Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 301–375

1303 questions total · 18pages · All types, answers revealed

Page 4

Page 5 of 18

Page 6
301
MCQhard

During a threat hunt, an analyst discovers that a user's device has been sending large amounts of data to an external IP address associated with a known C2 server. The analyst wants to trace the process responsible for the outbound connections. Which Microsoft Defender for Endpoint advanced hunting table should be queried to find the process that initiated the network connections?

A.DeviceProcessEvents
B.DeviceFileEvents
C.DeviceNetworkEvents
D.DeviceEvents
AnswerC

DeviceNetworkEvents is the Advanced Hunting table designed to capture network connection attempts, including local/remote IPs, ports, protocol, and connection state. Critically, it includes the initiating process information (InitiatingProcessId, InitiatingProcessFileName, InitiatingProcessCommandLine), so you can directly attribute the outbound connection to the user's dev process. This makes it the correct choice when the analyst needs the process responsible for an outbound connection.

Why this answer

DeviceNetworkEvents in Microsoft Defender for Endpoint advanced hunting contains network connection events, including the initiating process, remote IP, port, and protocol. To trace which process initiated outbound connections to a known C2 IP, the analyst must query DeviceNetworkEvents, which correlates network activity with the responsible process. This table is purpose-built for network connection telemetry.

Exam trap

SC-200 often tests the distinction between process, file, network, and generic event tables, so candidates must know exactly which table holds network connection telemetry with process attribution.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents records process creation, termination, and command-line details, but not network connections, so it cannot directly show which process sent data to an external IP. Option B is wrong because DeviceFileEvents captures file creation, modification, and deletion activity, not network traffic. Option D is wrong because DeviceEvents is a general-purpose table for miscellaneous events like registry changes, logon events, and script execution, not specifically network connection initiations.

302
MCQeasy

An analyst is investigating a malware incident in Microsoft 365 Defender and has isolated the compromised device using automated investigation and response. The analyst now needs to collect a copy of a suspicious file from that device for further analysis in a sandbox. Which action should the analyst take from the device's entity page?

A.Initiate 'Collect investigation package' action.
B.Run a live response session and manually download the file.
C.Use the 'Add indicator' to allow the file and then collect.
D.Use the 'Device isolation' action to isolate again with different settings.
AnswerA

The 'Collect investigation package' action instructs Microsoft Defender for Endpoint to gather a comprehensive forensic zip from the device, containing running processes, services, event logs, registry keys, and key system files—including the malware binary itself. The resulting package is uploaded directly to the Microsoft Defender portal, where it can be downloaded and submitted to a sandbox without an analyst ever needing to remote into the host. This is the standard, supported method to obtain a full artifact set for deep analysis.

Why this answer

The 'Collect investigation package' action is the correct choice because it is specifically designed to gather a comprehensive set of forensic data from a device, including suspicious files, without requiring interactive access. This action automatically collects the file and other relevant artifacts, which can then be submitted to Microsoft 365 Defender's sandbox for analysis. It is a one-click, automated process that aligns with the analyst's need to obtain a copy of the file for further investigation.

Exam trap

The trap here is that candidates often confuse the 'Collect investigation package' action with a live response session, assuming manual file download is required, but the exam tests the understanding that automated collection is the preferred method for gathering forensic data from an isolated device without interactive overhead.

How to eliminate wrong answers

Option B is wrong because running a live response session and manually downloading the file requires interactive, real-time access to the device, which is unnecessary and less efficient when the device is already isolated; the 'Collect investigation package' action provides a more streamlined, automated collection. Option C is wrong because using 'Add indicator' to allow the file is used for creating allow or block indicators for threat intelligence, not for collecting files; it does not initiate a file collection process. Option D is wrong because using 'Device isolation' again with different settings would only change the isolation level (e.g., full vs. selective), but it does not collect any files; isolation is a containment action, not a data collection action.

303
MCQmedium

Your organization uses Microsoft Defender XDR. You notice that automated investigations are being blocked for certain devices due to high-severity alerts. You need to ensure that automated actions can proceed for devices with a risk score below 30. What should you configure?

A.Configure a device group with an automated investigation and response rule that excludes devices with a risk score above 30.
B.Disable automated investigation for all devices and rely on manual investigation.
C.Adjust the Microsoft Defender for Cloud Apps policy to allow automated actions for low-risk devices.
D.Modify the attack surface reduction rules to allow automated actions on low-risk devices.
AnswerA

A device group in Microsoft Defender XDR defines the scope of automated investigation and response actions, and you can set a matching condition on the device risk score. By creating a device group that includes only devices with a risk score of 30 or lower and associating an AIR rule that excludes higher-risk devices, automated remediation will run for the low-risk group while high-risk devices require manual approval. This directly satisfies the requirement to proceed automatically only for low-risk devices.

Why this answer

Device groups in Microsoft Defender XDR allow you to scope automated investigation and response (AIR) rules based on device risk scores. By creating a device group that excludes devices with a risk score above 30, you ensure that automated actions proceed only for devices meeting your threshold, directly addressing the requirement.

Exam trap

The trap here is that candidates confuse device groups (which control AIR scope) with other security features like attack surface reduction rules or cloud app policies, leading them to select options that address unrelated controls rather than the correct mechanism for scoping automated investigations.

How to eliminate wrong answers

Option B is wrong because disabling automated investigation entirely would prevent all automated responses, not just for high-risk devices, and contradicts the requirement to allow actions for low-risk devices. Option C is wrong because Microsoft Defender for Cloud Apps policies govern cloud application behavior, not device-level automated investigation and response actions in Defender XDR. Option D is wrong because attack surface reduction rules control exploit mitigation behaviors (e.g., blocking macros or scripts), not the conditional execution of automated investigation actions based on risk scores.

304
Matchingmedium

Match each Kusto Query Language (KQL) operator to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Filters rows based on a condition

Groups rows and calculates aggregates

Selects specific columns

Creates computed columns

Combines rows from two tables

Why these pairings

These are fundamental KQL operators used in Microsoft Sentinel and Defender queries.

305
MCQmedium

You are a SOC analyst investigating an incident where a user's credentials were used to access a sensitive SharePoint site from an unusual location. Microsoft Defender for Cloud Apps detected the activity as a suspicious sign-in. You need to create a detection rule that alerts whenever a user accesses SharePoint from a location not in the allowed list. What type of rule should you create in Microsoft Defender for Cloud Apps?

A.App discovery policy.
B.Session policy.
C.Activity policy.
D.Anomaly detection policy.
AnswerC

Activity policy in Microsoft Defender for Cloud Apps allows you to define custom rules based on specific activities, including conditions like location, to trigger alerts. You can set thresholds and filters to detect exactly the kind of user activity in question, such as a sign-in from a particular geographic region. This makes it the appropriate policy type for investigating an incident where a user’s location is a defining factor of the suspicious behavior.

Why this answer

An Activity policy in Microsoft Defender for Cloud Apps allows you to create custom rules that trigger alerts based on specific user activities, such as accessing SharePoint from a location not in the allowed list. This policy type evaluates each activity against defined conditions (e.g., IP address ranges, geolocation) and can generate alerts or take automated actions. It is the correct choice because it directly matches the requirement to detect a specific access pattern (location-based anomaly) rather than broad behavioral patterns.

Exam trap

The trap here is that candidates confuse 'Anomaly detection policy' (which is built-in and uses ML) with the ability to create custom location-based alerts, but only Activity policies allow you to define explicit conditions like 'not in allowed list'.

How to eliminate wrong answers

Option A is wrong because App discovery policies are designed to identify and control the use of cloud apps (shadow IT) by analyzing traffic logs, not to monitor user access to specific SharePoint sites from unusual locations. Option B is wrong because Session policies control user sessions in real time (e.g., blocking downloads or requiring MFA) but do not generate alerts for past or ongoing suspicious sign-ins; they are reactive controls, not detection rules. Option D is wrong because Anomaly detection policies use machine learning to detect unusual patterns across the tenant (e.g., impossible travel, mass download), but they are predefined by Microsoft and cannot be customized to alert on a specific location-based condition like 'not in allowed list'.

306
MCQhard

A SOC analyst wants to create a watchlist in Microsoft Sentinel from a CSV file that contains IP addresses. The analyst needs to configure the watchlist so that it can be efficiently queried using IP address comparison operators (e.g., IP prefix matching). Which data type should be set for the key column?

A.ipaddress
B.string
C.dynamic
D.guid
AnswerA

The `ipaddress` data type is the correct choice for a watchlist column intended to store IP addresses. In KQL, this type unlocks native IP functions like `ipv4_is_match` and `ipv4_compare`, which support efficient subnet matching and CIDR notation comparisons directly at query time. Unlike a plain string, `ipaddress` ensures the stored values are parsed and validated as IP addresses, enabling optimized indexing and precise range queries without requiring manual conversion or parsing in every query.

Why this answer

The 'ipaddress' data type is correct because it enables Microsoft Sentinel to parse and index the column values as IP addresses, allowing efficient use of IP-specific operators such as 'has_ip_prefix()' for prefix matching. Without this type, the watchlist would treat IPs as plain strings, preventing optimized IP comparison queries.

Exam trap

The trap here is that candidates assume 'string' is sufficient for all text-based data, overlooking that Microsoft Sentinel requires specific data types like 'ipaddress' to enable optimized IP comparison operators and avoid query performance degradation.

How to eliminate wrong answers

Option B is wrong because 'string' would store IP addresses as plain text, forcing the use of string comparison operators (e.g., 'contains') that cannot perform efficient IP prefix matching or leverage IP-specific functions. Option C is wrong because 'dynamic' is used for complex nested data structures (e.g., JSON arrays or objects), not for a simple column of IP addresses, and would require parsing overhead. Option D is wrong because 'guid' is a globally unique identifier format, intended for unique IDs, not for IP addresses, and would not support IP comparison operators.

307
MCQhard

A threat hunter is using Microsoft Sentinel to hunt for a potential advanced persistent threat (APT) that is using living-off-the-land binaries (LOLBins). The hunter creates a KQL query that lists all instances of certutil.exe making network connections. The query returns many legitimate results. What is the best way to reduce false positives while still detecting malicious use?

A.Replace the query with a Sysmon Event ID 3 (network connect) filter for certutil.exe
B.Remove certutil.exe from the hunting query and focus on other binaries
C.Expand the query to include all LOLBins that make network connections
D.Add additional filters to the query to detect only certutil.exe processes with suspicious command-line arguments (e.g., '-urlcache' or '-split')
AnswerD

Adding filters that match suspicious certutil command-line patterns—such as '-urlcache', '-split', or '-decode'—directly targets the known malicious usage of this tool while ignoring routine certificate work like CRL checks and certificate store queries. In KQL, you would combine the process image with a condition on the command line, for example: where ProcessCommandLine contains "certutil" and (ProcessCommandLine contains "-urlcache" or ProcessCommandLine contains "-split"), to isolate the payload-download behavior. This is far more precise because legitimate administrators rarely invoke certutil with these file-handling switches, especially in conjunction with a remote URL, so the false-positive rate drops dramatically while detection fidelity remains high.

Why this answer

Malicious use of certutil.exe as a LOLBin often involves specific command-line arguments such as '-urlcache' or '-split' to download or encode data. By adding these filters to the KQL query, the hunter can reduce false positives from legitimate certutil.exe network connections while still capturing suspicious activity. Option A (Sysmon Event ID 3) still returns all network connections and does not filter on arguments, so it does not reduce false positives.

Option B would miss potential threats. Option C expands the query to include all LOLBins, which increases noise and does not target the specific binary in question.

308
MCQeasy

You are a security analyst at a company that uses Microsoft Sentinel. You need to ensure that only users with a specific tag in Microsoft Entra ID can access the Sentinel workspace. Which Azure feature should you use?

A.Assign Azure RBAC roles with a condition on the tag.
B.Use Microsoft Entra Privileged Identity Management (PIM) to require approval for access.
C.Apply an Azure Policy to deny access if the user does not have the tag.
D.Configure a Conditional Access policy in Microsoft Entra ID.
AnswerD

A Conditional Access policy in Microsoft Entra ID acts as a gatekeeper during the authentication process, evaluating signals before a sign-in token is issued. If the policy targets the Microsoft Azure Management application, it can require a user to have a specific tag or identity attribute—often represented as a group membership or custom security attribute—before allowing access to the Azure portal. This makes Conditional Access the correct identity-driven control for blocking portal access, because it evaluates the user's identity and session rather than relying on resource-level RBAC, PIM, or Azure Policy.

Why this answer

Conditional Access policies in Microsoft Entra ID can enforce access controls based on user attributes, including tags. By configuring a Conditional Access policy that grants access to Microsoft Sentinel only if the user has a specific tag, you can restrict workspace access at the authentication layer before any Azure RBAC evaluation occurs. This is the correct approach because Conditional Access operates at the identity level, directly controlling which users can authenticate to the Sentinel workspace.

Exam trap

The trap here is that candidates often confuse Azure RBAC with Conditional Access, assuming that RBAC conditions on tags can control initial access, when in fact RBAC only controls authorization after authentication, whereas Conditional Access controls authentication itself.

How to eliminate wrong answers

Option A is wrong because Azure RBAC roles with conditions on tags apply to Azure resources after authentication, but they cannot prevent a user from authenticating to the Sentinel workspace; they only control actions post-authentication. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time elevation and approval for privileged roles, not attribute-based access restrictions like tags. Option C is wrong because Azure Policy enforces compliance on Azure resource configurations (e.g., ensuring resources have tags), not on user identity attributes or authentication-level access to a workspace.

309
Multi-Selecthard

Your organization uses Microsoft Sentinel. A new analytics rule is needed to detect brute-force attacks against your Azure SQL databases. The rule should minimize false positives and trigger only when multiple failed logins occur from a single IP address within a short time window. Which THREE components are essential for building this rule?

Select 3 answers
A.An alert threshold set to trigger when the count exceeds 10 failed attempts in 5 minutes.
B.A reference to the SQLInsights table for performance data.
C.A summarize operator in KQL to count failed login attempts per IP address within a timebin.
D.A KQL query against the AzureDiagnostics table filtering for failed login events.
E.A watchlist containing known malicious IP addresses.
AnswersA, C, D

This threshold is a critical component of the rule's alert trigger condition because requiring more than 10 failed sign-ins within a 5-minute window filters out isolated, routine authentication errors while still catching high-volume brute-force patterns. In Sentinel, this is configured in the Threshold field of the analytics rule, and it complements the KQL aggregation by determining when the query's aggregate results should actually generate an incident.

Why this answer

Setting an alert threshold to trigger when the count exceeds 10 failed attempts in 5 minutes directly reduces false positives by requiring a meaningful number of failures before alerting. This threshold aligns with common brute-force detection patterns, ensuring the rule only fires when there is a high likelihood of an actual attack rather than occasional user errors.

Exam trap

The trap here is that candidates may think a watchlist of known malicious IPs (option E) is necessary for detection, but brute-force rules should detect patterns from any IP, not just pre-listed ones, and the SQLInsights table (option B) is a distractor because its name sounds relevant but it lacks authentication event data.

310
MCQmedium

Your organization uses Microsoft Sentinel with Microsoft Defender XDR integration. You have a scheduled analytics rule that detects failed logon attempts across multiple on-premises domain controllers. The rule is configured to run every 5 minutes and create an incident when more than 10 failed attempts occur from a single IP address within 5 minutes. Recently, the SOC team noticed that the rule is generating a high volume of low-fidelity incidents, mostly from legitimate users mistyping passwords. You need to reduce the number of false positive incidents while still detecting real brute-force attacks. What should you do?

A.Increase the query frequency to every 1 minute and reduce the threshold to 5.
B.Modify the query to require at least 20 failed attempts from a single IP and include a condition that the attempts are against multiple user accounts.
C.Disable the rule and create a new rule based on successful logons followed by failed attempts.
D.Decrease the threshold to 5 and add a condition to exclude known good IP addresses.
AnswerB

Requiring at least 20 failed attempts from a single IP together with the condition that those attempts target multiple user accounts directly targets deterministic password-spray behavior while filtering out a single user's accidental mistypes. A single IP sending many failures against many distinct accounts is a strong signal for credential stuffing or password spraying, whereas failures against one account are commonly caused by a user forgetting a password. This tuning raises the confidence level of the alert without compromising detection of sustained attacks.

Why this answer

The correct approach is to tune the analytics rule to be more specific: raising the threshold to 20 failed attempts and requiring attempts against multiple user accounts filters out single-user password mistypes while still catching brute-force attacks that spray across accounts. This directly reduces false positives without losing detection fidelity.

Exam trap

SC-200 often tests the misconception that simply lowering thresholds or increasing frequency improves detection, when in fact it amplifies false positives; candidates must recognize that adding specificity (multi-account condition) is the correct tuning strategy.

How to eliminate wrong answers

Option A is wrong because increasing frequency to 1 minute and lowering the threshold to 5 would generate even more low-fidelity incidents, worsening the false positive problem. Option C is wrong because disabling the rule and switching to successful-then-failed logons misses the brute-force pattern entirely and creates a detection gap. Option D is wrong because lowering the threshold to 5 increases noise, and excluding known good IPs only partially helps while still missing the multi-account brute-force signal.

311
MCQeasy

A security analyst in Microsoft Sentinel wants to create a scheduled analytics rule to detect repeated failed HTTP requests to an Azure Application Gateway, indicating a possible brute force attack. Which Azure Monitor table should the analyst query to capture the access and error logs from the Application Gateway?

A.AzureActivity
B.AzureDiagnostics
C.AzureMetrics
D.SecurityEvent
AnswerB

AzureDiagnostics is the correct table because it stores platform-style logs and metrics from Azure resources when diagnostic settings stream them to a Log Analytics workspace, and Sentinel reads from that data plane. For Application Gateway, the diagnostic categories include ApplicationGatewayAccessLog, ApplicationGatewayPerformanceLog, and ApplicationGatewayFirewallLog, all of which land in AzureDiagnostics with fields like clientIP, requestUri, and httpStatus. This makes it the only table here that contains the granular layer-7 HTTP request data required for the investigation, and it can be queried with a filter such as OperationName or ResourceType.

Why this answer

AzureDiagnostics is the correct table because it stores resource-level logs for Azure services, including Application Gateway access and error logs. These logs contain detailed HTTP request data (e.g., client IP, URI, status code) necessary to detect repeated failed requests indicative of a brute force attack. Other tables like AzureActivity, AzureMetrics, or SecurityEvent do not capture this specific HTTP-level telemetry.

Exam trap

The trap here is that candidates confuse AzureActivity (control plane) with diagnostic logs (data plane), or assume AzureMetrics contains detailed HTTP error data when it only stores aggregated performance counters.

How to eliminate wrong answers

Option A is wrong because AzureActivity stores subscription-level control plane audit logs (e.g., resource creation, policy changes), not data plane HTTP access logs from Application Gateway. Option C is wrong because AzureMetrics only stores numerical performance counters (e.g., requests per second, latency) and lacks the detailed request/response fields needed to identify failed HTTP status codes. Option D is wrong because SecurityEvent collects Windows security events (e.g., logon attempts, process creation) from virtual machines, not HTTP traffic logs from a network gateway.

312
MCQhard

Your organization uses Microsoft Sentinel with a hybrid environment including on-premises servers and Azure VMs. You notice that some Windows events from on-premises servers are not being collected in Sentinel. Log Analytics agent is installed on all servers. Other events are collected. What should you check first?

A.Confirm that the workspace key is correctly deployed on the servers.
B.Verify that the Log Analytics agent is running and has network connectivity to Azure.
C.Ensure that the servers are listed in the Azure Arc management pane.
D.Check the Windows Event Log collection configuration in the Log Analytics workspace data collection rules.
AnswerD

Since the agent is installed and other events arrive, the gap lies in which Windows event logs and event IDs the workspace actually collects. Data collection rules define that filtering, so a missing channel or level there explains selective non-collection from on-premises servers.

Why this answer

Since the Log Analytics agent is installed and some events are collected, connectivity and agent health are already proven. The most likely cause of selective event gaps is the data collection configuration — specifically the Windows Event Logs settings in the workspace's data collection rules (or legacy agent configuration) that define which event logs and severity levels are forwarded.

Exam trap

SC-200 often tests troubleshooting logic — candidates jump to agent/connectivity checks even when the scenario states other events are flowing, which already rules those out.

How to eliminate wrong answers

Option A is wrong because an incorrect workspace key would prevent all data from that server, not just some events — and other events are being collected. Option B is wrong because if the agent were stopped or had no connectivity, no events would arrive from that server, contradicting the scenario. Option C is wrong because Azure Arc enrollment is required for Azure Monitor Agent on non-Azure machines, but the scenario states the Log Analytics agent (MMA) is installed and functioning, so Arc is not the first thing to check.

313
Multi-Selecthard

Your organization uses Microsoft Sentinel and has configured analytics rules for detecting ransomware. You receive an alert indicating possible ransomware activity on a server. Which THREE actions should you take to contain and investigate the incident? (Choose three.)

Select 3 answers
A.Create a new analytics rule to detect similar behavior.
B.Initiate a live response session to collect forensic artifacts.
C.Review the incident timeline in Microsoft 365 Defender.
D.Reset the password of the account that showed anomalous behavior.
E.Isolate the server from the network using Microsoft Defender for Endpoint.
AnswersB, C, E

Live response connects directly to the affected endpoint, allowing collection of volatile forensic artifacts such as memory, running processes and network connections before they are lost. This satisfies the investigation requirement, gathering evidence needed to determine ransomware scope and persistence mechanisms.

Why this answer

Option B is correct because initiating a live response session in Microsoft Defender for Endpoint lets you run forensic commands (e.g., getfile, analyze, run) on the affected server to collect volatile artifacts such as memory, running processes, and network connections for investigation. Option C is correct because Microsoft Sentinel incidents are integrated with Microsoft 365 Defender, so reviewing the incident timeline provides correlated alerts, entities, and investigation data across endpoints, identities, and email to understand the attack scope. Option E is correct because isolating the server via Microsoft Defender for Endpoint network isolation blocks inbound/outbound traffic (except for Defender communication) to stop ransomware propagation while preserving the ability to investigate.

Option A is not appropriate during containment/investigation because creating a new analytics rule is a detection-engineering task, not an incident response action. Option D is not appropriate because resetting the password of the anomalous account is a remediation step that may destroy evidence and does not contain the server-based ransomware activity.

Exam trap

The SC-200 exam often tests the distinction between detection tuning and incident response, and candidates may choose to create new analytics rules or reset passwords instead of taking immediate containment actions like isolation.

314
MCQmedium

A cloud security administrator needs to ensure that all Azure virtual machines have the Microsoft Defender for Cloud agent (Log Analytics agent) installed automatically when they are provisioned. Which configuration should be set in Microsoft Defender for Cloud?

A.Enable auto-provisioning in the Defender for Cloud environment settings.
B.Deploy a custom Azure Policy to install the agent on all VMs.
C.Use an Azure Automation runbook to install the agent on newly created VMs.
D.Enable Azure Update Management on the VMs.
AnswerA

Auto-provisioning in Microsoft Defender for Cloud is the native, first-party mechanism that automatically installs the Log Analytics agent (or Azure Monitor Agent when selected) on both existing and newly created VMs by leveraging a built-in 'deployIfNotExists' policy assigned at the subscription or management group scope. Once enabled, Defender for Cloud continuously evaluates VMs for the agent extension, remediates any gaps without manual intervention, and configures each VM to connect to the designated Log Analytics workspace. This guarantees consistent security telemetry collection and is the recommended approach for ensuring all supported VMs are covered.

Why this answer

Microsoft Defender for Cloud includes an auto-provisioning setting that, when enabled, automatically installs the Log Analytics agent (Microsoft Monitoring Agent) on all existing and newly provisioned Azure virtual machines. This setting is configured in the Defender for Cloud environment settings under 'Auto provisioning' and ensures seamless coverage without manual intervention or additional policy management.

Exam trap

The trap here is that candidates may overthink the solution and choose a custom Azure Policy or automation method, not realizing that Defender for Cloud's built-in auto-provisioning is the simplest and most direct configuration to meet the requirement.

How to eliminate wrong answers

Option B is wrong because deploying a custom Azure Policy to install the agent is unnecessary and less efficient; Defender for Cloud's built-in auto-provisioning already handles this automatically without requiring custom policy definitions. Option C is wrong because using an Azure Automation runbook to install the agent on newly created VMs is a manual, reactive approach that does not scale and lacks the native integration and monitoring capabilities of Defender for Cloud's auto-provisioning. Option D is wrong because enabling Azure Update Management on VMs is focused on patching and update compliance, not on installing the Log Analytics agent for security monitoring, and it does not fulfill the requirement for automatic agent installation at provisioning time.

315
MCQmedium

Your organization has a Microsoft Sentinel workspace that ingests data from Microsoft 365 Defender (Defender for Endpoint, Office 365, Identity, Cloud Apps). You have configured a scheduled analytics rule to detect possible privilege escalation based on user activity. The rule runs every 5 minutes and looks at the last 5 minutes of data. Recently, the rule has been generating a high number of false positives. You analyze the alerts and find that they are triggered by legitimate administrative actions. You need to reduce false positives without completely disabling the rule. The rule uses a KQL query that joins the IdentityLogonEvents and CloudAppEvents tables. What should you do?

A.Increase the rule's run frequency to every 30 minutes.
B.Reduce the query's lookback period to 1 minute.
C.Modify the KQL query to exclude events from a list of known administrative user accounts or IP addresses.
D.Add an incident suppression rule that closes incidents from known admin accounts.
AnswerC

The correct approach is to refine the KQL query so that it explicitly excludes events from known administrative user accounts or IP addresses, typically using a watchlist or a static list. This removes the benign baseline activity from the detection scope while retaining coverage for non-admin users and unknown actors. Because the exclusion is part of the query logic, the rule will not generate incidents for those known safe actors, but it will still fire on unusual behavior from other principals.

Why this answer

The false positives come from legitimate administrative actions triggering a privilege-escalation detection. The most targeted fix is to refine the KQL query to exclude known administrative user accounts or IP addresses, which preserves the rule's ability to detect real privilege escalation while filtering out the noisy legitimate activity. This is the standard Sentinel tuning approach for high-fidelity detections.

Exam trap

SC-200 often tests the difference between suppressing incidents (cosmetic) and tuning the detection query (root cause), and candidates frequently pick suppression rules because they sound like a clean fix.

How to eliminate wrong answers

Option A is wrong because increasing the run frequency to every 30 minutes only changes how often the rule executes — it does not reduce false positives and actually delays detection of real threats. Option B is wrong because reducing the lookback to 1 minute would miss events and reduce detection coverage, not improve precision. Option D is wrong because an incident suppression rule that closes incidents from known admin accounts hides the noise but does not prevent the rule from firing, and it risks suppressing a real incident if an admin account is compromised.

316
Multi-Selectmedium

Which TWO of the following are valid actions that can be performed by an automation rule in Microsoft Sentinel? (Select two.)

Select 2 answers
A.Delete a watchlist
B.Create a task
C.Modify an analytics rule
D.Assign incident to an analyst
E.Run a playbook
AnswersD, E

Automation rules can assign an incident to an analyst by updating its owner field, typically using a property like Owner and a user principal name or object ID. This is a native action that helps route ownership immediately when an incident is created or when a condition such as severity is met, and it requires the same permissions as other incident updates. It is a valid action because it directly changes an incident property rather than a separate resource.

Why this answer

Automation rules in Microsoft Sentinel can assign incidents to specific analysts or groups as part of incident response workflows. This action helps ensure accountability and proper triage by routing incidents to the appropriate personnel based on criteria like severity or type.

Exam trap

The trap here is that candidates may confuse automation rule actions with other Sentinel capabilities, such as thinking automation rules can modify analytics rules or manage watchlists, when in fact those are separate administrative functions.

317
MCQeasy

A security analyst is using advanced hunting in Microsoft 365 Defender to investigate a potential brute-force attack against an on-premises Exchange server. The analyst wants to find authentication failures from a specific IP address. Which table should the analyst query?

A.EmailEvents
B.IdentityLogonEvents
C.DeviceLogonEvents
D.CloudAppEvents
AnswerB

IdentityLogonEvents is the correct table because it captures authentication attempts for both cloud and on-premises identity infrastructure, including servers connected to Azure Active Directory via Active Directory Federation Services or Password Hash Sync. It includes details such as user, target application, IP address, and success or failure status for logons against Active Directory, which covers on-premises Exchange authentication. This table is specifically designed for identity sign-in events, making it the right choice in Advanced Hunting.

Why this answer

IdentityLogonEvents is the correct table because it captures authentication attempts monitored by Microsoft Defender for Identity, which deploys a dedicated sensor directly on Active Directory Domain Controllers (and optionally AD FS/AD CS servers) to inspect Kerberos, NTLM, and LDAP traffic in real time. This gives visibility into on-premises Exchange server authentication against Active Directory, including details such as account, target device, IP address, protocol, and success/failure status. This table is specifically designed for identity sign-in events, making it the right choice in Advanced Hunting.

Exam trap

The trap here is that candidates often confuse DeviceLogonEvents (endpoint-focused) with IdentityLogonEvents (identity-focused), forgetting that on-premises Exchange authentication is handled by Active Directory and monitored by Defender for Identity, not by endpoint sensors.

How to eliminate wrong answers

Option A is wrong because EmailEvents tracks email delivery and threat events (e.g., phishing, spam), not authentication failures. Option C is wrong because DeviceLogonEvents logs logon events on endpoints (e.g., Windows devices) via Microsoft Defender for Endpoint, not on-premises Exchange server authentication. Option D is wrong because CloudAppEvents records activities from cloud applications (e.g., Office 365, Azure AD), not on-premises Exchange server logon failures.

318
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR (including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps). You have an incident response team that operates 24/7. Recently, there have been multiple incidents involving users receiving phishing emails that lead to credential theft. The phishing emails are sophisticated and bypass Exchange Online Protection (EOP) and Defender for Office 365's built-in phishing filters. The emails contain links to fake login pages that harvest credentials. Once credentials are stolen, the attacker uses them to sign in from anonymous IP addresses and attempts to access sensitive data in SharePoint Online. You need to design a response strategy that includes automated containment and investigation. The solution must: - Automatically disable user accounts when a phishing incident is confirmed. - Automatically trigger an investigation into the user's activity in Microsoft Defender for Cloud Apps. - Send a notification to the incident response team with a summary of the incident. - Minimize manual effort. You have the following components available: - Microsoft Sentinel with automation rules and playbooks. - Microsoft Defender XDR with advanced hunting. - Microsoft Power Automate. What is the most efficient way to achieve these requirements?

A.Use Microsoft Defender XDR's automated investigation and response (AIR) to automatically disable the user account.
B.Create a playbook in Microsoft Sentinel that uses the Microsoft Graph API to disable the user account in Microsoft Entra ID, trigger an investigation in Microsoft Defender for Cloud Apps, and send an email notification. Associate the playbook with an automation rule that runs when the incident is created.
C.Create an automation rule in Microsoft Sentinel that triggers a webhook to a third-party system, which then disables the user account.
D.Configure a Playbook in Power Automate that monitors Microsoft Sentinel incidents and automatically disables the user account.
AnswerB

This fully automates containment, investigation, and notification.

Why this answer

Creating a playbook in Microsoft Sentinel that uses the Microsoft Graph API to disable the user in Microsoft Entra ID, triggers an investigation in Defender for Cloud Apps, and sends an email notification, then associating it with an automation rule that runs automatically when the incident is created, meets all requirements with minimal manual effort. Option B is correct because it enables automated containment and investigation without manual intervention. Option A is incorrect because Microsoft Defender XDR's automated investigation and response (AIR) does not automatically disable user accounts across all services; it focuses on endpoint remediation.

Option C is incorrect because relying on a third-party system via webhook introduces additional complexity and may not integrate seamlessly with Microsoft tools. Option D is incorrect because while Power Automate can be used, creating a playbook directly in Microsoft Sentinel is more tightly integrated and efficient for incident response workflows.

319
MCQmedium

You are a SOC analyst using Microsoft Defender for Endpoint. You need to investigate a device that is suspected of being compromised. You want to collect a memory dump for offline analysis. Which action should you take from the Microsoft Defender XDR portal?

A.Initiate a live response session and use the 'Collect memory dump' command.
B.Isolate the device from the network to prevent further damage.
C.Run a PowerShell script through live response to copy the memory dump.
D.Run a full antivirus scan on the device.
AnswerA

Initiate a live response session and use the 'Collect memory dump' command because it is the built-in, Microsoft-supported method for acquiring a full physical memory image from a device. This command invokes a trusted kernel-mode component that captures all volatile data—including running processes, open network connections, injected code, and loaded drivers—without altering system state, making it the gold standard for forensic memory analysis in Microsoft Defender for Endpoint.

Why this answer

The 'Collect memory dump' command is a built-in capability within a live response session in Microsoft Defender for Endpoint. This command allows you to capture a full memory dump of the device for offline forensic analysis, which is essential for investigating a suspected compromise. It is specifically designed for this purpose and does not require additional scripting or external tools.

Exam trap

The trap here is that candidates may confuse the 'Collect memory dump' command with running a custom PowerShell script, assuming that any script can achieve the same result, but Microsoft Defender for Endpoint provides a dedicated, optimized command that ensures the dump is properly captured and uploaded without manual intervention.

How to eliminate wrong answers

Option B is wrong because isolating the device from the network is a containment action, not a method to collect a memory dump; it prevents further damage but does not provide the forensic data needed for offline analysis. Option C is wrong because while you can run PowerShell scripts through live response, there is no built-in 'copy memory dump' command; you would need to use the dedicated 'Collect memory dump' command instead, making this approach unnecessarily complex and error-prone. Option D is wrong because running a full antivirus scan is a reactive measure to detect malware, not a forensic data collection technique; it does not capture a memory dump for offline analysis.

320
MCQmedium

You are a security operations analyst at a company that uses Microsoft Sentinel. You need to ensure that all incidents generated from Microsoft Defender for Cloud Apps are automatically assigned to the same SOC team. The team uses Microsoft Teams to collaborate. Which configuration should you implement?

A.Create a playbook that assigns the incident to the team and configure an automation rule to run it.
B.Create an automation rule that sets the owner to the team entity.
C.Configure the Microsoft Defender for Cloud Apps connector to assign incidents to the team.
D.Use a logic app to automatically post incidents to a Teams channel and have the team claim them.
AnswerB

Correct: In Microsoft Sentinel, an automation rule's actions include 'Assign owner,' which can set the Owner to either a specific user or a Microsoft Entra ID team (group). This assignment occurs natively during the incident lifecycle (e.g., immediately after creation) with no external service or manual step required. Simply create a rule with a trigger such as 'When incident creation' and the action 'Assign owner' to the appropriate team entity.

Why this answer

Automation rules in Microsoft Sentinel can directly set the incident owner to a specific user or group (such as a SOC team) without requiring a playbook. This ensures all incidents from Microsoft Defender for Cloud Apps are automatically assigned to the designated team, streamlining ownership and collaboration via Microsoft Teams.

Exam trap

The trap here is that candidates often assume a playbook or logic app is required for any custom action, but Microsoft Sentinel's automation rules can directly set the incident owner without additional orchestration.

How to eliminate wrong answers

Option A is wrong because creating a playbook to assign incidents is unnecessary overhead; automation rules can set the owner directly without invoking a playbook, which adds latency and complexity. Option C is wrong because the Microsoft Defender for Cloud Apps connector does not have a configuration to assign incidents to a team; incident assignment is handled within Sentinel's automation rules. Option D is wrong because using a logic app to post incidents to a Teams channel and having the team claim them is a manual, inefficient process that does not automatically assign ownership, and it bypasses Sentinel's built-in assignment capabilities.

321
MCQhard

During a security incident, you need to create a custom detection rule in Microsoft Sentinel to alert on multiple failed logins followed by a successful login from the same IP within 10 minutes. Which KQL function should you use to group events by IP address and time window?

A.join
B.extend
C.project
D.summarize
AnswerD

The summarize operator aggregates rows into groups defined by your chosen dimensions, letting you bin events by IP address and a ten-minute time bucket, then apply count() and threshold logic to detect the failed-then-successful pattern within the required window.

Why this answer

The `summarize` operator is the correct choice because it groups events by one or more columns (e.g., IP address) and performs aggregations over a defined time window. In this scenario, you need to count failed logins and then check for a subsequent successful login within 10 minutes from the same IP, which requires grouping by IP and time. `summarize` allows you to use `bin()` on a timestamp to create time buckets, enabling the detection of multiple failed logins followed by a success within that window. This is the standard KQL approach for time-based correlation in Microsoft Sentinel.

Exam trap

SC-200 often tests the misconception that `join` is needed for correlating events, but the question specifically asks for grouping by IP and time window, which is the core purpose of `summarize`.

How to eliminate wrong answers

Option A is wrong because `join` combines rows from two tables based on a matching column, but it does not inherently group events by time window or perform aggregations; it would require additional operators to achieve the desired grouping. Option B is wrong because `extend` creates new calculated columns from existing data, but it does not group or aggregate events. Option C is wrong because `project` selects and renames columns, but it does not perform any grouping or aggregation.

322
MCQeasy

Your security operations center (SOC) uses Microsoft Sentinel. Analysts need to collaborate on incidents by adding comments and changing severity. Which feature should they use?

A.Hunting
B.Playbooks
C.Workbooks
D.Incident management
AnswerD

Incident management in Microsoft Sentinel provides the collaborative workspace where analysts add comments and revise severity on the same incident record, satisfying the SOC's requirement to work together on investigations rather than duplicating effort across separate tools.

Why this answer

Incident management in Microsoft Sentinel provides the built-in capability for SOC analysts to collaborate on incidents by adding comments and changing severity. This feature allows multiple analysts to work on the same incident, track changes, and update the severity level directly within the incident interface, which is essential for effective teamwork and triage.

Exam trap

The trap here is that candidates often confuse Hunting or Workbooks as tools for incident collaboration because they involve data exploration, but they lack the direct incident editing and commenting capabilities that incident management provides.

How to eliminate wrong answers

Option A is wrong because Hunting is a proactive search for threats using KQL queries, not a feature for collaborating on existing incidents or modifying their severity. Option B is wrong because Playbooks are automated workflows triggered by incidents or alerts, designed for response actions, not for manual collaboration or severity changes. Option C is wrong because Workbooks are interactive dashboards for visualizing data and metrics, not for direct incident collaboration or severity updates.

323
Multi-Selecthard

You are a Microsoft Sentinel analyst handling an incident where a compromised user account is being used to access cloud applications. Your response plan requires you to both terminate the attacker's active sessions and review what the account accessed. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Use the Microsoft Entra ID user entity action to revoke sessions or reset the password so existing refresh tokens are invalidated.
B.Change the incident status to Closed and add a benign positive classification.
C.Disable the analytics rule that generated the incident so it does not retrigger.
D.Query the Microsoft Sentinel workspace logs, such as SigninLogs and AuditLogs, to review the account's recent activity during the compromise window.
E.Delete the user's mailbox to prevent further email-based data theft.
AnswersA, D

Revoking sessions or resetting the password invalidates existing refresh tokens, which forces reauthentication and cuts off the attacker's persistent access obtained through stolen tokens. This addresses the common gap where disabling or blocking sign-in does not immediately kill already-issued tokens. Performing this action directly from the incident's user entity keeps the response within the investigation workflow and satisfies the requirement to terminate active sessions.

Why this answer

Terminating an attacker's access requires invalidating tokens, not just blocking new sign-ins, so revoking sessions or resetting the password is essential. Reviewing sign-in and audit logs reconstructs what the account touched, which the response plan explicitly requires. Destroying the mailbox, disabling detection, or prematurely closing the incident would either damage evidence, create visibility gaps, or misrepresent the incident's severity.

Exam trap

The trap here is believing that disabling an account immediately ends the attacker's access, when already-issued refresh tokens can remain usable until revoked.

324
MCQmedium

Your team uses Microsoft Sentinel to monitor Azure subscriptions. You need to ensure that only users with the 'Microsoft Sentinel Contributor' role can create and edit analytics rules. You want to enforce this using Azure Policy. What should you do?

A.Create an Azure Policy that denies creation of analytics rules if the user doesn't have the 'Microsoft Sentinel Contributor' role.
B.Use Azure Blueprints to assign the 'Microsoft Sentinel Contributor' role to a security group.
C.Assign the 'Microsoft Sentinel Contributor' role to all users at the subscription level.
D.Create a custom role that denies write access to analytics rules.
AnswerA

Azure Policy can enforce RBAC at deployment time by using the `requestContext.roleDefinitionIds` property in a policy rule. A custom policy with a `deny` effect on Microsoft.SecurityInsights/alertRules evaluates the caller's roles and blocks creation of analytics rules unless the user holds the Sentinel Contributor role ID. This is a centralized, subscription-wide governance control that prevents unauthorized changes, unlike a one-time role assignment.

Why this answer

Azure Policy can enforce guardrails by denying resource creation or modification based on conditions, such as the user's role. By creating a policy that denies the creation or editing of analytics rules unless the user has the 'Microsoft Sentinel Contributor' role, you directly enforce the requirement. This approach uses Azure Policy's 'deny' effect to prevent unauthorized actions at the Azure Resource Manager level, regardless of other permissions.

Exam trap

The trap here is confusing Azure Policy (which enforces rules at resource creation/modification time) with Azure RBAC (which controls access to actions) or Azure Blueprints (which is a deployment tool), leading candidates to incorrectly choose role assignments or custom roles instead of a policy-based denial.

How to eliminate wrong answers

Option B is wrong because Azure Blueprints are used for orchestrating and deploying environments (e.g., role assignments, resource groups, policies) but do not themselves enforce runtime access control; they cannot dynamically deny actions based on the user's role. Option C is wrong because assigning the 'Microsoft Sentinel Contributor' role to all users at the subscription level would grant excessive permissions, violating the principle of least privilege and not enforcing the requirement that only specific users can create/edit rules. Option D is wrong because a custom role that denies write access to analytics rules would be ineffective; Azure RBAC roles grant permissions (allow), not deny, and a custom role with 'deny' actions is not a supported pattern—Azure Policy is the correct tool for explicit denial.

325
MCQhard

An analyst is creating a custom detection rule in Microsoft 365 Defender to detect lateral movement. The rule should trigger when a device (DeviceA) connects to another device (DeviceB) via SMB (port 445) and, within 5 minutes, a scheduled task is created on DeviceB. Which Advanced Hunting query pattern correctly correlates these events across devices?

A.Join DeviceNetworkEvents (where RemoteIP is DeviceB's IP and RemotePort 445) with DeviceEvents (where ActionType == 'ScheduledTaskCreated' and DeviceId == DeviceB's ID) using a time window of 5 minutes
B.Use DeviceProcessEvents to find smb.exe on DeviceA, then join with DeviceFileEvents on DeviceB
C.Use only DeviceNetworkEvents on DeviceA and DeviceB separately
D.Use EmailEvents and DeviceEvents on DeviceB
AnswerA

This is correct because the rule correlates the two required events in a single chain: an inbound SMB connection from DeviceA to DeviceB's IP on TCP port 445, and a scheduled task created on DeviceB within 5 minutes. Joining DeviceNetworkEvents (filtered to RemoteIP = DeviceB's IP and RemotePort = 445) with DeviceEvents (filtered to ActionType == 'ScheduledTaskCreated' and DeviceId = DeviceB's ID) on DeviceId and a 5-minute time window ties the network attack to the persistence action. This design captures both the lateral movement and the scheduled task creation, making it a precise, high-fidelity detection.

Why this answer

It uses a `join` between `DeviceNetworkEvents` (filtered for SMB traffic on port 445 from DeviceA to DeviceB) and `DeviceEvents` (filtered for `ActionType == 'ScheduledTaskCreated'` on DeviceB) with a 5-minute time window. This directly correlates the network connection with the subsequent scheduled task creation, which is a classic lateral movement pattern (e.g., PsExec or WMI abuse). The time window ensures the events are causally related within the detection rule's scope.

Exam trap

The trap here is that candidates might think `DeviceProcessEvents` is needed to capture the SMB connection (Option B), but SMB is a kernel-mode protocol and not logged as a user-mode process, so `DeviceNetworkEvents` is the correct source for network-level correlation.

How to eliminate wrong answers

Option B is wrong because `DeviceProcessEvents` does not reliably capture SMB connections; `smb.exe` is not a standard process name for SMB traffic (SMB is handled by the kernel via `mrxsmb.sys`), and `DeviceFileEvents` on DeviceB would not directly show scheduled task creation. Option C is wrong because using only `DeviceNetworkEvents` on both devices separately cannot correlate the network connection with the specific scheduled task creation event on DeviceB, missing the required behavioral link. Option D is wrong because `EmailEvents` is irrelevant to lateral movement via SMB and scheduled tasks, and `DeviceEvents` alone on DeviceB does not capture the initiating network connection from DeviceA.

326
MCQhard

Refer to the exhibit. An alert in Microsoft Defender for Identity shows suspicious PowerCLI execution on an Exchange server. The service account 'svc_exchange' is used. What is the most likely true-positive scenario?

A.An attacker using a compromised service account to access mailboxes via remote PowerShell
B.A security tool scanning for vulnerabilities
C.A misconfigured backup application running from an external IP
D.A legitimate IT admin running Exchange management scripts
AnswerA

PowerCLI is a PowerShell-based module that an attacker can abuse to open a remote PowerShell session to Exchange's management and mailbox endpoints, despite being VMware's tooling. In this alert, the source is an internal service account that lacks the normal attributes of an approved admin account, and its remote PowerShell activity aligns with mailbox enumeration or data exfiltration via Exchange cmdlets. The use of PowerCLI as a launching point for these commands masks the attacker's intent while providing a shell for executing Get-Mailbox or Search-Mailbox queries.

Why this answer

PowerCLI execution on an Exchange server, especially using a service account like 'svc_exchange', is a strong indicator of an attacker leveraging compromised credentials to remotely access Exchange via PowerShell. Microsoft Defender for Identity detects this because PowerCLI is not a native Exchange management tool; it is typically used by attackers to interact with Exchange Web Services (EWS) or Remote PowerShell (WinRM) for mailbox access, data exfiltration, or persistence. The combination of a service account (often over-privileged and not monitored) and PowerCLI from an unusual source or time makes this a true-positive compromise scenario.

Exam trap

The trap here is that candidates assume any PowerShell on an Exchange server is legitimate admin activity, but the exam specifically tests that PowerCLI is a VMware tool, not an Exchange management tool, making its execution on an Exchange server a clear red flag for compromise.

How to eliminate wrong answers

Option B is wrong because vulnerability scanning tools do not use PowerCLI; they rely on network scanners (e.g., Nmap) or authenticated vulnerability assessment agents, not PowerShell cmdlets for Exchange. Option C is wrong because backup applications typically use native Exchange APIs (e.g., VSS writer or EWS impersonation) or dedicated backup agents, and they do not execute PowerCLI from an external IP; a misconfigured backup would generate different alerts (e.g., authentication failures, not suspicious script execution). Option D is wrong because a legitimate IT admin would use native Exchange Management Shell cmdlets (e.g., Get-Mailbox, Set-Mailbox) via Exchange Management Console or Remote PowerShell, not PowerCLI, which is a VMware tool; PowerCLI on an Exchange server is anomalous and indicates non-standard, likely malicious activity.

327
MCQmedium

Your organization uses Microsoft Defender for Endpoint. An endpoint is detected as infected with a trojan. The analyst needs to isolate the device from the network while preserving forensic data. What action should the analyst take?

A.Remove the device from the Active Directory domain.
B.Disable the network adapter on the device.
C.Initiate the 'Isolate device' action from the Microsoft Defender XDR portal.
D.Perform a full reimage of the device.
AnswerC

The 'Isolate device' action is the designed containment control in Microsoft Defender XDR; it enforces a network-level block on all inbound and outbound communications except for the trusted Defender for Endpoint cloud service, which remains available for management and forensic collection. This preserves your ability to run live response commands, gather evidence, and later release the device from isolation remotely. It is a reversible, evidence-preserving containment that does not require physical access.

Why this answer

The 'Isolate device' action in Microsoft Defender XDR (formerly Microsoft 365 Defender) disconnects the device from all network traffic except the Defender for Endpoint service, preserving forensic data on the device while preventing the trojan from communicating with command-and-control servers. This action uses a built-in network isolation mechanism that blocks inbound and outbound connections at the OS level, ensuring the device remains accessible for investigation and remediation.

Exam trap

The trap here is that candidates may confuse physical network disconnection (Option B) with the controlled, reversible isolation provided by Defender for Endpoint, failing to recognize that forensic preservation and remote management are key requirements in incident response.

How to eliminate wrong answers

Option A is wrong because removing the device from the Active Directory domain does not isolate it from the network; it only removes domain trust relationships, and the device can still communicate on the network, potentially spreading the trojan. Option B is wrong because disabling the network adapter physically cuts all network connectivity, but it also prevents remote management and forensic data collection via Defender for Endpoint, and it does not preserve the ability to monitor or remediate the device centrally. Option D is wrong because performing a full reimage destroys all forensic data on the device, including evidence of the trojan's origin and behavior, which is contrary to the requirement to preserve forensic data.

328
MCQmedium

During a threat hunt, an analyst discovers a PowerShell script that was executed on multiple servers in the environment. The script connects to an external IP address and downloads a payload. The analyst wants to find all other servers that may have been compromised by the same script. What is the most efficient way to search for this across the environment?

A.Use Sysmon Event ID 1 (process creation) to find PowerShell executions
B.Review the network logs from the firewall for connections to the external IP
C.Use the DeviceProcessEvents table in Microsoft Defender for Endpoint advanced hunting to search for the script's SHA256 hash or command line pattern
D.Query the Windows Event Log for Event ID 4104 (PowerShell script block logging) on each server
AnswerC

The DeviceProcessEvents table records process creation events, including command lines and file hashes, across all onboarded devices. Searching by the script's SHA256 hash or command-line pattern identifies every server where the same PowerShell execution occurred, directly satisfying the requirement to find other compromised servers efficiently.

Why this answer

It leverages Microsoft Defender for Endpoint's advanced hunting to centrally search for the script's SHA256 hash or command line pattern across all endpoints. Option A is incorrect because Sysmon may not be installed on all servers, and querying each server individually is inefficient. Option B is incorrect because network logs only show network connections and do not provide process execution details.

Option D is incorrect because querying Event ID 4104 requires enabling PowerShell script block logging and accessing each server individually, which is less efficient than centralized hunting.

329
Multi-Selecthard

Which THREE components are required to use Microsoft Sentinel's automation rules to automatically respond to incidents?

Select 3 answers
A.A playbook created in Azure Logic Apps.
B.An analytics rule generating alerts.
C.The appropriate permissions to run playbooks.
D.An automation rule with conditions and actions.
E.A Microsoft Sentinel workspace.
AnswersC, D, E

To execute a Logic Apps playbook from an automation rule, Sentinel invokes the Azure Resource Manager trigger using the identity of the user or service principal, which must hold Microsoft.Logic/workflows/triggers/run/action permission, often granted by the Sentinel Responder role. Without those permissions the playbook action is blocked and the automation rule reports a failure. Even if a playbook exists, the rule cannot trigger it unless the required permissions are assigned, so permissions are a required component.

Why this answer

Automation rules require appropriate permissions (e.g., Microsoft Sentinel Contributor or Automation Contributor) to execute playbooks. Without these permissions, the automation rule cannot invoke the playbook when an incident is created or updated, even if the rule and playbook are properly configured.

Exam trap

The trap here is that candidates often assume a playbook (Option A) or an analytics rule (Option B) is mandatory for automation rules, but Microsoft Sentinel automation rules can function without either—they only require a workspace, the rule itself, and appropriate permissions to execute actions.

330
MCQmedium

Refer to the exhibit. You are configuring an automation rule in Microsoft Sentinel. The JSON snippet defines an automation rule. What is the expected behavior of this rule?

A.It creates an incident when a phishing email is detected
B.It sends an email to the security team when an incident is created
C.It runs a playbook to quarantine an email when a specific alert is generated
D.It modifies the incident severity when a playbook runs
AnswerC

The rule's trigger is set to a specific alert name and its action is to invoke a playbook, which is exactly how automated response works in Sentinel. When that alert fires, the rule automatically runs the Quarantine playbook, which likely uses a Microsoft 365 or Defender connector to isolate the offending email. This matches the exhibit: the automation rule reacts to the alert, not to an incident, by executing a playbook.

Why this answer

The automation rule is triggered when a specific alert is generated (as defined by the trigger condition), and it runs a playbook that contains logic to quarantine an email. In Microsoft Sentinel, automation rules can be configured to trigger on alert creation and execute a playbook, which in this case performs the quarantine action.

Exam trap

The trap here is that candidates often confuse the trigger condition (alert creation vs. incident creation) and assume the rule directly performs an action like sending an email or modifying severity, when in fact the rule only triggers a playbook that performs those actions.

How to eliminate wrong answers

Option A is wrong because the rule does not create an incident; it triggers on an existing alert and runs a playbook. Option B is wrong because the rule does not send an email; it runs a playbook, and the playbook itself could send an email, but the rule's action is to run the playbook, not directly send an email. Option D is wrong because the rule does not modify incident severity; it runs a playbook when an alert is generated, and severity modification would require a different trigger or action within the playbook itself.

331
MCQhard

Your organization uses Microsoft Purview Data Loss Prevention (DLP) and Microsoft Defender for Cloud Apps. During an incident, you discover that a user is exfiltrating sensitive data via a sanctioned cloud app. You need to block the user's ability to share files in that app immediately. What should you do?

A.Create a session policy in Microsoft Defender for Cloud Apps to block the user's file sharing activity.
B.Disable the app connector for that cloud app in Microsoft Defender for Cloud Apps.
C.Remove the user from the Microsoft Entra ID group that allows access to the cloud app.
D.Create a Microsoft Purview DLP policy to block sharing of sensitive content.
AnswerA

Session policies in Defender for Cloud Apps proxy the sanctioned app's traffic, allowing real-time control actions such as blocking file sharing for a specific user. This satisfies the requirement to stop exfiltration immediately without revoking the app's sanctioned status.

Why this answer

To immediately block a user's file-sharing activity in a sanctioned cloud app, create a session policy in Microsoft Defender for Cloud Apps. Session policies use Conditional Access App Control to proxy the session and apply real-time controls such as block download, block upload, or block sharing for specific users or groups. This is the fastest, most targeted control for the described scenario.

Exam trap

SC-200 often tests the difference between session policies (real-time, user-scoped, app-level control) and DLP policies (content-based, broader) — candidates pick DLP because it sounds like the data-protection tool, but the scenario demands immediate user-level blocking in a sanctioned app.

How to eliminate wrong answers

Option B is wrong because disabling the app connector would stop all monitoring and control for that app across the entire organization, not just the user — it is a blunt, org-wide action that also loses visibility. Option C is wrong because removing the user from an Entra ID group may revoke app access entirely but does not specifically block file sharing, and it may take time to propagate; it also does not address the immediate exfiltration if the user has other access paths. Option D is wrong because a Purview DLP policy blocks sharing of sensitive content based on content inspection, but it is not the immediate, user-scoped session control that Defender for Cloud Apps provides for sanctioned apps.

332
Multi-Selecteasy

Which TWO actions can be taken directly from the Microsoft Defender XDR incident queue? (Select TWO.)

Select 2 answers
A.Isolate a device involved in the incident
B.Modify a data connector's log collection
C.Change the incident status to 'In progress'
D.Create a new analytics rule
E.Create an automation rule
AnswersA, C

From the Microsoft Defender XDR incident queue, you can directly initiate isolation of a device involved in the incident, provided the device is onboarded to Microsoft Defender for Endpoint. This action is available through the device details pane or 'Take actions' menu, allowing an analyst to contain a compromised endpoint immediately. This capability is part of Defender's integrated response tools and does not require Sentinel.

Why this answer

The Microsoft Defender XDR incident queue provides direct actions, including device isolation, to contain threats without navigating to separate device management consoles. This capability is built into the incident investigation pane, allowing security analysts to quickly isolate a device involved in an incident from the unified queue.

Exam trap

The trap here is that candidates confuse the Defender XDR incident queue with the broader Microsoft Sentinel workspace, assuming all security operations tasks (like creating rules or modifying data connectors) are available from the incident queue, when in fact only incident-specific response actions are permitted.

333
MCQeasy

Your organization uses Microsoft Sentinel. You receive a high-severity incident indicating a potential data exfiltration from an Azure Storage account. The incident contains entities such as IP addresses and user accounts. Which step should you perform first to contain the threat?

A.Contact the user associated with the storage account
B.Block the suspicious IP address in the Azure Firewall
C.Investigate the incident to confirm the activity is malicious
D.Disable the storage account
AnswerC

Confirming whether the flagged activity is genuinely malicious precedes containment, because isolating resources or disabling accounts on a false positive causes unnecessary disruption. Investigation validates the incident's entities and scope, ensuring subsequent containment actions target a real threat.

Why this answer

In Microsoft Sentinel, the first step after receiving a high-severity incident is to investigate and confirm whether the activity is truly malicious. This triage step prevents unnecessary containment actions that could disrupt legitimate business operations. Only after confirming the threat should you proceed with containment measures like blocking IPs or disabling accounts.

Exam trap

SC-200 often tests the principle of 'investigate before you contain' to ensure candidates understand the incident response lifecycle and avoid premature actions that could harm business operations or destroy evidence.

How to eliminate wrong answers

Option A is wrong because contacting the user is a communication step, not a containment action, and may alert an attacker if the user is compromised. Option B is wrong because blocking an IP in Azure Firewall is a containment action that should only be taken after confirming malicious activity; premature blocking can disrupt legitimate traffic. Option D is wrong because disabling the storage account is a drastic containment step that could cause significant downtime and should only be done after investigation confirms malicious exfiltration.

334
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You receive an alert that an administrator performed an unusual bulk download from SharePoint. What is the recommended first step to respond?

A.Report the activity to Microsoft for further analysis.
B.Suspend the administrator's account immediately.
C.Block the IP address of the administrator's device.
D.Review the activity log in Defender for Cloud Apps to determine the context.
AnswerD

Reviewing the activity log in Defender for Cloud Apps is the correct first step because it provides the full context of the risky action: the exact activity, affected application, source IP, geolocation, timestamp, and user agent. With this evidence, you can distinguish an expected administrative change from a sign of account compromise and then decide whether to apply adaptive protection, require reauthentication, or invoke a conditional access policy. This investigation-first approach aligns with Microsoft's incident response guidance and minimizes false-positive disruptions.

Why this answer

The recommended first step when investigating an alert in Microsoft Defender for Cloud Apps is to review the activity log to understand the context of the alert. This allows the analyst to determine whether the bulk download is legitimate (e.g., a scheduled backup or migration) or malicious (e.g., data exfiltration). Jumping to containment actions without context can disrupt business operations and potentially alert an attacker.

Exam trap

The trap here is that candidates often jump to immediate containment actions (like suspending the account or blocking the IP) without first gathering context, but Microsoft's recommended incident response process emphasizes 'investigate before contain' to avoid false positives and operational disruption.

How to eliminate wrong answers

Option A is wrong because reporting the activity to Microsoft for further analysis is not a first step; Microsoft does not perform initial triage for customer-specific alerts, and the organization is responsible for its own investigation. Option B is wrong because suspending the administrator's account immediately could be premature and disruptive if the activity is legitimate, and it may tip off a malicious insider. Option C is wrong because blocking the IP address of the administrator's device could be ineffective if the administrator uses a dynamic IP or VPN, and it does not address the root cause of the alert.

335
MCQhard

Your organization uses Microsoft Purview Compliance Manager to manage compliance activities. You need to assign a specific improvement action to a colleague for implementation. What should you do?

A.In the 'Improvement actions' tab, select the action and click 'Assign'
B.Create a new alert policy to notify the colleague
C.Modify the assessment to include the colleague as an owner
D.Use the 'Assessments' tab to delegate tasks
AnswerA

In Compliance Manager, an improvement action is the individual task that maps to a specific control or family of controls. Selecting the action and clicking 'Assign' lets you directly designate a user as the responsible party, which is the only built-in way to delegate accountability for that action. Once assigned, the action appears in the colleague's 'My improvement actions' list so they can track, update, and submit evidence for it.

Why this answer

In Microsoft Purview Compliance Manager, improvement actions are the specific tasks that need to be completed to meet compliance controls. Each improvement action can be directly assigned to a colleague by selecting the action in the 'Improvement actions' tab and clicking the 'Assign' button, which allows you to specify the assignee and due date. This is the intended workflow for delegating implementation responsibilities within Compliance Manager.

Exam trap

Microsoft often tests the distinction between assigning a specific improvement action versus modifying assessment ownership or using alert policies, so candidates mistakenly choose options that involve broader permissions or unrelated notification mechanisms instead of the direct assignment feature.

How to eliminate wrong answers

Option B is wrong because alert policies in Microsoft Purview are used to detect and notify about specific activities or threats (e.g., data loss prevention or insider risk events), not to assign improvement actions; they cannot delegate tasks. Option C is wrong because modifying an assessment to add a colleague as an owner changes the ownership of the entire assessment, not the assignment of a specific improvement action; this would give them broad control over the assessment rather than a single task. Option D is wrong because the 'Assessments' tab is used to manage assessments and their controls, not to delegate individual improvement actions; there is no task delegation feature in that tab.

336
MCQmedium

Refer to the exhibit. You are a security analyst reviewing a KQL query in Microsoft Sentinel. The query is intended to show the count of high-severity malware alerts in the last 24 hours. However, the query returns results only for alerts with exact severity string 'High', but you also need to include 'Informational' severity alerts that are related to malware. What should you modify?

A.Remove the 'summarize' and 'order by' clauses.
B.Remove the 'where AlertName contains "malware"' condition.
C.Change the 'where AlertSeverity == "High"' to 'where AlertSeverity in ("High", "Informational")'.
D.Change 'ago(24h)' to 'ago(48h)'.
AnswerC

Changing the equality filter to use the 'in' operator with a set of allowed values is the correct fix because it explicitly instructs the query to include rows where AlertSeverity is either "High" or "Informational". The original predicate 'where AlertSeverity == "High"' only passes rows with that exact value, so anything marked Informational is discarded before aggregation. Using 'in' with both severity levels preserves the malware-name filter and the 24-hour timeframe while expanding the severity scope to match the investigation's requirement to review both High and Informational alerts.

Why this answer

The query currently filters only for alerts where AlertSeverity equals 'High', but the requirement is to also include 'Informational' severity alerts related to malware. By changing the condition to 'where AlertSeverity in ("High", "Informational")', the query will return both severity levels while keeping the malware-related filter and the 24-hour time window intact.

Exam trap

The trap here is that candidates may think the issue is with the time range (Option D) or the aggregation (Option A), when the actual problem is a simple missing filter condition for the 'Informational' severity level, which is a common oversight when requirements specify multiple severity values.

How to eliminate wrong answers

Option A is wrong because removing the 'summarize' and 'order by' clauses would only affect the aggregation and sorting of results, not the filtering of severity levels; the query would still exclude 'Informational' alerts. Option B is wrong because removing the 'where AlertName contains "malware"' condition would include all alerts regardless of whether they are related to malware, which violates the requirement to focus on malware alerts. Option D is wrong because changing 'ago(24h)' to 'ago(48h)' would expand the time window to 48 hours, but the requirement specifies the last 24 hours, and this change does not address the missing 'Informational' severity alerts.

337
MCQmedium

A SOC analyst is creating a scheduled analytics rule in Microsoft Sentinel to detect potential account compromise. The rule should trigger when a user account is created in Microsoft Entra ID and, within one hour, that same account is used to sign in from an unfamiliar location. The queries use the AuditLogs table for account creation and the SigninLogs table for sign-ins. Which KQL operator should be used to correlate these two events from different tables within a specific time window?

A.where
B.join
C.union
D.summarize
AnswerB

The `join` operator is the correct choice because it merges columns from two tables into a single row when a common key matches, such as joining `SecurityEvent` (account creation) to `SigninLogs` on `AccountName`. Using a `kind` like `innerjoin` and optionally comparing timestamps within a `where` clause allows the analyst to detect accounts that were created and then immediately signed in, directly correlating the two event streams. This row-level merge is exactly what the analytics rule needs.

Why this answer

(join) because the scenario requires correlating two events from different tables (AuditLogs and SigninLogs) based on a common field (e.g., UserPrincipalName) and within a specific time window (one hour). The join operator in KQL allows you to combine rows from two tables by matching keys, and you can use the 'where' clause on the time fields to enforce the one-hour window. This is the only operator that supports row-wise correlation across tables with a time constraint.

Exam trap

The trap here is that candidates often confuse union (which stacks rows) with join (which correlates rows), especially when the question mentions 'different tables' and 'time window' — union cannot enforce a time-based relationship between rows from separate tables.

How to eliminate wrong answers

Option A (where) is wrong because the where operator filters rows in a single table based on conditions; it cannot correlate events from two different tables. Option C (union) is wrong because union concatenates rows from multiple tables into a single result set without matching or correlating rows by a common key or time window. Option D (summarize) is wrong because summarize aggregates data (e.g., counts, averages) over groups; it does not perform row-level correlation between two tables.

338
MCQmedium

You are a security operations analyst for a company that uses Microsoft Sentinel. The SOC wants to receive a Microsoft Teams notification whenever a high-severity incident is created. You need to configure this with the least administrative effort. What should you do?

A.Create an automation rule that triggers on incident creation, with a condition on severity, and an action to run a playbook that posts a message to Microsoft Teams.
B.Use the Microsoft Sentinel incident page and manually configure each analytics rule to send an email to a Teams channel.
C.Create a scheduled playbook that queries the SecurityIncident table for high-severity incidents every 5 minutes and posts new ones to Microsoft Teams.
D.Configure a Microsoft Sentinel workbook that displays high-severity incidents and set up a scheduled email subscription to the workbook.
AnswerA

Automation rules can trigger on incident creation and condition on severity. They can run a playbook, which can use the Microsoft Teams connector to post a message. This leverages native integration and requires minimal effort, as you only need to create the playbook and the automation rule.

Why this answer

The most efficient way to notify Teams on high-severity incident creation is to use an automation rule that triggers on incident creation, filters by severity, and runs a playbook. The playbook can use the Microsoft Teams connector to post a message. This is event-driven, immediate, and uses native integration, minimizing administrative effort.

Exam trap

The trap here is assuming that analytics rules can directly post to Teams or that workbooks provide real-time alerting, when a playbook triggered by an automation rule is required.

339
MCQmedium

You are investigating a security incident in Microsoft Sentinel where a user received a phishing email containing a link to a malicious domain. The link was clicked, but no further actions were observed. Which playbook action should you take immediately to prevent potential lateral movement?

A.Disable the user's account
B.Revoke the user's active sessions
C.Reset the user's password
D.Block the malicious domain on the firewall
AnswerD

Blocking the malicious domain at the firewall is a network-based containment action that stops all clients from resolving or connecting to the malicious site, effectively breaking the delivery chain for phishing or malware. It is a reversible, low-impact measure that addresses the root cause regardless of which user or device attempts access, and it aligns with security operations best practice to contain the threat at the earliest opportunity.

Why this answer

The user only clicked the link without performing any further actions (e.g., no credential entry or file download). Blocking the malicious domain on the firewall immediately prevents the user or any other host from reaching the domain, stopping potential lateral movement via subsequent connections. This aligns with the principle of containing the threat at the network layer before it can spread.

Exam trap

The trap here is that candidates often confuse a click-only incident with a credential compromise, leading them to choose password reset or session revocation, but the correct first step is to block the malicious domain to contain the network-based threat.

How to eliminate wrong answers

Option A is wrong because disabling the user's account is an overly aggressive step for a click-only incident with no observed lateral movement; it would disrupt legitimate access without addressing the network-level threat. Option B is wrong because revoking the user's active sessions only terminates current connections but does not prevent the user or other systems from reconnecting to the malicious domain later. Option C is wrong because resetting the user's password is irrelevant when no credentials were compromised; the attack vector is network-based, not credential-based.

340
MCQeasy

A SOC analyst is investigating a phishing campaign that targets Microsoft 365 users. The analyst needs to collect email message headers from multiple users' mailboxes. Which Microsoft 365 Defender action should the analyst use?

A.Use Microsoft 365 Defender > Actions & submissions to view email headers.
B.Use Microsoft 365 Defender > Threat hunters to search for email headers.
C.Use Microsoft 365 Defender > Attack simulation training to collect headers.
D.Use Microsoft 365 Defender > Email & collaboration > Explorer to query email headers.
AnswerD

Email & collaboration > Explorer (Threat Explorer) is the dedicated email investigation view that lets an analyst filter by phishing indicators (sender, subject, message ID, and more) and then select individual messages to view the full message header. It also provides an export option to save headers for offline analysis, making it the correct tool for this task.

Why this answer

Microsoft 365 Defender's Email & collaboration > Explorer (also known as Threat Explorer) is the dedicated tool for querying email message headers across multiple user mailboxes. It allows analysts to search for specific email messages by sender, recipient, subject, or other attributes, and then view the full internet message headers (RFC 5322) for forensic analysis. This is the standard workflow for investigating phishing campaigns in Microsoft 365 Defender.

Exam trap

The trap here is that candidates confuse Threat Explorer (a dedicated email investigation tool) with Advanced Hunting (a general-purpose query tool), leading them to incorrectly choose Option B, even though Advanced Hunting does not natively display raw email headers without custom KQL parsing.

How to eliminate wrong answers

Option A is wrong because Actions & submissions is used for submitting suspicious emails for analysis and reviewing submission results, not for querying or viewing email headers from multiple mailboxes. Option B is wrong because Threat hunters (Advanced Hunting) uses Kusto Query Language (KQL) to search for threat data across tables like EmailEvents, but it does not directly display raw email headers; headers must be extracted via additional queries. Option C is wrong because Attack simulation training is a tool for creating and managing simulated phishing attacks, not for collecting real email headers from user mailboxes.

341
Multi-Selectmedium

Which TWO actions should you take to improve the performance of Microsoft Sentinel analytics rules that are running slowly? (Choose two.)

Select 2 answers
A.Assign a higher severity to the rule
B.Reduce the query time window
C.Use summarized data in the query
D.Increase the rule run frequency
E.Add additional entity mapping
AnswersB, C

Reducing the query time window directly narrows the amount of log data that must be scanned by the detection rule, which lowers I/O and compute costs. For example, changing from 7 days to 24 hours can cut the data volume by roughly a factor of seven for a single execution, dramatically reducing latency and improving overall throughput without changing the query logic.

Why this answer

Reducing the query time window (Option B) directly limits the volume of data the analytics rule must process per execution, which reduces query latency and overall rule execution time. This is a common performance optimization because Sentinel analytics rules run KQL queries against the Log Analytics workspace, and smaller time ranges mean fewer log records to scan.

Exam trap

The trap here is that candidates often confuse rule configuration settings (like severity or frequency) with query performance optimizations, mistakenly thinking that increasing frequency or adding mappings will somehow speed up execution, when in fact they degrade it.

342
MCQeasy

You run the above KQL query in Microsoft Sentinel to identify ransomware alerts from the last day. The result shows zero rows. Which is the most likely reason?

A.The table name 'SecurityAlert' is incorrect; it should be 'Alert'
B.No alerts with 'ransomware' in the name occurred in the last day
C.The user does not have permission to access the SecurityAlert table
D.The time filter of 1 day is too restrictive; need to increase range
AnswerB

The empty result set is a valid query result: within the last 24 hours, no SecurityAlert row had an alert name containing the case-insensitive substring 'ransomware' (assuming a standard `contains` operator). KQL processing filters every row in the time window; when none satisfy the predicate, Kusto returns zero rows without error. This means the query executed successfully and the absence of matching alerts is the most accurate explanation.

Why this answer

The KQL query filters for alerts where the name contains 'ransomware'. If no such alerts were generated in the last day, the query returns zero rows. This is the most likely reason because the query logic is correct, and the absence of data is a valid outcome, not an error.

Exam trap

The SC-200 exam often tests the candidate's ability to distinguish between a query returning zero rows due to a lack of matching data versus a query failing due to syntax or permission errors, leading candidates to incorrectly assume a configuration or permission issue.

How to eliminate wrong answers

Option A is wrong because 'SecurityAlert' is the correct table name in Microsoft Sentinel for storing security alerts; 'Alert' is not a valid table name. Option C is wrong because if the user lacked permission, the query would typically return an access denied error, not zero rows. Option D is wrong because the time filter of 1 day is not inherently too restrictive; the query is designed to check for alerts within that specific timeframe, and if none exist, zero rows is the expected result.

343
MCQmedium

A security analyst receives a Microsoft Defender for Cloud Apps alert about a suspicious sign-in from an IP address in a sanctioned app. The analyst needs to immediately prevent further access from that IP. What should the analyst do?

A.Create a mailbox rule to delete emails from that IP.
B.Create a Conditional Access policy in Microsoft Entra ID to block the IP.
C.Create an IP address-based access policy in Microsoft Defender for Cloud Apps.
D.Reset the user's password and require MFA re-registration.
AnswerC

From the Defender for Cloud Apps alert, you can create an IP address-based access policy that blocks the suspicious IP from all or selected cloud apps. This policy is enforced via the Cloud Apps conditional access proxy, providing real-time control over user access. It is the recommended, alert-specific remediation because it directly addresses the source IP identified in the threat, preventing further malicious activity.

Why this answer

Microsoft Defender for Cloud Apps provides native IP address-based access policies that can immediately block traffic from a specific IP address for a sanctioned app. This action is taken directly within Defender for Cloud Apps, without needing to modify Entra ID Conditional Access policies, and it applies in real time to the app session. The analyst can create a policy that blocks access from the suspicious IP, preventing further sign-ins from that address.

Exam trap

The trap here is that candidates often confuse the scope of Conditional Access in Entra ID (which is a broader identity-level control) with the app-specific, session-level control provided by Defender for Cloud Apps access policies, leading them to choose Option B instead of C.

How to eliminate wrong answers

Option A is wrong because a mailbox rule in Exchange Online can only filter or delete emails after delivery; it cannot block sign-in attempts or prevent access to a sanctioned app. Option B is wrong because creating a Conditional Access policy in Microsoft Entra ID would block the IP at the authentication layer, but this is a broader, slower approach that affects all apps and requires careful configuration; the question specifies the action should be taken immediately within Defender for Cloud Apps for a sanctioned app. Option D is wrong because resetting the user's password and requiring MFA re-registration does not block the specific IP address; the attacker could still attempt sign-ins from that IP with other credentials or after the user resets.

344
MCQmedium

A security administrator wants to enforce Just-in-Time (JIT) VM access for all Azure virtual machines in a management group to reduce the attack surface. The administrator wants to automatically enable JIT on any new VM and remediate existing non-compliant VMs. What should the administrator configure in Microsoft Defender for Cloud?

A.Manually enable JIT in Defender for Cloud's 'Just-in-time VM access' blade for each subscription.
B.Assign the built-in policy initiative 'Configure just-in-time network access on virtual machines' at the management group level.
C.Configure Azure Policy Guest Configuration to require JIT on virtual machines.
D.Create a custom Azure Policy definition to enforce JIT and assign it to each subscription.
AnswerB

Assigning the built-in policy initiative 'Configure just-in-time network access on virtual machines' at the management group level is the correct approach because policy initiatives in Azure Policy are inherited by all child subscription and resource group scopes, and they include a deploymentIfNotExists effect that automatically enables JIT on existing VMs and applies the configuration to any new VM as soon as it is created. This initiative leverages the native integration between Azure Policy and Microsoft Defender for Cloud, so non-compliant VMs are either remediated automatically or flagged for remediation, giving you continuous enforcement across your entire environment without manual intervention. By assigning at the management group level, you cover every subscription in that hierarchy with a single, auditable, and idempotent governance action.

Why this answer

The built-in policy initiative 'Configure just-in-time network access on virtual machines' can be assigned at the management group scope to automatically enable JIT on new VMs and remediate existing non-compliant VMs via a DeployIfNotExists effect. This ensures consistent enforcement across all subscriptions under that management group without manual per-subscription configuration.

Exam trap

The trap here is that candidates may think manual configuration (A) or custom policies (D) are needed, but the exam tests knowledge of built-in policy initiatives that can be assigned at a management group for automated, scalable enforcement.

How to eliminate wrong answers

Option A is wrong because manually enabling JIT per subscription does not provide automatic enforcement for new VMs or remediate existing non-compliant VMs at scale; it requires ongoing manual effort. Option C is wrong because Azure Policy Guest Configuration is used for in-guest settings (e.g., OS configuration, compliance) and does not control network-level JIT access on Azure VMs. Option D is wrong because creating a custom Azure Policy definition is unnecessary when a built-in policy initiative already exists for this exact purpose, and assigning it per subscription is less efficient than a single management group assignment.

345
MCQhard

Your organization uses Microsoft Defender XDR and Microsoft Sentinel. You need to create a custom detection rule that triggers when a user is added to a privileged role in Microsoft Entra ID and within 5 minutes performs a mass download from SharePoint. Which approach should you use?

A.Create an advanced hunting query in Microsoft Defender XDR
B.Use a custom detection rule in Microsoft 365 Defender
C.Use a Microsoft Purview insider risk policy
D.Create a scheduled query rule in Microsoft Sentinel
AnswerD

A Microsoft Sentinel scheduled query rule is correct because Sentinel is a cloud-native SIEM that can ingest logs from both Microsoft Defender XDR (via the Defender XDR connector) and Microsoft 365/Purview (via the Office 365 and Microsoft 365 connectors). Using KQL, you can join these multiple tables on a common field like user principal name within a defined time window; the rule then runs on a schedule, applies detection logic, and raises an alert that can trigger incident creation and SOAR playbooks, enabling cross-workload correlation that Defender and Purview tools alone cannot provide.

Why this answer

The detection requires correlating events across Microsoft Entra ID (privileged role assignment) and SharePoint (mass download) within a 5-minute window. Microsoft Sentinel's scheduled query rules can ingest data from multiple sources (e.g., AuditLogs for Entra ID and SharePoint via Office 365 connector) and use KQL to join these events with a time constraint, making it the only native solution for cross-domain, time-bound custom detections.

Exam trap

The trap here is that candidates assume Microsoft 365 Defender (now Defender XDR) can correlate all Microsoft 365 data, but its custom detection rules are restricted to Defender XDR tables, not Entra ID or SharePoint audit logs, which are only available in Sentinel via dedicated connectors.

How to eliminate wrong answers

Option A is wrong because advanced hunting queries in Microsoft Defender XDR are limited to data within the Defender ecosystem (e.g., device, identity, email signals) and cannot natively query Microsoft Entra ID audit logs or SharePoint activity logs. Option B is wrong because Microsoft 365 Defender custom detection rules (now part of Defender XDR) only support data from Defender XDR tables (e.g., IdentityLogonEvents, CloudAppEvents) and cannot directly ingest Entra ID role assignment events or SharePoint download events with the required granularity. Option C is wrong because Microsoft Purview insider risk policies are designed for user behavior analytics and risk scoring based on predefined indicators, not for creating custom, time-bound correlation rules with specific event thresholds.

346
MCQmedium

Your company is deploying Microsoft Sentinel in a multi-tenant environment using Azure Lighthouse. You need to ensure that SOC analysts can triage incidents across all tenants from a single workspace. What is the minimum configuration required?

A.Create a second Sentinel workspace in the managing tenant and configure cross-workspace queries.
B.Configure Azure AD B2B collaboration to grant external users access to each tenant's Sentinel workspace.
C.Use Azure Policy to enforce a standard analytics rule across all tenants.
D.Onboard each tenant as a delegated resource under Azure Lighthouse, then route all logs to a single Sentinel workspace in the managing tenant.
AnswerD

Onboarding each tenant with Azure Lighthouse grants the managing tenant's users delegated access to administer resources, including configuring diagnostic settings and data connectors to route logs centrally. By sending all logs into a single Sentinel workspace in the managing tenant, events and alerts are consolidated and correlated in one analytical store, and Sentinel generates a unified incident queue for SOC analysts. This gives a single pane of glass for triage and response without the need to switch between tenants or manually craft cross-workspace KQL queries, which keeps the data fragmented.

Why this answer

Azure Lighthouse enables multi-tenant management by delegating subscriptions or resource groups from each tenant as delegated resources to the managing tenant. Once delegated, you can configure a single Microsoft Sentinel workspace in the managing tenant to ingest logs from all delegated tenants via diagnostic settings, allowing SOC analysts to triage incidents centrally without needing separate workspaces or cross-workspace queries.

Exam trap

The trap here is that candidates often confuse cross-workspace queries (Option A) as a valid centralized solution, but they fail to realize that Azure Lighthouse's delegated resource model is the minimum configuration required to route all logs into a single workspace without additional overhead.

How to eliminate wrong answers

Option A is wrong because creating a second Sentinel workspace in the managing tenant and using cross-workspace queries still requires maintaining multiple workspaces and does not centralize incident management into a single pane of glass; it only allows querying across workspaces, not unified triage. Option B is wrong because Azure AD B2B collaboration grants external user access to each tenant's Sentinel workspace individually, but it does not consolidate logs or incidents into a single workspace; analysts would still need to switch between tenants to triage incidents. Option C is wrong because Azure Policy enforces compliance rules (e.g., analytics rule deployment) but does not route logs or provide centralized incident triage; it is a governance tool, not a data ingestion or workspace unification solution.

347
MCQmedium

Your security operations team uses Microsoft Sentinel workbooks to monitor security posture. You notice that a workbook query is timing out when run against a large workspace. What is the best way to optimize the query without changing its results?

A.Remove some filter conditions to simplify the query.
B.Add a summarize operator at the end of the query.
C.Use the workspace() function to query specific workspaces only.
D.Reduce the time range of the query.
AnswerC

Using the workspace() function, such as workspace('ContosoSOC'), explicitly constrains the query to named Log Analytics workspaces, which lets the execution engine skip irrelevant workspace partitions entirely. In Microsoft Sentinel workbooks, this is a standard way to avoid querying all accessible workspaces when the security data of interest is known. It reduces the data volume analyzed, improves query response time, and preserves the intended results as long as the targeted workspace holds the needed tables.

Why this answer

The `workspace()` function in KQL allows you to explicitly scope a query to specific workspaces, reducing the data scanned and improving performance. By targeting only the necessary workspaces, you avoid the overhead of querying the entire large workspace, which is the root cause of the timeout. This optimization does not alter the query logic or results, as it simply restricts the data source.

Exam trap

The trap here is that candidates often confuse query optimization with result modification, choosing to reduce the time range or remove filters, which changes the data returned, rather than using workspace scoping to limit the data source without affecting the query logic.

How to eliminate wrong answers

Option A is wrong because removing filter conditions would likely increase the data volume scanned, worsening performance, and it would change the query results by including more rows. Option B is wrong because adding a `summarize` operator at the end of the query does not reduce the initial data scan; it aggregates results after retrieval, which can actually increase processing time and memory usage. Option D is wrong because reducing the time range changes the query results by excluding older data, which violates the requirement to keep results unchanged.

348
MCQeasy

You are a threat hunter using Microsoft Defender XDR. You want to identify all devices that have communicated with a known malicious IP address 203.0.113.10 in the last 30 days. Which Advanced Hunting query should you run?

A.DeviceFileEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
B.DeviceEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
C.DeviceLogonEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
D.DeviceNetworkEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
AnswerD

DeviceNetworkEvents contains network connection events from devices, including the remote IP address. Filtering by RemoteIP equal to the malicious IP and a timestamp within the last 30 days will return all devices that communicated with that IP. This is the correct table and fields for this purpose. The Timestamp field is used for time filtering in Advanced Hunting, and the query is straightforward and effective.

Why this answer

DeviceNetworkEvents is the correct Advanced Hunting table for network connection data. It includes fields such as RemoteIP, RemotePort, and LocalIP. By filtering for the specific malicious IP address and limiting to the last 30 days using Timestamp > ago(30d), you can retrieve all devices that communicated with that IP.

This query provides the necessary visibility for threat hunting network-based indicators.

Exam trap

The trap here is selecting tables based on the presence of an IP field without verifying that the table actually records network communications; only DeviceNetworkEvents captures general network connections.

349
MCQhard

Your company uses Microsoft Defender for Cloud Apps to monitor cloud applications. You have discovered that a user is accessing a sanctioned cloud storage app from an IP address that belongs to a known malicious botnet. You need to automatically block the user's access to the app and require them to re-authenticate. You have already configured session policies in Defender for Cloud Apps. What should you do next?

A.Create an access policy in Defender for Cloud Apps to block the user.
B.Create an app governance policy in Microsoft Purview to block the app.
C.Configure a session policy in Defender for Cloud Apps with the action 'Block' and 'Require re-authentication'.
D.Create a device compliance policy in Microsoft Intune to block the device.
AnswerC

A session policy in Defender for Cloud Apps, when combined with Conditional Access App Control, can inspect and control app sessions in real time using a reverse proxy. Setting the action to 'Block' and 'Require re-authentication' immediately terminates the current session and forces the user to sign in again, thereby meeting the requirement of both blocking access and enforcing fresh authentication. This is the only option that provides both capabilities together, distinguishing it from access policies that lack the re-authentication action.

Why this answer

Session policies in Defender for Cloud Apps can enforce real-time controls on sanctioned apps. By configuring a session policy with the actions 'Block' and 'Require re-authentication', you can immediately terminate the user's session and force them to re-authenticate, which effectively blocks access from the malicious IP while ensuring the user re-verifies their identity.

Exam trap

The trap here is confusing session policies with access policies; access policies only block or allow at the app level without session-level controls like re-authentication, while session policies provide the granular, real-time actions needed for this scenario.

How to eliminate wrong answers

Option A is wrong because access policies in Defender for Cloud Apps control access based on user, device, or location but cannot enforce re-authentication within an active session; they only allow or block access at the app level. Option B is wrong because app governance policies in Microsoft Purview are designed for managing app permissions and compliance in Microsoft 365, not for blocking user access to cloud storage apps based on IP reputation. Option D is wrong because device compliance policies in Microsoft Intune enforce device-level security requirements (e.g., encryption, OS version) and cannot block access to a specific cloud app based on IP address or require re-authentication.

350
MCQeasy

During a security incident, you need to collect email messages associated with a phishing campaign from multiple mailboxes in Microsoft 365. Which tool should you use to search and export these emails?

A.Advanced Hunting in Microsoft Defender XDR.
B.Incident investigation in the Microsoft 365 Defender portal.
C.Mail Flow in the Exchange admin center.
D.Content Search in the Microsoft Purview compliance portal.
AnswerD

Content Search in Microsoft Purview queries multiple mailboxes simultaneously and exports matching messages to PST, satisfying the cross-mailbox collection requirement. Unlike eDiscovery holds or mailbox audit logging, it performs immediate, targeted searches across Exchange Online without placing mailboxes on hold, making it appropriate for rapid incident response collection.

Why this answer

Content Search in the Microsoft Purview compliance portal is the purpose-built tool for searching across Exchange mailboxes (and SharePoint/OneDrive) and exporting results to a PST or mailbox. It supports keyword queries, date ranges, sender/recipient filters, and bulk export across multiple mailboxes, which matches the phishing-campaign scenario.

Exam trap

The trap is confusing alert-triage tools (Defender XDR, incident investigation) with content-search tools — candidates must map 'search and export mailbox content' to Purview Content Search, not to Defender.

How to eliminate wrong answers

Option A is wrong because Advanced Hunting in Defender XDR is a KQL-based threat-hunting tool for telemetry and alerts — it does not export mailbox contents. Option B is wrong because incident investigation in the Defender portal is for triaging and correlating alerts, not for bulk email search and export. Option C is wrong because Mail Flow in Exchange admin center is for message trace and transport rule troubleshooting, not for content search or export of mailbox items.

351
MCQhard

Your organization uses Microsoft Sentinel with Fusion and Microsoft Security incident creation rules. You receive a high-severity incident from Microsoft Defender for Cloud Apps. The incident has a low confidence score. What should you do first?

A.Dismiss the incident as a false positive due to low confidence.
B.Suppress all future alerts from Defender for Cloud Apps with low confidence.
C.Escalate the incident to the SOC manager immediately.
D.Validate the alert by correlating with other logs.
AnswerD

Validating the alert by correlating it with other logs is the correct first step in incident triage. This involves checking user sign-in logs, Azure AD audit logs, Microsoft 365 audit logs, and endpoint/data loss prevention events for corroborating evidence of the same activity. Correlation helps confirm whether the Alert is a true positive, a false positive, or part of a bigger campaign, enabling proper prioritization and response.

Why this answer

A low confidence score indicates the alert may be a false positive, but it should not be dismissed without investigation. In Microsoft Sentinel, low confidence alerts from Defender for Cloud Apps require validation through correlation with other logs (e.g., Azure AD sign-ins, network logs) to confirm malicious activity before taking action. This aligns with the incident response process of triage and verification, not immediate dismissal or suppression.

Exam trap

The trap here is that candidates assume low confidence automatically means false positive, leading them to dismiss or suppress the alert, but the correct approach is to validate through correlation before making a decision.

How to eliminate wrong answers

Option A is wrong because dismissing an incident solely due to low confidence ignores the possibility of a true positive; low confidence means the detection logic is uncertain, not that the alert is definitively false. Option B is wrong because suppressing all future low-confidence alerts from Defender for Cloud Apps would create a blind spot, as low confidence can still indicate real threats that need correlation with other data. Option C is wrong because escalating to the SOC manager immediately bypasses the necessary triage step; the analyst should first validate the alert before escalating, as low confidence incidents often require initial investigation.

352
MCQeasy

During a threat hunt, you want to identify processes that have made network connections to known malicious IP addresses. Which data source in Microsoft Defender for Endpoint would provide the necessary information?

A.DeviceFileEvents
B.DeviceNetworkEvents
C.DeviceProcessEvents
D.DeviceRegistryEvents
AnswerB

DeviceNetworkEvents records outbound and inbound connection attempts per device, including remote IP addresses, ports and the initiating process. Correlating these events against threat intelligence identifies processes connecting to known malicious IPs, satisfying the hunt requirement.

Why this answer

DeviceNetworkEvents logs network connections including destination IP addresses, which is needed for this threat hunt. Option A is wrong because DeviceFileEvents logs file operations, not network connections. Option C is wrong because DeviceProcessEvents logs process creation, not network connections.

Option D is wrong because DeviceRegistryEvents logs registry changes, not network connections.

353
MCQmedium

Your organization uses Microsoft Sentinel. You have an incident that involves multiple alerts. You want to automatically assign the incident to the appropriate analyst based on the alert type. What should you use?

A.Create a playbook that assigns the incident.
B.Configure the analytics rule to set the incident owner.
C.Use a workbook to filter incidents by alert type.
D.Create an automation rule with an 'Assign incident to owner' action.
AnswerD

Automation rules in Microsoft Sentinel trigger on incident creation and can run the 'Assign incident to owner' action, routing incidents by alert type or other conditions. This satisfies the stem's requirement for automatic analyst assignment without manual triage.

Why this answer

An automation rule with an 'Assign incident to owner' action is the correct mechanism to automatically assign incidents based on alert type. Automation rules in Microsoft Sentinel support conditions on incident properties (including alert type/analytics rule) and can assign the incident to a specific owner or group. This directly fulfills the requirement.

Exam trap

SC-200 often tests the confusion between automation rules and playbooks, tricking candidates into selecting playbooks for simple assignment tasks that automation rules handle natively.

How to eliminate wrong answers

Option A is wrong because a playbook can assign incidents, but it is more complex and not the designed feature for simple assignment based on alert type; automation rules are the native, no-code solution. Option B is wrong because analytics rules can set incident owner at creation, but they cannot dynamically assign based on alert type across multiple alerts in the way automation rules can, and the question implies post-creation assignment logic. Option C is wrong because workbooks are for visualization and reporting, not for assigning incidents.

354
MCQhard

Your SOC uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that all incidents from Defender XDR are automatically synchronized to Sentinel. You have enabled the Defender XDR connector. However, some incidents are not appearing. What should you check first?

A.Check the connector's data filter settings for severity or status.
B.Confirm that the incident is displayed in a Sentinel workbook.
C.Ensure that alert grouping is enabled in Sentinel.
D.Verify that the Microsoft Defender XDR license is active.
AnswerA

The Microsoft Defender XDR connector in Sentinel exposes data filter settings that directly dictate which incidents are ingested based on severity and status. If an incident is missing, the most likely culprit is that its severity or status value is filtered out at the connector level. This filter operates before the incident ever reaches Sentinel, so no other workspace component would have a chance to ingest it.

Why this answer

The Defender XDR connector in Microsoft Sentinel allows filtering of incidents based on severity and status during configuration. If incidents are not appearing, the most common cause is that the connector's data filter settings are excluding them—for example, filtering out 'Informational' severity or 'Resolved' status incidents. This is the first thing to check because the connector is enabled and working, but the filter is preventing synchronization of certain incidents.

Exam trap

The trap here is that candidates assume the connector is fully functional once enabled, overlooking the granular filter settings that control which incidents are actually ingested.

How to eliminate wrong answers

Option B is wrong because Sentinel workbooks are visualization tools that display data already ingested; they do not control incident ingestion or synchronization. Option C is wrong because alert grouping in Sentinel is a feature for grouping related alerts into incidents, but it does not affect the initial ingestion of incidents from Defender XDR. Option D is wrong because if the Defender XDR license were inactive, the connector would likely fail entirely or show a connection error, not selectively miss some incidents.

355
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You need to block downloads from unmanaged devices for a specific cloud app. What should you configure?

A.Create a file policy with a governance action.
B.Create a session policy with device tag condition.
C.Create an app permissions policy.
D.Create an anomaly detection policy.
AnswerB

This is correct because Defender for Cloud Apps session policies leverage conditional access app control to enforce real-time session restrictions based on contextual conditions like device tags. By configuring a condition that targets unmanaged devices (using the device tag), the policy can explicitly block or warn on downloads within the user's active browser session. This works by routing the session through the reversing proxy in Defender for Cloud Apps, which inspects and controls actions such as file downloads, uploads, and copy/paste before they reach the user's endpoint.

Why this answer

Session policies in Microsoft Defender for Cloud Apps allow you to control user activities in real time based on device tags. By configuring a session policy with a device tag condition (e.g., 'Device tag equals Unmanaged'), you can enforce actions like blocking downloads from unmanaged devices for a specific cloud app, leveraging reverse proxy architecture to inspect and control traffic.

Exam trap

The trap here is that candidates often confuse session policies (real-time proxy control) with file policies (data-at-rest governance) or anomaly detection (behavioral alerts), failing to recognize that device tag conditions are exclusive to session policies for conditional access on unmanaged devices.

How to eliminate wrong answers

Option A is wrong because file policies are designed to detect and govern data at rest (e.g., files stored in cloud apps) using content inspection and governance actions like quarantine or apply label, not to control real-time download actions from unmanaged devices. Option C is wrong because app permissions policies govern OAuth app permissions (e.g., third-party app access to cloud app data), not device-based download blocking. Option D is wrong because anomaly detection policies identify suspicious user or entity behavior (e.g., impossible travel, mass download) but cannot enforce device-specific conditional access like blocking downloads from unmanaged devices.

356
MCQeasy

To hunt for malicious PowerShell encoded commands, which columns in the DeviceProcessEvents table in Microsoft 365 Defender advanced hunting should you focus on?

A.DeviceName
B.FileName
C.ProcessCommandLine
D.InitiatingProcessFileName
AnswerC

ProcessCommandLine contains the full command line, including the -EncodedCommand parameter and the base64 string attackers use to hide their payload. This is the primary field to inspect when hunting for obfuscated PowerShell, as the encoded blob is present verbatim. In Microsoft 365 Defender's DeviceProcessEvents, this field enables decoding and further analysis, making it the directly relevant column.

Why this answer

Encoded PowerShell commands (e.g., -EncodedCommand or -enc) appear in the full command line used to launch the process, which is captured in the ProcessCommandLine column of DeviceProcessEvents. Filtering or searching ProcessCommandLine for base64-like strings or the -enc switch is the standard hunting technique for detecting obfuscated PowerShell execution.

Exam trap

SC-200 often tests whether candidates know which column holds the actual command-line arguments — candidates pick FileName or InitiatingProcessFileName because they sound process-related, missing that ProcessCommandLine is where encoded payloads live.

How to eliminate wrong answers

Option A is wrong because DeviceName only identifies the host — it tells you where the process ran, not what command was executed, so it cannot reveal encoded PowerShell. Option B is wrong because FileName shows the executable name (e.g., powershell.exe), which is useful for scoping but does not contain the encoded payload. Option D is wrong because InitiatingProcessFileName identifies the parent process (e.g., winword.exe spawning powershell.exe), which is a useful correlation signal but not where the encoded command string lives.

357
MCQmedium

A company uses Microsoft Defender for Cloud and wants to automatically remediate non-compliant Azure resources by deploying missing configurations (e.g., enabling diagnostics when not enabled). Which feature should they enable?

A.Azure Policy's DeployIfNotExists effect
B.Just-In-Time VM access
C.Adaptive network hardening
D.File integrity monitoring
AnswerA

DeployIfNotExists evaluates resources against a policy rule and, when the required configuration is absent, triggers a remediation task that deploys the missing setting via an ARM template. This delivers automatic remediation of non-compliant Azure resources without manual intervention.

Why this answer

Azure Policy's DeployIfNotExists effect is the correct feature because it automatically remediates non-compliant Azure resources by deploying missing configurations, such as enabling diagnostic settings, when the resource is created or updated. This effect evaluates resources against a policy definition and, if the specified configuration does not exist, triggers a deployment task to apply the required settings. In Defender for Cloud, this is used to enforce security baselines by automatically correcting non-compliant resources without manual intervention.

Exam trap

The trap here is that candidates may confuse 'automatic remediation' with security controls like JIT or network hardening, but the question specifically asks about deploying missing configurations, which is a policy-based remediation feature, not a threat mitigation control.

How to eliminate wrong answers

Option B is wrong because Just-In-Time (JIT) VM access is a Defender for Cloud feature that reduces the attack surface by controlling network access to VMs, not for deploying missing configurations like diagnostics. Option C is wrong because Adaptive network hardening uses machine learning to recommend and enforce network security group rules based on traffic patterns, not for deploying missing resource configurations. Option D is wrong because File integrity monitoring (FIM) tracks changes to files and registries on VMs to detect unauthorized modifications, not for deploying missing configurations like enabling diagnostics.

358
MCQmedium

A security analyst receives an alert in Microsoft Defender XDR indicating that a user account was compromised. The analyst needs to isolate the affected device to prevent lateral movement. Which action should the analyst take first?

A.Run a full antimalware scan on the device
B.Initiate device isolation from Microsoft Defender for Endpoint
C.Reset the user's password in Microsoft Entra ID
D.Create a custom detection rule in Microsoft Sentinel
AnswerB

Initiating device isolation from Microsoft Defender for Endpoint is the immediate containment action because it severs the compromised device's network connections—both wired and wireless—while preserving a secure channel to the Defender for Endpoint service for ongoing investigation and remediation. This prevents the attacker from moving laterally, exfiltrating data, or communicating with C2, effectively containing the breach at the endpoint.

Why this answer

Initiating device isolation in Microsoft Defender for Endpoint immediately contains the compromised device, preventing lateral movement. Option A is wrong because a full antimalware scan does not isolate the device and may not stop ongoing malicious activity. Option C is wrong because resetting the user's password does not isolate the device; it only revokes access to cloud resources.

Option D is wrong because creating a custom detection rule in Microsoft Sentinel does not take immediate action to contain the threat.

359
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft 365 Defender. You have a playbook that automatically isolates a device when a malware incident is confirmed. The playbook uses the Microsoft Defender for Endpoint connector. During a recent incident, the playbook failed to isolate a device because the device was not found in Defender for Endpoint. Upon investigation, you find that the device is onboarded to Microsoft Defender for Endpoint but the playbook is using an incorrect device ID format. What should you do to ensure the playbook works correctly?

A.Ensure the device is properly onboarded to Microsoft Defender for Endpoint by running the onboarding script again.
B.Reconfigure the Microsoft Defender for Endpoint connector in Sentinel to use a different API version.
C.Modify the playbook to use the device ID from the incident's entities instead of a manually entered ID.
D.Use the device name instead of the device ID in the playbook.
AnswerC

Using the incident entity's device ID guarantees the identifier matches Defender for Endpoint's onboarded record, because Sentinel incidents carry the exact machine ID surfaced by the connector. A manually entered ID risks format mismatches, such as Azure AD object ID versus Defender machine ID, which caused the lookup failure.

Why this answer

The playbook failed because it used an incorrect device ID format. The correct approach is to modify the playbook to dynamically retrieve the device ID from the incident's entities, which ensures the correct ID is used. This leverages the integration between Microsoft Sentinel and Microsoft 365 Defender, where incident entities include the proper device ID.

Exam trap

SC-200 often tests the integration between Sentinel and Defender, where candidates might focus on onboarding or connector configuration instead of the correct use of incident entities for dynamic values.

How to eliminate wrong answers

Option A is wrong because the device is already onboarded to Defender for Endpoint; re-running the onboarding script would not fix the incorrect device ID format used in the playbook. Option B is wrong because changing the API version of the connector is unlikely to resolve the issue; the problem is the device ID format, not the API version. Option D is wrong because using the device name instead of the device ID may not be supported by the isolation action, which typically requires the device ID; device names can be ambiguous or change.

360
MCQeasy

A security analyst is configuring a Microsoft Sentinel workspace. The analyst needs to connect a third-party firewall that sends logs via Syslog and supports a common event format (CEF). Which data connector should the analyst use to ingest these logs?

A.Common Event Format (CEF) via AMA
B.Windows Security Events via AMA
C.Azure Activity Log
D.Office 365 connector
AnswerA

The Common Event Format (CEF) via AMA connector is the correct choice for ingesting firewall logs because it is specifically designed to collect ArcSight CEF-formatted syslog messages from security appliances like firewalls, IDS/IPS, and other network devices. It uses the Azure Monitor Agent (AMA) on a Linux log forwarder, with a data collection rule (DCR) that forwards the CEF traffic to the Sentinel Log Analytics workspace. This preserves the structured CEF header and extension fields, enabling precise parsing and correlation in Sentinel analytics rules.

Why this answer

The Common Event Format (CEF) via AMA data connector is specifically designed to ingest logs from security appliances that send Syslog messages in CEF format. CEF is an industry-standard format that allows firewalls and other devices to send structured event data, and the Azure Monitor Agent (AMA) replaces the older Log Analytics Agent for this purpose. This connector parses the CEF headers and maps the fields to the appropriate Microsoft Sentinel tables, enabling efficient threat detection and analysis.

Exam trap

The trap here is that candidates may confuse the older Log Analytics Agent (which also supports CEF) with the newer AMA-based connector, or mistakenly think that any Syslog connector can handle CEF without the specific parsing logic, leading them to choose a generic Syslog option not listed here.

How to eliminate wrong answers

Option B is wrong because Windows Security Events via AMA is used to collect security logs from Windows machines, not from third-party firewalls sending Syslog/CEF data. Option C is wrong because the Azure Activity Log connector ingests subscription-level events from Azure itself, such as resource creation or policy changes, not external firewall logs. Option D is wrong because the Office 365 connector collects audit and activity logs from Microsoft 365 services like Exchange and SharePoint, not from third-party network devices.

361
MCQmedium

Your organization uses Microsoft Defender for Cloud and you need to ensure that security recommendations are automatically remediated for non-compliant resources. You have enabled 'Auto provisioning' for the Log Analytics agent. What additional step is required to enable automatic remediation?

A.No additional step is required; auto provisioning automatically remediates
B.Configure manual remediation in Defender for Cloud
C.Enable the 'DeployIfNotExists' policy for specific recommendations
D.Create a custom Azure Policy initiative with audit effect
AnswerC

The DeployIfNotExists policy effect is the correct method because it automatically deploys a required configuration or resource when Azure Policy evaluates a resource as non-compliant. When you assign such a policy for a specific Defender for Cloud recommendation, it performs the remediation task on the spot and continuously in subsequent evaluations. This makes it the only automated approach listed that actually fixes the underlying issue.

Why this answer

Enabling 'Auto provisioning' for the Log Analytics agent only ensures the agent is installed on VMs, but does not automatically remediate security recommendations. To achieve automatic remediation, you must enable the 'DeployIfNotExists' effect on specific Azure Policy definitions (e.g., 'System updates should be installed on your machines'), which triggers remediation tasks when resources are non-compliant. This is a separate step in Defender for Cloud's 'Security policy' blade under 'Settings & monitoring'.

Exam trap

The trap here is that candidates confuse 'Auto provisioning' (which only deploys the Log Analytics agent) with automatic remediation of all security recommendations, leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because 'Auto provisioning' only handles agent deployment, not remediation of recommendations; it does not automatically fix non-compliant resources. Option B is wrong because 'manual remediation' requires human intervention to apply fixes, which contradicts the goal of automatic remediation. Option D is wrong because creating a custom Azure Policy initiative with 'audit' effect only logs non-compliance without taking any corrective action; you need 'DeployIfNotExists' or 'Modify' effects for automatic remediation.

362
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to ensure that all cloud security alerts are automatically ingested into Sentinel. What should you configure?

A.Configure the Microsoft 365 Defender data connector.
B.Configure the Azure Activity data connector.
C.Create a custom log table and a PowerShell script to push alerts.
D.Configure the Microsoft Defender for Cloud data connector (Legacy).
AnswerD

The Microsoft Defender for Cloud data connector (Legacy) directly ingests security alerts from Defender for Cloud into Microsoft Sentinel via the Azure Resource Graph API, satisfying the requirement for automatic ingestion without manual forwarding. This connector specifically handles cloud security alerts, not broader signals, aligning with the stem’s constraint of ingesting all cloud security alerts from Defender for Cloud into Sentinel.

Why this answer

The Microsoft Defender for Cloud data connector (Legacy) is the correct choice because it specifically ingests security alerts from Microsoft Defender for Cloud into Microsoft Sentinel. This connector ensures that all alerts generated by Defender for Cloud's security policies and threat detection are automatically streamed into Sentinel for centralized monitoring and incident response.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender data connector (which handles endpoint and office alerts) with the Defender for Cloud data connector (which handles cloud security alerts), leading them to select option A incorrectly.

How to eliminate wrong answers

Option A is wrong because the Microsoft 365 Defender data connector ingests alerts from Microsoft 365 Defender (e.g., Defender for Endpoint, Defender for Office 365), not from Microsoft Defender for Cloud. Option B is wrong because the Azure Activity data connector ingests subscription-level operational logs (e.g., resource creation, policy changes) from the Azure Activity Log, not security alerts from Defender for Cloud. Option C is wrong because creating a custom log table and a PowerShell script is an inefficient, manual workaround that bypasses the native, automated integration provided by the Defender for Cloud data connector; it is not the recommended or supported method for this requirement.

363
MCQeasy

A security administrator in Microsoft Defender for Cloud notices that the Secure Score is lower than expected. Which action would most effectively improve the Secure Score by reducing the attack surface?

A.Enable Just-in-Time (JIT) VM access for all virtual machines.
B.Configure auditing on all SQL databases.
C.Disable all low-severity security alerts in the subscription.
D.Install EDR agents on all on-premises servers.
AnswerA

Enabling Just-in-Time (JIT) VM access is a built-in security recommendation in Microsoft Defender for Cloud that directly improves your Secure Score through the 'Enable management ports to be closed just-in-time' control. By restricting access to management ports (SSH/RDP) to authorized users, approved IP ranges, and limited time windows, JIT reduces the network attack surface. This is a high-impact, infrastructure-level control that is part of the default Azure Security Benchmark initiative, so implementing it yields an immediate and measurable increase in the Secure Score.

Why this answer

Enabling Just-in-Time (JIT) VM access reduces the attack surface by locking down inbound traffic to Azure VMs, allowing only authorized users to open specific ports (e.g., RDP 3389, SSH 22) for a limited time. This directly improves the Secure Score because Microsoft Defender for Cloud includes JIT recommendations as a high-impact security control, and implementing it reduces the number of exposed management ports that attackers can target.

Exam trap

The trap here is that candidates often confuse 'reducing the attack surface' with 'improving detection' (e.g., enabling auditing or installing EDR agents), but the Secure Score's attack surface reduction category specifically rewards proactive controls like JIT that limit exposure, not reactive monitoring or alert management.

How to eliminate wrong answers

Option B is wrong because configuring auditing on SQL databases improves compliance and threat detection but does not directly reduce the attack surface; it is a monitoring control, not a preventive one that lowers the Secure Score's attack surface reduction category. Option C is wrong because disabling low-severity security alerts does not improve the Secure Score; it only suppresses notifications and may hide real threats, while the Secure Score is based on implementing security recommendations, not alert suppression. Option D is wrong because installing EDR agents on on-premises servers enhances detection and response but does not directly reduce the attack surface in the context of Microsoft Defender for Cloud's Secure Score; the score focuses on cloud-specific controls like JIT, adaptive application controls, and vulnerability assessments.

364
MCQmedium

You are a security analyst for a company that uses Microsoft Defender for Office 365. You receive an incident indicating that a user reported a phishing email. You need to investigate the email and determine if it was delivered to other users. You also need to ensure that similar emails are blocked in the future. What should you do?

A.Use Threat Explorer to search for similar emails and delete them.
B.Submit the email to Microsoft for analysis and quarantine it.
C.Create a Safe Links policy to block URLs in the email.
D.Run a simulated phishing attack to test user awareness.
AnswerA

Threat Explorer in Microsoft 365 Defender provides deep email search across mailboxes and enables bulk remediation actions such as soft/hard delete. By filtering on sender, subject, or URL, you can identify every instance of this phishing campaign and purge them directly, which immediately contains the threat and prevents further user exposure.

Why this answer

Threat Explorer in Microsoft Defender for Office 365 allows you to search for and take bulk action on emails matching specific criteria, such as sender, subject, or URL. By using Threat Explorer, you can identify all instances of the reported phishing email across your tenant and delete them from user mailboxes, which directly addresses the need to determine if the email was delivered to other users and to remediate it. This tool is designed for hunting and remediation, making it the correct choice for this investigation.

Exam trap

The trap here is that candidates often confuse the investigative and remediation capabilities of Threat Explorer with the policy-based prevention features of Safe Links or Safe Attachments, leading them to choose a policy creation option (C) instead of the correct hunting and removal tool (A).

How to eliminate wrong answers

Option B is wrong because submitting the email to Microsoft for analysis is a reactive step that helps improve detection but does not immediately identify other recipients or remove the email from their mailboxes; quarantine is a separate action that may not cover all delivery scenarios. Option C is wrong because creating a Safe Links policy blocks URLs in future emails but does not help investigate whether the current phishing email was delivered to other users or remove it from their inboxes. Option D is wrong because running a simulated phishing attack tests user awareness but does not investigate the current incident or block similar emails in the future.

365
MCQmedium

After a security incident, you need to collect forensic evidence from a Windows 10 machine. Which Microsoft tool should you use to create a memory dump?

A.Remote Desktop Protocol (RDP)
B.Microsoft Defender for Endpoint Live Response
C.Microsoft Crash Dump Tool (e.g., NotMyFault or Sysinternals tools)
D.Microsoft Defender for Cloud Apps
AnswerB

Live Response connects to the device through Microsoft Defender for Endpoint and can run the 'getfile' or memory-dump collection commands, capturing volatile memory without disrupting the host. This satisfies the forensic-evidence constraint by preserving RAM contents for offline analysis.

Why this answer

Microsoft Defender for Endpoint Live Response provides a `dump` command that can capture a full memory dump from a live Windows 10 system without causing a crash. This preserves volatile forensic evidence such as running processes, network connections, and encryption keys. In contrast, the Microsoft Crash Dump Tool (NotMyFault or Sysinternals) is designed to trigger a system crash (BSOD) for debugging purposes, which is destructive and not appropriate for forensic collection.

Therefore, for a security incident requiring a memory dump without system disruption, Live Response is the correct tool.

Exam trap

The trap is that candidates may assume Sysinternals tools (like NotMyFault) are the dedicated memory dump tools, but they create crash dumps by crashing the system, which destroys volatile evidence. In the context of forensic collection within Microsoft Defender XDR, Live Response is the correct method to capture a memory dump nondestructively.

How to eliminate wrong answers

Option A is wrong because Remote Desktop Protocol (RDP) is a network protocol for remote desktop access, not a tool for creating memory dumps; it provides no mechanism to capture volatile memory. Option B is wrong because Microsoft Defender for Endpoint Live Response can collect a memory dump using the `dump` command, but it is a remote investigation and response tool, not a dedicated crash dump tool; the question asks for a tool that creates a memory dump, and Live Response is a platform feature, not the specific tool referenced in the exam context. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) for monitoring cloud applications, not a tool for local forensic memory capture on a Windows 10 machine.

366
Multi-Selecthard

Which THREE elements are essential when creating a custom incident response playbook in Microsoft Sentinel? (Choose THREE.)

Select 3 answers
A.Appropriate permissions via managed identity or service principal for the playbook to execute actions.
B.A mandatory approval step before any action is taken.
C.One or more actions using connectors like Azure Automation or Logic Apps.
D.An analytics rule that generates the incident.
E.A trigger condition based on an incident creation or alert.
AnswersA, C, E

Every action in a playbook that interacts with Microsoft Sentinel or another resource must authenticate; without a managed identity or service principal, the Logic App will receive 401/403 errors and the automation fails. A managed identity (system-assigned or user-assigned) is the recommended option because it removes the need for client secrets and allows you to grant Microsoft Sentinel Responder or a custom role directly to the identity. This permission assignment is mandatory, not optional, because the playbook runs as a separate security principal in Azure AD.

Why this answer

A custom incident response playbook in Microsoft Sentinel requires appropriate permissions to execute actions against Azure resources. This is achieved by assigning a managed identity or configuring a service principal for the Logic App, which authenticates and authorizes the playbook to run actions such as blocking IPs, isolating machines, or querying threat intelligence. Without these permissions, the playbook would fail at runtime due to authentication errors, making it non-functional.

Exam trap

The trap here is that candidates confuse the components of a playbook (trigger, actions, permissions) with external dependencies like analytics rules or optional approval steps, leading them to select non-essential items that are not part of the playbook's core definition.

367
MCQhard

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspected Kerberoasting attack targeting a service account. You need to investigate the affected user and identify any related lateral movement. Which Microsoft Defender for Identity feature should you use to view the user's profile, including their activity timeline, associated alerts, and lateral movement paths?

A.The user's profile page in the Microsoft 365 Defender portal
B.The 'Advanced hunting' page in the Microsoft 365 Defender portal
C.The 'Users' page in the Microsoft Defender for Identity portal
D.The 'Health issues' page in the Microsoft Defender for Identity portal
AnswerA

In Microsoft 365 Defender, the user profile page aggregates identity signals from Defender for Identity, including the user's activity timeline, associated alerts, and lateral movement paths. This unified view allows you to investigate the Kerberoasting alert in context, see related activities, and identify potential lateral movement. It is the correct feature for deep investigation of an affected user across identity workloads.

Why this answer

The user profile page in Microsoft 365 Defender consolidates identity data from Defender for Identity, including the activity timeline, alerts, and lateral movement paths. It is designed for investigating a specific user and understanding their behavior and relationships. Other pages either list users, show health status, or provide raw query access, but none offer the integrated investigative profile needed here.

Exam trap

The trap here is assuming the Users page in the Defender for Identity portal provides the full investigation view; the richer, unified user profile is in the Microsoft 365 Defender portal.

368
MCQhard

Your company uses Microsoft Defender for Cloud Apps. You discover that a user's account is compromised and used to access a sensitive SharePoint site from an unfamiliar IP. You need to immediately revoke the user's session and force them to re-authenticate. Which action should you take?

A.Add the IP to the blocked IP addresses list.
B.Create a governance action to suspend the user.
C.Send a notification to the user to change their password.
D.Apply a policy with the 'Revoke session' action.
AnswerD

The 'Revoke session' action is the correct governance action because it is a targeted, corrective control that specifically terminates the user's active access to the cloud app without disabling the account. Defender for Cloud Apps works with Conditional Access App Control to remove the session cookie and force a fresh authentication with the identity provider. This immediately stops the attacker's access while preserving the user's ability to sign in again after the risk is mitigated.

Why this answer

The 'Revoke session' governance action in Defender for Cloud Apps invalidates the user's active sessions across connected SaaS apps (SharePoint, Exchange, Teams, etc.) and forces re-authentication, which is the correct immediate response to an active session hijack. It is applied via an access or session policy and works with Conditional Access App Control to terminate the session in real time.

Exam trap

SC-200 often tests the confusion between blocking an indicator (IP) and revoking the compromised credential/session — candidates pick the IP block because it feels like 'stopping the attacker', but the active session token is what actually needs to be killed.

How to eliminate wrong answers

Option A is wrong because blocking the IP only prevents future connections from that address — the attacker's already-authenticated session token remains valid and continues to access SharePoint. Option B is wrong because suspending the user disables the account but does not invalidate already-issued session cookies or OAuth tokens, so the attacker's active session persists until token expiry. Option C is wrong because notifying the user to change their password is a slow, manual remediation that leaves the attacker's session live and depends on user action.

369
Multi-Selecteasy

Which TWO features are available in Microsoft Sentinel to automate incident response?

Select 2 answers
A.Playbooks based on Azure Logic Apps.
B.Workbooks.
C.Kusto Query Language (KQL) queries.
D.UEBA.
E.Automation rules.
AnswersA, E

Playbooks built on Azure Logic Apps provide the orchestration engine in Microsoft Sentinel, running multi-step response workflows triggered manually or by automation rules. They connect to Microsoft Entra ID, Defender and third-party tools, satisfying the requirement for automated incident response actions such as enrichment, notification and remediation.

Why this answer

Playbooks based on Azure Logic Apps (A) are the core automation mechanism in Microsoft Sentinel: they are Logic Apps workflows triggered by analytics rules or incidents that can run actions such as blocking an IP, posting to Teams, or opening a ticket, so they directly automate incident response. Automation rules (E) are also correct because they let you centrally manage and orchestrate incident handling — assigning owners, changing severity or status, tagging, and triggering playbooks — without writing code, which is exactly automation of incident response. Workbooks (B) are only for visualization and reporting dashboards, and KQL queries (C) are the query language used for hunting and analytics, not an automation feature.

UEBA (D) provides behavioral analytics and entity insights to enrich detection, but it does not itself automate response actions.

Exam trap

The trap here is that candidates often confuse detection or analysis tools (Workbooks, KQL, UEBA) with automation tools, failing to recognize that only Playbooks and Automation Rules provide the actual execution of response actions in Sentinel.

370
MCQhard

The exhibit shows an automation rule in Microsoft Sentinel. The analyst reports that the playbook is not triggered for high-severity incidents. What is the most likely cause?

A.The playbook resource ID is invalid.
B.The condition syntax is incorrect.
C.The tenant ID is missing.
D.The rule triggers only on incident creation, not on updates.
AnswerD

The rule triggers only on incident creation, not on updates. The automation rule's trigger is set to 'When incident created', which means it evaluates only at the moment an incident is generated. If an existing incident is later modified to raise its severity to 'High', the rule will not run because it does not subscribe to incident update events. To handle such changes, the rule would need to use the 'When incident update' trigger or include both creation and update triggers.

Why this answer

The automation rule is configured to trigger 'When incident is created,' which means it only runs the playbook at the moment the incident is first generated. If the incident's severity is updated after creation (e.g., from medium to high), the rule does not re-trigger, so the playbook will not execute for that high-severity incident. This is the most likely cause because the analyst reports that high-severity incidents are not triggering the playbook, and the rule's trigger condition explicitly excludes updates.

Exam trap

The trap here is that candidates assume the rule will re-evaluate conditions whenever the incident changes, but Sentinel's automation rules only evaluate the trigger condition at the moment of incident creation or update, not continuously, so a severity change after creation will not fire a rule set to 'When incident is created.'

How to eliminate wrong answers

Option A is wrong because an invalid playbook resource ID would cause a persistent failure for all incidents, not just high-severity ones, and the error would appear in the automation rule's run history. Option B is wrong because the condition syntax (e.g., 'Severity equals High') is validated at rule creation time; an incorrect syntax would prevent the rule from being saved, not cause it to silently fail for specific incidents. Option C is wrong because the tenant ID is automatically populated by Sentinel when the rule is created and is not a configurable field; a missing tenant ID would prevent the rule from being created at all.

371
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. An alert indicates that an external IP address is downloading large amounts of data from a SharePoint site containing confidential documents. The activity is coming from a valid user account that appears to be compromised. What should you do first to stop the data exfiltration?

A.Delete the confidential documents from SharePoint
B.Suspend the user account in Microsoft Entra ID
C.Block the external IP address in Microsoft Defender for Cloud Apps
D.Change the SharePoint site permissions to deny access
AnswerB

Suspending the account in Microsoft Entra ID immediately blocks the compromised identity's authentication, halting the ongoing SharePoint download before further data leaves. Containment precedes investigation, so revoking the valid credentials stops exfiltration at its source rather than merely alerting on it.

Why this answer

The first priority is to immediately stop the ongoing data exfiltration by suspending the compromised user account in Microsoft Entra ID. This disables the attacker's access via that account, halting the download. Blocking the external IP address (Option C) is less effective because the attacker could switch IPs.

Changing SharePoint permissions (Option D) or deleting documents (Option A) would not stop the current download session as quickly as suspending the account.

372
MCQmedium

During an incident response, you need to collect email messages from a user's mailbox in Microsoft 365 for evidence. The user is suspected of phishing. Which Microsoft Purview solution should you use?

A.eDiscovery (Standard)
B.Data Loss Prevention
C.Records Management
D.Audit (Standard)
AnswerA

eDiscovery (Standard) supports searching, holding and exporting mailbox content for legal or investigative purposes, matching the need to collect email evidence. It preserves messages in place, so suspected phishing correspondence is captured without altering the user's mailbox.

Why this answer

Microsoft Purview eDiscovery (Standard) is designed for identifying, collecting, and preserving electronically stored information (ESI) such as email messages for legal or investigative purposes. It supports mailbox searches, holds, and export of evidence, making it the correct tool for collecting a user's mailbox during incident response.

Exam trap

SC-200 often tests the confusion between Audit (which shows activity logs) and eDiscovery (which collects content) — candidates pick Audit thinking it retrieves emails, but it only shows metadata about mailbox operations.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) is for preventing exfiltration of sensitive data in real time, not for collecting evidence after an incident. Option C is wrong because Records Management is for declaring and retaining content per compliance policies, not for investigative collection. Option D is wrong because Audit (Standard) provides activity logs and search, but it does not collect or export mailbox content as evidence — it shows what happened, not the messages themselves.

373
MCQeasy

You are a security operations analyst for a company that uses Microsoft Sentinel. You need to create a workbook that displays the top 10 most common alert types over the last 7 days. The workbook will be used by the SOC manager to identify trends. You have already created a new workbook and added a query step. Which KQL query should you use in the query step?

A.AlertInfo | where TimeGenerated > ago(7d) | project AlertName
B.AlertInfo | where TimeGenerated > ago(7d) | project AlertName, count()
C.AlertInfo | where TimeGenerated > ago(7d) | summarize Count = count() by AlertName | top 10 by Count desc | render barchart
D.AlertInfo | where TimeGenerated > ago(7d) | summarize count() by bin(TimeGenerated, 1d) | render timechart
AnswerC

This query filters alerts from the last 7 days, then groups them by AlertName using summarize to count occurrences per alert type. The top 10 operator sorts the aggregated counts in descending order and returns the ten alert names with the highest frequencies, and render barchart visualizes the result as a bar chart. This satisfies the requirement to display the top 10 alert names by count.

Why this answer

It uses the `summarize` operator to count alerts by `AlertName`, then `top 10 by Count desc` to return the ten most frequent alert types, and `render barchart` to visualize the data in the workbook. This directly meets the requirement to display the top 10 most common alert types over the last 7 days.

Exam trap

The trap here is that candidates often confuse the `project` operator with `summarize`, mistakenly thinking they can use `count()` in a `project` clause, or they choose a query that shows alert volume over time instead of the top alert types by name.

How to eliminate wrong answers

Option A is wrong because it only projects the `AlertName` column without any aggregation, so it would return a list of all individual alerts rather than a count of the most common types. Option B is wrong because `project AlertName, count()` is invalid syntax; `count()` is an aggregation function that must be used within a `summarize` operator, not in a `project` clause. Option D is wrong because it summarizes by `bin(TimeGenerated, 1d)`, which groups alerts by day rather than by alert name, and renders a timechart showing alert volume over time, not the top 10 alert types.

374
MCQeasy

A security analyst is investigating an incident in Microsoft 365 Defender where a device is detected as infected with a trojan. The analyst wants to use automated investigation to contain the threat. Which action can be automatically taken on the affected device as part of a standard AIR playbook for endpoint detection and response?

A.Remove the user account from the device.
B.Execute a full antivirus scan on the device.
C.Disable the network adapter.
D.Initiate a device isolation.
AnswerD

Initiating device isolation is the correct containment action for an impacted device in Microsoft 365 Defender AIR. Device isolation quarantines the endpoint by enforcing a firewall policy that drops all inbound and outbound traffic except communication with Defender for Endpoint services, which keeps the device manageable and allows AI and analysts to continue investigation or remediation. This action directly limits the attacker's ability to move laterally or exfiltrate data, and it is auditable and reversible when the investigation concludes.

Why this answer

In Microsoft Defender for Endpoint, the Automated Investigation and Response (AIR) playbook for endpoint detection and response includes the ability to isolate a device from the network. This action stops the device from communicating with other devices or the internet, containing the threat while allowing the investigation to continue. Option D is correct because device isolation is a standard containment action in the AIR playbook for trojan infections.

Exam trap

The trap here is that candidates often confuse 'run a full antivirus scan' (a remediation action) with 'containment' (a first-step action), leading them to select Option B instead of recognizing that isolation is the primary automated containment action in the AIR playbook.

How to eliminate wrong answers

Option A is wrong because removing a user account is not an automated action in the AIR playbook; user account management is a manual remediation step and does not contain the threat at the device level. Option B is wrong because executing a full antivirus scan is a response action that can be triggered manually or via a live response command, but it is not an automated containment action in the standard AIR playbook; the playbook focuses on containment first. Option C is wrong because disabling the network adapter is not a supported automated action in the AIR playbook; device isolation achieves the same goal by blocking network communication at the Defender platform level without physically disabling the adapter.

375
MCQmedium

Refer to the exhibit. You are configuring a Microsoft Sentinel Windows Security Events via AMA connector using an ARM template. After deployment, you notice that no Windows events are being ingested. The AMA agent is installed on the Windows servers. What is the most likely issue?

A.The WindowsEvent and SecurityEvent data types are disabled.
B.The Azure Monitor Agent is not installed on the servers.
C.The data collection rule is not associated with the virtual machines.
D.The workspace ID is missing from the template.
AnswerC

An Azure Monitor Agent only collects events once it is linked to a data collection rule (DCR), and that DCR must be explicitly associated with each virtual machine in its scope. The template likely creates the DCR object and defines the WindowsEvent and SecurityEvent data sources, but without a scope assignment or association to the target VMs, the agent receives no instruction on what to collect. This perfectly explains why the tables exist and the agent is installed, yet no Windows security events appear in Sentinel.

Why this answer

The most likely issue is that the data collection rule (DCR) is not associated with the virtual machines. Even when the Azure Monitor Agent (AMA) is installed, it will not send any Windows security events to Microsoft Sentinel unless a DCR is linked to the VM. The DCR defines which events to collect and where to send them; without this association, the agent has no instructions and remains idle.

Exam trap

The trap here is that candidates often assume installing the agent is sufficient for data ingestion, but Microsoft Sentinel requires the explicit link of a Data Collection Rule to the VM to define what events to collect and where to send them.

How to eliminate wrong answers

Option A is wrong because the WindowsEvent and SecurityEvent data types are not 'disabled' in the ARM template context; they are schema tables in the Log Analytics workspace, and the DCR controls which events are collected, not a toggle on the data types themselves. Option B is wrong because the question explicitly states 'The AMA agent is installed on the Windows servers,' so the agent is present and this is not the issue. Option D is wrong because the workspace ID is a required parameter in the ARM template for the DCR destination, and if it were missing, the template deployment would fail outright, not result in silent ingestion failure after deployment.

Page 4

Page 5 of 18

Page 6