral movement, which guides the entire hunt. Option C (Data sources to query) is correct because a hypothesis is only actionable if it maps to concrete telemetry in Sentinel, such as SecurityEvent, Syslog, SigninLogs, or OfficeActivity tables queried via KQL, so the hunter knows where to look. Option E (Expected indicators of compromise (IOCs)) is correct because the hypothesis must specify the observable artifacts that would confirm or refute it, such as specific process names, IP addresses, hashes, or anomalous sign-in patterns, enabling validation of the hunt.

Option B (Alert severity level) is not essential because severity is a triage attribute of analytics rules and incidents, not a defining element of a hunting hypothesis. Option D (Automated response plan) is not essential because automation and playbooks belong to incident response and SOAR workflows, whereas threat hunting is an investigative, hypothesis-driven activity that may not trigger automated actions.

Exam trap

SC-200 often tests whether candidates can separate the hunting hypothesis (goal, data, expected evidence) from detection and response artifacts (severity, playbooks) — the distractor options sound relevant to security operations but are not part of the hypothesis construct.

166
MCQmedium

A security administrator wants to enable vulnerability assessment for all existing and future Azure virtual machines in a subscription using the integrated Microsoft Defender Vulnerability Management solution. What is the recommended action in Microsoft Defender for Cloud?

A.Enable the 'Vulnerability assessment for machines' component in the Defender for Servers plan settings within the subscription's pricing & settings page.
B.Manually install the Microsoft Defender Vulnerability Management agent on each VM via an Azure Policy initiative.
C.Create an Azure Policy that assigns the 'Configure machines to receive a vulnerability assessment provider' built-in policy to the subscription.
D.Enable 'Vulnerability assessment for machines' in the Azure Security Benchmark compliance dashboard.
AnswerA

Enabling the 'Vulnerability assessment for machines' component in the Defender for Servers plan settings is the native, integrated approach within Microsoft Defender for Cloud. This action automatically provisions the Microsoft Defender Vulnerability Management solution to all existing and future Azure VMs and Arc-enabled servers, eliminating the need for per-VM manual steps. It ensures continuous coverage as new machines are added, directly satisfying the requirement to enable vulnerability assessment for existing and future resources at the subscription level.

Why this answer

Enabling the 'Vulnerability assessment for machines' component in the Defender for Servers plan settings within the subscription's pricing & settings page automatically provisions the integrated Microsoft Defender Vulnerability Management (MDVM) solution to all existing and future Azure VMs without manual agent installation. This is the recommended and native method in Microsoft Defender for Cloud to enable vulnerability assessment at scale, leveraging the built-in Qualys or MDVM scanner that is managed by the platform.

Exam trap

The trap here is that candidates often confuse the 'Vulnerability assessment for machines' component with a separate policy assignment or manual agent installation, not realizing that the correct action is a simple toggle in the Defender for Servers plan settings that automatically handles provisioning and lifecycle management.

How to eliminate wrong answers

Option B is wrong because manually installing the Microsoft Defender Vulnerability Management agent on each VM is not the recommended action; Defender for Cloud can automatically provision the agent via the plan settings, and manual installation is inefficient and error-prone for scaling. Option C is wrong because the 'Configure machines to receive a vulnerability assessment provider' built-in policy assigns a specific provider (e.g., Qualys or a BYOL solution) but does not enable the integrated MDVM solution; it requires additional configuration and does not automatically cover future VMs without policy assignment scope management. Option D is wrong because the Azure Security Benchmark compliance dashboard is a compliance monitoring tool, not a configuration pane for enabling vulnerability assessment; it does not have a setting to enable vulnerability assessment for machines.

167
Multi-Selecthard

Your organization uses Microsoft Defender XDR and Microsoft Sentinel. You need to ensure that when a user reports a phishing email in Microsoft 365 Defender, the incident in Microsoft Sentinel is automatically updated with the user's comments. Which THREE components are required?

Select 3 answers
A.A logic app in Azure that is triggered by the Microsoft 365 Defender alert.
B.The Microsoft 365 Defender data connector in Microsoft Sentinel.
C.The Microsoft Entra ID data connector in Microsoft Sentinel.
D.A playbook in Microsoft Sentinel that updates the incident with the user's comments.
E.An automation rule in Microsoft Sentinel that triggers the playbook when an incident is created from a Microsoft 365 Defender alert.
AnswersB, D, E

The Microsoft 365 Defender data connector in Microsoft Sentinel is essential because it ingests alerts and raw events from Defender XDR into the Log Analytics workspace. This connector creates the SecurityAlert and SecurityIncident tables that Sentinel uses to generate incidents, and without it, no Microsoft 365 Defender alert would ever reach Sentinel to trigger any automation. This is why it is the correct component to include, as it is the foundational source of the incident data.

Why this answer

The Microsoft 365 Defender data connector in Microsoft Sentinel is required because it ingests alerts and incidents from Microsoft 365 Defender into Sentinel. Without this connector, the phishing email report from Microsoft 365 Defender would not create an incident in Sentinel, making it impossible to automatically update that incident with user comments.

Exam trap

The trap here is that candidates often think a logic app triggered directly by the alert (Option A) is sufficient, but the required flow must use a Sentinel playbook triggered by an automation rule to ensure the incident update occurs within Sentinel's context.

168
MCQeasy

An incident response playbook in Microsoft Sentinel has a step: 'Investigate the user's recent activities using Microsoft 365 Defender.' Which data source would provide the most relevant information for this step?

A.Azure Activity Log
B.Microsoft Purview Data Loss Prevention reports
C.Microsoft 365 Defender's user investigation page
D.Azure Resource Graph
AnswerC

The Microsoft 365 Defender user investigation page (now within the unified Microsoft Defender XDR) provides a single, entity-centric view of a user's alerts, incidents, sign-ins, and related activities across identities, endpoints, email, and cloud apps. It automatically correlates evidence and provides a timeline that allows an incident responder to quickly detect the scope and blast radius of a compromised account. This is the correct investigation surface because it is specifically designed for user entity investigation, and Sentinel can ingest these detections through the Microsoft 365 Defender connector.

Why this answer

The Microsoft 365 Defender user investigation page is the correct data source because it provides a consolidated view of a user's activities across Microsoft 365 services, including email, Teams, and endpoint alerts. This directly supports the incident response step of investigating recent user activities within the Microsoft 365 Defender ecosystem, which is the explicit scope of the playbook step.

Exam trap

The trap here is that candidates may confuse Azure Activity Log (which logs Azure resource operations) with user activity logs in Microsoft 365, or assume that any Microsoft security tool (like Purview DLP) would contain the needed user activity data, when only the Microsoft 365 Defender user investigation page provides the specific, integrated view required by the playbook step.

How to eliminate wrong answers

Option A is wrong because Azure Activity Log records management-plane operations on Azure resources (e.g., creating VMs), not user activities within Microsoft 365 services like email or Teams. Option B is wrong because Microsoft Purview Data Loss Prevention reports focus on policy violations and sensitive data exposure, not a comprehensive timeline of a user's recent activities across Microsoft 365. Option D is wrong because Azure Resource Graph is used for querying and exploring Azure resources at scale, not for investigating user activities in Microsoft 365 Defender.

169
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to ensure that security incidents from Defender for Cloud are automatically sent to Sentinel. What should you configure?

A.Configure the Azure Active Directory data connector
B.Configure the Microsoft Defender for Cloud data connector
C.Create an Azure Event Hub and push Defender for Cloud alerts to Sentinel via a custom connector
D.Configure the Microsoft 365 Defender data connector
AnswerB

The Microsoft Defender for Cloud data connector is the native, purpose-built integration that ingests Defender for Cloud security alerts, recommendations, and incidents directly into Microsoft Sentinel. It requires no extra infrastructure or custom code, automatically streaming alerts from Azure, on-premises, and other cloud workloads protected by Defender for Cloud, and it supports bidirectional status synchronization. This is the correct connector because it directly satisfies the requirement to ingest Defender for Cloud incidents into Sentinel.

Why this answer

The Microsoft Defender for Cloud data connector is the correct choice because it is specifically designed to ingest security alerts and incidents from Defender for Cloud into Microsoft Sentinel. This connector enables automatic synchronization of Defender for Cloud's security findings, ensuring that incidents are created in Sentinel without manual intervention or custom infrastructure.

Exam trap

The trap here is that candidates often confuse the Microsoft Defender for Cloud data connector with the Microsoft 365 Defender data connector, mistakenly thinking that all 'Defender' services are covered by a single connector, when in fact each has its own dedicated connector for specific alert sources.

How to eliminate wrong answers

Option A is wrong because the Azure Active Directory data connector ingests sign-in logs and audit logs, not security incidents from Defender for Cloud. Option C is wrong because while an Event Hub can be used for custom data ingestion, it is unnecessary and overly complex; the native Defender for Cloud data connector provides a direct, supported integration without custom development. Option D is wrong because the Microsoft 365 Defender data connector ingests alerts from Microsoft 365 Defender (e.g., Defender for Endpoint, Defender for Office 365), not from Defender for Cloud.

170
MCQmedium

A security analyst receives an alert in Microsoft Defender for Cloud about a suspicious process on an Azure VM. The alert indicates a potential credential dumping tool. The analyst needs to see the full command line and parent process of the suspicious process. Which Defender for Cloud feature should the analyst use?

A.Live Response
B.Fileless attack detection
C.Just-In-Time VM access
D.Adaptive application controls
AnswerA

Live Response provides a remote, interactive shell session to the VM, allowing an analyst to execute built-in commands or PowerShell scripts directly on the machine. Through this shell, you can enumerate running processes, retrieve their command-line arguments, identify parent-child process relationships, and terminate malicious processes. This hands-on capability is exactly what is needed to investigate the alert and determine whether the process is benign or malicious.

Why this answer

Live Response in Microsoft Defender for Cloud provides the analyst with the ability to remotely investigate a live Azure VM. It allows the analyst to run commands, collect forensic artifacts, and view detailed process information, including the full command line and parent process of the suspicious process, which is essential for analyzing a potential credential dumping tool.

Exam trap

The trap here is that candidates often confuse Live Response with other Defender for Cloud features like Fileless attack detection or Adaptive application controls, mistakenly thinking those features provide forensic process investigation capabilities when they are actually focused on detection or prevention, not post-breach analysis.

How to eliminate wrong answers

Option B is wrong because Fileless attack detection is a feature that identifies threats that execute code without writing to disk, such as PowerShell scripts or WMI activity; it does not provide the ability to view the full command line or parent process of a specific alert. Option C is wrong because Just-In-Time VM access is a network security feature that controls inbound traffic to VMs by opening ports only when needed; it is unrelated to investigating process details. Option D is wrong because Adaptive application controls are a whitelisting mechanism that defines which applications are allowed to run on VMs; they do not offer forensic investigation capabilities like viewing command-line arguments or parent processes.

171
MCQmedium

You are a security analyst at a company that uses Microsoft Defender XDR. You receive an alert about a potential ransomware activity on a workstation. The alert is generated by Microsoft Defender for Endpoint. You need to contain the threat by isolating the workstation from the network while allowing forensic analysis to proceed. You want to use Microsoft Defender XDR's built-in actions. What should you do?

A.Create a firewall rule in Microsoft Defender for Cloud Apps to block the device's IP.
B.Use the 'Isolate device' action from the Microsoft Defender XDR portal.
C.Unenroll the device from Microsoft Intune.
D.Disable the network adapter on the workstation remotely.
AnswerB

Use the 'Isolate device' action from the Microsoft Defender XDR portal, which invokes Defender for Endpoint's machine isolation and breaks the attack chain by severing all inbound and outbound network traffic, except traffic between the device and the MDE cloud service plus any forensic processes you explicitly allow. This preserves the agent's ability to receive future commands and send telemetry, enabling continued investigation while the threat actor loses connectivity. It is the direct, built-in containment action for an endpoint in an incident.

Why this answer

The 'Isolate device' action in Microsoft Defender XDR (specifically from the Microsoft Defender for Endpoint component) disconnects the device from all network traffic except for the Defender for Endpoint service and a few authorized services (such as Windows Update and the Microsoft Update Service). This allows forensic analysis tools (like Live Response) to continue communicating with the device while preventing the ransomware from spreading laterally or communicating with command-and-control servers. This is the built-in, recommended containment action for such scenarios.

Exam trap

The trap here is that candidates may confuse network isolation with other security controls (like blocking an IP in a CASB or unenrolling from MDM) and fail to recognize that Microsoft Defender XDR's 'Isolate device' is the only built-in action that both contains the threat and preserves forensic access.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps (MCAS) is a cloud access security broker that controls access to cloud applications, not a tool for isolating a workstation from the network; blocking an IP in MCAS would not isolate the device itself. Option C is wrong because unenrolling the device from Microsoft Intune removes management and policy enforcement, but does not contain the threat—it actually removes the ability to perform any further actions on the device and does not stop network communication. Option D is wrong because disabling the network adapter remotely is not a built-in action in Microsoft Defender XDR; it would require separate remote management tools (e.g., PowerShell, RMM) and would also cut off the forensic analysis channel, preventing Live Response or any other remote investigation.

172
MCQeasy

A security analyst is using Microsoft 365 Defender advanced hunting to investigate a ransomware incident. The analyst wants to find all processes that were created with a specific parent process ID. Which column in the DeviceProcessEvents table should the analyst use to filter the parent process?

A.ProcessId
B.ParentProcessId
C.InitiatingProcessId
D.LogonId
AnswerB

ParentProcessId is the authoritative column for direct process lineage because it stores the process ID of the process that created the current process. When a process creation event is logged, this field is populated with the parent process's unique identifier, enabling an exact one-level relationship in the process tree. Using it lets you join back to the same DeviceProcessEvents table to retrieve the parent process's command line and metadata.

Why this answer

The ParentProcessId column in the DeviceProcessEvents table stores the process ID (PID) of the parent process that created a given process. By filtering on this column, the analyst can identify all child processes spawned by a specific parent, which is critical for tracing ransomware execution chains in advanced hunting queries.

Exam trap

The trap here is confusing InitiatingProcessId (used in cross-table joins for email or alert context) with ParentProcessId, which is the direct column for parent-child process relationships in DeviceProcessEvents.

How to eliminate wrong answers

Option A is wrong because ProcessId identifies the current process itself, not its parent. Option C is wrong because InitiatingProcessId refers to the process that initiated the action in other tables (e.g., EmailEvents), not the parent process in DeviceProcessEvents. Option D is wrong because LogonId is a session identifier for the user logon session, unrelated to parent-child process relationships.

173
MCQeasy

You are investigating a suspicious sign-in to a privileged account. You need to determine if the sign-in was from a known malicious IP address. Which Microsoft Sentinel data source should you query?

A.ThreatIntelligenceIndicator
B.SecurityEvent
C.SigninLogs
D.AuditLogs
AnswerA

ThreatIntelligenceIndicator tables store ingested threat indicators, including malicious IP addresses, matched against your environment. Querying it lets you confirm whether the sign-in's source IP appears in known threat intelligence, directly satisfying the requirement to identify a known malicious IP address rather than relying on sign-in logs alone.

Why this answer

The ThreatIntelligenceIndicator table in Microsoft Sentinel stores threat intelligence indicators (IPs, domains, URLs, file hashes) imported from TI providers or uploaded via API. To determine if a sign-in originated from a known malicious IP, you query this table for the IP address and check for matches.

Exam trap

SC-200 often tests the confusion between sign-in logs (which show the IP) and threat intelligence indicators (which classify the IP as malicious); candidates pick SigninLogs thinking it contains reputation data.

How to eliminate wrong answers

Option B (SecurityEvent) is wrong because it contains Windows security events from agents (e.g., logon events), not threat intelligence indicators; it would not tell you if an IP is known malicious. Option C (SigninLogs) is wrong because it contains Azure AD sign-in records (user, IP, status), but does not itself classify IPs as malicious — you would need to join it with ThreatIntelligenceIndicator. Option D (AuditLogs) is wrong because it contains Azure AD audit events (e.g., user management, role changes), not threat intelligence or sign-in IP reputation data.

174
MCQhard

During a ransomware incident, the security team needs to prevent the encryption of files while allowing the investigation to continue. Which feature in Microsoft Defender for Endpoint should be used to achieve this?

A.Controlled folder access.
B.Device isolation.
C.Attack surface reduction (ASR) rules.
D.Custom detection rules.
AnswerA

Controlled folder access (CFA) in Microsoft Defender for Endpoint is the correct proactive control because it uses a Windows kernel mini-filter to intercept file-write and delete operations, blocking any process that is not on an approved allowlist from modifying files inside protected directories. This directly stops ransomware from encrypting user data in real time, even if the malware has already executed. CFA can be configured via Intune or group policy and provides a targeted, low-disruption defense that preserves forensic data and remote remediation capabilities.

Why this answer

Controlled folder access (CFA) blocks unauthorized applications from modifying files in protected folders, which is exactly what ransomware does. ASR rules are broader and may not target file encryption specifically. Device isolation disconnects the device from the network but stops the investigation.

Custom detection rules are reactive.

175
Multi-Selecteasy

Which TWO are valid methods to connect a non-Azure Windows server to Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Install the Azure Monitor Agent (AMA)
B.Install the Azure Security Center agent
C.Configure Windows Event Forwarding (WEF) and point it to Sentinel
D.Install the Log Analytics agent (MMA)
E.Configure the server to forward syslog to Sentinel
AnswersA, D

The Azure Monitor Agent (AMA) is the current, unified agent for collecting telemetry from both Azure and non-Azure resources, including Windows servers outside Azure. After you install AMA and associate it with your Log Analytics workspace, you define collection rules via Data Collection Rules (DCRs) to capture security events such as 4624/4625, performance counters, and custom logs for Microsoft Sentinel. For a non-Azure Windows server, you install AMA with an onboarding script or via a management tool, and Sentinel then ingests the data from the Log Analytics workspace as its underlying telemetry source.

Why this answer

The Azure Monitor Agent (AMA) is the current, recommended agent for collecting data from non-Azure Windows servers and sending it to Microsoft Sentinel. It replaces the older Log Analytics agent and supports data collection via Data Collection Rules (DCRs), which allow granular control over which events and performance counters are ingested. Option D is correct because the Log Analytics agent (MMA) was the original method to connect Windows servers to Sentinel, and while it is being phased out in favor of AMA, it remains a valid supported method for existing deployments.

Exam trap

The trap here is that candidates may confuse Windows Event Forwarding (WEF) as a direct data connector to Sentinel, when in fact WEF only centralizes events on a collector server, which still requires an agent to forward to Sentinel, making it an indirect method not listed as a direct connection option.

176
MCQhard

A security analyst uses Microsoft Defender for Cloud to monitor Azure SQL Databases. The analyst wants to generate alerts for SQL injection attempts but only for databases that contain sensitive data (e.g., credit card numbers). What is the most efficient way to configure alerting to focus on these databases?

A.Enable a custom alert rule in Microsoft Sentinel that queries Azure SQL audit logs and filters based on database classification tags.
B.Use Data Discovery & Classification in Azure SQL to label sensitive columns, then configure Advanced Threat Protection to alert only when a SQL injection event is detected against a database with those labels.
C.Disable Advanced Threat Protection for all databases except those that contain sensitive data by manually enabling ATP per database.
D.Create a workflow automation in Defender for Cloud that filters SQL injection alerts based on database name.
AnswerA

A Microsoft Sentinel custom rule that queries Azure SQL audit logs would require shipping all SQL audit telemetry to the Log Analytics workspace, writing and maintaining KQL logic, and mapping data classification tags, which are stored as database metadata rather than as fields within individual audit log records. This approach is operationally heavy, adds detection latency, and fails to leverage the built-in machine-learning anomaly detection in Defender for Cloud's Advanced Threat Protection, so it is not the recommended or efficient solution.

Why this answer

The correct approach is to use an Azure Sentinel custom alert rule that queries Azure SQL audit logs and filters based on database classification tags. This ensures alerts are generated only for databases with sensitive data. Advanced Threat Protection (ATP) does not support filtering by classification labels and is enabled at the server level, making options B and C invalid.

Exam trap

Candidates may assume ATP can be scoped to specific databases or labels, but ATP is server-wide and does not integrate with Data Discovery & Classification labels. A Sentinel custom rule provides the required granularity.

How to eliminate wrong answers

Option A is wrong because it relies on Microsoft Sentinel custom alert rules querying Azure SQL audit logs, which introduces latency, additional cost, and complexity compared to using Defender for Cloud's native ATP, and it does not directly integrate with Data Discovery & Classification labels for efficient filtering. Option C is wrong because manually enabling or disabling ATP per database is inefficient and error-prone, especially in large environments, and it does not leverage the automated classification-based filtering that ATP supports. Option D is wrong because creating a workflow automation in Defender for Cloud that filters alerts based on database name is a post-alert workaround that does not prevent alerts from being generated for non-sensitive databases, wasting resources and potentially causing alert fatigue.

177
MCQeasy

Your organization has deployed Microsoft Sentinel. You need to ensure that user and entity behavior analytics (UEBA) is enabled for all data sources. What is the minimum role required to enable UEBA in Microsoft Sentinel?

A.Microsoft Sentinel Contributor
B.Global Administrator
C.Security Reader
D.Log Analytics Contributor
AnswerA

The Microsoft Sentinel Contributor role is the minimal built-in Azure RBAC role that provides full access to Sentinel resources, including the ability to enable UEBA. It grants write permissions to Sentinel settings, such as turning on User and Entity Behavior Analytics from the Settings blade. This role is scoped to the Sentinel workspace or resource group, ensuring least-privilege access for security operators. Because it specifically targets Sentinel's control plane, no additional tenant-level permissions are needed.

Why this answer

To enable UEBA in Microsoft Sentinel, you need the Microsoft Sentinel Contributor role because it includes the necessary permissions to manage Sentinel settings, including turning on UEBA for all data sources. This role allows you to access the UEBA configuration blade and modify the analytics settings, which is the minimum privilege required for this task.

Exam trap

The trap here is that candidates often assume a higher-privilege role like Global Administrator is needed for any security configuration, but Microsoft Sentinel has its own granular RBAC roles, and the exam tests knowledge of these specific permissions.

How to eliminate wrong answers

Option B (Global Administrator) is wrong because it is overprivileged for this task; while it can enable UEBA, it is not the minimum role required, and using it violates the principle of least privilege. Option C (Security Reader) is wrong because it only provides read-only access to security configurations and cannot modify settings like enabling UEBA. Option D (Log Analytics Contributor) is wrong because it grants permissions to manage Log Analytics workspaces but lacks the specific Sentinel-level permissions needed to configure UEBA, which is a Sentinel-specific feature.

178
MCQmedium

Refer to the exhibit. You run the PowerShell command against Microsoft Defender for Endpoint. What is the result?

A.The investigation package is collected.
B.An antivirus scan runs on the device.
C.The device is isolated from the network.
D.A Live Response session is started.
AnswerB

The ActionType 'RunAntiMalwareScan' sends a command through the Defender for Endpoint sensor to the antimalware engine, instructing it to execute a scan on the endpoint. This is a non-interactive, one-time response action that can be a full or quick scan depending on device policy, with results reported back to the console. It does not require isolation or a Live Response session.

Why this answer

The `Start-MpScan` cmdlet initiates a Microsoft Defender Antivirus scan on the device. The `-ScanType` parameter with value `QuickScan` specifies a quick scan of common malware locations, not a full scan. This is a direct antivirus action, not an investigation package collection, isolation, or Live Response session.

Exam trap

The trap here is that candidates confuse the `Start-MpScan` cmdlet with other Defender for Endpoint actions like investigation package collection or device isolation, because all are available under the 'Actions' menu in the portal, but each uses a distinct PowerShell cmdlet or API call.

How to eliminate wrong answers

Option A is wrong because collecting an investigation package requires the `Start-MpInvestigation` cmdlet or the `CollectInvestigationPackage` action via Microsoft Defender for Endpoint API, not `Start-MpScan`. Option C is wrong because device isolation is performed using the `Isolate-Device` cmdlet or the corresponding API action, not a scan command. Option D is wrong because starting a Live Response session requires the `Start-MpLiveResponse` cmdlet or initiating a session via the Defender portal, not a scan cmdlet.

179
MCQeasy

Refer to the exhibit. You are reviewing an alert in Microsoft Defender for Endpoint. The alert details are shown. Which of the following actions should you take first?

A.Investigate the device and the alert details
B.Mark the alert as a false positive
C.Initiate device isolation to contain the threat
D.Run a full antivirus scan on the device
AnswerA

Before containing or remediating, you must establish scope and impact. Reviewing the device timeline and alert details reveals the affected processes, files and network connections, ensuring subsequent response actions target the actual threat rather than disrupting legitimate activity.

Why this answer

The first step in incident response is to investigate the alert details and the affected device to understand the scope and severity of the threat. Without investigation, you cannot determine whether the alert is a true positive, whether isolation is appropriate, or which remediation steps are needed. Microsoft Defender for Endpoint provides a rich investigation experience, including the alert story, device timeline, and related events, which must be reviewed before taking any containment or remediation actions.

Exam trap

The trap here is that candidates often jump to containment (isolation) or remediation (scan) because they think speed is critical, but the SC-200 exam emphasizes that investigation must always come first to avoid disrupting business operations or misclassifying alerts.

How to eliminate wrong answers

Option B is wrong because marking an alert as a false positive without investigation risks ignoring a real threat; you must first analyze the alert to confirm it is indeed benign. Option C is wrong because initiating device isolation should only be done after confirming the alert is a true positive and understanding the threat's behavior, as premature isolation can disrupt legitimate operations and lose forensic data. Option D is wrong because running a full antivirus scan is a remediation step that should follow investigation and containment, not precede them; scanning without context may miss advanced threats or alert on known good files.

180
Multi-Selecteasy

Which TWO permissions are required for a user to manage Microsoft Sentinel playbooks?

Select 2 answers
A.Microsoft Sentinel Reader
B.Logic App Contributor
C.Microsoft Sentinel Contributor
D.Automation Operator
E.Global Administrator
AnswersB, C

Logic App Contributor is one of the two required permissions because Sentinel playbooks are implemented as Azure Logic Apps. This role provides full management authority over Logic Apps, enabling users to create, edit, and execute the workflows that playbooks depend on. Without it, even with Sentinel-level permissions, the underlying playbook logic cannot be altered or run, making it essential for managing playbooks.

Why this answer

Microsoft Sentinel playbooks are built on Azure Logic Apps, so managing them requires the Logic App Contributor role to create, edit, and delete the underlying logic app resources. Additionally, Microsoft Sentinel Contributor is needed to attach playbooks to analytics rules or automation rules within Sentinel, as this involves modifying Sentinel-specific configurations. Without both roles, a user cannot fully manage playbooks in the Sentinel context.

Exam trap

The trap here is that candidates often assume only a Sentinel-specific role (like Microsoft Sentinel Contributor) is sufficient, forgetting that playbooks are built on Azure Logic Apps and thus require the Logic App Contributor role for direct management of the playbook resource itself.

181
MCQmedium

A security analyst reports that a scheduled analytics rule in Microsoft Sentinel has stopped generating incidents after a recent update. The rule still runs but produces no alerts. What should you check first?

A.Verify that the rule is enabled and not paused.
B.Check the entity mapping configuration for missing fields.
C.Review the rule's query logic for changes or syntax errors.
D.Ensure that the automation rule triggering the incident is still active.
AnswerC

Scheduled analytics rules only raise an alert for each row returned by their KQL query. If the query logic was recently changed—adding an overly restrictive where clause, altering the time range, referencing a renamed table or column—or contains a syntax error, the query can return zero results or fail before producing output. That directly explains why the rule runs on schedule yet no alerts are generated, making query review the first diagnostic step.

Why this answer

The most likely cause of a scheduled analytics rule running but producing no alerts is a change or error in the KQL query logic. Since the rule still executes, the issue is not with the rule being disabled or paused, but rather with the query failing to return results due to syntax errors, schema changes, or logic flaws introduced during the update.

Exam trap

The trap here is that candidates assume a rule that 'still runs' is functioning correctly, but Microsoft tests the distinction between execution and result generation—a rule can execute its query yet produce zero alerts due to query logic issues, not configuration or automation problems.

How to eliminate wrong answers

Option A is wrong because the rule is explicitly stated to still run, so it is enabled and not paused; checking this would not resolve the issue. Option B is wrong because entity mapping configuration affects how alerts are structured, not whether alerts are generated; missing fields would cause mapping errors, not a lack of alerts. Option D is wrong because automation rules trigger actions after an incident is created; if no alerts are generated, no incidents exist to trigger automation rules, so checking automation rules is premature.

182
MCQeasy

A SOC analyst is reviewing an incident in Microsoft Sentinel that involves a user receiving a phishing email with a malicious attachment. The attachment was opened on a device managed by Microsoft Intune. Which Microsoft Defender XDR component would have provided the earliest detection of the malicious file?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Office 365
C.Microsoft Defender for Endpoint
D.Microsoft Purview Data Loss Prevention
AnswerC

Microsoft Defender for Endpoint is the correct source because it is an endpoint detection and response (EDR) solution that installs a sensor on the device, continuously monitoring processes, file executions, registry changes, and behaviors. Its real-time protection and behavioral analytics would detect the malicious file directly on the endpoint, and this detection would surface as an alert in Microsoft Sentinel. As the only option with a local agent capable of seeing file execution, it is the definitive source for this incident.

Why this answer

Microsoft Defender for Endpoint (MDE) provides the earliest detection of malicious files at the endpoint level. When the user opens the malicious attachment on an Intune-managed device, MDE's real-time protection (antivirus and behavior monitoring) scans the file immediately upon execution or write, blocking the threat before it can execute further. This is faster than cloud-based or email-level detections because the file is already on the device.

Exam trap

The trap here is that candidates often choose Microsoft Defender for Office 365 (Option B) because they focus on the phishing email vector, but the question explicitly states the attachment was already opened on the device, shifting the earliest detection point to the endpoint protection layer.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps (formerly MCAS) is a cloud access security broker that detects threats in cloud applications (e.g., anomalous behavior in SaaS apps), not malicious files on endpoints. Option B is wrong because Microsoft Defender for Office 365 protects against phishing emails and attachments at the email gateway level, but the question states the attachment was already opened on the device, meaning the email-level detection was bypassed or occurred later. Option D is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent unauthorized data exfiltration, not to detect malicious files or malware.

183
MCQmedium

A security operations center (SOC) analyst is investigating an incident involving a user who received a phishing email with a malicious macro. The analyst needs to determine if any other users received the same email. Which Microsoft 365 Defender feature should the analyst use?

A.Advanced Hunting
B.Alert queue filtering
C.Threat Explorer (Investigation)
D.Email entity page
AnswerC

Threat Explorer (Investigation) is the correct choice because it is a purpose-built email security search tool that lets the analyst search all mail across the organization using filters like sender, recipient, subject, message ID, and delivery status. It provides a comprehensive, KQL-free view of every instance of the email, including delivery actions and threat detections, and supports direct remediation. This makes it the natural first tool for locating and analyzing a specific reported email.

Why this answer

Threat Explorer in Microsoft 365 Defender allows hunting for email messages by sender, subject, or other attributes. Advanced Hunting is for raw queries; Email entity page shows one email; Alert queue filters by alert not email.

184
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You are responsible for managing the security operations environment. Recently, the SOC team reported that incidents from Microsoft Defender for Endpoint are not appearing in Microsoft Sentinel. You have already configured the data connector for Microsoft Defender XDR and verified that logs are flowing into the 'SecurityAlert' table. However, incidents are not being created in Sentinel. What should you do?

A.Enable 'Create incidents from Microsoft 365 Defender' in the Microsoft Defender XDR data connector.
B.Create an analytics rule that queries the SecurityAlert table and generates incidents.
C.Verify the Azure Sentinel solution is installed and enable the streaming of incidents.
D.Configure the Microsoft Defender for Endpoint data connector.
AnswerA

Enabling 'Create incidents from Microsoft 365 Defender' on the Microsoft Defender XDR data connector is the designated method for ingesting already-correlated incidents into Microsoft Sentinel. This toggle allows the connector to pull Defender XDR incidents directly from the Microsoft Graph Security API, ensuring Sentinel receives the full incident with its related alerts, entities, and attack story. Without this setting, the connector would only ingest raw alerts, leaving you to rebuild the correlation that Defender XDR already performed, which defeats the purpose of unified incident management.

Why this answer

Enabling 'Create incidents from Microsoft 365 Defender' in the Microsoft Defender XDR data connector (A) is the correct action. This setting allows Microsoft Sentinel to automatically create incidents from alerts generated by Microsoft Defender XDR, including those from Defender for Endpoint. Even though alerts are flowing into the SecurityAlert table, incident creation requires this specific toggle to be enabled.

Exam trap

SC-200 often tests the distinction between data ingestion and incident creation, causing candidates to focus on analytics rules or other connectors when the missing step is enabling the incident creation toggle in the Defender XDR connector.

How to eliminate wrong answers

Option B is wrong because creating an analytics rule that queries SecurityAlert would generate incidents, but it is not the native integration method and may duplicate or miss incidents; the built-in connector setting is the intended solution. Option C is wrong because the Azure Sentinel solution installation and streaming of incidents is not the correct configuration for this scenario; the data connector already exists. Option D is wrong because configuring the Microsoft Defender for Endpoint data connector is unnecessary since the Defender XDR connector is already configured and logs are flowing.

185
MCQeasy

You are a security operations analyst for a company that uses Microsoft Sentinel. You need to ensure that all incidents generated by a specific analytics rule are automatically assigned to a specific analyst group. What should you do?

A.Create a playbook that queries the incidents table for incidents from the analytics rule and uses the Microsoft Sentinel API to assign them to the analyst group on a schedule.
B.Create an automation rule that triggers when an incident is created, with a condition on the analytics rule name, and an action to assign the incident to the analyst group.
C.Configure a workbook that displays incidents filtered by the analytics rule and instruct the analyst group to monitor it and self-assign incidents.
D.Modify the analytics rule to include a custom entity mapping that specifies the analyst group as the owner.
AnswerB

Automation rules in Microsoft Sentinel can trigger on incident creation and evaluate conditions such as the analytics rule name. The 'Assign owner' action can set the incident owner to a user or group. This directly meets the requirement with minimal effort and is the native method for automatic assignment.

Why this answer

Microsoft Sentinel automation rules are purpose-built for automatic incident handling. By triggering on incident creation and conditioning on the analytics rule name, the rule can apply the 'Assign owner' action to route all relevant incidents to the specified analyst group. This is the native, low-effort method and ensures immediate assignment without custom code or manual intervention.

Exam trap

The trap here is confusing entity mapping with ownership assignment; entity mapping is for investigation entities, not for setting incident owners.

186
MCQhard

A SOC analyst is using Microsoft Sentinel to investigate an incident involving a user who accessed a sensitive database from an unusual location. The analyst wants to find all activities performed by this user within the last 24 hours from multiple data sources. Which KQL operator should the analyst use to combine the results of two queries that return different schemas?

A.summarize
B.join
C.union
D.where
AnswerC

The KQL `union` operator is the correct choice because it appends rows from two or more tables vertically into a single result set. If the tables have different columns, `union` returns all distinct columns and fills missing values with nulls, which is exactly what is needed to consolidate security data from various sources like SigninLogs, SecurityEvent, and AzureActivity. In Sentinel hunting queries, `union` allows an analyst to stack data sources with different schemas without losing any columns and is standard for cross-source investigation.

Why this answer

The union operator in KQL combines the results of two or more queries that may have different schemas, appending rows and filling missing columns with nulls. This is exactly what the analyst needs to pull user activity from multiple data sources (e.g., SigninLogs, AuditLogs, OfficeActivity) into a single result set for the last 24 hours. join, by contrast, requires matching columns and merges rows horizontally.

Exam trap

SC-200 often tests the difference between union (append, different schemas) and join (match, same key columns), causing candidates to pick join when the question explicitly says 'different schemas'.

How to eliminate wrong answers

Option A is wrong because summarize aggregates data (count, sum, avg, etc.) and does not combine result sets from different queries. Option B is wrong because join merges rows from two tables based on matching key columns and requires compatible schemas — it does not append results with different schemas. Option D is wrong because where filters rows in a single query and does not combine multiple queries at all.

187
MCQeasy

Your organization uses Microsoft Sentinel. You have configured a data connector to ingest events from a third-party firewall. However, you notice that the logs are not appearing in Sentinel. What is the first thing you should check?

A.Check the firewall's syslog server configuration.
B.Verify that the workspace is in the correct region.
C.Reinstall the Log Analytics agent on the firewall.
D.Check the connector health page in Microsoft Sentinel.
AnswerD

Checking the connector health page in Microsoft Sentinel is the correct first step because it provides a centralized view of each data connector's status, including whether it's connected, when the last event was received, and any ingestion errors. This page also shows the connector type, relevant log tables, and version information. If the connector is healthy, the issue likely lies in the source device or forwarder; if unhealthy, you can see specific error messages and take targeted corrective action.

Why this answer

The connector health page in Microsoft Sentinel is the first place to check because it shows whether the data connector is connected, when data was last received, and any ingestion errors. If the connector shows a healthy status but no data arrives, the issue is likely upstream (firewall or agent); if it shows disconnected or error, the problem is with the connector itself. This diagnostic step narrows the fault domain before investigating the firewall or agent.

Exam trap

SC-200 often tests troubleshooting order — candidates jump to source-side or remediation actions (firewall config, agent reinstall) instead of first using Sentinel's built-in connector health telemetry to localize the fault.

How to eliminate wrong answers

Option A is wrong as a first step because checking the firewall's syslog configuration assumes the problem is on the source side, but you should first confirm whether Sentinel is even receiving anything via the connector health page — otherwise you may troubleshoot the wrong layer. Option B is wrong because workspace region affects data residency and feature availability, not whether logs from a configured connector appear; region mismatch would not silently drop ingested events. Option C is wrong because reinstalling the Log Analytics agent is a disruptive remediation step, not a diagnostic first step, and for a third-party firewall connector the agent may not even be the ingestion path (many use syslog via a Linux forwarder or CEF).

188
MCQmedium

Your organization uses Microsoft Sentinel. You need to configure a playbook that automatically responds to incidents by creating a support ticket in ServiceNow. Which connector should you use?

A.HTTP connector
B.ServiceNow connector
C.Azure Monitor connector
D.Office 365 Outlook connector
AnswerB

The ServiceNow connector in Microsoft Sentinel provides a native, out-of-the-box integration that allows security operations teams to automatically create, update, and close incidents as ServiceNow tickets. It leverages the ServiceNow API with prebuilt authentication handling and a data collection rule, eliminating the need for custom code or manual API calls. This directly meets the requirement to configure the environment for ticket creation, making it the correct choice.

Why this answer

The ServiceNow connector is the correct choice because it provides a direct, pre-built integration between Microsoft Sentinel and ServiceNow, enabling automated creation of incidents or tickets in ServiceNow when a Sentinel incident is triggered. This connector uses the ServiceNow REST API to map Sentinel fields to ServiceNow ticket fields, eliminating the need for custom HTTP calls or additional middleware.

Exam trap

The trap here is that candidates may choose the HTTP connector thinking it is more flexible, but the ServiceNow connector is the purpose-built, supported solution that handles authentication and field mapping natively, making it the correct choice for this specific integration.

How to eliminate wrong answers

Option A is wrong because the HTTP connector is a generic connector that requires manual configuration of endpoints, authentication, and payload formatting, which is more complex and error-prone than using a dedicated ServiceNow connector. Option C is wrong because the Azure Monitor connector is designed to send data from Azure Monitor to other systems, not to create tickets in ServiceNow from Sentinel incidents. Option D is wrong because the Office 365 Outlook connector is used for email-based actions (e.g., sending notifications) and does not support direct integration with ServiceNow's ticketing system.

189
MCQhard

Your organization uses Microsoft Sentinel in a multi-workspace environment with a central SOC. You need to create a single incident view across all workspaces while minimizing latency. What should you deploy?

A.Use cross-workspace queries in a workbook
B.Enable incident across workspaces in Microsoft Sentinel
C.Merge all workspaces into one Log Analytics workspace
D.Set up Azure Lighthouse and connect workspaces
AnswerB

The 'Enable incident across workspaces' feature in Microsoft Sentinel is a built-in capability that creates a central incident view by aggregating incidents from up to 100 Sentinel workspaces, typically spread across regions or tenants, into a single incident list. It leverages Azure Lighthouse for onboarding, but the key is that Sentinel's incident pipeline synchronizes incidents (by incident ARM ID) into a designated central workspace, preserving the original workspace context for each incident. This gives security operations teams a unified queue for detection, investigation, and response without migrating or re-ingesting any data.

Why this answer

Microsoft Sentinel's 'Incident across workspaces' feature (enabled via the 'SecurityIncident' table union) provides a single incident view across multiple workspaces with minimal latency by leveraging built-in cross-workspace incident synchronization. This avoids the overhead of manual queries or external orchestration, ensuring near-real-time incident correlation for a central SOC.

Exam trap

The trap here is that candidates often confuse Azure Lighthouse (which provides cross-workspace visibility through delegated access) with the native incident synchronization feature, not realizing that Lighthouse alone does not create a unified incident view and requires additional manual configuration to achieve the same low-latency result.

How to eliminate wrong answers

Option A is wrong because cross-workspace queries in a workbook are read-only and do not create a unified incident management view; they are for ad-hoc analysis, not operational incident handling, and introduce latency from repeated query execution. Option C is wrong because merging workspaces violates multi-workspace architecture requirements, causes data ingestion and retention cost bloat, and is not a scalable solution for a central SOC. Option D is wrong because Azure Lighthouse enables delegated resource management but does not natively provide a single incident view across workspaces; it requires additional configuration and does not minimize latency as effectively as the built-in incident synchronization.

190
MCQmedium

During an incident, an analyst finds that a user's account was compromised and used to send spam. The analyst needs to revoke all active sessions for that user. What should the analyst do?

A.Reset the user's password.
B.Revoke the user's sessions in Microsoft Entra ID.
C.Create a Conditional Access policy to block the user.
D.Disable the user account in Microsoft Entra ID.
AnswerB

Revoking sessions in Microsoft Entra ID invalidates all refresh tokens and active sessions for the compromised account, immediately cutting off the attacker's access while the password is reset. This directly satisfies the requirement to revoke all active sessions.

Why this answer

Revoking sessions in Microsoft Entra ID immediately invalidates all refresh tokens and active sign-in sessions for the compromised user, cutting off the attacker's access without disrupting the account's ability to be re-secured. This is the targeted response for session hijacking because it terminates existing tokens rather than just changing credentials. Password reset alone does not invalidate already-issued tokens, so the attacker could remain authenticated.

Exam trap

SC-200 often tests the misconception that resetting a password immediately logs out an attacker — candidates must recognize that token revocation is the only action that invalidates existing sessions.

How to eliminate wrong answers

Option A is wrong because resetting a password does not revoke existing refresh tokens or access tokens — the attacker's active session can persist until token expiry. Option C is wrong because creating a Conditional Access policy to block the user is a preventive control applied at future sign-in attempts, not an immediate revocation of already-issued sessions. Option D is wrong because disabling the account blocks future authentication but does not necessarily terminate already-issued refresh tokens, and it is a broader, more disruptive action than session revocation.

191
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. A security investigator discovers that a user's session token was stolen and used to access sensitive data in SharePoint Online from an anomalous IP address. You need to immediately revoke the attacker's access while minimizing impact on the legitimate user. What should you do?

A.Suspend the user account in Microsoft Entra ID until the investigation is complete.
B.From Microsoft Defender for Cloud Apps, use the 'Require re-authentication' action on the anomalous session.
C.Revoke all refresh tokens for the user in Microsoft Entra ID.
D.Reset the user's password immediately.
AnswerB

The 'Require re-authentication' action is a session-level conditional access app control in Microsoft Defender for Cloud Apps that terminates only the specific anomalous session, leaving the user's other active sessions unaffected. It forces both the user and the attacker to re-authenticate, effectively invalidating the stolen access token for that session and any associated refresh token for that session context. Because it is applied solely to the identified risky session, it minimizes user productivity loss while successfully revoking the attacker's unauthorized access, making it the most targeted and proportionate response.

Why this answer

The 'Require re-authentication' action in Microsoft Defender for Cloud Apps immediately terminates the attacker's session by invalidating the stolen session token, forcing the attacker to re-authenticate. This action targets only the anomalous session, leaving the legitimate user's other sessions intact and minimizing disruption. It directly addresses the session token theft without affecting the user's account status or requiring password changes.

Exam trap

The trap here is that candidates confuse session-level remediation (requiring re-authentication for a specific session) with account-level remediation (suspending the user or resetting passwords), failing to recognize that the stolen token is independent of the user's credentials and can be invalidated without affecting other sessions.

How to eliminate wrong answers

Option A is wrong because suspending the user account in Microsoft Entra ID would block all access for the legitimate user, causing unnecessary disruption and potentially locking them out of critical resources while the investigation is ongoing. Option C is wrong because revoking all refresh tokens for the user in Microsoft Entra ID would invalidate all sessions, including the legitimate user's active sessions, forcing them to re-authenticate everywhere and causing significant productivity loss. Option D is wrong because resetting the user's password immediately would not revoke the stolen session token; the attacker could still use the existing token until it expires, and it would also disrupt the legitimate user's access across all services.

192
Multi-Selectmedium

Which THREE resources can be used as data sources for Microsoft Sentinel to detect security incidents? (Choose three.)

Select 3 answers
A.Microsoft 365 Defender
B.Microsoft Defender for Cloud
C.Azure Activity Log
D.Azure Cost Management
E.Azure Advisor
AnswersA, B, C

Microsoft 365 Defender is a valid data source because its built-in connector streams unified alerts and incidents from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into Microsoft Sentinel. These security signals include attacker activities, malware events, and phishing detections, which are mapped directly to Sentinel's incident schema for correlation and investigation.

Why this answer

Options A, B, and C are correct. Microsoft 365 Defender provides integrated threat signals across endpoints, email, and identities. Microsoft Defender for Cloud delivers security alerts and posture assessments for cloud workloads.

Azure Activity Log captures subscription-level operational events, which can be streamed to Sentinel. Option D is incorrect because Azure Cost Management focuses on cost tracking and budgeting, not security events. Option E is incorrect because Azure Advisor provides optimization recommendations, not security incident data.

193
MCQhard

During an incident response, you need to collect forensic evidence from a compromised Azure virtual machine that is currently offline. What is the most efficient method to acquire a disk snapshot for analysis while preserving the integrity of the evidence?

A.Attach a new data disk and copy the contents manually
B.Create a snapshot of the OS disk from the Azure portal
C.Start the VM and use Azure Backup to take a backup
D.Export the disk to a storage account using AzCopy
AnswerB

Creating a snapshot of the OS disk from the Azure portal is the correct first step because it produces a read-only, point-in-time copy of the entire virtual disk without powering on the VM, ensuring no writes alter the original evidence. The snapshot captures the raw disk structure including deleted data and file slack, and you can later attach it to a secure analysis VM or use it to instantiate a new disk for offline forensic examination, while storing the snapshot in a separate, access-controlled resource group to maintain chain of custody.

Why this answer

Exporting a disk via AzCopy is not the most efficient forensic-sound method here because it requires first generating a SAS URL for the disk (e.g., via Grant-AzDiskAccess), which typically means the disk should not be attached to a running VM — the opposite of what this option implies. Even done correctly, going straight to an AzCopy export skips the read-only, platform-level point-in-time snapshot step, so any error or interruption during export risks touching the original disk. Taking a snapshot first (option B) is safer and is the standard first step; the snapshot can subsequently be exported with AzCopy for offline analysis if needed.

194
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident has been generated from Microsoft Defender for Cloud indicating that a Linux VM in Azure is running a cryptocurrency miner. The VM is part of a production application and cannot be shut down immediately. The incident severity is High. You need to contain the threat while maintaining application availability, investigate the root cause, and prevent recurrence. The environment includes Azure Policy, Microsoft Defender for Endpoint on the VM, and a Log Analytics workspace. You must minimize manual steps. What course of action should you take?

A.Remotely connect to the VM and run a script to kill the miner process, then update antivirus definitions
B.Remove the VM from the load balancer, then use Azure Policy to enforce that all VMs have antivirus enabled
C.Stop the VM immediately, take a snapshot for forensic analysis, and then redeploy a clean VM from a backup
D.Use Microsoft Sentinel automation to apply a block rule on the VM's network security group (NSG) to block outbound traffic to known mining pools, initiate Live Response to collect evidence, and create an Azure Policy to automatically deploy Microsoft Defender for Endpoint on all VMs
AnswerD

Using Sentinel automation to block outbound traffic to mining pools via NSG rules contains the threat without affecting legitimate traffic; Live Response collects evidence for investigation; Azure Policy to enforce Defender for Endpoint deployment prevents future occurrences by ensuring all VMs have EDR coverage.

Why this answer

It uses Microsoft Sentinel automation to apply a network security group (NSG) rule to block outbound traffic to known mining pools, which contains the threat without disrupting the VM's availability for production traffic. Initiating Live Response on the VM allows collection of forensic evidence for investigation. Creating an Azure Policy to enforce Microsoft Defender for Endpoint deployment on all VMs helps prevent recurrence by ensuring all VMs have endpoint detection and response (EDR) capabilities.

Option A is incorrect because remotely connecting and killing the process is a manual step that does not block the miner from restarting or communicating outbound, and it may not be immediately effective. Option B is incorrect because removing the VM from the load balancer alone does not stop the miner from running locally or potentially communicating via other routes, and Azure Policy for antivirus is insufficient for modern threats like miners. Option C is incorrect because stopping the VM immediately would disrupt production, and taking a snapshot then redeploying from backup does not address the immediate containment of the threat on the current VM.

195
MCQeasy

You need to ensure that critical incidents in Microsoft Sentinel are automatically assigned to a senior security analyst. What should you configure?

A.Create an analytics rule with a custom schedule.
B.Configure a workbook to filter incidents by owner.
C.Add the analyst to a watchlist used in analytics rules.
D.Create an automation rule that assigns the incident to the analyst.
AnswerD

Automation rules are the only one of these options that directly acts on incident properties after an incident is created or updated. You can configure a rule with conditions like 'incident title contains critical' and an action of 'Assign to analyst,' which automatically sets the owner field to the chosen analyst. This is the intended, supported mechanism in Microsoft Sentinel for ensuring critical incidents are owned by a specific person.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific users or groups based on conditions like severity or title. By creating an automation rule that triggers on incident creation and sets the owner to the senior security analyst, you ensure critical incidents are assigned without manual intervention.

Exam trap

The trap here is that candidates confuse automation rules (which handle incident lifecycle actions like assignment) with analytics rules (which generate alerts), leading them to pick option A incorrectly.

How to eliminate wrong answers

Option A is wrong because analytics rules with custom schedules are used to generate alerts from log data, not to assign ownership of incidents. Option B is wrong because workbooks are visualization tools that display data, not mechanisms for assigning incident ownership. Option C is wrong because watchlists are used to correlate data or filter alerts in analytics rules, not to assign incidents to specific users.

196
MCQhard

During an incident, you need to isolate a compromised device from the network while allowing communication with Microsoft Defender for Endpoint cloud services. Which isolation type should you choose in Microsoft Defender XDR?

A.Controlled folder access
B.Network protection
C.Block file
D.Full isolation
E.Selective isolation
AnswerE

Selective isolation is the preferred containment action in Microsoft Defender for Endpoint because it blocks all network traffic except communication with the Defender for Endpoint cloud service. This preserves the sensor's ability to send telemetry and receive automated or manual remediation commands, so the security team retains visibility and control during the incident. It effectively halts lateral movement and command-and-control while keeping the device within the security management plane, making it the only option that both contains the threat and maintains operational monitoring.

Why this answer

Selective isolation (E) is the correct choice because it restricts network communication to only Microsoft Defender for Endpoint cloud services, blocking all other inbound and outbound traffic. This allows the compromised device to remain manageable and receive security updates while preventing lateral movement and further compromise. Full isolation would block all network traffic, including Defender services, rendering the device unmanageable.

Exam trap

The trap here is that candidates often confuse 'full isolation' with 'selective isolation,' assuming full isolation is always the safest choice, but they overlook that full isolation breaks the device's ability to communicate with Defender cloud services, making it unmanageable.

How to eliminate wrong answers

Option A is wrong because Controlled folder access is a Windows Defender Exploit Guard feature that protects files and folders from unauthorized changes by untrusted applications, not a network isolation mechanism. Option B is wrong because Network protection is a feature that blocks outbound connections to malicious IPs/domains using the Windows Filtering Platform, but it does not isolate a device from the network while selectively allowing Defender cloud services. Option C is wrong because Block file is an action in Microsoft Defender for Endpoint that prevents a specific file from executing or being written, not a device-level network isolation.

Option D is wrong because Full isolation blocks all network traffic, including communication with Microsoft Defender for Endpoint cloud services, which would prevent the device from receiving policy updates or reporting telemetry.

197
Multi-Selecthard

Which THREE are valid methods to collect forensic evidence from a compromised Windows machine during incident response in Microsoft Defender XDR? (Choose three.)

Select 3 answers
A.Reset the device to a clean state
B.Collect a memory dump from the device using Live Response
C.Perform a full disk image using Microsoft Defender for Endpoint
D.Run Live Response commands to collect files and run scripts
E.Export Windows Event Logs using Live Response
AnswersB, D, E

Live Response in Microsoft Defender XDR supports running the `Get-File` and memory-dump collection commands directly on a compromised Windows endpoint, satisfying the requirement to gather volatile forensic evidence without disrupting the device. This preserves RAM contents that would otherwise be lost on shutdown, which is essential for incident response.

Why this answer

Options B, D, and E are correct: Live Response allows script execution and file collection; collecting a memory dump captures volatile evidence necessary for forensic analysis; exporting Windows Event Logs provides a timeline of events. Option A is incorrect because resetting the device destroys evidence instead of preserving it. Option C is incorrect because full disk imaging is not natively supported in Microsoft Defender XDR; it requires external tools.

198
MCQeasy

Your organization uses Microsoft Purview Data Loss Prevention (DLP). You need to receive an alert when a user attempts to share a credit card number via email. What should you configure?

A.Create a sensitivity label that blocks sharing.
B.Create a DLP policy in Microsoft Purview with the credit card number sensitive info type.
C.Create a retention label that identifies credit card data.
D.Create a file policy in Microsoft Defender for Cloud Apps.
AnswerB

A DLP policy in Microsoft Purview is the correct control because it can be configured with the Credit Card Number sensitive info type, which uses pattern matching and checksum validation to detect this data in Exchange Online mail. The policy can specify an action to send an alert to the security team whenever the data is detected, meeting the alerting requirement precisely.

Why this answer

Microsoft Purview DLP policies can be configured to detect sensitive information types, such as credit card numbers, and trigger alerts when users attempt to share that data via email. By creating a DLP policy with the credit card number sensitive info type and setting an action to send an alert, you meet the requirement to receive an alert on such sharing attempts.

Exam trap

The trap here is that candidates often confuse sensitivity labels or retention labels with DLP policies, not realizing that only DLP policies can directly detect and alert on sensitive data in transit like email sharing.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used for classification and protection (e.g., encryption or visual markings) but do not natively generate alerts on sharing attempts; they require integration with DLP or other mechanisms for alerting. Option C is wrong because retention labels are designed to manage data lifecycle and retention policies, not to detect or alert on sharing of sensitive data. Option D is wrong because a file policy in Microsoft Defender for Cloud Apps focuses on monitoring and controlling cloud app usage, not directly on email sharing within Exchange Online; DLP policies in Purview are the correct tool for email-based sensitive data detection.

199
MCQhard

Your company uses Microsoft Defender XDR. The security team needs to restrict access to the Microsoft Defender portal so that only analysts in the 'Security Operations' group can view incidents. What is the most efficient way to achieve this?

A.Assign the Security Operations group the Defender for Endpoint administrator role.
B.Configure Conditional Access policy to allow only Security Operations group to sign in to the Defender portal.
C.Assign the Security Operations group the Security Reader role in Microsoft Entra ID.
D.Create a custom role in the Microsoft Defender portal with permissions to view incidents and assign it to the Security Operations group.
AnswerD

Microsoft Defender XDR supports custom roles created in the portal with granular permissions, such as the specific 'View incidents' permission under the Security operations category. Assigning that custom role to the Security Operations group grants them exactly the read-only incident access they need without broadening to endpoint management or unrelated security workloads. This is the precise, least-privilege approach and aligns with Defender XDR's unified RBAC model for isolated access to alert and incident data.

Why this answer

Microsoft Defender XDR uses role-based access control (RBAC) within the portal itself. Creating a custom role with permissions to view incidents and assigning it to the Security Operations group directly controls access to incident data without affecting broader Azure AD roles or requiring Conditional Access policies. This is the most efficient method as it scopes permissions precisely to the Defender portal's incident management functionality.

Exam trap

The trap here is that candidates often confuse Azure AD roles (like Security Reader) with Defender portal RBAC roles, or assume Conditional Access can control data-level permissions, when in fact only custom Defender roles can restrict incident viewing to a specific group without granting broader privileges.

How to eliminate wrong answers

Option A is wrong because the Defender for Endpoint administrator role grants full administrative access to the Defender for Endpoint configuration and settings, not just incident viewing, which is overly permissive and violates the principle of least privilege. Option B is wrong because Conditional Access policies control authentication and sign-in access to the portal, not authorization to view specific data like incidents; they can block sign-in entirely but cannot restrict what a signed-in user sees within the portal. Option C is wrong because the Security Reader role in Microsoft Entra ID provides read-only access to security-related information across Azure services, but it does not grant granular permissions to view incidents specifically within the Microsoft Defender portal; it is a broad Azure AD role, not a Defender-specific RBAC role.

200
MCQeasy

You are configuring Microsoft Sentinel SOAR capabilities. You need to create an automated response that, when a critical incident is created, triggers a playbook that sends a message to a Teams channel. Which connector should you use in the playbook?

A.Microsoft Exchange connector
B.Azure DevOps connector
C.Microsoft Teams connector
D.Microsoft Entra ID connector
AnswerC

The Microsoft Teams connector in Sentinel automation rules can post messages to a Teams channel or send adaptive cards, which is the standard way to notify analysts of incidents. It supports actions such as 'Post message (V3)' that can include incident details, and it also allows for approval flows via Teams. This aligns with the requirement to configure SOAR capabilities for messaging a team.

Why this answer

The Microsoft Teams connector is the correct choice because it enables the playbook to post messages directly to a Teams channel via an HTTP trigger and the Teams webhook action. This connector is specifically designed for sending notifications and messages to Teams, which aligns with the requirement to alert a channel when a critical incident is created.

Exam trap

The trap here is that candidates may confuse the Microsoft Teams connector with the Microsoft Exchange connector, assuming both can send notifications, but Exchange is strictly for email, not Teams messaging.

How to eliminate wrong answers

Option A is wrong because the Microsoft Exchange connector is used for email-related operations (e.g., sending emails, managing mailboxes), not for posting messages to Teams channels. Option B is wrong because the Azure DevOps connector is designed for managing work items, pipelines, and repositories in Azure DevOps, not for sending messages to Teams. Option D is wrong because the Microsoft Entra ID connector (formerly Azure AD) is used for identity and access management tasks (e.g., managing users, groups, and roles), not for sending messages to Teams channels.

201
MCQmedium

A security analyst detects a suspicious sign-in from an unfamiliar IP address for a user with high privileges. The analyst wants to immediately contain the threat while preserving the user's ability to work with proper approvals. What is the most effective first step?

A.Block the IP address in the firewall.
B.Disable the user account in Microsoft Entra ID.
C.Reset the user's password without revoking sessions.
D.Initiate a user risk remediation in Microsoft Entra ID Protection by confirming compromise and resetting password with session revocation.
AnswerD

Initiating user risk remediation in Microsoft Entra ID Protection is the correct, containment-focused response because it lets you confirm the sign-in as compromised, immediately revoke all refresh tokens and session cookies, and force the user to reauthenticate with a new password. This directly neutralizes the attacker's token-based access while preserving the legitimate user's ability to regain access after verification. It combines detection with automated, policy-driven response and is the documented best practice for handling confirmed user risk in Entra ID.

Why this answer

It directly addresses the immediate threat by confirming compromise in Microsoft Entra ID Protection, which triggers a password reset and revokes all existing sessions, effectively terminating the attacker's access. This approach preserves the user's ability to work after re-authentication with proper approvals, as the account remains enabled and can be restored once the risk is mitigated. It is the most effective first step because it combines containment (session revocation) with remediation (password reset) while maintaining operational continuity.

Exam trap

The trap here is that candidates may choose to disable the user account (Option B) thinking it is the fastest containment, but they overlook that session revocation is necessary to stop active attacker sessions, and disabling the account also blocks the legitimate user without a clear path for re-enabling with approvals.

How to eliminate wrong answers

Option A is wrong because blocking the IP address in the firewall is a network-level control that does not revoke the attacker's existing authenticated session; the attacker may still have active tokens or cookies that bypass the firewall. Option B is wrong because disabling the user account in Microsoft Entra ID completely prevents the user from working, even with proper approvals, and does not automatically revoke existing sessions or tokens, leaving potential for lateral movement. Option C is wrong because resetting the password without revoking sessions leaves the attacker's active tokens and sessions intact, allowing continued access despite the password change.

202
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. The security team wants to automatically create an incident in Microsoft Sentinel when a Microsoft Defender for Endpoint alert is triggered. What should you configure?

A.Enable the Microsoft Defender XDR connector in Microsoft Sentinel and select the incident creation settings.
B.Set up a Logic App custom connector to poll Defender alerts.
C.Configure the Security Events connector to forward Defender alerts.
D.Create analytics rules in Microsoft Sentinel for each Defender alert type.
AnswerA

Enabling the Microsoft Defender XDR connector streams Defender for Endpoint alerts into Microsoft Sentinel, where the "Create incidents" toggle governs automatic incident generation. This directly satisfies the requirement to auto-create Sentinel incidents from endpoint alerts, since the connector's incident creation setting is the mechanism controlling that behaviour.

Why this answer

The Microsoft Defender XDR connector in Microsoft Sentinel is specifically designed to ingest alerts and incidents from Microsoft Defender for Endpoint and other Defender products. By enabling this connector and configuring its incident creation settings, Sentinel automatically creates incidents when Defender for Endpoint alerts are triggered, without requiring custom logic or manual polling.

Exam trap

The trap here is that candidates often confuse the purpose of analytics rules (which generate alerts from raw data) with the connector's role (which ingests pre-existing alerts from external sources), leading them to incorrectly select Option D.

How to eliminate wrong answers

Option B is wrong because a Logic App custom connector would require building a custom polling mechanism, which is unnecessary and inefficient when the native Microsoft Defender XDR connector already provides automated, real-time incident ingestion. Option C is wrong because the Security Events connector is used to collect Windows security event logs (e.g., Event ID 4625) from on-premises or cloud-based systems, not Defender for Endpoint alerts. Option D is wrong because analytics rules in Sentinel are used to generate alerts from raw data sources (like Syslog or Windows Events), not to import existing alerts from Defender for Endpoint; the connector handles that ingestion automatically.

203
MCQmedium

You are configuring Microsoft Sentinel automation rules to handle incidents generated from Microsoft Defender for Cloud. You need to ensure that when a high-severity security alert is triggered, an automated response runs a playbook that creates a support ticket in ServiceNow. However, the playbook fails to execute for some alerts. Upon investigation, you find that the automation rule is triggered only when the incident is created. What is the most likely cause of the failure?

A.The automation rule is configured to trigger only on incident creation, but the playbook requires the incident to be in an updated state.
B.The automation rule lacks permissions to the ServiceNow connector because of Microsoft Entra ID conditional access policies.
C.Playbooks cannot be called by automation rules in Microsoft Sentinel.
D.Automation rules cannot be triggered on incident creation from Microsoft Defender for Cloud.
AnswerA

The automation rule's trigger is the likely culprit. In Microsoft Sentinel, automation rules can be configured to run when an incident is created, when an incident is updated, or when an alert is generated. If your rule runs only at creation time, the playbook executes immediately after the incident is born, before any status changes, owner assignments, or alert grouping that would normally follow. Many playbooks—especially those using the Sentinel incident connector's 'Get incident' action—expect the incident to have these post-creation values, and without them the playbook may error out or take an incorrect action. To resolve this, you should create a second automation rule triggered on incident update, or change the trigger to match the playbook's dependency.

Why this answer

The automation rule is configured to trigger only on incident creation. However, the playbook requires the incident to be in an updated state to execute, meaning the automation rule does not fire when the incident is updated after creation. This mismatch causes the playbook to fail for alerts that require an update trigger.

Exam trap

The trap here is that candidates assume all playbooks can run on incident creation, but many playbooks require the incident to be updated first to access complete data, and the automation rule must be configured with the correct trigger condition.

How to eliminate wrong answers

Option B is wrong because conditional access policies in Microsoft Entra ID affect user authentication, not the service-to-service permissions used by automation rules and playbooks; the issue is about trigger timing, not permissions. Option C is wrong because playbooks can indeed be called by automation rules in Microsoft Sentinel; this is a core feature. Option D is wrong because automation rules can be triggered on incident creation from Microsoft Defender for Cloud; the problem is that the rule is not configured to trigger on updates.

204
MCQeasy

Your organization is using Microsoft Defender for Office 365. A user reports receiving a suspicious email that appears to be from the CEO requesting an urgent wire transfer. You need to investigate the email and take immediate action. What should you do first?

A.Use the Exchange admin center to run a message trace.
B.Use Threat Explorer in the Microsoft 365 Defender portal to find and delete the email.
C.Use the Security & Compliance Center to create a mail flow rule.
D.Submit the email to Microsoft for analysis using the Submissions page.
AnswerB

Threat Explorer in the Microsoft 365 Defender portal is the actual investigation-and-remediation surface for email threats; it combines a robust queryable event store with built-in actions. You can filter by threat type, sender, subject, or detection technology, select one or multiple messages, and directly delete (soft or hard) them from user mailboxes. For a suspicious email already delivered, this is the only option that both finds and removes it. Also supports in-place review of the payload and email summary.

Why this answer

Threat Explorer in the Microsoft 365 Defender portal provides the fastest and most direct way to investigate and remediate a specific suspicious email across all mailboxes. It allows you to search for the email by sender, subject, or recipient, and then take immediate action such as soft-delete or hard-delete to remove it from user inboxes. This is the correct first step for an urgent incident response scenario involving a targeted phishing attack.

Exam trap

The trap here is that candidates often confuse the purpose of message traces (delivery tracking) with the immediate remediation capabilities of Threat Explorer, or they mistakenly think that creating a mail flow rule can retroactively remove already delivered emails.

How to eliminate wrong answers

Option A is wrong because a message trace in the Exchange admin center is designed for delivery troubleshooting and tracking, not for immediate remediation or bulk deletion of a malicious email across multiple mailboxes. Option C is wrong because creating a mail flow rule in the Security & Compliance Center is a proactive configuration change that takes time to propagate and does not remove an already delivered email; it is not an immediate investigative or response action. Option D is wrong because submitting the email to Microsoft for analysis is a secondary step used for improving detection, not for urgent containment or removal of the threat from user mailboxes.

205
MCQhard

Refer to the exhibit. You are troubleshooting an endpoint that is not receiving real-time protection from Microsoft Defender Antivirus. The output shows RealTimeProtectionEnabled is False. Which command should you run next to enable real-time protection?

A.Set-MpPreference -DisableRealtimeMonitoring $false
B.Add-MpPreference -ExclusionPath C:\Temp
C.Start-MpScan
D.Update-MpSignature
AnswerA

Set-MpPreference -DisableRealtimeMonitoring $false is the correct command because it explicitly sets the DisableRealtimeMonitoring configuration to false, which re-enables Microsoft Defender's real-time scanning engine. This preference is the direct control for the monitoring state, and applying it reverses any setting that previously disabled the service. It is the only option that addresses the root cause of a disabled real-time protection rather than performing an unrelated action.

Why this answer

The Set-MpPreference cmdlet with the -DisableRealtimeMonitoring $false parameter is the correct command to enable real-time protection in Microsoft Defender Antivirus. The output shows RealTimeProtectionEnabled is False, which directly corresponds to the DisableRealtimeMonitoring setting; setting it to $false re-enables the feature. This cmdlet modifies the local policy for the Microsoft Defender Antivirus engine, immediately activating real-time scanning of file operations and process activity.

Exam trap

The trap here is that candidates often confuse disabling real-time monitoring with other maintenance tasks like scanning or updating signatures, assuming any Defender-related command will fix the protection state, but only Set-MpPreference directly controls the RealTimeProtectionEnabled flag.

How to eliminate wrong answers

Option B is wrong because Add-MpPreference -ExclusionPath C:\Temp adds a file or folder exclusion from scanning, which does not affect the RealTimeProtectionEnabled state; it only prevents Defender from scanning the specified path. Option C is wrong because Start-MpScan initiates a one-time on-demand scan (e.g., quick, full, or custom scan) but does not toggle the real-time protection setting; it runs a scan regardless of whether real-time monitoring is enabled. Option D is wrong because Update-MpSignature downloads and installs the latest security intelligence updates (virus definitions) but has no impact on the RealTimeProtectionEnabled flag; it updates signatures without enabling or disabling real-time protection.

206
MCQhard

Arrange the steps in the correct order to create and save a custom hunting query in Microsoft Sentinel.

A.Open the Microsoft Sentinel workspace in the Azure portal → Navigate to the Hunting blade in the Sentinel menu → Click on the 'New Query' button → Write the KQL query in the query editor → Run the query to verify results → Save the query with a meaningful name and description
B.Verify results before configuring the source or rule settings.
C.Configure alert grouping before defining the detection query or source.
D.Skip validation and enable the rule or plan immediately.
AnswerA

This sequence is the exact workflow for a Microsoft Sentinel saved hunting query. You must first select the Sentinel workspace, open the Hunting blade, and click 'New Query' to instantiate a blank query editor. Writing and running the KQL before saving is critical because Run executes the query against the workspace's Log Analytics tables and lets you validate the result set. Only after confirming the query returns the intended rows should you save it with a meaningful name and description for future hunting loops.

Why this answer

Creating a custom hunting query in Microsoft Sentinel requires first accessing the workspace, then navigating to the Hunting blade, clicking 'New Query', writing the KQL query, running it to validate results, and finally saving it with a meaningful name and description. This sequence ensures the query is tested before being stored, aligning with Sentinel's workflow for ad-hoc threat hunting.

Exam trap

The trap here is that candidates confuse the workflow for creating an analytics rule (which involves configuring source, alert grouping, and rule settings) with the simpler, validation-focused process for creating a hunting query, leading them to select options B, C, or D that describe rule creation steps rather than hunting query steps.

How to eliminate wrong answers

Option B is wrong because it describes verifying results before configuring source or rule settings, which is irrelevant to creating a hunting query—hunting queries are not tied to alert rules or data sources; they are standalone KQL searches. Option C is wrong because alert grouping is a configuration step for analytics rules, not for hunting queries; hunting queries do not involve alert grouping or detection logic. Option D is wrong because skipping validation and enabling the rule or plan immediately ignores the necessary step of running the query to verify its syntax and results, which is critical for ensuring the query returns meaningful data before saving.

207
MCQmedium

A threat hunter is investigating a potential compromise involving a user account that has been used to sign in from multiple locations within a short time. The hunter wants to use Microsoft Sentinel to find all sign-in events for that user from different IP addresses in the last 24 hours. Which KQL query should be used?

A.SigninLogs | where TimeGenerated > ago(24h) | where UserPrincipalName == "user@domain.com" | summarize count() by IPAddress
B.SecurityEvent | where TimeGenerated > ago(24h) | where TargetUserName == "user@domain.com" | summarize count() by IpAddress
C.AuditLogs | where TimeGenerated > ago(24h) | where InitiatedBy.user.userPrincipalName == "user@domain.com" | summarize count() by IPAddress
D.CommonSecurityLog | where TimeGenerated > ago(24h) | where SourceUserID == "user@domain.com" | summarize count() by SourceIP
AnswerA

SigninLogs holds Microsoft Entra ID interactive sign-in events with UserPrincipalName and IPAddress, so filtering the last 24 hours and summarising by IPAddress satisfies the requirement to enumerate distinct source addresses for that user. AADNonInteractiveUserSignInLogs would not match interactive portal sign-ins.

Why this answer

The SigninLogs table in Microsoft Sentinel stores Azure AD (Entra ID) interactive and non-interactive sign-in events, including the UserPrincipalName and IPAddress fields needed to trace a user's authentication activity across locations. Querying SigninLogs with a 24-hour time filter, matching on UserPrincipalName, and summarizing by IPAddress directly answers the hunter's question about which IPs the account signed in from. This is the canonical table for identity-based sign-in hunting in Sentinel.

Exam trap

SC-200 often tests whether candidates know which Sentinel table holds which telemetry type — specifically confusing Azure AD sign-in data (SigninLogs) with audit activity (AuditLogs) or on-prem Windows logons (SecurityEvent).

How to eliminate wrong answers

Option B is wrong because SecurityEvent holds Windows Security event log data (e.g., 4624/4625) from onboarded machines or the Log Analytics agent, not Azure AD sign-in telemetry, and TargetUserName/IpAddress refer to local or domain logon events rather than cloud identity sign-ins. Option C is wrong because AuditLogs contains Azure AD audit/activity events (like role changes or app consent) via the InitiatedBy property, not sign-in records, so it would miss authentication events entirely. Option D is wrong because CommonSecurityLog ingests CEF-formatted logs from third-party security appliances (firewalls, proxies, IDS), and SourceUserID/SourceIP reflect those devices' events, not Azure AD sign-in data.

208
Multi-Selecteasy

Which TWO tasks can you perform using Microsoft Sentinel automation rules?

Select 2 answers
A.Send an email notification without a playbook.
B.Assign an incident to an analyst.
C.Delete an incident.
D.Change the severity of an incident.
E.Create a new analytics rule.
AnswersB, D

Automation rules support the "Assign owner" action, which lets you set the incident's owner to a specific analyst, a group, or a user by email address. This action can be triggered when an incident is created or updated based on conditions such as severity or analytics rule, thereby enabling systematic incident triage and routing directly from the rule.

Why this answer

Automation rules in Microsoft Sentinel can directly assign incidents to specific analysts or groups without requiring a playbook. This is a native action within the automation rule configuration, enabling immediate ownership and accountability for incident response.

Exam trap

The trap here is that candidates often confuse automation rule capabilities with playbook actions, assuming email notifications or deletions are possible natively, but Microsoft Sentinel restricts automation rules to incident property changes and playbook triggers only.

209
MCQeasy

A company wants to enable vulnerability scanning for Azure virtual machines using the integrated Microsoft Defender Vulnerability Management solution. What is the first step?

A.Install the Defender Vulnerability Management extension on each VM.
B.Enable the 'Servers' plan in Defender for Cloud.
C.Configure a vulnerability assessment solution in the VM's security settings.
D.Create a vulnerability assessment rule in Azure Policy.
AnswerB

Enabling the Servers plan in Microsoft Defender for Cloud is the required subscription-level action that activates the built-in vulnerability assessment for Azure VMs. This plan automatically deploys the Defender Vulnerability Management solution to both existing and newly created VMs, and the resulting scans are surfaced as recommendations and findings within Defender for Cloud. Without this plan enabled, there is no integrated vulnerability scanning available.

Why this answer

The first step to enable vulnerability scanning for Azure VMs using the integrated Microsoft Defender Vulnerability Management solution is to enable the 'Servers' plan in Defender for Cloud. This plan activates the Defender for Cloud integration with Microsoft Defender Vulnerability Management, which automatically discovers and assesses vulnerabilities on supported Azure VMs without requiring any additional agent or extension installation. Once the plan is enabled, vulnerability assessment is performed natively by the Defender for Cloud platform.

Exam trap

The trap here is that candidates often assume a separate extension or agent must be installed (Option A) because they are familiar with traditional vulnerability scanning tools, but Microsoft Defender for Cloud's integrated solution is agentless and activated by enabling the 'Servers' plan.

How to eliminate wrong answers

Option A is wrong because the Defender Vulnerability Management extension is not required; the vulnerability scanning is built into the 'Servers' plan and does not need a separate extension to be installed on each VM. Option C is wrong because configuring a vulnerability assessment solution in the VM's security settings is a manual, legacy approach that is not the first step; the integrated solution is automatically enabled when the 'Servers' plan is turned on. Option D is wrong because creating a vulnerability assessment rule in Azure Policy is not the initial step; Azure Policy can be used to enforce compliance, but the prerequisite is enabling the 'Servers' plan in Defender for Cloud.

210
Multi-Selecthard

Which TWO actions should you take to ensure that Microsoft Sentinel can properly ingest logs from a Linux server running rsyslog? (Choose two.)

Select 2 answers
A.Install and configure syslog-ng instead of rsyslog
B.Configure rsyslog to forward logs to the agent on TCP 514
C.Install the Log Analytics agent (or Azure Monitor Agent) on the Linux server
D.Configure Windows Event Forwarding (WEF) to collect logs from the Linux server
E.Configure rsyslog to forward logs to the Log Analytics agent on UDP 25224
AnswersC, E

The Log Analytics agent (or Azure Monitor Agent) must be installed on the Linux server before any syslog collection can occur. The agent acts as the local collector: it listens on UDP 25224 for syslog messages forwarded by the rsyslog daemon, applies filtering rules for facilities and severities, and then sends the parsed events to the Log Analytics workspace. Without the agent, there is no component to receive and ingest the syslog stream, regardless of rsyslog configuration.

Why this answer

The Log Analytics agent (or Azure Monitor Agent) must be installed on the Linux server to receive and forward syslog data to Microsoft Sentinel. Without the agent, Sentinel has no direct mechanism to collect logs from the server. The agent listens for syslog messages forwarded by rsyslog and then sends them to the Log Analytics workspace.

Exam trap

The trap here is that candidates often assume syslog must be sent on the standard port 514 (TCP or UDP) or that replacing rsyslog with syslog-ng is necessary, but the Log Analytics agent specifically requires forwarding to UDP 25224 and works with rsyslog out of the box.

211
MCQeasy

A user reports receiving a suspicious email that bypassed the spam filter. An analyst opens the Microsoft 365 Defender portal to investigate. Which component provides a detailed entity view of the email including delivery actions, phish simulation details, and campaign information?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365 (Threat Explorer)
C.Microsoft Defender for Identity
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Defender for Office 365 Threat Explorer is the correct tool because it provides a granular email-focused entity view that includes delivery actions, threat types, phish simulation tags, and associated campaign information for messages that bypassed filtering. Analysts can pivot from a single email ID to see message traces, sender and recipient details, and the specific policy or isolation verdict applied. This investigative capability directly addresses the need to examine a suspicious email received despite the existing spam filter.

Why this answer

Microsoft Defender for Office 365's Threat Explorer (now part of the unified investigation experience) provides a detailed entity view of an email, including delivery actions (e.g., delivered to Junk, blocked, or allowed), whether the email was part of a phishing simulation, and the associated campaign information. This tool is specifically designed for deep email threat investigation within the Defender for Office 365 portal, leveraging telemetry from Exchange Online Protection (EOP) and Defender for Office 365.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365's Threat Explorer with Microsoft Defender for Endpoint's advanced hunting, but only Threat Explorer provides the specific email entity view with delivery actions, phish simulation flags, and campaign metadata required for this investigation.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint focuses on endpoint-level threats (e.g., malware, file-based attacks, and process behaviors) and does not provide email-specific entity views, delivery actions, or phish simulation details. Option C is wrong because Microsoft Defender for Identity monitors on-premises Active Directory signals for identity-based attacks (e.g., Kerberoasting, pass-the-hash) and has no capability to inspect email transport or campaign data. Option D is wrong because Microsoft Defender for Cloud Apps (formerly MCAS) provides visibility into cloud application usage and shadow IT, but it does not offer granular email delivery actions, phish simulation flags, or campaign tracking for individual messages.

212
MCQeasy

While threat hunting in Microsoft Defender for Cloud Apps, you notice a user has an unusually high number of failed login attempts from a single IP address. What is the most effective next step to determine if this is a brute-force attack?

A.Immediately block the IP address
B.Investigate the IP address in the Microsoft Defender for Cloud Apps Activity log to review all failed attempts
C.Create a new anomaly detection policy for that user
D.Check the user's device for malware
AnswerB

Reviewing all failed attempts from that IP in the Activity log reveals the pattern, volume and targeted accounts, confirming whether the behaviour constitutes brute-force credential guessing rather than isolated user error. This evidence-based correlation is the most effective next investigative step.

Why this answer

The most direct method is to investigate the IP address in the Microsoft Defender for Cloud Apps Activity log by filtering for that IP and reviewing the failed attempts. Option A (Immediately block the IP) is premature without confirming the pattern. Option C (Creating an anomaly detection policy) is for future detection, not for immediate analysis.

Option D (Checking the user's device for malware) is not relevant for cloud app access failures.

213
MCQmedium

You are investigating a potential ransomware incident in Microsoft Defender XDR. You need to identify files that have been modified with a known ransomware extension across all devices. Which advanced hunting operator should you use to search for file names ending with '.locked' in the DeviceFileEvents table?

A.endswith
B.contains
C.matches regex
D.startswith
AnswerA

The endswith operator checks if a string ends with a specified suffix. Using endswith '.locked' on the FileName column will accurately identify files that have been renamed with the '.locked' extension, which is characteristic of ransomware encryption. This operator is case-insensitive and efficient for this purpose.

Why this answer

To find files with a specific extension, you need to match the end of the file name. The endswith operator is designed for this purpose and will correctly identify files ending with '.locked'. Using contains might match unintended substrings, and startswith would look at the wrong end of the string.

Exam trap

The trap here is using contains instead of endswith, which can lead to false positives by matching the substring anywhere in the file name.

214
MCQeasy

A SOC analyst wants to create a scheduled analytics rule in Microsoft Sentinel that runs every hour and detects multiple failed user login attempts from a single IP address within a 5-minute window. Which KQL function should be used in the query to group the failed events by 5-minute time intervals?

A.summarize count() by IPAddress, bin(TimeGenerated, 5m)
B.summarize count() by IPAddress, TimeGenerated
C.extend interval = datetime_diff('minute', TimeGenerated, ago(5m))
D.scan with (match all events within 5m by IPAddress)
AnswerA

The bin(TimeGenerated, 5m) function rounds each event's timestamp down to the start of its containing five-minute interval, so summarize groups all events from the same IPAddress that occur within that same bucket and counts them as a single aggregate. This is the standard KQL pattern for time-windowed aggregation in scheduled analytics rules because it collapses many raw events into per-IP, per-window counts. Without a bin expression, the query would not define fixed time windows, making this the only option that correctly produces the desired 5-minute grouping.

Why this answer

The `bin()` function in KQL is specifically designed to group data into fixed-size time buckets, such as 5-minute intervals. By using `summarize count() by IPAddress, bin(TimeGenerated, 5m)`, the query counts failed login attempts per IP address within each 5-minute window, which directly meets the requirement for a scheduled rule that detects multiple failures from a single IP in a 5-minute period.

Exam trap

The trap here is that candidates often confuse the `bin()` function with simple grouping by timestamp (Option B) or mistakenly think that `datetime_diff` (Option C) can be used to group events, when in fact only `bin()` provides the correct fixed-interval bucketing required for time-windowed aggregations.

How to eliminate wrong answers

Option B is wrong because it groups by the exact `TimeGenerated` value (including seconds and milliseconds), not by 5-minute intervals, so it would produce separate counts for each individual timestamp rather than aggregating over the desired window. Option C is wrong because `datetime_diff` calculates the difference between two timestamps, but it does not group or bucket events; it only returns a scalar value for each row, making it unsuitable for aggregating events into time intervals. Option D is wrong because the `scan` operator is used for sequence analysis (e.g., detecting patterns across ordered events), not for simple time-based grouping; it is overly complex and not designed for bucketing by fixed time intervals.

215
Multi-Selecthard

You are responding to a ransomware incident where multiple devices are encrypted. The incident is captured in Microsoft Sentinel. Which TWO actions should you take first to contain the incident?

Select 2 answers
A.Disable user accounts associated with the affected devices in Microsoft Entra ID.
B.Isolate affected devices using Microsoft Defender for Endpoint.
C.Reset passwords for all affected users.
D.Run a malware analysis on a sample of the ransomware.
E.Restore encrypted files from backups.
AnswersA, B

Disabling the associated accounts in Microsoft Entra ID revokes authentication tokens and prevents the attacker reusing compromised credentials to re-encrypt or pivot. This satisfies containment by cutting the identity path, since ransomware operators routinely retain valid accounts to re-establish access after device-level cleanup.

Why this answer

Option A is correct because disabling the associated user accounts in Microsoft Entra ID immediately blocks the compromised identities from authenticating and prevents the attacker from using those credentials to move laterally or re-access resources during containment. Option B is correct because isolating affected devices through Microsoft Defender for Endpoint severs network communication while preserving the device state for forensic investigation, which is the standard first containment step for ransomware. Option C is not a first containment action; password resets are remediation steps that come after disabling accounts and can be performed later without stopping active spread.

Option D is incorrect because malware analysis is a post-containment investigative activity, not an immediate containment measure. Option E is incorrect because restoring from backups is a recovery action and should only occur after the threat is fully contained and eradicated, otherwise restored data can be re-encrypted.

Exam trap

The trap is confusing containment with recovery or investigation; candidates pick password resets or backup restoration because they sound urgent, but those are later phases — the first actions must stop the spread by isolating devices and disabling accounts.

216
Matchingmedium

Match each Microsoft Sentinel incident management action to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Designate an owner for the incident

Resolve the incident as false positive or true positive

Document investigation notes

Adjust impact level based on findings

Trigger automated response actions

Why these pairings

The correct matches are: Change incident status updates the state, Assign incident assigns to an analyst, and Close incident resolves. Common confusions involve swapping Add comments (for notes) and Add tags (for custom labels).

217
MCQeasy

You receive an alert in Microsoft Sentinel indicating a potential privilege escalation using the 'AzureHound' tool. You need to determine if the alert is a true positive. What is the first step you should take?

A.Check the user's recent activity and the targeted resource in Microsoft Entra ID audit logs
B.Review the Microsoft Defender for Cloud recommendation for the resource
C.Block the user account immediately
D.Run a full antivirus scan on all devices
AnswerA

Reviewing Microsoft Entra ID audit logs exposes the specific directory operations AzureHound performs, such as role assignments and service principal enumeration, letting you confirm whether the flagged activity is genuine privilege-escalation reconnaissance rather than benign administrative behaviour. This directly satisfies the stem's requirement to validate the alert before escalating.

Why this answer

To determine whether an AzureHound privilege-escalation alert is a true positive, you must validate the underlying identity activity — specifically what the user did and which resource was targeted — using Microsoft Entra ID audit logs. AzureHound enumerates Azure AD/Entra ID objects and permissions, so the audit trail of directory reads, role assignments, or consent grants is the authoritative evidence. This confirms or refutes the alert before taking disruptive action.

Exam trap

SC-200 often tests the ordering of incident response steps, so candidates who jump to containment (blocking the account) instead of first validating the alert with identity audit logs pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because Defender for Cloud recommendations are posture/configuration guidance, not evidence of whether a specific identity performed malicious enumeration. Option C is wrong because immediately blocking the account is a containment action taken after validation — doing it first risks disrupting a legitimate user and destroying forensic context. Option D is wrong because AzureHound is a cloud identity reconnaissance tool, not endpoint malware, so an antivirus scan on devices is irrelevant to confirming the alert.

218
Multi-Selecthard

Which THREE components are required to ingest Microsoft Entra ID (Azure AD) audit logs into Microsoft Sentinel?

Select 3 answers
A.A Log Analytics workspace in the same region as Microsoft Entra ID.
B.A user account with Security Administrator or Global Administrator role to configure the connector.
C.A playbook to parse the audit logs.
D.Microsoft Sentinel's Microsoft Entra ID data connector.
E.Microsoft Entra ID P1 or P2 license.
AnswersB, D, E

Configuring the Microsoft Sentinel Entra ID connector requires interactive authentication with a user who holds the Security Administrator or Global Administrator role. This role is necessary to grant the connector consent to access Microsoft Graph APIs for reading directory audit and sign-in logs, and to create the required diagnostic settings. Without this privilege, the connector cannot be enabled even if the workspace and licenses are in place.

Why this answer

Configuring the Microsoft Entra ID (Azure AD) data connector in Microsoft Sentinel requires a user account with at least the Security Administrator role (or Global Administrator) to grant the necessary permissions for the connector to read audit logs and sign-in logs from Microsoft Entra ID via the Microsoft Graph API. Without this role, the connector cannot authenticate and retrieve the required data.

Exam trap

The trap here is that candidates often assume a Log Analytics workspace must be regionally aligned with the data source, but Microsoft Entra ID is a global service and the workspace region is irrelevant for ingestion.

219
MCQhard

You are analyzing sign-in logs in Microsoft Sentinel. The KQL query shown in the exhibit returns a list of users who have signed into Office 365 Exchange Online more than 10 times in the last 24 hours. You need to identify potential brute-force attacks. What additional information should you add to the query to improve detection?

A.Include both successful and failed sign-in attempts, then filter for users with a high number of failed attempts and at least one successful attempt.
B.Change the time window to 1 hour to detect rapid attempts.
C.Add a condition to only include sign-ins from unusual geographic locations.
D.Add a condition to exclude users who have multi-factor authentication (MFA) enabled.
AnswerA

Brute-force detection requires correlating failures with eventual success, not just counting successful sign-ins. Including failed attempts and filtering for users with many failures plus at least one success exposes password-guessing that succeeded, which the current success-only query misses entirely.

Why this answer

To detect brute-force attacks, you need to look for multiple failed sign-in attempts followed by a success. The current query only shows successful sign-ins. Option A is correct because adding a condition to include failed attempts (ResultType != 0) and then filtering for users with many failures and at least one success would better indicate brute-force.

Option B (changing the time window to 1 hour) may help detect rapid attempts but does not consider the success pattern. Option C (filtering by unusual geographic locations) may reduce false positives but does not directly detect brute-force. Option D (excluding users with MFA) is not relevant because MFA reduces risk but does not prevent brute-force detection.

220
MCQmedium

A company runs SQL Server on Azure Virtual Machines (IaaS). They want to enable Advanced Threat Protection (ATP) for these instances to detect SQL injection attempts. What must they do first?

A.Deploy the Azure Security Center agent on the VM
B.Enable Azure Defender for SQL on the server
C.Enable Azure Defender for Servers
D.Configure SQL Server auditing manually
AnswerB

Enabling Azure Defender for SQL on the SQL Server VM activates Advanced Threat Protection (ATP), which surfaces SQL injection attempts, anomalous user logins, and brute-force attacks specific to the database engine. This plan integrates with the Log Analytics agent to evaluate SQL audit logs in real time and generates actionable security alerts. It is the only option that directly provides the SQL-specific threat detection required by the scenario.

Why this answer

Azure Defender for SQL is the specific plan within Microsoft Defender for Cloud that provides Advanced Threat Protection (ATP) for Azure SQL resources, including SQL Server on Azure VMs. Enabling this plan activates threat detection capabilities such as SQL injection alerts, anomalous access patterns, and vulnerability assessments. Without this plan, the VM's SQL Server instance is not monitored by Defender for Cloud's SQL-specific threat detection engine.

Exam trap

The trap here is that candidates confuse Azure Defender for Servers (which protects the OS) with Azure Defender for SQL (which protects the database engine), leading them to select the server-level plan when the question specifically asks for SQL injection detection.

How to eliminate wrong answers

Option A is wrong because the Azure Security Center agent (now the Log Analytics agent or Azure Monitor Agent) is used for collecting OS-level security events and is not required for SQL-specific ATP; Defender for SQL uses SQL-specific telemetry collected via the SQL IaaS Agent extension, not the general VM agent. Option C is wrong because Azure Defender for Servers provides threat detection for the VM's operating system and network layer, but does not include SQL-specific protections like SQL injection detection; that requires the dedicated Azure Defender for SQL plan. Option D is wrong because manual SQL Server auditing is a separate compliance and logging feature that does not enable ATP's real-time threat detection; ATP uses its own built-in detection logic and does not depend on manual auditing configuration.

221
MCQhard

Your organization uses Microsoft Sentinel and has enabled UEBA (User and Entity Behavior Analytics). You notice a series of incidents involving anomalous logon times for a privileged user. You want to automate the response to disable the user's account in Microsoft Entra ID when such incidents are created. What should you configure?

A.Create an automation rule that runs a playbook when an incident from the UEBA analytics rule is created, and configure the playbook to disable the user in Microsoft Entra ID.
B.Create an analytics rule that triggers on UEBA anomalies and directly disables the user.
C.Add the user to a watchlist and create a playbook that runs on a schedule.
D.Configure UEBA to automatically disable the user when anomalous behavior is detected.
AnswerA

In Microsoft Sentinel, an automation rule is the correct mechanism to trigger a playbook when an incident is created. Since the UEBA analytics rule generates incidents for suspicious behavior, you attach an automation rule to that rule that invokes a playbook. The playbook can then call Microsoft Entra ID to disable a user account, providing immediate, coordinated incident response.

Why this answer

Microsoft Sentinel automation rules can trigger a playbook when an incident is created by a specific analytics rule (e.g., a UEBA-based rule). The playbook, built in Azure Logic Apps, can then use the Microsoft Graph API to disable the user's account in Microsoft Entra ID. This provides a fully automated, event-driven response to anomalous logon time incidents without manual intervention.

Exam trap

The trap here is that candidates often assume UEBA or analytics rules can directly perform remediation actions, but in Sentinel, detection and response are separated—analytics rules only detect, while playbooks (via automation rules) execute the response.

How to eliminate wrong answers

Option B is wrong because analytics rules in Sentinel are designed to generate alerts or incidents, not to directly execute actions like disabling a user; direct user disablement must be performed by a playbook or a separate automation mechanism. Option C is wrong because adding a user to a watchlist and running a playbook on a schedule would not react to the specific incident creation event; it would run periodically regardless of whether an incident occurred, leading to delayed or unnecessary actions. Option D is wrong because UEBA itself is a detection engine that identifies anomalies and generates alerts; it does not have built-in remediation capabilities to automatically disable user accounts—that requires an external automation layer like a playbook.

222
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You suspect a compromised on-premises admin account that has been used to modify security groups. You want to quickly contain the threat. What should you do first?

A.Move the user account to an Organizational Unit (OU) with blocked logon hours.
B.Reset the user's password in on-premises Active Directory.
C.Revoke the user's sessions in Microsoft Entra ID and reset the password in both on-premises AD and Entra ID.
D.Disable the user account in Microsoft Entra ID.
AnswerC

Revoking Entra ID sessions invalidates refresh tokens immediately, while resetting the password in both directories removes the attacker's on-premises and cloud credentials. This dual reset contains the compromised admin account before further security group modifications occur.

Why this answer

When a hybrid identity admin account is compromised and has modified security groups, the fastest containment is to revoke the user's sessions in Microsoft Entra ID and reset the password in both on-premises AD and Entra ID. Revoking sessions invalidates refresh tokens and active sessions, while resetting in both directories ensures the attacker cannot re-authenticate via either identity plane. This addresses both cloud and on-premises access paths.

Exam trap

SC-200 often tests whether candidates forget that disabling or resetting in only one identity plane leaves the other plane accessible in hybrid environments.

How to eliminate wrong answers

Option A is wrong because moving an account to an OU with blocked logon hours does not immediately stop an active attacker and does not affect cloud sessions or existing tokens. Option B is wrong because resetting only the on-premises password leaves Entra ID sessions and tokens valid, allowing the attacker to continue cloud access. Option D is wrong because disabling only the Entra ID account does not stop on-premises AD authentication or on-premises resource access, and the attacker could still use the on-premises identity.

223
MCQeasy

Your organization uses Microsoft Sentinel. An incident is created from an Azure Active Directory (now Microsoft Entra ID) sign-in alert. You need to determine if the sign-in was from a compromised token. What data source should you examine?

A.Audit logs in Microsoft Entra ID
B.Azure Activity Log
C.Sign-in logs in Microsoft Entra ID
D.Microsoft Defender for Cloud Apps logs
AnswerC

Sign-in logs record token issuance details, including the token's unique identifier and authentication context, letting you correlate the alert with the specific session and confirm whether a stolen or replayed token was used rather than legitimate credentials.

Why this answer

Sign-in logs in Microsoft Entra ID contain detailed token information such as token issuer, session ID, and device details, which are essential for determining if a token was compromised. Option A is incorrect because audit logs track changes to directory objects, not sign-in details. Option B is incorrect because Azure Activity Log monitors Azure resource operations, not sign-in events.

Option D is incorrect because Microsoft Defender for Cloud Apps logs focus on cloud application sessions and anomalies, but do not provide the granular sign-in token details found in sign-in logs.

224
Multi-Selectmedium

Which TWO actions require the Global Administrator role in Microsoft 365?

Select 2 answers
A.Create a data loss prevention (DLP) policy in Microsoft Purview
B.Create a custom role in Microsoft Defender XDR
C.View the Microsoft 365 Defender incident queue
D.Configure tenant-wide settings in Microsoft 365
E.Manage roles and administrators in Microsoft Entra ID
AnswersD, E

Configuring tenant-wide settings in Microsoft 365 requires the Global Administrator role because these settings affect the entire organization, such as organizational profile, privacy preferences, and integration options. Only Global Administrators have the necessary authorization to modify settings that apply to all users and services across the tenant, ensuring central control and compliance with organizational governance.

Why this answer

Configuring tenant-wide settings in Microsoft 365 requires the Global Administrator role because these settings affect the entire organization, including security, compliance, and user management. Only the Global Administrator has the broadest permissions to modify such high-level configurations, as defined by Microsoft's role-based access control (RBAC) model.

Exam trap

The trap here is that candidates often confuse 'tenant-wide settings' with workload-specific configurations, assuming that any security or compliance task requires Global Administrator, when in fact Microsoft has delegated many such tasks to specialized roles like Security Administrator or Compliance Administrator.

225
MCQmedium

A SOC analyst is creating a Microsoft Sentinel scheduled analytics rule to detect failed sign-in attempts from a specific list of known malicious IP addresses. The IP addresses are stored in a CSV file that is updated weekly. The analyst uploads the file as a new table in the Log Analytics workspace. Which KQL operator should the analyst use to reference this table within the rule's query?

A.Use the custom table name directly in the query, e.g., 'MaliciousIPs_CL'.
B.Use 'externaldata()' to point to the CSV file in Azure Blob storage.
C.Use 'union' with the workspace name to include the CSV data.
D.Use 'watchlist' function, because CSV files are automatically treated as watchlists.
AnswerA

When a CSV file is uploaded as a new custom table in a Microsoft Sentinel Log Analytics workspace, it is assigned a name with the '_CL' suffix and stored as a regular KQL table. You can directly reference that table name, e.g., 'MaliciousIPs_CL', in a scheduled query just like any other table, because the data is already ingested and available for Kusto to scan. This is the standard and most efficient way to query custom log data, as no additional functions, operators, or external references are required.

Why this answer

When a CSV file is uploaded as a new table in the Log Analytics workspace, it becomes a custom table with a '_CL' suffix (e.g., 'MaliciousIPs_CL'). The analyst can then reference this table directly in the KQL query, just like any other table in the workspace. This is the standard method for using custom log data ingested via the Log Analytics agent or direct upload.

Exam trap

The trap here is that candidates may confuse the 'externaldata()' operator (used for ad-hoc queries on external files) with the direct table reference for already-ingested custom logs, or assume that any uploaded CSV becomes a watchlist, when in fact watchlists require explicit creation and are accessed via a dedicated function.

How to eliminate wrong answers

Option B is wrong because 'externaldata()' is used to query data from external storage (like Azure Blob or ADLS) without ingesting it into the workspace, but the CSV has already been uploaded as a table, so externaldata() is unnecessary and would bypass the ingested table. Option C is wrong because 'union' is used to combine results from multiple tables or queries, not to reference a single table; the custom table can be queried directly without union. Option D is wrong because CSV files are not automatically treated as watchlists; watchlists are a separate feature in Microsoft Sentinel that must be explicitly created and managed via the watchlist UI or API, and they are accessed using the '_GetWatchlist()' function, not by direct table reference.

Page 2

Page 3 of 18

Page 4