Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 226–300

1303 questions total · 18pages · All types, answers revealed

Page 3

Page 4 of 18

Page 5
226
MCQeasy

You are configuring Microsoft Sentinel to detect potential ransomware activity. The security team wants to be alerted when a single host contacts multiple suspicious domains within a short time. Which analytic rule type should you create?

A.NRT (Near-Real-Time) rule
B.Scheduled query rule
C.Anomaly rule
D.Microsoft security rule
AnswerA

A Near-Real-Time (NRT) rule in Microsoft Sentinel evaluates the triggering query every minute with a maximum lookback of 30 minutes, using streaming analytics to preserve event ordering and timing. This enables you to catch rapid sequences of events—such as multiple failed logons immediately followed by a successful authentication—that would be missed by periodic batch processing. NRT rules are specifically engineered for low-latency, time-sensitive detections while still allowing KQL logic to match the exact pattern.

Why this answer

A NRT (Near-Real-Time) rule is the correct choice because it continuously processes events with a minimum latency of about 1 minute, making it ideal for detecting patterns like a single host contacting multiple suspicious domains within a short time window. Unlike scheduled rules that run on a fixed interval (e.g., every 5 minutes), NRT rules evaluate data as it arrives, enabling rapid detection of multi-event sequences such as DNS queries to known malicious domains.

Exam trap

The trap here is that candidates often confuse NRT rules with scheduled query rules, assuming a scheduled rule can achieve the same low latency by setting a short interval, but scheduled rules still incur a processing delay and cannot match the continuous streaming evaluation of NRT rules.

How to eliminate wrong answers

Option B (Scheduled query rule) is wrong because it runs on a predefined schedule (e.g., every 5 or 15 minutes), which introduces latency that could miss the tight time window required for detecting rapid multi-domain contacts. Option C (Anomaly rule) is wrong because it uses machine learning to baseline normal behavior and flag statistical outliers, not to match a specific pattern of a single host contacting multiple known suspicious domains. Option D (Microsoft security rule) is wrong because it ingests alerts from other Microsoft security products (e.g., Microsoft Defender for Endpoint) and does not allow custom detection logic based on raw event sequences like DNS queries.

227
MCQhard

Refer to the exhibit. You run the KQL query in Microsoft Sentinel to identify analysts with high incident assignments. The query returns no results, but you know incidents exist. What is the most likely reason?

A.The summarize operator is incorrectly used
B.The SecurityIncident table does not exist
C.The query period is too short to capture incidents
D.Incidents are not assigned to any owner, so the Owner field is null
AnswerD

In Sentinel, the Owner field is nullable, and incidents that have not yet been assigned to an analyst or group will contain a null value rather than an empty string. When you summarize by Owner, null values are grouped into a single bucket, but KQL does not consider a null value equal to null with the equality operator (==); it requires the isnull() function to test for absence. The query likely filters with something like where Owner == null, which evaluates to false for all rows and omits the exact incidents the user intended to count, resulting in zero incidents being returned.

Why this answer

If incidents have no assigned owner, the Owner field is null. The KQL query likely filters or groups by Owner, and null values are excluded from results by default in aggregation operations like summarize. Since incidents exist but are unassigned, the query returns no results.

Exam trap

Microsoft often tests the nuance that KQL aggregation operators like summarize exclude null group-by keys by default, leading candidates to overlook the data quality issue and instead blame syntax or table existence.

How to eliminate wrong answers

Option A is wrong because the summarize operator is correctly used for grouping by owner; the issue is not syntax but data content. Option B is wrong because the SecurityIncident table does exist in Microsoft Sentinel; it is a standard table for incident data. Option C is wrong because the query period is not specified as too short; the problem is that incidents exist but lack owner assignments, not that they fall outside the time range.

228
MCQhard

You are designing a Microsoft Sentinel deployment. You need to minimize ingestion costs while ensuring that all security-relevant events are collected. Which strategy should you use?

A.Use Analytic Logs for all data sources to ensure full query capabilities
B.Use Basic Logs for verbose data sources like Windows firewall logs, and Analytic Logs for high-value security logs
C.Set short retention periods for all logs and export to storage
D.Collect only logs from Microsoft 365 Defender and ignore other sources
AnswerB

Basic Logs cost less per gigabyte but support only limited querying, so routing verbose, low-value sources such as firewall logs there cuts spend. Analytic Logs retain full KQL and analytics-rule support for high-value security events, meeting both cost and detection requirements.

Why this answer

Microsoft Sentinel offers two log plan tiers: Analytic Logs (full KQL, alerts, workbooks) and Basic Logs (cheaper ingestion, limited query, 30-day retention). Placing high-volume, low-value sources like Windows firewall logs in Basic Logs and reserving Analytic Logs for high-value security events minimizes cost while still collecting all relevant data. This is the documented cost-optimization pattern.

Exam trap

SC-200 often tests the assumption that all logs must be Analytic for full security coverage — candidates miss that Basic Logs still collect data and can be queried, just with limitations, making them ideal for verbose sources.

How to eliminate wrong answers

Option A is wrong because putting everything in Analytic Logs maximizes ingestion and retention cost, defeating the goal of minimizing spend. Option C is wrong because short retention plus export to storage does not reduce ingestion cost and removes the ability to query recent data in Sentinel. Option D is wrong because ignoring non-M365 sources creates visibility gaps and violates the requirement to collect all security-relevant events.

229
Multi-Selecteasy

Which TWO Microsoft 365 security solutions include capabilities for managing security incidents?

Select 2 answers
A.Microsoft Intune
B.Microsoft Defender XDR
C.Microsoft Entra ID Protection
D.Microsoft Purview
E.Microsoft Sentinel
AnswersB, E

Microsoft Defender XDR includes a unified incident queue and automated investigation and response, letting security teams manage and remediate incidents across endpoints, identities, email and cloud apps. This built-in incident management capability satisfies the requirement for a Microsoft 365 security solution that manages security incidents.

Why this answer

Microsoft Defender XDR (B) is correct because it natively correlates alerts across endpoints, identities, email, and cloud apps into unified incidents, providing incident management through the Microsoft Defender portal with investigation, automated response, and remediation capabilities. Microsoft Sentinel (E) is correct because it is a cloud-native SIEM/SOAR solution that creates incidents from analytics rules and offers full incident management, including triage, investigation graphs, automation rules, and playbooks. Microsoft Intune (A) is a device and application management (MDM/MAM) service and does not provide security incident management.

Microsoft Entra ID Protection (C) detects identity-based risks and generates risk detections and risky user/sign-in reports, but it is not an incident management solution. Microsoft Purview (D) focuses on data governance, compliance, and information protection (e.g., DLP, eDiscovery), not on managing security incidents.

230
MCQeasy

Your organization uses Microsoft Sentinel. An analyst reports that a scheduled analytics rule is not firing. You verify that the rule is enabled and the query returns results when run manually. What is the most likely cause?

A.The alert threshold is set too high
B.The data connector is disconnected
C.The workspace is in a different region
D.The query uses unsupported KQL functions
AnswerA

An alert rule's threshold is set in the 'Alert threshold' field under query scheduling. This defines the minimum number of query results that must be returned for a single run to generate an alert. If, for example, the threshold is 50 and the underlying query currently returns only 20 matching events, the rule will evaluate to 'low' instead of firing and no alert will be created. This can be verified by manually running the rule's query in Log Analytics—if results are present but below the threshold, the misconfiguration is exactly this.

Why this answer

The most likely cause is that the alert threshold is set too high. Even though the query returns results when run manually, the rule's threshold condition (e.g., 'Number of results greater than X') may not be met by the volume of results returned during each scheduled run. If the threshold is higher than the typical result count, the rule will not trigger an alert despite the query being valid.

Exam trap

The trap here is that candidates assume a working query automatically means the rule will fire, overlooking the threshold condition that must be met for alert generation.

How to eliminate wrong answers

Option B is wrong because a disconnected data connector would prevent the query from returning any results at all, but the analyst verified the query returns results when run manually. Option C is wrong because the workspace region does not affect the execution of scheduled analytics rules; Sentinel rules run within the workspace regardless of region. Option D is wrong because if the query used unsupported KQL functions, it would fail to execute or return an error, but the analyst confirmed the query runs successfully.

231
MCQmedium

You are the security analyst for a company that uses Microsoft Sentinel. You notice that a critical analytics rule has not generated any incidents in the past week, but you know that relevant logs are being ingested. You need to troubleshoot why the rule is not firing. What is the first step you should take?

A.Check the incident creation rule configuration.
B.Verify that the log sources are connected and sending data to the workspace.
C.Disable and re-enable the analytics rule.
D.Run the analytics rule's query directly in Log Analytics to see if it returns results.
AnswerD

Running the analytics rule's KQL query directly in Log Analytics is the correct first step because it isolates whether the problem lies in the rule logic or in the downstream alert/incident pipeline. By executing the exact query with the same time range and filters, you can see if any rows are returned; if none are, the rule will never fire regardless of its other settings. If the query does return data, then you should examine the rule's alert creation, incident settings, and run history. This approach provides concrete evidence and prevents you from blindly altering configuration.

Why this answer

The first step in troubleshooting a Sentinel analytics rule that is not generating incidents despite relevant logs being ingested is to run the rule's query directly in Log Analytics. This isolates whether the issue is with the query logic itself (e.g., syntax errors, time range misconfiguration, or data not matching the KQL conditions) rather than with data ingestion or rule settings. If the query returns results in Log Analytics, the problem lies elsewhere; if it returns no results, the query needs adjustment.

Exam trap

The trap here is that candidates often jump to checking data ingestion (Option B) even when the question states logs are being ingested, or they assume a rule reset (Option C) will fix a logic problem, missing the fundamental step of validating the query itself.

How to eliminate wrong answers

Option A is wrong because incident creation rule configuration is not a concept in Microsoft Sentinel; analytics rules define incident creation, and checking this is premature before verifying the query returns data. Option B is wrong because the question explicitly states that relevant logs are being ingested, so verifying connectivity is unnecessary and wastes time. Option C is wrong because disabling and re-enabling the rule is a brute-force reset that does not diagnose the root cause and may reset rule state without addressing underlying query or scheduling issues.

232
MCQeasy

Your organization uses Microsoft Defender XDR and Microsoft Sentinel. The security operations center (SOC) team frequently receives false positive alerts for a specific user login pattern from a legacy application. You need to reduce alert fatigue without disabling the underlying detection rule. What should you configure?

A.Use Microsoft Sentinel bookmarks to mark the alerts as false positives.
B.Configure an automated investigation and remediation rule in Microsoft Defender XDR to suppress alerts matching the legacy application pattern.
C.Create a watchlist in Microsoft Sentinel containing the legacy application's user accounts and use it in the rule.
D.Modify the analytics rule in Microsoft Sentinel to exclude the legacy application IP range.
AnswerB

An automated investigation and remediation rule in Microsoft Defender XDR can define precise conditions to match the legacy application's characteristic behavior, such as specific process names, users, or IP addresses, and then automatically take an action like closing or suppressing the alert. This works directly at the XDR layer, addressing the root cause of the false positive without modifying the underlying detection query or disabling broader threat visibility. It is the intended, scalable approach for recurring harmless patterns, requiring no manual intervention once configured.

Why this answer

Configuring an automated investigation and remediation rule in Microsoft Defender XDR allows you to suppress alerts that match a specific pattern (e.g., legacy application login behavior) without disabling the underlying detection rule. This directly reduces alert fatigue by automatically closing or ignoring false positive alerts while keeping the rule active for genuine threats.

Exam trap

The trap here is that candidates often confuse modifying the detection rule (options C or D) with configuring a separate suppression or response mechanism, failing to realize that automated investigation and remediation rules in Defender XDR can suppress alerts without altering the original detection logic.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel bookmarks are used to preserve and annotate specific events for later investigation, not to suppress or mark alerts as false positives in an automated manner. Option C is wrong because creating a watchlist in Microsoft Sentinel containing user accounts and using it in the rule would require modifying the analytics rule logic to exclude those accounts, which does not reduce alert fatigue without disabling the rule; it changes the rule's behavior. Option D is wrong because modifying the analytics rule to exclude the legacy application IP range would alter the rule's detection logic, effectively disabling detection for that IP range, which contradicts the requirement to not disable the underlying detection rule.

233
MCQmedium

A SOC team ingests Microsoft 365 Defender advanced hunting data into Microsoft Sentinel. They want to create a scheduled analytics rule that detects when a user receives more than 5 emails from an external sender containing a specific attachment name within 1 hour. Which KQL tables and approach should the analyst use?

A.EmailEvents and EmailAttachmentInfo; summarize count() by AccountUpn, AttachmentFileName, bin(Timestamp,1h)
B.EmailEvents and EmailUrlInfo; summarize count() by SenderObjectId
C.EmailEvents only; filter by AttachmentFileName
D.EmailPostDeliveryEvents; summarize count() by RecipientEmailAddress
AnswerA

EmailEvents carries the core mail flow metadata—sender, recipient, subject, and delivery timestamp—but no attachment details; EmailAttachmentInfo provides AttachmentFileName and references the parent email through NetworkMessageId. Joining these tables on NetworkMessageId lets you count how many times a given attachment name reached a specific AccountUpn, and binning Timestamp every 1h reveals temporal bursts. This is the correct combination because only this pair supplies both the recipient identity and the file name in the same logical context.

Why this answer

The detection requires joining EmailEvents (which contains sender/recipient metadata) with EmailAttachmentInfo (which contains attachment file names) to filter by external senders and a specific attachment name, then using summarize count() with bin(Timestamp,1h) to group events into 1-hour windows and identify users receiving more than 5 such emails. This approach directly maps to the requirement: external sender, attachment name, user identity (AccountUpn), and time-based aggregation.

Exam trap

The trap here is that candidates often assume EmailEvents contains all email data including attachments, but attachment details are stored in a separate table (EmailAttachmentInfo) and require a join to access the file name.

How to eliminate wrong answers

Option B is wrong because EmailUrlInfo contains URL data, not attachment names, and summarizing by SenderObjectId does not capture the recipient user or attachment name. Option C is wrong because EmailEvents alone does not include attachment file names; that data resides in EmailAttachmentInfo, so filtering by AttachmentFileName on EmailEvents is invalid. Option D is wrong because EmailPostDeliveryEvents tracks post-delivery actions (like phishing report or delete), not the original email receipt or attachment metadata, and summarizing by RecipientEmailAddress ignores the attachment name and external sender filter.

234
Multi-Selecteasy

Which TWO are valid incident classification categories in Microsoft Sentinel?

Select 2 answers
A.Benign positive
B.Unknown
C.True positive
D.Informational
E.False positive
AnswersC, E

True positive is one of the two valid incident classification categories in Microsoft Sentinel. You select this classification when investigation confirms the alert correctly identified a real security threat. Applying True positive is important because it enables accurate reporting on detection effectiveness and helps tune analytics rules for future incidents. It must be paired with the incident status 'Closed' (or 'Resolved') in the classification workflow.

Why this answer

Microsoft Sentinel incidents are closed with one of THREE classification categories, not two: True Positive (reason: Suspicious activity), False Positive (reasons: Inaccurate data or Inaccurate alert logic), and Benign Positive (reason: Suspicious but expected — used when the detected activity is real but was expected/authorized, e.g., an approved penetration test or a known admin script). 'Unknown' and 'Informational' are not valid classification values; they are respectively an alert-severity-adjacent concept and a severity level, not part of the incident-closing classification field. Because 3 of the 5 options (A, C, E) are actually valid, the stem must also be changed from 'Select TWO' to 'Select THREE' when this question is corrected.

Exam trap

The trap here is that candidates often confuse incident classification categories (True positive, False positive, Benign positive) with alert severity levels (Informational, Low, Medium, High) or investigation statuses (New, In progress, Resolved), leading them to select 'Informational' or 'Unknown' as valid classifications.

235
MCQeasy

A threat hunter is investigating a potential data exfiltration via DNS tunneling. Which Microsoft Defender XDR advanced hunting table should the analyst primarily use to examine DNS queries from endpoints?

A.DeviceEvents
B.IdentityLogonEvents
C.AlertInfo
D.EmailEvents
AnswerA

DeviceNetworkEvents records network connection events from onboarded endpoints, including DNS query details and remote addresses. This makes it the primary table for spotting DNS tunnelling patterns such as high-volume or encoded queries to suspicious domains.

Why this answer

In Microsoft Defender XDR advanced hunting, raw DNS query telemetry from endpoints is recorded in the DeviceEvents table, where events with ActionType equal to 'DnsQuery' include the queried domain (in AdditionalFields) and the initiating process. DeviceNetworkEvents records network connection events (RemoteIP, RemoteUrl, RemotePort, etc.) and does not contain a DnsQuery field or per-query DNS resolution data. Therefore, to examine DNS queries from endpoints for suspected DNS tunneling, the analyst should use DeviceEvents filtered on ActionType == 'DnsQuery'.

Exam trap

The trap is assuming that any table with 'Network' in the name contains DNS data, or defaulting to AlertInfo because the scenario mentions an investigation. The exam tests whether you know that raw endpoint DNS query telemetry lives in DeviceEvents (ActionType == 'DnsQuery'), not DeviceNetworkEvents.

How to eliminate wrong answers

Option B is wrong because IdentityLogonEvents contains authentication events (logons, failed logons, credential usage) from identity providers — it has no DNS query data. Option C is wrong because AlertInfo stores metadata about generated alerts (title, severity, category), not raw DNS telemetry; it tells you an alert fired, not what DNS queries occurred. Option D is wrong because EmailEvents covers email message flow and delivery metadata (sender, recipient, attachments, URLs), which is relevant to phishing investigations but contains no endpoint DNS query records.

236
MCQhard

Your organization has deployed Microsoft Sentinel in multiple regions. You need to ensure that incidents created in one workspace are available for correlation in a central workspace. What should you implement?

A.Cross-workspace queries in KQL
B.Sentinel workspace manager (incident replication)
C.Automated export of incidents to central workspace using Logic Apps
D.Azure Lighthouse
AnswerB

Sentinel workspace manager's incident replication feature is the native, built-in mechanism that replicates incidents from multiple workspaces to a central workspace, providing a single pane of glass for SOC triage. It maintains a one-way copy of incident metadata and status in the central workspace, enabling centralized metrics, queries, and automation without altering the original incident. This is the recommended method over custom exports or cross-workspace queries because it is purpose-built for incident aggregation and requires no manual pipeline.

Why this answer

Sentinel Workspace Manager (incident replication) is the correct choice because it provides native, built-in replication of incidents from multiple workspaces to a central workspace without requiring custom code or external automation. This feature ensures that incidents created in regional workspaces are automatically synchronized to a designated central workspace, enabling unified correlation and investigation across regions.

Exam trap

The trap here is that candidates often confuse cross-workspace queries (which allow querying data across workspaces but do not replicate incidents) with the native incident replication feature, leading them to select Option A instead of the correct Workspace Manager solution.

How to eliminate wrong answers

Option A is wrong because cross-workspace queries in KQL allow querying data across multiple workspaces but do not replicate incidents; they require manual querying and do not provide automatic incident synchronization. Option C is wrong because automated export using Logic Apps is a custom, complex solution that introduces latency and maintenance overhead, whereas Sentinel Workspace Manager provides a native, low-latency replication mechanism without additional components. Option D is wrong because Azure Lighthouse enables cross-tenant management and visibility but does not replicate incidents between workspaces; it allows administrators to manage multiple workspaces from a single pane but does not synchronize incident data.

237
MCQhard

You are configuring Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 100 files in 10 minutes from SharePoint. Which policy type should you use?

A.Anomaly detection policy
B.Activity policy
C.File policy
D.Cloud discovery policy
AnswerB

An activity policy is designed specifically to monitor user sign-in and app activity events, and it allows you to define custom behavioral conditions using filters, thresholds, and time windows. For example, you can create a policy that alerts when a user performs more than N file downloads within a set number of minutes, then automatically respond by suspending the user or requiring re-authentication. This matches the requirement for a custom threshold on download volume.

Why this answer

An Activity policy in Microsoft Defender for Cloud Apps monitors specific user activities (e.g., file downloads) and can trigger alerts based on thresholds like 'more than 100 downloads in 10 minutes'. This policy type is designed for granular, behavior-based detection of suspicious actions, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse 'Anomaly detection policy' (which uses machine learning for behavioral baselines) with 'Activity policy' (which uses explicit thresholds), leading them to select Option A for any threshold-based alert.

How to eliminate wrong answers

Option A is wrong because Anomaly detection policies use machine learning to detect deviations from a user's baseline behavior, not fixed thresholds like '100 files in 10 minutes'. Option C is wrong because File policies focus on file attributes (e.g., metadata, content, sharing settings) rather than user activity counts over time. Option D is wrong because Cloud discovery policies analyze traffic logs to identify shadow IT usage, not user-specific download activities within a known SharePoint environment.

238
MCQeasy

Your SOC team uses Microsoft Sentinel incident management. You need to ensure that when an incident is created, it automatically runs a playbook to gather additional context from threat intelligence sources. What should you create?

A.Workbook that queries threat intelligence.
B.Watchlist that maps to the incident.
C.Automation rule with a trigger on incident creation.
D.Analytics rule that generates an alert.
AnswerC

Automation rules are the native orchestration feature in Microsoft Sentinel that let you define conditions and actions executed when an incident meets predefined criteria. By setting the trigger type to 'When incident is created,' the rule fires immediately upon incident generation, and you can configure it to run a playbook, change the incident status, assign ownership, or add tasks. This is the correct and intended mechanism for automatically invoking a playbook at incident creation time.

Why this answer

Microsoft Sentinel automation rules can be configured with a trigger on incident creation to automatically run a playbook. This allows the SOC team to gather additional context from threat intelligence sources without manual intervention, directly addressing the requirement to execute a playbook when an incident is created.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rules, thinking that analytics rules can directly trigger playbooks on incident creation, when in fact automation rules are the dedicated mechanism for incident-triggered playbook execution.

How to eliminate wrong answers

Option A is wrong because a Workbook in Microsoft Sentinel is a visualization and reporting tool that queries data for analysis, not an automated action that runs a playbook upon incident creation. Option B is wrong because a Watchlist is a static reference data source used for correlation and enrichment within analytics rules or queries, not a mechanism to trigger playbooks automatically. Option D is wrong because an Analytics rule generates alerts based on detection logic, but it does not directly trigger a playbook on incident creation; playbook execution on incident creation requires an automation rule, not the analytics rule itself.

239
MCQmedium

Your security team uses Microsoft Sentinel automation rules to respond to incidents. You need to ensure that critical incidents are automatically assigned to a senior analyst in the Americas time zone and that a Teams message is sent to a specific channel. Which configuration should you use?

A.Use a watchlist to map critical incidents to senior analysts and trigger an email
B.Configure the analytics rule to set the incident owner and add a playbook action
C.Create a custom connector in Power Automate to monitor Sentinel incidents
D.Create a playbook that assigns the incident and sends a Teams message, then attach it to a automation rule
AnswerD

A playbook in Microsoft Sentinel is an Azure Logic Apps workflow that can perform actions such as updating the incident owner and sending a Teams message. By attaching this playbook to an automation rule, the rule triggers the playbook when incidents meet specific conditions (e.g., creation, severity, or status change), automating the assignment and notification. This is the correct approach because automation rules are designed to run playbooks as incident-triggered actions, and the playbook can use the 'Update incident' action to set the owner.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook when an incident is created or updated. By creating a playbook that assigns the incident to a specific senior analyst (using Microsoft Entra ID or a watchlist for mapping) and sends a Teams message via the Teams connector, then attaching that playbook to an automation rule with conditions for critical severity, you meet both requirements. This approach leverages native Sentinel automation without custom connectors or manual email triggers.

Exam trap

The trap here is that candidates often confuse the capabilities of analytics rules versus automation rules, thinking that analytics rules can directly execute playbooks or set owners, when in fact automation rules are the correct mechanism for triggering playbooks and modifying incident properties after creation.

How to eliminate wrong answers

Option A is wrong because a watchlist alone cannot trigger actions; it is a static data source, and the email action would require a playbook or automation rule, not just a watchlist. Option B is wrong because analytics rules can set the incident owner via the 'Alert Details' configuration, but they cannot directly add a playbook action; playbooks are attached via automation rules, not analytics rules. Option C is wrong because creating a custom connector in Power Automate is unnecessary and overly complex; Sentinel already provides native connectors for Teams and incident management through automation rules and playbooks.

240
MCQeasy

Your SOC uses Microsoft Sentinel and Microsoft Defender for Cloud Apps. You need to configure a policy that triggers when a user downloads a large number of files from SharePoint Online within a short period. Which policy type should you use?

A.Session policy
B.File policy
C.Anomaly detection policy
D.Activity policy
AnswerD

Activity policies in Microsoft Defender for Cloud Apps evaluate user activity against thresholds, such as mass file downloads from SharePoint Online within a defined period. They generate alerts or governance actions directly on the activity stream, matching the download-volume scenario.

Why this answer

An activity policy in Microsoft Defender for Cloud Apps is designed to monitor and respond to specific user activities, such as downloading a large number of files from SharePoint Online within a short period. This policy type allows you to set thresholds and triggers based on user actions, making it the correct choice for detecting anomalous download behavior.

Exam trap

The trap here is that candidates often confuse anomaly detection policies (which are predefined and use machine learning) with activity policies (which are customizable and rule-based), leading them to select anomaly detection when a custom threshold-based trigger is required.

How to eliminate wrong answers

Option A is wrong because session policies are used for real-time monitoring and control of user sessions, such as blocking downloads during a session, but they do not trigger based on historical activity thresholds like a large number of downloads over time. Option B is wrong because file policies focus on detecting specific file types, content, or metadata (e.g., sensitive data in files), not on the volume or frequency of file downloads. Option C is wrong because anomaly detection policies in Defender for Cloud Apps use machine learning to detect unusual patterns across users, but they are predefined and cannot be customized to trigger specifically on a high volume of downloads from SharePoint Online within a short period.

241
MCQeasy

A SOC analyst receives a phishing alert in Microsoft Defender for Office 365. The analyst needs to quickly determine if any users clicked the malicious link. Which action should the analyst take first?

A.Use Threat Explorer to search for the email subject
B.Open the user entity page for each recipient
C.Open the email entity page to view click details
D.Run a hunting query in Microsoft Sentinel
AnswerC

The email entity page is the correct destination because it consolidates the full message record from Microsoft Defender for Office 365, including delivery status, threat name, detection technology, and the recipient-specific URL click verdict. Its Click details section explicitly indicates whether each intended recipient clicked the link, whether the click was allowed or blocked, and the time of the click, which is exactly the evidence needed to assess the impact of a phishing alert. This page is purpose-built for single-message triage and provides near-instant visibility without requiring a custom query or cross-referencing multiple data sources.

Why this answer

The email entity page in Microsoft Defender for Office 365 provides detailed information about a specific email, including click verdicts for any URLs contained within. This allows the analyst to quickly see if any users clicked the malicious link. Option A (Threat Explorer) can also be used, but it requires more steps to filter for the specific email and then view click details.

Option B (user entity page) shows user-specific activities and alerts, but not email-specific click details. Option D (hunting query in Microsoft Sentinel) is effective but slower than directly viewing the email entity page in Defender for Office 365.

242
MCQeasy

You are investigating a brute force attack on a user account in Microsoft Entra ID. The sign-in logs show multiple failed attempts from different IP addresses. Which property in the sign-in logs indicates the type of authentication used?

A.riskEventTypes
B.conditionalAccessStatus
C.clientAppUsed
D.authenticationRequirement
AnswerD

authenticationRequirement is a sign-in log property that directly specifies the authentication strength required for the sign-in, such as singleFactorAuthentication or multiFactorAuthentication. In a brute force scenario, checking this field helps you determine whether the attacker only needed a valid password or whether they also had to satisfy an MFA challenge to succeed. This is the right field to inspect because it answers the exact question of which authentication type was used to access the account.

Why this answer

The `authenticationRequirement` property in Microsoft Entra ID sign-in logs specifies the type of authentication used for the sign-in attempt, such as single-factor authentication (password), multi-factor authentication, or passwordless authentication. In a brute force attack investigation, this property helps determine whether the failed attempts were against password-based authentication or a more secure method, providing critical context for the attack vector.

Exam trap

The trap here is that candidates confuse `clientAppUsed` (which describes the application or client type) with the authentication method, but `clientAppUsed` only indicates the client software (e.g., 'Browser' or 'Mobile Apps and Desktop clients') and not the underlying authentication protocol or factor.

How to eliminate wrong answers

Option A is wrong because `riskEventTypes` indicates the risk events detected during sign-in (e.g., impossible travel, anonymous IP) and does not specify the authentication type used. Option B is wrong because `conditionalAccessStatus` shows whether Conditional Access policies were applied or satisfied, not the authentication method. Option C is wrong because `clientAppUsed` identifies the client application (e.g., browser, mobile app, legacy authentication) but does not indicate the type of authentication (e.g., password, MFA, certificate).

243
MCQhard

Your organization uses Microsoft Sentinel as its SIEM and Microsoft Defender XDR for endpoint detection. A critical incident has been generated: 'Possible ransomware activity detected on multiple endpoints.' The incident includes alerts from Microsoft Defender for Endpoint (MDE) about file encryption behaviors and from Microsoft Defender for Identity (MDI) about anomalous service account logins. You have been assigned the incident and need to contain the threat effectively. You have Microsoft Sentinel automation rules that can trigger playbooks, and you have Microsoft Defender XDR actions available. The environment includes 500 Windows 10 devices managed by Microsoft Intune, and 50 servers on-premises. Some servers are domain controllers. Which of the following is the BEST first course of action?

A.Disable all compromised service accounts in Microsoft Entra ID and reset their passwords.
B.Reset passwords for all domain administrator accounts and enforce MFA.
C.Trigger a Microsoft Sentinel playbook to collect forensic evidence from affected endpoints before remediation.
D.Isolate the affected devices using Microsoft Defender for Endpoint device isolation.
AnswerD

Device isolation via Microsoft Defender for Endpoint immediately cuts network communication while preserving forensic evidence, halting ransomware spread across endpoints. It addresses the active encryption behaviour first, before investigating the MDI service account logins, containing the threat fastest.

Why this answer

For active ransomware encrypting files across multiple endpoints, the priority is to stop the spread immediately. Microsoft Defender for Endpoint device isolation cuts network communication while preserving the Defender sensor channel for investigation, containing the threat before lateral movement or further encryption. Forensic collection and account remediation are important but secondary to stopping active encryption.

Exam trap

SC-200 often tests the order of incident response phases — candidates pick forensic collection or account resets because they sound thorough, but containment (isolation) must come first to stop active encryption.

How to eliminate wrong answers

Option A is wrong because disabling service accounts is a remediation step that does not stop active file encryption on endpoints and may disrupt legitimate services. Option B is wrong because resetting domain admin passwords and enforcing MFA is a broad identity hardening step, not immediate containment of endpoint ransomware. Option C is wrong because collecting forensic evidence before remediation allows the ransomware to continue encrypting and spreading, violating containment-first incident response.

244
MCQhard

A SOC analyst is configuring a multi-region deployment of Microsoft Sentinel. The requirement is to ingest security logs from Azure resources located in three different Azure regions. The analyst needs to create the workspace in one region and then use cross-workspace queries to view data from all regions. What is the correct sequence of steps?

A.Step 1: Create Log Analytics workspaces in each region. Step 2: Enable Sentinel on each workspace. Step 3: Connect data sources. Step 4: Configure cross-workspace queries.
B.Step 1: Enable Sentinel in one region. Step 2: Create workspaces in other regions. Step 3: Connect data sources. Step 4: Configure cross-workspace queries.
C.Step 1: Connect data sources. Step 2: Create workspaces. Step 3: Enable Sentinel. Step 4: Configure cross-workspace queries.
D.Step 1: Create a central workspace. Step 2: Enable Sentinel on it. Step 3: Connect data sources from all regions to the central workspace. Step 4: Configure cross-workspace queries.
AnswerA

This sequence is correct because Microsoft Sentinel is built on top of a Log Analytics workspace; the workspace must be provisioned before Sentinel can be enabled. Enabling Sentinel on each regional workspace first ensures that the data connectors have a valid destination and can immediately begin ingesting and normalizing logs. Once all regional workspaces have Sentinel active, you can configure cross-workspace queries to unify monitoring while preserving data residency, which is the recommended pattern for multi-region deployments.

Why this answer

To use cross-workspace queries in Microsoft Sentinel, you must first create a Log Analytics workspace in each region, enable Sentinel on each workspace, connect the data sources to their respective regional workspaces, and then configure cross-workspace queries to unify the data. This sequence ensures that each region's logs are ingested locally, which is required for cross-workspace queries to reference them via the `workspace()` expression.

Exam trap

The trap here is that candidates often assume a single central workspace can ingest logs from all regions, but the question explicitly requires using cross-workspace queries, which necessitates separate workspaces per region.

How to eliminate wrong answers

Option B is wrong because you cannot enable Sentinel on a workspace that does not yet exist; the workspace must be created first before Sentinel can be enabled on it. Option C is wrong because data sources cannot be connected before the workspaces are created and Sentinel is enabled, as the data connectors depend on the workspace and Sentinel being provisioned. Option D is wrong because connecting all data sources from multiple regions to a single central workspace violates the requirement to ingest logs from each region into their own regional workspace, and cross-workspace queries are used to query across separate workspaces, not within a single workspace.

245
Multi-Selectmedium

Which TWO of the following are valid sources for creating incidents in Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Hunting query results
B.Microsoft 365 Defender alerts
C.Analytics rule triggering
D.Workbook creation
E.Playbook execution
AnswersB, C

Microsoft 365 Defender alerts are a legitimate incident source when you have the Microsoft 365 Defender data connector enabled in Sentinel. This connector automatically ingests high-fidelity alerts from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. The connector's incident creation setting then creates an incident each time one of these alerts is ingested, plus any related alerts are grouped into the same incident.

Why this answer

Microsoft 365 Defender alerts are a valid source for creating incidents in Microsoft Sentinel because Sentinel can ingest alerts from Microsoft 365 Defender (which includes Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps) via the Microsoft 365 Defender connector. When these alerts are ingested, Sentinel can automatically create incidents based on them, enabling unified incident management across the Microsoft security ecosystem.

Exam trap

The trap here is that candidates often confuse 'hunting query results' with analytics rule results, but hunting queries are ad-hoc investigations that do not automatically generate incidents, whereas analytics rules are scheduled detections that do.

246
MCQeasy

A threat hunter wants to use Microsoft Sentinel's UEBA to identify anomalous behavior. Which data connector must be enabled to provide the necessary Azure Active Directory (now Microsoft Entra ID) sign-in logs for UEBA?

A.Office 365
B.Microsoft Entra ID Audit
C.Microsoft Entra ID
D.Windows Security Events via AMA
AnswerC

The Microsoft Entra ID data connector ingests sign-in and audit logs into Microsoft Sentinel, supplying the identity events UEBA analyses for anomalous behaviour detection. Enabling it is required before UEBA can surface risky sign-in activity.

Why this answer

UEBA in Microsoft Sentinel requires sign-in logs to detect anomalous behavior. The Microsoft Entra ID connector (option C) provides these sign-in logs from Azure AD/Entra ID. Option A (Office 365) provides Exchange, Teams, and SharePoint logs, but not sign-in logs.

Option B (Microsoft Entra ID Audit) provides only audit logs, not sign-in events. Option D (Windows Security Events via AMA) provides security event logs from Windows machines, which do not contain cloud sign-in data. Therefore, the Microsoft Entra ID connector is the correct choice.

247
MCQmedium

A company uses Microsoft Defender for Cloud to protect Azure resources. They have an Azure SQL Database containing sensitive customer data. The security team wants to be alerted if a user attempts to perform SQL injection attacks against the database. Which Defender for Cloud plan must be enabled to receive SQL injection alerts?

A.Defender for SQL
B.Defender for Servers
C.Defender for Storage
D.Defender for App Service
AnswerA

Defender for SQL is the correct plan because it is the Defender for Cloud plan specifically designed to secure SQL databases, including Azure SQL Database. It provides threat detection for SQL injection attempts by monitoring database query patterns and comparing them against known attack signatures and anomalous activity. This plan also surfaces recommendations like vulnerability assessment findings and configuration weaknesses, making it the direct source for SQL injection alerting against PaaS SQL databases.

Why this answer

Defender for SQL is the correct plan because it specifically provides threat detection for Azure SQL Database, including alerts for SQL injection attempts. It analyzes database audit logs and anomalous query patterns to detect SQL injection attacks, which are a primary threat to sensitive data in SQL databases.

Exam trap

The trap here is that candidates may confuse Defender for App Service with protecting the database, but App Service only protects the web application layer, not the SQL database itself, so SQL injection alerts require Defender for SQL.

How to eliminate wrong answers

Option B is wrong because Defender for Servers protects virtual machines and servers, not Azure SQL Database, and does not include SQL injection detection. Option C is wrong because Defender for Storage protects Azure Blob Storage, Azure Files, and Data Lake Storage, not SQL databases, and focuses on anomalies like unusual access patterns or data exfiltration. Option D is wrong because Defender for App Service protects web applications running on App Service, not the underlying database, and its alerts cover web application attacks like DDoS or brute force, not SQL injection against a database.

248
Matchingmedium

Match each Microsoft 365 Defender role to its permission level.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Full access to all admin features

Manage security policies and view reports

Read-only access to security settings and logs

Respond to alerts and manage incidents

Manage compliance features and data loss prevention

Why these pairings

The correct matches: Global Administrator has full access; Security Administrator manages security; Security Reader has read-only access; Compliance Administrator manages compliance. Common confusions include swapping full access with read-only or misattributing the Global Administrator's scope.

249
Multi-Selecthard

Which THREE actions can you perform using Microsoft Sentinel automation rules?

Select 3 answers
A.Create a new analytics rule
B.Add threat intelligence indicators to Sentinel
C.Run a playbook
D.Change the severity of an incident
E.Assign an incident to a specific analyst
AnswersC, D, E

Automation rules can invoke playbooks, which are Azure Logic Apps workflows, as an automated response when an incident is created or updated. The run playbook action lets you enrich, notify, investigate, or remediate without manual intervention. Playbooks triggered by automation rules require a connection with the appropriate permissions in the resource group.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook as an automated response to an incident or alert. Playbooks are based on Azure Logic Apps and allow you to run complex workflows, such as gathering additional data, sending notifications, or taking remediation actions, directly from the automation rule.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rules, thinking automation rules can create or modify analytics rules, but automation rules only handle incident and alert response actions, not rule creation.

250
MCQeasy

You are investigating an incident in Microsoft Sentinel where a user account was used to sign in from an unfamiliar location and then accessed multiple sensitive files. Which step is most important to perform first?

A.Block the IP address of the unfamiliar location.
B.Check firewall logs for related network traffic.
C.Review file permissions on the accessed files.
D.Disable the user account and reset the password.
AnswerD

Disabling the account and resetting the password immediately contains the active compromise, satisfying the stem's priority of stopping ongoing malicious access before deeper forensic scoping. This neutralises the attacker's session and credentials, preventing further sensitive file exfiltration while investigation continues in Microsoft Sentinel.

Why this answer

Confirming account compromise and immediately disabling the user account is the highest priority to stop further malicious activity. Resetting the password prevents the attacker from using the compromised credentials. Option A is incorrect because blocking the IP address alone may be ineffective if the attacker uses proxies, and it does not secure the account.

Option B is incorrect because checking firewall logs is a secondary forensic step that does not address the immediate threat. Option C is incorrect because reviewing file permissions should be done after securing the account.

251
Multi-Selecthard

Which THREE components are required to enable automation in Microsoft Sentinel? (Choose three.)

Select 3 answers
A.Microsoft Power Automate license
B.Playbooks based on Azure Logic Apps
C.Microsoft Entra ID P2 license
D.Managed identity or service principal for authentication
E.Automation rules
AnswersB, D, E

Playbooks based on Azure Logic Apps are the execution component that actually performs automated response actions in Microsoft Sentinel. These playbooks represent the procedural logic—such as isolating a compromised host, resetting credentials, or enriching an incident—by calling APIs and orchestrating Azure services. Without a playbook, an automation rule has no substantive task to run, so playbooks are a required foundation for enabling security automation.

Why this answer

Playbooks based on Azure Logic Apps are required because they provide the workflow automation engine that executes response actions in Microsoft Sentinel. Without a Logic Apps resource to define the steps (e.g., triggers, conditions, and actions), there is no executable automation to run when an incident or alert is generated.

Exam trap

The trap here is that candidates often confuse the licensing requirements for Power Automate (Option A) with the actual compute engine (Azure Logic Apps) needed for playbooks, or they mistakenly think Entra ID P2 (Option C) is required for automation when it is only needed for identity protection features.

252
MCQmedium

A security analyst is investigating lateral movement in Microsoft 365 Defender. They have identified a compromised device (DeviceA) and want to find all other devices that have been accessed from DeviceA via RDP in the last 24 hours. Which advanced hunting table contains RDP connection events?

A.DeviceNetworkEvents
B.DeviceLogonEvents
C.DeviceProcessEvents
D.IdentityLogonEvents
AnswerA

DeviceNetworkEvents is the correct source because it records every network connection attempt and established session at the device level, including the remote IP address, remote port (e.g., 3389 for RDP), protocol, and the process that initiated the connection. This table directly surfaces the outbound or inbound network flows that constitute lateral movement over RDP, enabling an analyst to trace which endpoint connected to which target and when. Unlike other event tables, DeviceNetworkEvents preserves both direction and destination details, which are essential for reconstructing lateral movement paths.

Why this answer

DeviceNetworkEvents is the correct table because it captures network-level connection events, including outbound RDP (TCP port 3389) connections. When a compromised device initiates an RDP session to another device, the network event is logged here, allowing the analyst to trace lateral movement by filtering for `RemotePort == 3389` and `RemoteIP` of the target.

Exam trap

The trap here is that candidates confuse 'RDP connection events' with authentication events (DeviceLogonEvents) or process creation (DeviceProcessEvents), but the question specifically asks for the table containing the network connection data, not the logon or process launch.

How to eliminate wrong answers

Option B is wrong because DeviceLogonEvents records authentication events (logon type, account, success/failure) but not the network-level RDP connection details like source/destination IP and port. Option C is wrong because DeviceProcessEvents logs process creation and execution events (e.g., mstsc.exe launch) but not the actual network connection to the remote RDP port. Option D is wrong because IdentityLogonEvents tracks cloud-based identity logons (Azure AD, Microsoft Account) and does not include device-level RDP network connections.

253
MCQeasy

A security administrator wants to quickly view the overall security posture of all Azure subscriptions under a single management group that are monitored by Microsoft Defender for Cloud. Where in the Azure portal should they navigate?

A.Microsoft Defender for Cloud overview page
B.Azure Monitor
C.Azure Policy Compliance dashboard
D.Azure Advisor
AnswerA

Microsoft Defender for Cloud's overview page is the correct destination because it aggregates security posture across all enrolled subscriptions in a single pane. It displays the overall secure score, the number of active recommendations, and actionable security alerts, all filtered by the current management-group or subscription scope. This gives a security administrator an immediate, at-a-glance measure of the organization's cloud defense posture.

Why this answer

The Microsoft Defender for Cloud overview page provides a unified dashboard that displays the secure score, regulatory compliance, and security alerts across all subscriptions under a management group. This is the default landing page for assessing the overall security posture, aggregating data from all monitored subscriptions in a single view.

Exam trap

The trap here is that candidates may confuse the Defender for Cloud overview page with Azure Monitor or Azure Advisor, thinking those tools also provide a security posture summary, but only Defender for Cloud's overview page is designed specifically for cross-subscription security posture visibility.

How to eliminate wrong answers

Option B is wrong because Azure Monitor focuses on collecting and analyzing telemetry data (metrics, logs) from resources, not on providing a consolidated security posture score or compliance status across subscriptions. Option C is wrong because the Azure Policy Compliance dashboard shows compliance against Azure Policy definitions, not the comprehensive security posture (including secure score, recommendations, and alerts) that Defender for Cloud offers. Option D is wrong because Azure Advisor provides best-practice recommendations for cost, performance, reliability, and security, but it does not aggregate security posture data across multiple subscriptions under a management group like Defender for Cloud's overview page does.

254
Multi-Selectmedium

Which THREE features are available in Microsoft Defender XDR to help automate incident response? (Choose three.)

Select 3 answers
A.Automated investigation and response (AIR)
B.Microsoft Power Automate
C.Advanced hunting
D.Playbooks
E.Microsoft Sentinel fusion rule
AnswersA, C, D

Automated investigation and response (AIR) is a built-in capability of Microsoft Defender XDR that self-executes security investigations triggered by alerts, applying algorithms to examine evidence like files, processes, and network communications. It automatically takes corrective actions, such as isolating devices or blocking malicious indicators, and records findings for analysts. AIR reduces alert fatigue by containing threats with minimal human intervention.

Why this answer

Automated investigation and response (AIR) in Microsoft Defender XDR automatically runs playbooks on alerts to investigate and remediate threats without manual intervention. It leverages machine learning and security signals across endpoints, email, and identities to contain malicious activity, such as isolating a compromised device or blocking a malicious file, directly within the incident response workflow.

Exam trap

The trap here is that candidates may confuse Microsoft Power Automate as a native Defender XDR feature for automation, when in fact it is an external tool that requires custom configuration and is not part of Defender XDR's built-in automated investigation and response capabilities.

255
MCQhard

A security analyst is investigating a suspected lateral movement attack in Microsoft 365 Defender. The analyst wants to identify all devices where a specific user account (user@contoso.com) had an interactive logon, and then check which of those devices subsequently made outbound RDP connections to other internal IP addresses. Which KQL query approach is most efficient to find this chain?

A.Join DeviceLogonEvents (where AccountName == 'user@contoso.com' and LogonType == 'Interactive') with DeviceNetworkEvents (where RemotePort == 3389) on DeviceName, and filter for NetworkEvents timestamp > LogonEvents timestamp
B.Use IdentityLogonEvents to find the user's logons and join with DeviceNetworkEvents on IP address
C.Query EmailEvents to find emails sent from the user and then check DeviceNetworkEvents on the sender device
D.Union DeviceLogonEvents and DeviceNetworkEvents, then summarize by DeviceName and filter for the user
AnswerA

This query correctly links the user's interactive logon on a device to subsequent outbound RDP traffic to port 3389 from that same device. The timestamp filter ensures the network event occurred after the logon, proving the user (or attacker) established an interactive session before initiating the remote desktop connection. This temporal and device-based correlation is the essential pattern for detecting lateral movement via RDP.

Why this answer

It directly correlates interactive logon events (DeviceLogonEvents with LogonType == 'Interactive') for the specific user with subsequent outbound RDP connections (DeviceNetworkEvents with RemotePort == 3389) on the same device, using a join on DeviceName and a timestamp filter to ensure the network event occurs after the logon. This approach efficiently identifies the lateral movement chain by linking the initial compromise device to the target device via RDP, leveraging the native schema of Microsoft 365 Defender.

Exam trap

The trap here is that candidates may choose Option B, thinking IdentityLogonEvents covers all logons, but it lacks device-level details and LogonType filtering, which are essential for identifying interactive logons on a specific machine in a lateral movement investigation.

How to eliminate wrong answers

Option B is wrong because IdentityLogonEvents captures cloud identity logons (e.g., Azure AD) and does not include device-level interactive logon details like LogonType, making it unsuitable for identifying interactive logons on specific devices. Option C is wrong because EmailEvents tracks email activities, not logon or network events; it cannot provide the device-level interactive logon or outbound RDP connections needed for lateral movement analysis. Option D is wrong because a union of DeviceLogonEvents and DeviceNetworkEvents would mix disparate event types without preserving the temporal and relational link between a logon and subsequent network connection, and summarizing by DeviceName loses the critical timestamp ordering required to prove the chain.

256
MCQmedium

You are testing this analytics rule. It should detect encoded PowerShell commands not from System32, but it is generating false positives. What is the most likely cause?

A.The severity should be Informational
B.The rule should also include System32
C.The query syntax is incorrect
D.The rule does not exclude other legitimate paths like SysWOW64
AnswerD

The rule flags encoded PowerShell outside System32, but legitimate 32-bit processes launch from SysWOW64, which the path exclusion omits. Adding SysWOW64 to the exclusion list removes those benign executions, addressing the false positives described in the stem.

Why this answer

The rule is designed to detect encoded PowerShell commands not originating from System32, but it is generating false positives. The most likely cause is that the rule does not exclude other legitimate paths such as SysWOW64, which also contains legitimate PowerShell executables on 64-bit Windows. Adding an exclusion for SysWOW64 (and possibly other trusted paths) would reduce false positives while maintaining detection of suspicious executions.

Exam trap

The trap is assuming the rule is broken or misconfigured when the real issue is incomplete tuning — candidates may overlook that SysWOW64 is a legitimate path that must be excluded alongside System32.

How to eliminate wrong answers

Option A is wrong because changing severity to Informational does not address the false positives; it only changes the alert priority. Option B is wrong because including System32 would broaden the rule and likely increase false positives, not reduce them. Option C is wrong because if the query syntax were incorrect, the rule would fail to run or produce errors, not generate false positives.

257
MCQhard

Your organization uses Microsoft Defender for Cloud to monitor hybrid workloads. You receive an alert that a fileless malware attack was detected on an on-premises server connected via Azure Arc. The server is running Windows Server 2019. What is the BEST action to contain the threat?

A.Apply a security update using Azure Update Manager.
B.Run a script via Azure Arc to disable the network interfaces on the server.
C.Use Azure Automation runbook to restart the server.
D.Uninstall the Azure Arc agent from the server to isolate it.
AnswerB

Running a script via Azure Arc to disable the network interfaces is a network-based containment action that immediately cuts off all inbound and outbound traffic on the server. By using the Azure Arc 'Run Command' or a custom script extension, the server's NICs are brought down, which blocks data exfiltration, lateral movement, and command-and-control communication with the attacker's infrastructure. This preserves the machine in its current state for forensic analysis while the fileless malware is isolated from the rest of the network. It is an effective first response because it neutralizes the attacker's ability to communicate without disabling management channels.

Why this answer

Disabling the network interfaces via Azure Arc immediately cuts off the compromised server's network connectivity, preventing lateral movement or data exfiltration by the fileless malware. Since fileless malware operates in memory and may not leave persistent artifacts, containment via network isolation is the fastest and most effective initial response.

Exam trap

The trap here is that candidates confuse 'containment' with 'remediation' and choose a long-term fix like patching or restarting, rather than the immediate network isolation required to stop an active fileless attack.

How to eliminate wrong answers

Option A is wrong because applying a security update does not contain an active fileless malware attack; it only patches vulnerabilities for future prevention. Option C is wrong because restarting the server may temporarily disrupt the malware but does not prevent it from re-executing on reboot, and it could also destroy volatile evidence in memory. Option D is wrong because uninstalling the Azure Arc agent does not isolate the server; it only removes management connectivity, leaving the server still accessible on the network and the malware active.

258
Multi-Selecteasy

You are configuring Microsoft Sentinel to use Microsoft Copilot for Security. Which TWO prerequisites must be met?

Select 2 answers
A.Ensure that the Microsoft Defender XDR tenant is integrated with Copilot for Security.
B.Enable Copilot for Security in the Microsoft Sentinel workspace settings.
C.Deploy Copilot for Security in the same Azure region as the Sentinel workspace.
D.Purchase a Microsoft Sentinel premium license.
E.Provision Security Compute Units (SCUs) in the Copilot for Security portal.
AnswersA, E

To enable Microsoft Copilot for Security to access Sentinel incident data, you must integrate the Microsoft Defender XDR tenant (which serves as the identity and data plane) with Copilot for Security. This integration establishes the required permissions and data flow, allowing the Copilot to retrieve and analyze security signals from Sentinel. Without this tenant-level integration, Copilot cannot authenticate to Sentinel workspaces or access their incidents, even if other components are correctly configured.

Why this answer

Microsoft Copilot for Security must be integrated with the Microsoft Defender XDR tenant to access and correlate security data across the Microsoft security ecosystem. This integration enables Copilot to leverage signals from Defender XDR, Microsoft Sentinel, and other sources for incident response and investigation. Without this tenant-level integration, Copilot cannot authenticate or retrieve the necessary security context from Defender XDR.

Exam trap

The trap here is that candidates often confuse enabling Copilot in Sentinel workspace settings (Option B) with the actual tenant-level integration required, or they assume a premium Sentinel license is mandatory when only SCU provisioning and Defender XDR integration are needed.

259
MCQhard

Your organization has multiple offices across the globe and uses Microsoft Sentinel as the primary SIEM. You have deployed Azure Arc on all on-premises servers to manage them centrally. The security team needs to collect Windows Security Events from all servers, including domain controllers, and forward them to Sentinel using the Windows Security Events via AMA connector. The team also wants to minimize administrative overhead when adding new servers. The current environment includes: 500 on-premises Windows servers (200 domain controllers, 300 member servers) managed via Azure Arc, 200 Azure VMs running Windows Server, and a centralized Log Analytics workspace named 'LAW-Security' in the East US region. You have already installed the Azure Monitor Agent (AMA) on all servers via Azure Arc and Azure VMs. However, you notice that security events from domain controllers are not appearing in Sentinel. You have verified that the AMA agent is running and the data collection rule (DCR) is correctly configured to collect Security events. No other issues are present. You need to ensure that security events from domain controllers are collected. What should you do?

A.Reinstall the Windows Security Events via AMA connector in Sentinel.
B.Restart the Azure Monitor Agent on all domain controllers.
C.Recreate the data collection rule with a different namespace.
D.Check the network connectivity from the domain controllers to the Log Analytics workspace endpoint. Ensure that the domain controllers can reach the required URLs.
AnswerD

Domain controllers generate the Security events, but AMA forwards them over HTTPS to the Log Analytics ingestion endpoint. If outbound connectivity to the required URLs is blocked, events silently fail to reach LAW-Security despite correct DCR configuration.

Why this answer

Domain controllers often have more restrictive network policies, and they must be able to reach the Log Analytics workspace endpoint (the data collection endpoint and the Log Analytics service) to send events. The AMA agent is running and the DCR is configured, but if domain controllers cannot connect to the required URLs (e.g., *.ods.opinsights.azure.com, *.oms.opinsights.azure.com, etc.), events will not be collected. Option A is incorrect because the connector configuration is not the issue; the connector is already working for other servers.

Option B is incorrect because restarting the agent does not address network issues. Option C is incorrect because the DCR namespace is irrelevant; the DCR configuration is correct for other servers.

260
MCQeasy

Your organization uses Microsoft Sentinel. You need to ensure that an incident is automatically assigned to the appropriate team based on the type of alert. What should you configure?

A.Workbook
B.Playbook
C.Analytics rule
D.Automation rule
AnswerD

Automation rules in Microsoft Sentinel can be configured to trigger on alert creation and use conditions such as alert name or severity to automatically assign incidents to a specific team via the "Assign owner" action. This satisfies the stem’s constraint of routing incidents based on alert type without requiring manual triage or separate playbook logic.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific teams based on conditions such as alert type or severity. This is the correct configuration because automation rules can trigger actions like incident assignment, tagging, or status changes without requiring a complex logic app or custom code.

Exam trap

The trap here is that candidates often confuse Playbooks (which can also assign incidents via Logic Apps) with Automation rules, but Automation rules are the native, simpler, and more efficient method for straightforward assignment tasks, while Playbooks are better for complex multi-step workflows.

How to eliminate wrong answers

Option A is wrong because Workbooks are visualization tools for querying and displaying data, not for automating incident assignment. Option B is wrong because Playbooks are automated workflows (often using Azure Logic Apps) that can respond to alerts or incidents, but they are not the primary or simplest method for automatic assignment; automation rules are designed for this purpose. Option C is wrong because Analytics rules generate alerts based on data queries, but they do not handle post-alert actions like incident assignment; that is the role of automation rules.

261
Multi-Selectmedium

A security analyst is investigating a potential ransomware incident in Microsoft Defender XDR. The analyst needs to confirm the scope of the attack and halt further propagation. Which TWO actions should the analyst take first?

Select 2 answers
A.Initiate automated investigation on the affected devices
B.Reset passwords for all users in the organization
C.Collect forensic evidence from affected systems
D.Isolate the affected devices from the network
E.Run a full antivirus scan on all endpoints
AnswersA, D

Microsoft Defender for Endpoint's automated investigation leverages behavioral analytics and threat intelligence to immediately scope a ransomware incident, identifying all affected files, processes, and user accounts in parallel while containing the threat. Because it executes investigation playbooks automatically and can trigger containment actions such as device isolation or indicator blocking, it is faster than manual triage and preserves forensic context for the incident graph. Initiating automated investigation is the recommended first step in Defender for Endpoint because it converts a suspected outbreak into a scoped, machine-readable set of evidence.

Why this answer

Initiating automated investigation on affected devices (A) is correct because Microsoft Defender XDR's automated investigation uses built-in playbooks to automatically analyze alerts, determine the scope of compromise, and suggest remediation actions without manual intervention. This is the fastest way to confirm the attack scope while simultaneously halting propagation. Isolating affected devices (D) is correct because network isolation immediately cuts off communication between the compromised device and other systems, preventing lateral movement and further encryption of network shares.

Both actions are first-response steps in a ransomware incident.

Exam trap

The SC-200 exam often tests the distinction between containment-first vs. investigation-first; the trap here is that candidates may choose 'collect forensic evidence' (C) thinking it is necessary before isolation, but in a ransomware scenario, stopping propagation is the immediate priority, and forensic collection can be done after isolation.

262
Multi-Selecteasy

You are a security operations analyst for a company that uses Microsoft Sentinel. You need to ensure that incidents are automatically assigned to the appropriate team based on the incident type. Which two actions should you take?

Select 2 answers
A.Modify the analytics rule to set the incident owner directly.
B.Create a playbook that assigns incidents based on the incident type.
C.Create a workbook that filters incidents by type and assigns them manually.
D.Define custom details in the analytics rule to include the team name, then use an automation rule to assign.
E.Create an automation rule that uses conditions to set the incident owner.
AnswersD, E

To assign incidents to teams based on a team name, you can first configure custom details in the analytics rule to extract the team name from the alert into a custom property on the incident. Then, in the automation rule, you can create a condition that checks this custom detail and set the incident owner accordingly. This approach works because automation rules can only evaluate incident properties, so custom details bridge the gap when the team is not a standard incident field.

Why this answer

Custom details in an analytics rule allow you to extract and store the team name from the incident data, and then an automation rule can use that custom detail as a condition to automatically assign the incident to the appropriate owner. This approach ensures dynamic assignment based on the incident type without requiring a playbook or manual intervention.

Exam trap

The trap here is that candidates often think a playbook (Option B) is required for any automated action beyond basic alerting, but Microsoft Sentinel's automation rules can directly set incident owners based on conditions without needing a playbook.

263
Multi-Selecthard

Which THREE of the following are recommended practices for creating effective threat hunting queries in Microsoft Sentinel? (Select three.)

Select 3 answers
A.Use only broad patterns to avoid missing anything
B.Use wildcards extensively to capture variations
C.Include known indicators of compromise from threat feeds
D.Map queries to MITRE ATT&CK techniques
E.Limit the query to a specific time range
AnswersC, D, E

Incorporating threat-feed indicators of compromise lets queries match observed malicious artefacts—IP addresses, domains, file hashes—against telemetry already ingested in Microsoft Sentinel, satisfying the stem's requirement for effective hunting queries. This converts external threat intelligence into concrete detection logic, surfacing known adversary infrastructure without waiting for an alert to fire.

Why this answer

Option C is correct because incorporating known indicators of compromise (IOCs) such as malicious IP addresses, domains, file hashes, and URLs from threat intelligence feeds lets hunting queries directly surface activity tied to known adversaries, which is a core recommended practice in Microsoft Sentinel. Option D is correct because mapping queries to MITRE ATT&CK techniques aligns hunting with specific adversary tactics and techniques, enabling coverage tracking, prioritization of gaps, and consistent query design across the kill chain. Option E is correct because constraining a query to a specific, relevant time range improves performance and reduces noise, ensuring the hunt focuses on the window of interest rather than scanning the entire retention period.

Option A is not recommended because overly broad patterns generate excessive false positives and dilute the signal, and Option B is not recommended because excessive wildcard use degrades KQL query performance and precision, making results harder to triage.

264
MCQhard

An analyst creates a playbook in Microsoft Sentinel to automatically block an IP address when an alert fires. However, the playbook fails to block the IP. What is the most likely cause?

A.The IP address is being extracted from an incorrect field in the alert
B.The block duration is set to one day, which is too short
C.The playbook actions array has only one action, which is insufficient
D.The playbook is using the wrong trigger type; it should be on incident creation
AnswerA

The playbook is correctly triggered but fails because it references 'alertRuleId' as the IP address. In Sentinel alert payloads, alertRuleId is merely the identifier of the analytics rule that generated the alert, not a network entity. The IP address must be extracted from the 'Entities' collection of the incident, specifically from an entity with type 'IP' (e.g., Entities.IP.address). Passing a non-IP string to a block action causes input validation failure, so the playbook cannot block the address.

Why this answer

The most likely cause is that the playbook is extracting the IP address from an incorrect field in the alert. In Microsoft Sentinel, playbooks use the SecurityAlert schema, where the IP address may be stored in different fields (e.g., 'RemoteIP', 'SourceIP', 'DestinationIP') depending on the alert provider. If the playbook references the wrong field, it will pass a null or incorrect value to the block action, causing the automation to fail silently or target the wrong entity.

Exam trap

The trap here is that candidates assume the playbook trigger or action count is the problem, when the real issue is data extraction from the alert schema—a common oversight in automation workflows.

How to eliminate wrong answers

Option B is wrong because a block duration of one day is not inherently too short; the playbook would still execute the block action successfully for that duration, so duration does not cause the failure. Option C is wrong because a playbook actions array can contain a single action and still function correctly; there is no minimum number of actions required for execution. Option D is wrong because the playbook trigger type should be on alert creation (when the alert fires), not on incident creation; using incident creation would delay or miss the automated block, but the question states the playbook fails to block the IP, implying the trigger is not the root cause—the extraction logic is.

265
MCQmedium

You are threat hunting in Microsoft Defender for Cloud Apps. You want to identify users who have enabled mailbox forwarding rules to external domains, which could indicate data exfiltration. Which log source should you query?

A.Office 365 audit logs
B.Microsoft Entra ID sign-in logs
C.Windows Event logs from domain controllers
D.Azure Network Watcher logs
AnswerA

Office 365 audit logs capture Exchange mailbox rule creation and modification events, including Set-InboxRule operations that forward mail externally. Querying this source in Microsoft Sentinel surfaces users who configured external forwarding, matching the exfiltration hunt.

Why this answer

Microsoft Defender for Cloud Apps can ingest Office 365 audit logs, which include Exchange mailbox audit events for forwarding rules. Options B, C, and D are incorrect: Microsoft Entra ID sign-in logs (B) do not contain mailbox forwarding events, Windows Event logs from domain controllers (C) are device-focused and do not include Exchange mailbox rules, and Azure Network Watcher logs (D) are for network monitoring and do not include mailbox rules.

266
MCQhard

You are a security operations analyst for a company that uses Microsoft Sentinel. You have a playbook that remediates compromised user accounts by disabling the account and revoking sessions. You need to ensure that the playbook runs automatically whenever an incident is created with the 'Compromised User' tag. What should you configure?

A.An automation rule with a condition that checks for the 'Compromised User' tag and an action to run the playbook.
B.A playbook trigger configured in the Logic App Designer to start when a Sentinel incident is created.
C.A scheduled analytics rule that runs every 5 minutes and triggers the playbook.
D.A Microsoft Sentinel workbook that monitors incidents with the 'Compromised User' tag and sends a command to run the playbook.
AnswerA

Automation rules in Microsoft Sentinel can trigger playbooks based on incident conditions, including tags. You can create a rule that evaluates the incident's tags and, if the 'Compromised User' tag is present, runs the specified playbook. This is the correct method to automatically execute a playbook when an incident with a specific tag is created. It provides the required automation without manual intervention.

Why this answer

Automation rules are the mechanism in Microsoft Sentinel to automatically respond to incidents. By creating an automation rule that checks for the 'Compromised User' tag and then runs the playbook, you ensure the playbook executes only for incidents with that tag. This is the intended use of automation rules for playbook triggering.

Exam trap

The trap here is thinking that a playbook's own trigger can filter by tags, when in fact automation rules provide that conditional logic.

267
MCQmedium

A security team enables Microsoft Defender for Cloud on an Azure subscription and wants to ensure that all Azure SQL databases have threat detection enabled. Which plan must be enabled to receive alerts for SQL injection attempts?

A.Defender for Servers
B.Defender for SQL
C.Defender for Storage
D.Defender for Key Vault
AnswerB

Microsoft Defender for SQL is the specialized plan that secures Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure VMs/on-premises through Defender for Cloud. It combines advanced threat protection with SQL injection detection, anomalous access-pattern alerts, and vulnerability assessments at the database layer. This is the only plan among the choices that is designed to protect a SQL database and surface database-specific recommendations.

Why this answer

Defender for SQL is the specific Microsoft Defender for Cloud plan that provides threat detection for Azure SQL databases, including alerts for SQL injection attacks. It monitors database activity for anomalous patterns, such as SQL injection attempts, and generates security alerts. Without this plan enabled, threat detection for SQL databases remains disabled, even if other Defender plans are active.

Exam trap

The trap here is that candidates may confuse Defender for Servers with general database protection, not realizing that SQL-specific threat detection requires the dedicated Defender for SQL plan, not the server-level plan.

How to eliminate wrong answers

Option A is wrong because Defender for Servers protects virtual machines and their workloads, not Azure SQL databases; it does not include SQL-specific threat detection. Option C is wrong because Defender for Storage monitors storage accounts for threats like malware uploads or anonymous access, not SQL injection attempts. Option D is wrong because Defender for Key Vault focuses on detecting threats against key vaults, such as unauthorized access or secret exfiltration, and has no visibility into SQL database activity.

268
MCQeasy

You are reviewing an incident in Microsoft Sentinel. The incident is assigned to a user. What does the 'assignedTo' field indicate?

A.The incident was created by that user.
B.The incident was closed by that user.
C.The incident is assigned to that user for investigation.
D.The incident is assigned to a Microsoft Entra group.
AnswerC

In Microsoft Sentinel, the 'Owner' field (also displayed as 'Assigned to' in the incident details) identifies the single user who is currently responsible for investigating and managing the incident. When a user's name appears in this field, it means that user has been assigned the incident, either manually through the 'Assign owner' button or automatically via an automation rule. This assignment is used for tracking ownership, routing work, and reporting on investigation progress, and it is the direct answer to the question of who is handling the incident. Therefore, a user in that field indicates the incident is assigned to that user for investigation.

Why this answer

In Microsoft Sentinel, the 'assignedTo' field is used to track ownership of an incident during its lifecycle. When an incident is assigned to a user, it indicates that user is responsible for investigating and resolving the incident, not that they created or closed it. This field is set manually or via automation rules to ensure clear accountability for incident response.

Exam trap

The trap here is that candidates confuse 'assignedTo' with 'createdBy' or 'closedBy', assuming ownership implies creation or closure, but Sentinel separates these fields to track distinct stages of the incident lifecycle.

How to eliminate wrong answers

Option A is wrong because the 'assignedTo' field does not indicate who created the incident; the 'createdBy' field tracks the creator (e.g., an analytics rule or a user). Option B is wrong because the 'assignedTo' field does not indicate who closed the incident; the 'closedBy' field records the user who resolved it. Option D is wrong because the 'assignedTo' field in Sentinel incidents is a single user (a string value representing a user principal name), not a Microsoft Entra group; group assignment is not supported for incident ownership.

269
MCQmedium

Your security team uses Microsoft Sentinel to hunt for signs of credential theft. They want to correlate Azure AD sign-in logs with Microsoft Defender for Cloud Apps alerts. Which KQL operator should they use to join the two tables on the user principal name?

A.union
B.join
C.lookup
D.evaluate
AnswerB

join is correct because the KQL join operator correlates rows from two tabular expressions on one or more equality conditions (keys), returning rows that contain columns from both sides. For example, joining SigninLogs with AADAuditLogs on UserId or IP address lets you see a logon event and the subsequent activity side by side, which is exactly the kind of key-based matching needed when hunting across heterogeneous data sources. You can control the output with join kinds such as innerunique, inner, leftouter, and rightouter to tailor the hunt to your hypothesis.

Why this answer

The 'join' operator merges rows from two tables based on a matching key. Option A is incorrect because 'union' appends rows, not correlates. Option C is incorrect because 'lookup' is a type of join but is less common for this scenario.

Option D is incorrect because 'evaluate' is used for plugin execution, not joining tables.

270
Multi-Selectmedium

Which TWO data sources should you enable in Microsoft Sentinel to improve detection of credential theft attacks?

Select 2 answers
A.Windows Security Events (via AMA)
B.DNS logs
C.Azure Active Directory Sign-in logs
D.Windows Firewall logs
E.Performance counters
AnswersA, C

Windows Security Events via AMA stream logon events such as 4624, 4625 and 4672, which expose brute-force, pass-the-hash and privilege-escalation patterns. Ingesting these satisfies the credential-theft detection requirement by feeding Sentinel analytics rules that correlate suspicious authentication behaviour on Windows hosts.

Why this answer

Option A, Windows Security Events (via AMA), is correct because it collects the Security event log through the Azure Monitor Agent and surfaces the exact events credential-theft detection relies on, such as 4624/4625 logons, 4648 explicit-credential use, 4672 special privileges, and 4768/4769 Kerberos TGT/TGS requests used to spot pass-the-hash, pass-the-ticket, and Kerberoasting. Option C, Azure Active Directory Sign-in logs, is correct because it captures Entra ID authentication telemetry — sign-in results, conditional access outcomes, MFA details, and risk detections — which Sentinel uses to detect password spray, brute force, impossible travel, and token/session theft against cloud identities. Option B, DNS logs, is not required here since DNS telemetry supports exfiltration, C2, and DGA detection rather than credential theft.

Option D, Windows Firewall logs, records allowed/blocked network connections and is irrelevant to authentication abuse. Option E, Performance counters, provides host resource metrics and has no bearing on detecting stolen credentials.

Exam trap

SC-200 often tests whether candidates confuse network-layer telemetry (DNS, firewall) with identity-layer telemetry, causing them to pick sources that detect lateral movement rather than credential theft.

271
Multi-Selecteasy

Which TWO actions can be performed using Microsoft Sentinel automation rules? (Choose two.)

Select 2 answers
A.Change the severity of an incident
B.Add a tag to an incident
C.Deploy a data connector
D.Modify a watchlist
E.Create a scheduled query rule
AnswersA, B

Automation rules in Microsoft Sentinel include a built-in action that updates the incident severity field. This action can be triggered conditionally, for example when an incident is assigned a MITRE technique or when entity analytics raise the risk score. Because severity directly drives triage priority in the SOC queue, being able to auto-adjust it based on changing context is a core incident-response action, making this a correct answer.

Why this answer

Automation rules in Microsoft Sentinel allow you to automate incident management tasks, including changing the severity of an incident and adding tags. These actions are part of the incident-handling workflow and can be triggered when an incident is created or updated, enabling consistent triage and enrichment without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks or other Sentinel configuration tasks, assuming that any automated action (like deploying connectors or creating rules) can be done via automation rules, when in fact automation rules are strictly for incident management actions.

272
MCQhard

You are managing a Microsoft Sentinel environment. You need to ensure that incidents are automatically assigned to the appropriate analyst based on the type of attack. The assignment must consider the current workload of each analyst. What should you use?

A.Configure multiple analytics rules, each with a different incident owner.
B.Use an automation rule with a playbook that queries the current incident assignments and assigns to the least busy analyst.
C.Create a watchlist that maps attack types to analyst names and use it in an analytics rule.
D.Create a workbook that shows analyst workload and manually assign.
AnswerB

An automation rule can be triggered on incident creation and invoke a playbook built in Azure Logic Apps. The playbook queries the Microsoft Sentinel API (security insights 'Incident' resource) to retrieve all active incidents, counts the open assignments per analyst, determines the analyst with the fewest open incidents, and then updates the incident owner using an action such as 'Entity Incident Management' or an HTTP call to the API. This provides dynamic, workload-aware assignment that static configuration cannot.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook (Azure Logic App) that queries the current incident assignments and assigns the incident to the analyst with the fewest active incidents. This satisfies both the attack-type mapping (via the analytics rule that generates the incident) and the workload-balancing requirement, as the playbook can dynamically evaluate workload using Azure Resource Graph or Sentinel's API.

Exam trap

The trap here is that candidates often confuse static assignment (Option A or C) with dynamic assignment, failing to realize that only a playbook can query real-time workload data and make a runtime decision based on it.

How to eliminate wrong answers

Option A is wrong because configuring multiple analytics rules with different incident owners only allows static assignment per rule, not dynamic workload-based assignment; it cannot consider current analyst workload. Option C is wrong because a watchlist can map attack types to analyst names, but using it in an analytics rule only sets a static owner field, not a dynamic assignment based on real-time workload. Option D is wrong because a workbook only provides a visual report of analyst workload; it cannot automate assignment, and manual assignment does not meet the requirement for automatic assignment.

273
MCQhard

Your SOC uses Microsoft Sentinel and Microsoft Defender XDR. An incident is generated from a Microsoft Defender for Identity alert about a suspicious Kerberos ticket request. The incident is assigned the 'Medium' severity. You want to automatically increase the severity to 'High' if the user is in a privileged role, based on data from Microsoft Entra ID. What is the most efficient way to achieve this?

A.Enable automatic attack disruption in Microsoft Defender XDR to handle the incident.
B.Modify the analytics rule that generates the incident to check user roles during query execution.
C.Create an automation rule in Microsoft Sentinel triggered on incident creation, which runs a playbook that checks Microsoft Entra ID roles and updates the severity accordingly.
D.Create a scheduled analytics rule that queries Microsoft Entra ID audit logs and updates incident severity via a watchlist.
AnswerC

An automation rule with an incident creation trigger can invoke a playbook that uses Logic Apps and the Microsoft Entra ID connector or Graph API to read the incident's user entity and retrieve their directory role assignments. The playbook can then call the 'Update incident' action to set the severity to a higher value if the user holds a privileged role, such as Global Administrator. This approach is purpose-built for incident lifecycle management and provides real-time, agentless enrichment without altering detection logic.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook on incident creation, and that playbook can use the Microsoft Graph API to query Microsoft Entra ID for the user's role assignments. If the user holds a privileged role (e.g., Global Administrator), the playbook can programmatically update the incident's severity to 'High'. This approach is event-driven, efficient, and does not require modifying existing analytics rules or creating additional scheduled queries.

Exam trap

The trap here is that candidates may think modifying the analytics rule (Option B) is simpler, but they overlook that analytics rules cannot natively query external identity stores like Microsoft Entra ID during query execution without complex KQL cross-workspace joins or enrichment, making the automation rule with a playbook the most efficient and maintainable solution.

How to eliminate wrong answers

Option A is wrong because automatic attack disruption in Microsoft Defender XDR is designed to automatically contain active attacks (e.g., by isolating devices or blocking accounts), not to adjust incident severity based on user role data from Microsoft Entra ID. Option B is wrong because analytics rules in Microsoft Sentinel query data already ingested into the Log Analytics workspace (e.g., from Microsoft Defender for Identity), and they cannot directly query Microsoft Entra ID roles during rule execution without a separate data connector or enrichment step, making this approach inefficient and not the most efficient. Option D is wrong because creating a scheduled analytics rule that queries Microsoft Entra ID audit logs and updates severity via a watchlist is an indirect, batch-oriented method that introduces latency and complexity; it is less efficient than a real-time automation rule triggered on incident creation.

274
MCQeasy

A security analyst is investigating a suspicious process on an endpoint and wants to see all changes made to the Windows Registry by that process. Which advanced hunting table should the analyst query to find registry modification events associated with the process?

A.DeviceProcessEvents
B.DeviceRegistryEvents
C.DeviceEvents
D.DeviceFileEvents
AnswerB

DeviceRegistryEvents is the correct answer because it is the dedicated advanced hunting table for registry changes, recording event types such as RegistryValueSet, RegistryKeyDeleted, and RegistryValueDeleted. Each event includes the affected RegistryKey, RegistryValueName, RegistryValueData, and the initiating process with its command line. This schema allows the analyst to directly link a specific registry modification to the process that performed it, which is the core requirement of this investigation.

Why this answer

DeviceRegistryEvents is the correct table because it specifically captures Windows Registry modification events, including create, modify, and delete operations. For a process-based investigation, this table includes the InitiatingProcessId and InitiatingProcessFileName columns, allowing the analyst to filter by the suspicious process's PID or name to see all registry changes it made.

Exam trap

The trap here is that candidates often confuse DeviceEvents (which sounds generic enough to include registry events) with the dedicated DeviceRegistryEvents table, but DeviceEvents only contains security alerts and not raw registry modification telemetry.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents logs process creation and termination events, not registry modifications. Option C is wrong because DeviceEvents is a generic table that captures security alerts and various system events, but it does not have dedicated registry change columns like DeviceRegistryEvents. Option D is wrong because DeviceFileEvents logs file creation, modification, and deletion events, not registry key or value changes.

275
Multi-Selectmedium

Which TWO actions should you take when configuring Microsoft Sentinel to minimize false positives from an analytics rule?

Select 2 answers
A.Add a playbook to automatically close low-severity alerts
B.Map entities correctly
C.Enable incident creation automatically
D.Adjust the rule's query threshold
E.Configure alert grouping
AnswersB, D

Mapping entities correctly ties alerts to the right accounts, hosts and IP addresses, so Microsoft Sentinel correlates activity accurately and stops unrelated events triggering the rule. This directly reduces false positives by ensuring entity-based logic matches genuine incidents.

Why this answer

Option B (Map entities correctly) is correct because accurate entity mapping (for example, mapping Account, Host, or IP custom entities in the rule's entity mapping section) lets Sentinel correlate and enrich alerts with the right context, so benign activity isn't misattributed and duplicate or unrelated alerts aren't generated. Option D (Adjust the rule's query threshold) is correct because tuning the rule's KQL query — for example, raising the count or time-window threshold, filtering known-good accounts, or adding exclusions — directly reduces the volume of low-fidelity matches that become false-positive incidents. Option A is not a false-positive reduction measure; a playbook that auto-closes low-severity alerts only handles alerts after they are created and does not stop them from firing.

Option C (Enable incident creation automatically) actually increases noise by turning every matching alert into an incident rather than suppressing false positives. Option E (Configure alert grouping) consolidates related alerts into fewer incidents but does not reduce the underlying false-positive detections.

276
MCQmedium

Your Microsoft Sentinel workspace ingests logs from multiple sources but you notice that some custom logs are missing in the Log Analytics workspace. You've confirmed that the data connectors are healthy. What is the most likely cause?

A.The custom log table schema does not match the incoming log format.
B.There is a time gap between log generation and ingestion.
C.The workspace has exceeded its daily ingestion limit.
D.The data connectors are not properly configured for custom log ingestion.
AnswerA

Custom log tables in Microsoft Sentinel have a fixed schema defined at creation (via DCR, custom log API, or saved as a table). When the incoming log records contain fields that do not match this defined schema — such as a different column name, wrong data type, or extra fields that are not in the table — the Log Analytics ingestion pipeline validates each record and rejects the entire record during parsing. This causes the logs to be silently dropped before they can be indexed, so you see missing custom log data even though connectors and workspace health are normal.

Why this answer

When data connectors are healthy but custom logs are missing, the most common cause is a schema mismatch between the custom log table definition in the Log Analytics workspace and the actual log data being sent. Microsoft Sentinel requires the custom log table's schema (columns, data types, and delimiters) to exactly match the incoming log format; otherwise, the ingestion pipeline drops the records without error. This is because the Log Analytics agent or AMA uses the table schema to parse and transform the data, and any deviation results in silent failures.

Exam trap

The trap here is that candidates assume a healthy data connector guarantees all logs are ingested, but Microsoft tests the nuance that schema mismatches cause silent ingestion failures even when the connector itself is operational.

How to eliminate wrong answers

Option B is wrong because a time gap between log generation and ingestion does not cause logs to be missing; it only delays their appearance in the workspace, and Sentinel can still ingest them later. Option C is wrong because exceeding the daily ingestion limit would cause all log ingestion to stop or be throttled, not just custom logs, and you would see ingestion quota warnings in the workspace. Option D is wrong because the question explicitly states that data connectors are healthy, meaning they are properly configured for custom log ingestion; if they were misconfigured, the connectors would show an unhealthy status or fail to connect.

277
MCQeasy

Refer to the exhibit. You have an analytics rule in Microsoft Sentinel that uses this KQL query. The rule is configured to run every hour and alert when the result count is greater than 0. Which type of attack is this rule most likely detecting?

A.Privileged account misuse
B.Data exfiltration via sign-in
C.Account takeover from a new location
D.Brute force attack on user accounts
AnswerD

A brute force attack on user accounts is the correct classification because high-risk sign-ins reflect patterns such as repeated failed password attempts, impossible travel across many accounts, or logins from known malicious IPs—all hallmarks of password guessing or credential stuffing. Sentinel analytics rules that aggregate risk signals from Microsoft Entra ID Protection will generate a single incident when multiple users experience elevated sign-in risk, which matches a coordinated brute-force or password-spray attack rather than a targeted compromise.

Why this answer

The KQL query counts failed sign-in events (ResultType != 0) aggregated by User, IPAddress, and a 5-minute bin, then filters for users with more than 10 failures. This pattern of multiple rapid failed logins from the same IP against a single user is the classic signature of a brute force attack, where an attacker tries many passwords to guess credentials. The rule triggers when the count exceeds 10 within any 5-minute window, making it highly specific to brute force detection.

Exam trap

The trap here is that candidates confuse 'account takeover from a new location' (which requires a successful sign-in from an unfamiliar location) with 'brute force attack' (which is characterized by multiple failed sign-ins), leading them to pick Option C instead of D.

How to eliminate wrong answers

Option A is wrong because privileged account misuse typically involves unusual activity after successful authentication (e.g., abnormal role assignments, privilege escalation), not repeated failed logins. Option B is wrong because data exfiltration via sign-in would focus on successful sign-ins followed by data transfer anomalies, not failed authentication attempts. Option C is wrong because account takeover from a new location would be detected by successful sign-ins from unfamiliar geographic locations or devices, not by a high volume of failed attempts from a single IP.

278
MCQhard

During a ransomware incident, Microsoft Sentinel generated an incident with high severity. The incident includes alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Entra ID. Your team needs to automate the containment process. What is the best approach to automatically isolate affected devices and disable compromised accounts?

A.Use advanced hunting to find all affected devices and accounts
B.Create an automation rule in Microsoft Sentinel that runs a playbook to isolate devices and disable accounts
C.Create a custom detection rule in Microsoft Sentinel to trigger an incident
D.Configure automated investigation and response in Microsoft Defender for Endpoint
AnswerB

An automation rule triggers a playbook on incident creation, and the playbook calls Defender for Endpoint and Microsoft Entra ID actions to isolate devices and disable accounts. This satisfies the containment requirement without manual intervention.

Why this answer

The best approach is to create an automation rule in Microsoft Sentinel that triggers a playbook to isolate devices and disable accounts. Automation rules can be configured to run playbooks automatically when an incident is created, and the playbook can call Microsoft Defender for Endpoint to isolate devices and Microsoft Entra ID to disable accounts. This provides a centralized, automated containment workflow across multiple sources.

Exam trap

SC-200 often tests the difference between detection (creating incidents) and response (automation rules/playbooks), and candidates may incorrectly choose Defender for Endpoint AIR because it only covers endpoints, not the multi-domain incident.

How to eliminate wrong answers

Option A is wrong because advanced hunting is a manual query tool for investigation, not an automated containment mechanism; it does not isolate devices or disable accounts. Option C is wrong because creating a custom detection rule only generates incidents; it does not perform containment actions. Option D is wrong because configuring automated investigation and response in Defender for Endpoint only covers endpoint devices and does not disable Entra ID accounts, and it is limited to the Defender for Endpoint scope, not the multi-source incident in Sentinel.

279
MCQeasy

In Microsoft 365 Defender, an incident is created automatically. An analyst wants to see all related alerts for that incident. Which tab on the incident details page should the analyst select?

A.Alerts tab
B.Devices tab
C.Users tab
D.Evidence tab
AnswerA

The Alerts tab is the correct location because it aggregates all individual security alerts that Microsoft 365 Defender correlation logic has grouped into the incident. This tab provides a unified, chronological list of detections from workloads such as Defender for Endpoint, Defender for Office 365, and Defender for Identity, including each alert's severity, status, and investigative priority. Analysts use this tab to identify the full attack chain and determine which alerts warrant immediate action, making it the authoritative alert list for the incident.

Why this answer

The Alerts tab on the incident details page in Microsoft 365 Defender displays all alerts that have been automatically correlated into the incident. Since an incident is a collection of related alerts, selecting the Alerts tab is the correct way for an analyst to view every individual alert that contributed to the incident.

Exam trap

The trap here is that candidates may confuse the Evidence tab (which shows supporting artifacts) with the Alerts tab, not realizing that the Evidence tab only contains a subset of entities and not the full alert list.

How to eliminate wrong answers

Option B (Devices tab) is wrong because it shows the devices involved in the incident, not the alerts themselves. Option C (Users tab) is wrong because it lists the user accounts associated with the incident, not the alerts. Option D (Evidence tab) is wrong because it provides supporting evidence and entities (such as files, IPs, or emails) rather than the full list of alerts.

280
Multi-Selecteasy

Which TWO KQL operators are commonly used in threat hunting to join tables based on a key?

Select 2 answers
A.lookup
B.join
C.extend
D.summarize
E.union
AnswersA, B

The lookup operator enriches a fact table by pulling values from a dimension-style table based on equality of specified keys, using left-outer semantics that preserve the left side's row count and only add columns. This is essential in threat hunting for attaching authoritative context—such as user names, asset owners, or threat-intel tags—to raw events without the risk of row multiplication. Unlike join, lookup is optimized for dimension-style, one-to-many enrichment and is a common choice when the goal is to decorate events with descriptive attributes.

Why this answer

Option A, lookup, is correct because it enriches events by joining a fact table with a dimension table on a matching key column, returning only the columns from the lookup table and is optimized for this common threat-hunting enrichment pattern. Option B, join, is correct because it combines rows from two tables based on matching values of a specified key column (e.g., join kind=inner on Account), which is the general-purpose operator for correlating tables in KQL. Option C, extend, is not a join operator; it adds or computes new columns on a single table.

Option D, summarize, aggregates rows into groups using functions like count() or dcount(), not a key-based table join. Option E, union, appends rows from multiple tables into one result set without matching on a key.

Exam trap

SC-200 often tests the distinction between operators that combine tables (join, lookup, union) versus those that transform a single table (extend, summarize), and candidates may mistakenly select `union` for key-based joins.

281
MCQeasy

You are investigating a security incident in Microsoft Sentinel. You want to visualize the relationships between entities such as IP addresses, users, and hosts. Which tool should you use?

A.Investigation graph
B.Analytics rules
C.Automation rules
D.Workbooks
AnswerA

The investigation graph in Microsoft Sentinel renders entities such as IP addresses, users and hosts as connected nodes, exposing relationships and lateral movement paths visually. This satisfies the requirement to visualise entity relationships during incident investigation, unlike log queries or workbooks.

Why this answer

The Investigation graph in Microsoft Sentinel is specifically designed to visualize relationships between entities such as IP addresses, users, and hosts, making it the correct tool for this task. Analytics rules (B) are used for detection, automation rules (C) for automated responses, and workbooks (D) for dashboards and reporting, not for entity relationship visualization.

282
MCQeasy

An organization uses Microsoft Defender for Cloud Apps to detect anomalous behavior. An alert indicates that a user has signed in from an impossible travel scenario. The SOC analyst confirms the alert is a false positive due to a VPN. What should the analyst do to prevent future false positives for this user?

A.Change the user's location in Microsoft Entra ID.
B.Ignore the alert and continue monitoring.
C.Disable the impossible travel detection rule.
D.Add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps.
AnswerD

Adding the VPN IP range to Defender for Cloud Apps trusted IP addresses suppresses impossible-travel detections originating from those addresses, since the engine treats trusted ranges as known-good locations. This directly addresses the confirmed false positive caused by VPN egress, preventing recurrence for this user without disabling the detection policy itself.

Why this answer

The correct action is to add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps (D). Trusted IP addresses are excluded from impossible travel and other anomalous location detections, so legitimate VPN egress IPs will not trigger false positives. This is a targeted, user-impacting fix that preserves detection for other scenarios.

Changing Entra ID location or disabling the rule are not appropriate.

Exam trap

SC-200 often tests the misconception that changing a user's location in Entra ID or disabling the detection rule is the right fix — the correct scoped remediation is adding the VPN IP range to trusted IP addresses in Defender for Cloud Apps.

How to eliminate wrong answers

Option A is wrong because changing the user's location in Microsoft Entra ID does not affect Defender for Cloud Apps impossible travel detection; that detection uses its own IP geolocation and does not rely on the Entra ID user location attribute. Option B is wrong because ignoring the alert and continuing to monitor does not prevent future false positives; the same VPN IP will keep triggering alerts, creating alert fatigue. Option C is wrong because disabling the impossible travel detection rule entirely would suppress all impossible travel alerts, including true positives, weakening security posture — the fix should be scoped to the trusted VPN IP range.

283
Multi-Selectmedium

Which of the following detection scenarios can be implemented using a scheduled analytics rule in Microsoft Sentinel? (Select all that apply.) (Choose 2.)

Select 2 answers
A.Identifying sign-ins from IP addresses listed in a custom threat intelligence watchlist.
B.Detecting anomalous sign-in behavior based on user entity behavior.
C.Correlating Windows Security Events to detect brute-force attacks.
D.Automatically blocking malicious IPs on a firewall.
AnswersA, C

Scheduled analytics rules are the correct vehicle for matching sign-in events against a custom threat intelligence watchlist. In a scheduled rule’s KQL query, you can use the _GetWatchlist() function or a watchlist alias to join SigninLogs with known malicious IPs, generating alerts whenever a match occurs. This is a straightforward, deterministic indicator-based detection that fits scheduled-rule logic perfectly.

Why this answer

Scheduled analytics rules in Microsoft Sentinel can be configured to run KQL queries at regular intervals. These queries can join multiple data sources, including watchlists and Windows Security Events (SecurityEvent table). For option A, querying SigninLogs and joining with a custom threat intelligence watchlist identifies sign-ins from malicious IPs.

For option C, aggregating failed logon events from SecurityEvent (e.g., EventID 4625) and grouping by source IP or account can detect brute-force patterns. Option B is better suited for UEBA anomaly detection, and option D is an automated response action, not detection. Therefore, A and C are correct.

Exam trap

The trap here is that candidates may confuse detection scenarios with response actions, or assume that all behavioral detection (like UEBA) can be done with scheduled rules, when in fact scheduled rules are only for static, query-based detection, not for machine learning or automated remediation.

284
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps to discover shadow IT. You notice that a new cloud app is being used by multiple users but has a risk score of 8. What should you do first to manage the risk?

A.Investigate the app's risk factors and user activity
B.Block the app at the proxy
C.Immediately unsanction the app in Defender for Cloud Apps
D.Create a policy to alert on use of this app
AnswerA

In Defender for Cloud Apps, investigation involves reviewing the app's cloud app catalog risk score, which includes factors such as data sharing, authentication methods, and compliance certifications, alongside actual user activity like sign-in events, file access, and IP addresses. This allows security analysts to differentiate unsanctioned but benign applications from those posing genuine threats such as credential theft or data exfiltration. By correlating risk factors with usage patterns, an analyst can make an informed governance decision—whether to sanction, alert, or block—without interrupting business continuity.

Why this answer

A risk score of 8 indicates the app is high-risk, but immediate blocking or unsanctioning could disrupt business operations if the app is legitimate or used for approved purposes. The first step is to investigate the app's risk factors (e.g., data residency, encryption standards, compliance certifications) and user activity (e.g., volume of data uploaded, types of files shared) to understand the actual threat. This aligns with Microsoft's recommended incident response process: assess before acting.

Exam trap

The trap here is that candidates assume a high risk score automatically requires immediate blocking or unsanctioning, but Microsoft's guidance emphasizes investigation first to avoid false positives and ensure business continuity.

How to eliminate wrong answers

Option B is wrong because blocking the app at the proxy without investigation could break legitimate business workflows and bypass the need to understand the app's risk profile; Defender for Cloud Apps uses reverse proxy controls only after assessment. Option C is wrong because immediately unsanctioning the app without investigation may cause unnecessary disruption and ignores the possibility that the app is low-risk despite a high score; unsanctioning should be a deliberate action based on evidence. Option D is wrong because creating a policy to alert on use of the app is a reactive measure that does not address the immediate risk; alerts are useful for ongoing monitoring but not the first step when a high-risk app is already in use.

285
MCQhard

Your organization uses Microsoft Sentinel and has multiple workspaces for different business units. You need to enable cross-workspace querying for the security operations center (SOC) analysts. What should you do?

A.Configure a data connector for each workspace
B.Use the workspace() expression in KQL queries
C.Enable incident merging across workspaces
D.Create a single workspace and migrate all data
AnswerB

The workspace() expression in Kusto Query Language allows you to reference a table in another Log Analytics workspace by appending the workspace resource ID or name to the table name, such as `union workspace('workspace1').SignedInLogs, workspace('workspace2').SignedInLogs`. This enables a single KQL query to span multiple Microsoft Sentinel workspaces, which is exactly the capability you need to search for threats or aggregate data across all your workspaces.

Why this answer

The `workspace()` expression in KQL allows a query to reference tables from multiple Log Analytics workspaces within a single query. This enables SOC analysts to perform cross-workspace queries without moving data, which is the correct approach for a multi-workspace Sentinel deployment.

Exam trap

The trap here is that candidates may confuse data collection configuration (data connectors) with query capabilities, or assume that incident merging is the same as cross-workspace querying, when in fact they serve entirely different purposes.

How to eliminate wrong answers

Option A is wrong because configuring a data connector for each workspace ingests data into each workspace separately but does not enable cross-workspace querying; it only ensures data is collected. Option C is wrong because incident merging across workspaces is a feature for correlating alerts into a single incident, not for querying data across workspaces. Option D is wrong because creating a single workspace and migrating all data is an architectural change that may not be feasible or desired, and it is not the recommended method for enabling cross-workspace queries in a multi-workspace environment.

286
MCQeasy

A security operations center (SOC) uses Microsoft Sentinel. They want to automatically block a user's account when a high-severity incident is created. Which automation action should you use in a playbook?

A.Run a playbook that revokes the user's current sessions using Microsoft Graph API.
B.Run a playbook that resets the user's password.
C.Run a playbook that calls the Microsoft Graph API to disable the user account.
D.Run a playbook that updates a conditional access policy in Microsoft Entra ID.
AnswerC

A Microsoft Sentinel playbook, powered by Azure Logic Apps, can directly interact with Microsoft Entra ID to manage user accounts. By calling the Microsoft Graph API within the playbook, specifically the Users endpoint to update a user's properties, the `accountEnabled` attribute can be set to `false`. This precise technical mechanism allows the playbook to automatically disable the user account in Microsoft Entra ID, directly fulfilling the requirement to block the user's account upon a high-severity incident.

Why this answer

Disabling the user account via Microsoft Graph API is the most direct and effective way to prevent further access when a high-severity incident is created. This action immediately blocks the user from authenticating across all services, which aligns with the requirement to automatically block the account. Other options either do not block the account (e.g., revoking sessions or resetting password) or are indirect and less reliable (e.g., updating Conditional Access policies).

Exam trap

The trap here is that candidates may confuse 'blocking a user' with temporary measures like revoking sessions or resetting passwords, but only disabling the account (via Graph API) permanently prevents authentication until the account is re-enabled.

How to eliminate wrong answers

Option A is wrong because revoking the user's current sessions only terminates active sessions but does not prevent the user from re-authenticating with valid credentials, so the account remains unblocked. Option B is wrong because resetting the user's password changes the credential but does not disable the account; the user could still be blocked by other means, and the account remains active. Option D is wrong because updating a Conditional Access policy is a tenant-wide or group-level change that may not immediately or reliably block a specific user account, and it does not directly disable the user object in Microsoft Entra ID.

287
MCQmedium

A security analyst is investigating a ransomware incident in Microsoft 365 Defender. The analyst wants to view all processes that initiated outbound network connections to known malicious IPs on a specific device. Which advanced hunting table should the analyst query?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.DeviceFileEvents
D.DeviceRegistryEvents
AnswerA

The correct choice is DeviceNetworkEvents because this table captures outbound network connection attempts and established connections, recording the destination IP, port, protocol, and the initiating process's ID and name. In a ransomware investigation, this table reveals the process that communicates with attacker-controlled infrastructure, enabling the analyst to map lateral movement or identify the ransomware's beaconing behavior. Unlike process creation logs, this table specifically correlates each connection to the process that made it, which is essential to confirm the malicious process's network activity.

Why this answer

The DeviceNetworkEvents table in Microsoft 365 Defender captures network connection events, including outbound connections to IP addresses, ports, and protocols. To investigate processes that initiated outbound connections to known malicious IPs on a specific device, this table provides the necessary data, such as the initiating process ID, remote IP, and port. The DeviceProcessEvents table only logs process creation events, not network activity, making it unsuitable for this query.

Exam trap

Microsoft often tests the distinction between process creation events (DeviceProcessEvents) and network connection events (DeviceNetworkEvents), trapping candidates who assume that process logs include network activity.

How to eliminate wrong answers

Option B (DeviceProcessEvents) is wrong because it logs process creation and termination events, not network connections; it cannot show which processes initiated outbound connections to specific IPs. Option C (DeviceFileEvents) is wrong because it tracks file creation, modification, and deletion events, which are unrelated to network connections. Option D (DeviceRegistryEvents) is wrong because it records registry key modifications, which have no bearing on network communication or IP addresses.

288
MCQeasy

A security operations center (SOC) uses Microsoft Sentinel. You need to ensure that when a high-severity incident is created, an automated email notification is sent to the on-call security engineer. Which automation option should you use?

A.Set an analytics rule to run a KQL query and send email.
B.Create a workbook that emails the on-call engineer daily.
C.Configure a logic app manually triggered by the analyst.
D.Create a playbook that sends an email and associate it with an automation rule that triggers on high-severity incidents.
AnswerD

This is correct because Sentinel integrates with Azure Logic Apps to create playbooks—workflows that can perform actions like sending email via the Office 365 Outlook connector. An automation rule can be configured with a condition for high-severity incidents and an action to run a playbook, which automatically executes the email-sending workflow when an incident is created. This provides the fully automated notification mechanism required, with no manual steps.

Why this answer

Microsoft Sentinel uses automation rules to trigger playbooks (Azure Logic Apps) based on incident creation or update conditions. By associating a playbook that sends an email with an automation rule set to trigger on high-severity incidents, the SOC achieves fully automated, event-driven notification without manual intervention.

Exam trap

The trap here is confusing analytics rules (which generate alerts) with automation rules (which respond to incidents), leading candidates to incorrectly select Option A instead of recognizing that playbooks are the correct automation mechanism for email notifications.

How to eliminate wrong answers

Option A is wrong because analytics rules generate alerts based on KQL queries, but they cannot directly send email; they can only trigger playbooks or automation rules. Option B is wrong because workbooks are visualization dashboards, not automation tools; they cannot send email notifications. Option C is wrong because manually triggering a logic app defeats the purpose of automated incident response; the requirement is for automatic notification, not analyst-initiated action.

289
MCQmedium

You deploy this ARM template to a Microsoft Sentinel workspace. After deployment, you notice that the saved search does not appear as an analytics rule. What is the most likely reason?

A.The tags are incorrectly formatted.
B.The resource type is 'savedSearches', not 'scheduledQueryRules' or 'alertRules'.
C.The API version is incorrect.
D.The KQL query syntax is invalid.
AnswerB

A Microsoft Sentinel analytics rule must be deployed using either 'Microsoft.OperationalInsights/workspaces/scheduledQueryRules' (for scheduled rules) or 'Microsoft.SecurityInsights/alertRules' (the Sentinel-native provider). The template declares 'Microsoft.OperationalInsights/workspaces/savedSearches', which only stores a KQL query in the Log Analytics workspace and does not trigger any alert or incident logic. Because the resource type is wrong, nothing appears under the Analytics Rules blade in Sentinel; this is the root cause of the deployment's apparent failure.

Why this answer

In Azure Resource Manager, the resource type determines what kind of object is created. A 'savedSearches' resource creates a saved search query in Log Analytics/Sentinel, which is a reusable query definition — not an analytics rule. Analytics rules in Microsoft Sentinel are created using the 'scheduledQueryRules' resource type (or the older 'alertRules' type).

Therefore, even though the template deployed successfully, the saved search will never appear as an analytics rule because it is a fundamentally different resource type.

Exam trap

SC-200 often tests the distinction between saved searches and analytics rules in ARM templates, trapping candidates who assume any query resource will automatically become an analytics rule.

How to eliminate wrong answers

Option A is wrong because tags are metadata and do not affect the resource type or whether a saved search becomes an analytics rule; misformatted tags would not prevent the resource from being created as a saved search. Option C is wrong because an incorrect API version would typically cause a deployment error or use a different schema, but it would not change the fundamental resource type from savedSearches to scheduledQueryRules. Option D is wrong because invalid KQL syntax would cause the query to fail at runtime or during validation, but it would not change the resource type; the resource would still be a saved search, not an analytics rule.

290
MCQeasy

A security analyst in Microsoft 365 Defender is investigating an incident that involves a malicious email attachment. Which advanced hunting table should the analyst use to find information about the email including sender, recipient, and subject?

A.EmailEvents
B.EmailAttachmentInfo
C.EmailUrlInfo
D.IdentityLogonEvents
AnswerA

EmailEvents is the correct choice because it is the primary Microsoft 365 Defender advanced hunting table that stores email message-level metadata, including the sender (From), recipient (To), subject, delivery status, and critical identifiers like NetworkMessageId and InternetMessageId. When investigating an email-related incident, this table provides the authoritative record of the email's header and routing details, enabling correlation of delivery and threat actions.

Why this answer

The EmailEvents table in Microsoft 365 Defender advanced hunting contains the core email metadata, including sender (SenderFromAddress), recipient (RecipientEmailAddress), and subject (Subject). This table records events such as email delivery, blocking, and filtering actions, making it the primary source for investigating email-related incidents. The other tables focus on specific components like attachments or URLs, not the full email envelope details.

Exam trap

The trap here is that candidates confuse the purpose of the tables, thinking EmailAttachmentInfo or EmailUrlInfo contain the email header data, when in fact they only store metadata about specific elements (attachments or URLs) and require a join with EmailEvents to get sender/recipient/subject.

How to eliminate wrong answers

Option B (EmailAttachmentInfo) is wrong because it stores details about file names, hashes, and sizes of attachments, but not the sender, recipient, or subject of the email. Option C (EmailUrlInfo) is wrong because it contains URLs extracted from the email body or attachments, not the email's routing or header information. Option D (IdentityLogonEvents) is wrong because it tracks user authentication events (logons, logoffs) from Azure Active Directory and has no relation to email message metadata.

291
MCQmedium

Your company uses Microsoft Defender for Cloud Apps. You discover that a user is accessing sensitive data from an unfamiliar IP address. You need to immediately block the user's access to all cloud apps while preserving the session for investigation. What should you do?

A.Use the 'Block' governance action in Defender for Cloud Apps
B.Create a conditional access policy to block the IP
C.Add the IP to the blocked IP address range list
D.Suspend the user from Microsoft Entra ID
AnswerA

Using the 'Block' governance action in Defender for Cloud Apps immediately terminates the flagged session via the session proxy and prevents new access from that session, while the full activity log is preserved for forensic review. This action is applied manually from the user or activity page and takes effect instantly, unlike policy-based controls. It is the appropriate granular containment that stops only the suspicious session without disabling the user account.

Why this answer

The 'Block' governance action in Defender for Cloud Apps immediately blocks the user's access to all cloud apps while preserving the session for investigation. This action is applied directly within the Defender for Cloud Apps portal, allowing you to stop data exfiltration without disrupting the ability to analyze the session logs or alerts. It is the only option that meets the requirement of blocking access while keeping the session intact for forensic review.

Exam trap

The trap here is that candidates often confuse the 'Block' governance action with IP-based blocking or user suspension, not realizing that only the governance action within Defender for Cloud Apps can block access while preserving the session for investigation.

How to eliminate wrong answers

Option B is wrong because creating a conditional access policy in Microsoft Entra ID would block access at the authentication level, but it does not preserve the session for investigation; it terminates the session entirely. Option C is wrong because adding the IP to the blocked IP address range list in Defender for Cloud Apps blocks all traffic from that IP, but it does not target the specific user and does not preserve the session for investigation. Option D is wrong because suspending the user from Microsoft Entra ID disables the user account, which blocks all access and terminates the session, preventing any further investigation of the ongoing session.

292
MCQhard

Refer to the exhibit. You are analyzing a potential C2 communication pattern. The KQL query returns no results despite known malicious IPs being active. What is the most likely cause?

A.The query is missing a filter for Direction equal to 'Outbound'.
B.The devices generating the events are not onboarded to Microsoft Defender for Endpoint.
C.The query does not include a filter for ActionType equal to 'ConnectionSuccess'.
D.The RemoteIP field should be replaced with DestinationIpAddress.
AnswerB

Microsoft Defender for Endpoint supplies the device telemetry that Sentinel's advanced hunting and C2-related tables query. Without onboarding, those devices emit no events, so the KQL query returns nothing despite the malicious IPs being active.

Why this answer

If the devices generating the network events are not onboarded to Microsoft Defender for Endpoint, they will not produce any DeviceNetworkEvents, resulting in no query results even when malicious IPs are active. Option A is incorrect because the query does not need a Direction filter to return results; it may include both inbound and outbound by default. Option C is incorrect because filtering on ActionType is not necessary to see the connection events; the absence of a filter does not cause empty results.

Option D is incorrect because RemoteIP is the correct field for the destination IP address in DeviceNetworkEvents; replacing it with DestinationIpAddress would not fix the missing data issue.

293
Multi-Selectmedium

Which TWO actions should you take to improve the performance of Microsoft Sentinel analytics rules that query large datasets?

Select 2 answers
A.Use a time filter in the query to limit the data range.
B.Use a watchlist to pre-filter results.
C.Change the data type of the columns to string.
D.Use summarize operators to aggregate data before performing joins.
E.Simplify the event by removing unused columns using project.
AnswersA, D

Applying a time filter (e.g., where Timestamp between datetime(...) and datetime(...)) restricts the query to only the relevant time range, which directly reduces the number of records scanned. Kusto queries are highly optimized for time-based sharding, so narrowing the window lets the engine skip entire extents that fall outside the filter. This is the most effective first step because it reduces I/O and CPU cost at the source, before any other processing or aggregation occurs.

Why this answer

Applying a time filter (e.g., using the `TimeGenerated` column) in a KQL query restricts the dataset to only the relevant time window, which significantly reduces the amount of data scanned by Microsoft Sentinel. This directly improves query performance by minimizing I/O and processing overhead, especially when analytics rules run against large log tables.

Exam trap

The trap here is that candidates often confuse result-set optimization (like removing columns with `project`) with query-performance optimization, not realizing that the real bottleneck is the amount of raw data scanned from storage.

294
MCQeasy

You are a Security Operations Analyst using Microsoft Sentinel. An incident has been created from an analytics rule. You need to assign the incident to a specific analyst and change its status to 'Active' so that it appears in their queue. Which action should you perform in the Microsoft Sentinel incident page?

A.Create a new automation rule to set the owner and status
B.Edit the incident's tags to include the analyst's name
C.Use the 'Assign to' field and set the status to 'Active'
D.Modify the analytics rule that generated the incident
AnswerC

The incident page in Microsoft Sentinel provides fields for owner (Assign to) and status (New, Active, Closed). Setting the owner to the specific analyst and changing the status to Active assigns the incident and moves it into the active workflow, making it appear in their queue. This directly fulfills the requirement to assign and activate the incident for the analyst.

Why this answer

In Microsoft Sentinel, incident assignment and status are managed directly on the incident page. The 'Assign to' field sets the owner, and the status field (New, Active, Closed) controls the workflow state. Setting both assigns the incident to the analyst and marks it Active, ensuring it appears in their queue.

Other actions like tagging or modifying rules do not achieve the required assignment and activation.

Exam trap

The trap here is thinking that tags or automation rules are needed for manual assignment; the incident page itself has direct fields for owner and status.

295
MCQeasy

A SOC analyst is configuring a scheduled analytics rule in Microsoft Sentinel. The rule runs every hour and queries the SigninLogs table for failed sign-ins. The analyst wants to avoid generating multiple incidents for the same user and IP address within a 1-hour window. Which configuration should the analyst use in the 'Incident creation' section of the rule?

A.Set 'Alert per rule run' to 'Single alert per run' and enable 'Grouping' with 'Group all alerts into a single incident' and time window of 1 hour.
B.Set 'Alert per rule run' to 'Every event' and disable grouping.
C.Set 'Alert per rule run' to 'Single alert per run' and disable grouping.
D.Configure the rule to use 'Supply chain' analytics rule type.
AnswerA

With 'Single alert per run' and grouping enabled, the rule generates one alert per scheduled run, and the alert grouping engine then combines all alerts produced during the 1-hour grouping window into a single incident. This prevents duplicate incidents for recurring detections within that window, consolidating related alerts so analysts investigate one incident instead of many. It also preserves the ability to see the full scope of activity within the incident.

Why this answer

Setting 'Alert per rule run' to 'Single alert per run' ensures that all matching query results from a single run are bundled into one alert. Enabling 'Grouping' with 'Group all alerts into a single incident' and a 1-hour time window then merges alerts across multiple runs for the same user and IP into one incident, preventing duplicate incidents within that window. This directly meets the requirement to avoid multiple incidents for the same user and IP within an hour.

Exam trap

The trap here is that candidates often confuse 'Alert per rule run' settings with incident deduplication, mistakenly thinking 'Every event' or disabling grouping will reduce incidents, when in fact only the combination of 'Single alert per run' and enabled grouping with a time window achieves the desired deduplication.

How to eliminate wrong answers

Option B is wrong because 'Every event' generates a separate alert for each row returned by the query, and disabling grouping means each alert becomes its own incident, causing many duplicate incidents for the same user and IP. Option C is wrong because while 'Single alert per run' bundles alerts per run, disabling grouping prevents merging alerts across runs, so each hour's alert would create a new incident for the same user and IP, still generating duplicates. Option D is wrong because 'Supply chain' analytics rule type is not a valid configuration in Microsoft Sentinel; the correct types are 'Scheduled' or 'NRT', and this option is a distractor with no relevance to incident deduplication.

296
MCQeasy

A security analyst is reviewing a phishing incident in Microsoft 365 Defender. They need to find all users who received a specific email message by searching for the email's Internet Message ID. Which advanced hunting table should the analyst query?

A.EmailEvents
B.EmailAttachmentInfo
C.EmailUrlInfo
D.AADSignInEventsBeta
AnswerA

EmailEvents is the correct table because it stores the metadata for every email message processed by Microsoft 365, including the InternetMessageId header that uniquely identifies a particular message. Querying on InternetMessageId lets an analyst retrieve every row for that message, and each row contains RecipientEmailAddress, so aggregating those rows lists all recipients of the phishing email. This table also includes subject, sender, and delivery status, making it the central starting point for email incident investigation.

Why this answer

The EmailEvents table in Advanced Hunting stores metadata about email transactions, including the Internet Message ID (a unique identifier defined in RFC 5322). By querying this table with the specific Internet Message ID, the analyst can retrieve all recipients who received that exact email, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates may confuse the Internet Message ID with other identifiers like the NetworkMessageId (a Microsoft-generated ID) or assume attachment or URL tables contain recipient data, leading them to pick EmailAttachmentInfo or EmailUrlInfo instead of EmailEvents.

How to eliminate wrong answers

Option B (EmailAttachmentInfo) is wrong because it stores metadata about email attachments (e.g., file names, hashes), not the email's Internet Message ID or recipient list. Option C (EmailUrlInfo) is wrong because it contains URLs extracted from email bodies, not the email's routing or delivery information. Option D (AADSignInEventsBeta) is wrong because it tracks Azure AD sign-in events (e.g., user authentication), not email delivery or message tracking.

297
MCQmedium

Refer to the exhibit. The KQL query is used in a Microsoft Sentinel scheduled alert rule. What scenario does this query detect?

A.Multiple MFA denial events from a single user.
B.Brute force attacks against Azure AD accounts using invalid passwords.
C.Attempts to sign in with disabled user accounts.
D.Brute force attacks from a single IP address against multiple accounts.
AnswerC

This is correct because Azure AD returns ResultType 50057 specifically when a user attempts to sign in with an account that has been disabled by an administrator. The KQL query filtering on this ResultType will surface every such attempt, regardless of whether the provided password is accurate. Disabled accounts cannot authenticate at all, so these events represent a clear account-state failure rather than a credential mismatch.

Why this answer

The KQL query filters for `ResultType == 50057`, which specifically indicates a sign-in attempt by a disabled user account in Azure AD. This result type is unique to disabled accounts and does not cover MFA denials (53003), invalid password attempts (50126), or brute force patterns. Therefore, the query detects attempts to sign in with disabled user accounts.

Exam trap

The trap here is that candidates confuse the generic 'sign-in failure' concept with the specific `ResultType` code 50057, assuming any failure could indicate brute force or MFA issues, when in fact each code maps to a distinct Azure AD error condition.

How to eliminate wrong answers

Option A is wrong because MFA denial events are identified by `ResultType == 53003` (MFA challenge failed or denied), not 50057. Option B is wrong because brute force attacks using invalid passwords are detected by `ResultType == 50126` (invalid username or password), not 50057. Option D is wrong because brute force attacks from a single IP against multiple accounts would require aggregation on `IPAddress` and `UserPrincipalName` fields, not a simple filter on `ResultType == 50057`.

298
MCQmedium

Your organization uses Microsoft Sentinel to manage security incidents. You need to ensure that critical incidents are automatically assigned to the senior security analyst on duty. What should you configure?

A.Configure an automation rule with an 'Assign incident' action
B.Modify the analytics rule to set the owner in the incident creation
C.Create a playbook that assigns incidents
D.Use a workbook to filter incidents by severity and assign manually
AnswerA

An automation rule with the 'Assign incident' action runs on incident creation, setting the owner to the senior analyst on duty. This directly satisfies the automatic assignment requirement, as analytics rules detect incidents but cannot assign ownership themselves.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to a specific owner based on conditions such as severity or title. Configuring an automation rule with the 'Assign incident' action ensures critical incidents are routed to the senior analyst on duty without manual intervention. This is the native, no-code method for incident assignment.

Exam trap

The trap is choosing a playbook because it sounds more powerful, but automation rules are the native, simpler feature for incident assignment—playbooks are overkill and require more setup.

How to eliminate wrong answers

Option B is wrong because analytics rules create incidents but do not provide an option to set the owner during creation; ownership is managed post-creation via automation rules or playbooks. Option C is wrong because a playbook (Logic App) can assign incidents, but it requires additional configuration and is not the simplest or most direct method; automation rules are purpose-built for this. Option D is wrong because workbooks are for visualization and reporting, not for automated assignment—manual assignment defeats the requirement for automation.

299
Multi-Selectmedium

A hybrid environment contains Azure VMs and on-premises servers connected through Azure Arc. Which two outcomes can Defender for Cloud provide for these servers? (Choose 2.)

Select 2 answers
A.Security recommendations for misconfigurations and missing updates.
B.Threat detection alerts for protected server workloads.
C.Automatic replacement of all unsupported operating systems.
D.Guaranteed compliance certification for every regulatory standard.
AnswersA, B

Defender for Cloud continuously assesses hybrid workloads against security baselines using Azure Policy and industry benchmarks to identify misconfigurations such as open management ports, unencrypted data stores, or weak network security group rules. It also aggregates missing update data from Azure VMs and Azure Arc-enabled on-premises servers, integrating with update management services to produce prioritized, actionable recommendations. These recommendations help administrators remediate posture gaps in a centralized portal.

Why this answer

Defender for Cloud continuously assesses the security posture of Azure VMs and Azure Arc-enabled on-premises servers. It generates security recommendations for misconfigurations (e.g., open management ports, weak encryption) and missing updates (e.g., OS patches, critical CVE fixes) by comparing the server's configuration against built-in security baselines and the Microsoft Security Response Center (MSRC) threat intelligence. This is a core capability of the cloud security posture management (CSPM) module within Defender for Cloud.

Exam trap

The trap here is that candidates confuse 'providing compliance assessments and recommendations' with 'guaranteeing compliance certification,' and they mistakenly think Defender for Cloud can automatically remediate unsupported OS replacements when it only detects and advises on such issues.

300
MCQeasy

Your organization uses Microsoft Sentinel for security operations. The SOC team receives an incident that was generated from a Microsoft Defender for Cloud Apps alert. The incident involves a user who is downloading a large number of files from SharePoint Online. The analyst needs to suspend the user's account immediately to stop the potential data exfiltration. The organization has a Microsoft Sentinel playbook that can suspend a user in Microsoft Entra ID. However, the playbook is not triggering automatically. You need to ensure that the playbook runs automatically whenever a Defender for Cloud Apps alert generates an incident in Sentinel. What should you configure?

A.Create an automation rule that triggers the playbook when an incident is created from Defender for Cloud Apps
B.Create a scheduled analytics rule that detects large file downloads
C.Enable the Microsoft Defender for Cloud Apps connector to sync alerts
D.Modify the playbook to run on alert creation
AnswerA

Automation rules in Microsoft Sentinel evaluate incident creation and can invoke a playbook conditionally. Scoping the trigger to incidents whose alert product is Defender for Cloud Apps ensures the suspend-user playbook runs automatically on those incidents.

Why this answer

An automation rule can be created to trigger a playbook on incident creation, specifically filtering for incidents from Defender for Cloud Apps. This enables automatic execution of the playbook to suspend the user. Option B is incorrect because a scheduled analytics rule is for generating alerts based on queries, not for triggering playbooks on existing incidents.

Option C is incorrect because enabling the connector only syncs alerts, but does not automatically run playbooks; an automation rule is required. Option D is incorrect because the playbook's trigger is configured in the automation rule, not by modifying the playbook itself.

Page 3

Page 4 of 18

Page 5