Courseiva

Microsoft Security Operations Analyst SC-200 (SC-200) — Questions 451–525

1303 questions total · 18pages · All types, answers revealed

Page 6

Page 7 of 18

Page 8
451
MCQeasy

You are using Microsoft Sentinel UEBA to hunt for insider threats. Which entity type would you investigate to detect unusual access to sensitive data?

A.IP
B.Application
C.Device
D.User
AnswerD

The user entity is the core anchor for UEBA in Microsoft Sentinel, enabling the engine to build a behavioral baseline and detect anomalies like unusual logon times, failed logins, or peers' rare access to sensitive resources. Insider threat hunting depends on correlating identity, access, and action attributes around a unique user, which is why user entity analysis correctly identifies abnormal access patterns. Without user-level behavioral analytics, insider threats that leverage legitimate credentials would remain undetected.

Why this answer

Microsoft Sentinel UEBA builds behavior profiles around entity types including User, Host, IP, and Application. To detect insider threats involving unusual access to sensitive data, the User entity is the right focus because UEBA tracks each user's normal data access patterns, peer group comparisons, and anomalies like accessing files or sites they normally do not. Investigating the User entity surfaces deviations such as mass downloads, access outside normal hours, or access to sensitive SharePoint sites.

Exam trap

SC-200 often tests entity-type selection by presenting IP, Device, and Application as plausible alternatives — candidates must recognize that insider data-access anomalies are modeled on the User entity, not infrastructure entities.

How to eliminate wrong answers

Option A is wrong because the IP entity is useful for detecting anomalous network origins or impossible travel, but it does not directly model a user's data access behavior or peer group. Option B is wrong because the Application entity focuses on application usage anomalies (e.g., unusual app access), not the user's access to sensitive data. Option C is wrong because the Device entity tracks device behavior and anomalies (e.g., unusual processes), but insider data access is best modeled at the user level where peer group and access patterns are analyzed.

452
MCQhard

During an incident response, a SOC analyst identifies that a malicious PowerShell script was executed on multiple endpoints. The analyst needs to collect relevant files from all affected endpoints for further analysis. What should the analyst use?

A.Microsoft Defender for Cloud Apps file investigation.
B.Microsoft Purview eDiscovery.
C.Microsoft Defender for Endpoint Live Response.
D.Microsoft Sentinel incident investigation graph.
AnswerC

Microsoft Defender for Endpoint Live Response is the correct tool because it provides a secure, remote shell session to an endpoint that is onboarded to Microsoft Defender for Endpoint. Analysts can use Live Response commands like 'collect' to retrieve specific files, run forensic scripts, and inspect system artifacts in real time. It also supports a managed library of commands and can be restricted through RBAC roles, making it purpose-built for incident response file collection.

Why this answer

Microsoft Defender for Endpoint Live Response allows analysts to remotely connect to endpoints and collect files, run scripts, and perform forensic actions in real time. This is the correct tool for gathering malicious PowerShell scripts from multiple affected endpoints during incident response.

Exam trap

The trap here is that candidates may confuse Microsoft Sentinel's investigation graph (which visualizes relationships) with a tool that can actually collect files, or they may think cloud app investigation or eDiscovery can be used for endpoint file collection, when neither supports live endpoint access.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps file investigation is designed for investigating files stored in cloud apps (e.g., SharePoint, OneDrive), not for collecting files from endpoints. Option B is wrong because Microsoft Purview eDiscovery is used for legal discovery and compliance searches across Microsoft 365 data, not for live forensic file collection from endpoints. Option D is wrong because Microsoft Sentinel incident investigation graph provides a visual map of entities and relationships in an incident but does not support direct file collection from endpoints.

453
MCQmedium

A company uses Microsoft Defender for Cloud and wants to automatically ensure that all Azure virtual machines have a specific security configuration baseline applied (e.g., default password policies). Which Defender for Cloud feature should they leverage to audit and enforce these configurations inside the VMs?

A.Security policies
B.Azure Policy Guest Configuration
C.Just-In-Time VM access
D.Adaptive application controls
AnswerB

Guest Configuration is an Azure Policy extension that can audit and deploy configurations inside Azure VMs, including Arc-enabled servers, using PowerShell Desired State Configuration (DSC). It enforces baselines by remediating settings such as password policy, Windows Defender Firewall rules, and TLS versions through DeployIfNotExists and Modify effects. This aligns with the goal of automating security baseline enforcement. Therefore, it is the correct choice.

Why this answer

Azure Policy Guest Configuration is the correct feature because it extends Azure Policy to audit and enforce configurations inside the operating system of Azure VMs, including security baseline settings like default password policies. Unlike host-level policies, Guest Configuration can evaluate and remediate settings within the guest OS, making it the appropriate tool for this requirement.

Exam trap

The trap here is that candidates often confuse Azure Policy (which applies to Azure resource properties) with Guest Configuration (which applies to settings inside the VM guest OS), leading them to incorrectly select Security policies or Adaptive application controls.

How to eliminate wrong answers

Option A is wrong because Security policies in Defender for Cloud define security standards and compliance rules at the subscription or resource level, but they do not audit or enforce configurations inside the VM's operating system. Option C is wrong because Just-In-Time VM access controls network access to management ports (e.g., RDP, SSH) and has no capability to audit or enforce OS-level security baselines. Option D is wrong because Adaptive application controls create allowlists for applications running on VMs to prevent malware, but they do not audit or enforce configuration baselines like password policies.

454
MCQhard

A SOC analyst is creating an automation rule in Microsoft Sentinel to trigger a playbook when a new incident is created. The analyst wants the rule to apply only to incidents that have a severity of 'High' and where the 'User' entity is present. Which condition configuration should the analyst use?

A.Set 'Incident severity equals High' and 'Incident tag contains User'
B.Set 'Incident severity equals High' and 'Entity type contains User'
C.Set 'Alert severity equals High' and 'Alert entity type contains User'
D.Set 'Incident provider equals Microsoft Sentinel' and 'Entity type contains User'
AnswerB

This is the correct condition set because automation rules in Microsoft Sentinel trigger on incidents, and they can evaluate incident-level properties such as Incident severity and Entity type. The 'Entity type contains User' condition checks the first-class entities associated with the incident, ensuring the rule only runs on high-severity incidents that actually include a user entity, which is precisely what the requirement asks for.

Why this answer

Microsoft Sentinel automation rules evaluate conditions at the incident level, not the alert level. The 'Incident severity equals High' condition filters by incident severity, and 'Entity type contains User' checks that the incident's entities include a User entity, which is required for the playbook to receive entity context.

Exam trap

The trap here is that candidates confuse incident-level conditions (severity, entity type) with alert-level conditions (alert severity, alert entity type), leading them to select Option C, which would not work because automation rules evaluate at the incident scope.

How to eliminate wrong answers

Option A is wrong because 'Incident tag contains User' is not a valid condition; tags are custom labels, not entity types, and cannot be used to verify the presence of a User entity. Option C is wrong because 'Alert severity' and 'Alert entity type' operate at the alert level, not the incident level, and automation rules trigger on incidents, not individual alerts. Option D is wrong because 'Incident provider equals Microsoft Sentinel' is a valid condition but does not filter by severity, and it would apply to all incidents from Microsoft Sentinel regardless of severity or entity presence.

455
MCQmedium

As a threat hunter, you want to proactively search for signs of privilege escalation using the 'AzureHound' tool within your Microsoft Sentinel environment. Which data source is most relevant to ingest to detect AzureHound usage?

A.Azure VM Insights logs
B.Azure Active Directory Audit Logs (now Microsoft Entra ID Audit Logs)
C.Azure Storage analytics logs
D.Azure Network Watcher logs
AnswerB

AzureHound enumerates Microsoft Entra ID objects, users, groups and role assignments via the Graph API, so Microsoft Entra ID Audit Logs capture the directory read and consent activity that reveals enumeration. These logs expose the reconnaissance patterns AzureHound generates.

Why this answer

AzureHound queries the Microsoft Graph API to gather Azure AD data, and those API calls are logged in the Azure Active Directory Audit Logs (Microsoft Entra ID Audit Logs). Option A is incorrect because AzureHound does not run on VMs; it is a standalone tool that uses Graph API. Option C is incorrect because AzureHound does not interact with Azure Storage.

Option D is incorrect because Azure Network Watcher logs do not capture Azure AD API activity.

456
MCQeasy

You receive an incident in Microsoft Sentinel that is a low-confidence alert from Microsoft Defender for Identity. What should be your first step?

A.Investigate the alert by reviewing related entities and logs.
B.Close the incident as a false positive.
C.Escalate to senior management.
D.Isolate the affected account immediately.
AnswerA

Investigating the alert by reviewing related entities (e.g., user, IP, host) and the underlying logs is the correct first step because it determines whether the detected activity is a true positive. Sentinel's incident investigation canvas allows you to track entity relationships, pivot to related events, and query KQL to confirm the alert's validity before any containment or remediation action is taken.

Why this answer

A low-confidence alert from Microsoft Defender for Identity indicates a potential but uncertain threat. The first step should always be to investigate the alert by reviewing related entities and logs to gather context and determine if the alert is a true positive or false positive. Prematurely closing, escalating, or isolating without investigation risks missing a real threat or causing unnecessary disruption.

Exam trap

The trap here is that candidates may assume low-confidence alerts are always false positives and close them immediately, but the correct triage process requires investigation first to avoid missing subtle attacks that manifest as low-confidence alerts.

How to eliminate wrong answers

Option B is wrong because closing a low-confidence alert as a false positive without investigation bypasses the triage process and could miss a real but subtle attack. Option C is wrong because escalating to senior management is premature before confirming the alert's validity through investigation. Option D is wrong because isolating the affected account immediately is an overreaction to a low-confidence alert and could disrupt legitimate user activity without evidence of compromise.

457
Multi-Selecthard

Which THREE of the following are valid components of Microsoft Defender XDR? (Select three.)

Select 3 answers
A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365
C.Microsoft Purview
D.Microsoft Defender for Identity
E.Microsoft Sentinel
AnswersA, B, D

Microsoft Defender for Endpoint is a cloud-based endpoint detection and response (EDR) solution that provides risk-based vulnerability management, antivirus, attack surface reduction, and automated investigation and remediation on devices. It natively shares signals with other Defender products in the Defender XDR portal, allowing correlated incidents across endpoints, identities, and email. This makes it a fitting component of the XDR suite because it contributes telemetry from the physical and virtual endpoints across your organization.

Why this answer

Microsoft Defender XDR is a unified security operations platform that integrates signals from multiple Microsoft security products. Microsoft Defender for Endpoint provides endpoint detection and response (EDR) capabilities, including behavioral-based detection and automated investigation. It is a core component of the XDR solution, enabling cross-domain correlation of alerts from endpoints.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (a compliance and data governance tool) or Microsoft Sentinel (a SIEM) as being part of Defender XDR, when in fact they are separate services that integrate with, but are not components of, the XDR platform.

458
MCQeasy

You have been tasked with creating an automated response in Microsoft Sentinel for incidents involving lateral movement. Which Azure service allows you to run a playbook to automatically isolate a compromised VM?

A.Azure Logic Apps
B.Kusto Query Language (KQL)
C.Microsoft Defender XDR advanced hunting
D.Azure Event Hubs
AnswerA

Playbooks in Microsoft Sentinel are built on Azure Logic Apps, which provide a visual designer to automate incident response actions such as blocking IPs, resetting passwords, or opening tickets. Logic Apps connectors integrate with many services, allowing you to orchestrate a wide range of response workflows. Therefore, Azure Logic Apps is the correct choice for creating an automated response in Sentinel.

Why this answer

Azure Logic Apps is the correct answer because it provides the workflow automation engine that powers Microsoft Sentinel playbooks. When a lateral movement incident is detected, a Logic Apps-based playbook can execute automated actions such as isolating a compromised VM via Azure Network Security Groups (NSGs) or Azure Firewall rules, using connectors like the Azure VM or Azure Resource Manager. This enables a no-code or low-code response directly from Sentinel without manual intervention.

Exam trap

The trap here is that candidates often confuse 'automated response' with 'querying or hunting tools' (like KQL or advanced hunting) and overlook that only Logic Apps provides the actual workflow execution engine for playbooks in Sentinel.

How to eliminate wrong answers

Option B is wrong because Kusto Query Language (KQL) is a query language used to analyze data in Azure Data Explorer and Sentinel logs, not a service for running automated response actions like VM isolation. Option C is wrong because Microsoft Defender XDR advanced hunting is a threat-hunting and querying tool for cross-domain telemetry, not an automation platform capable of executing playbooks or isolating resources. Option D is wrong because Azure Event Hubs is a big data streaming platform and event ingestion service, not a workflow automation service; it cannot run playbooks or directly isolate a VM.

459
MCQhard

You are a security analyst at a company that uses Microsoft Sentinel and Microsoft Defender for Identity (now part of Microsoft Defender XDR). During a threat hunt, you need to identify potential golden ticket attacks. You have Windows Security Events (Event ID 4672: Special Logon) and Kerberos service ticket events (Event ID 4769) ingested. A golden ticket attack often involves service ticket requests with unusual encryption types or ticket options. You want to find service ticket requests (4769) that have TicketOptions containing '0x40810000' (forwardable, renewable, canonicalize) and TicketEncryptionType == '0x17' (RC4), which are common in attacks. You need to write a KQL query that returns the top 10 accounts requesting such tickets in the last 7 days. Which query should you use?

A.SecurityEvent | where EventID == 4769 | where TicketOptions == "0x40810000" | summarize count() by AccountName | top 10 by count_
B.SecurityEvent | where EventID == 4769 | where TicketOptions == "0x40810000" and TicketEncryptionType == "0x17" | summarize count() by AccountName | top 10 by count_
C.SecurityEvent | where EventID == 4672 | where TicketOptions == "0x40810000" and TicketEncryptionType == "0x17" | summarize count() by AccountName | top 10 by count_
D.SecurityEvent | where EventID == 4769 | where TicketOptions contains "0x40810000" and TicketEncryptionType contains "0x17" | summarize count() by AccountName | top 10 by count_
AnswerB

Matching EventID 4769 with TicketOptions "0x40810000" and TicketEncryptionType "0x17" isolates RC4-encrypted, forwardable, renewable service ticket requests typical of golden ticket activity, then summarising count() by AccountName and taking the top 10 surfaces the most prolific requesters.

Why this answer

The correct query filters SecurityEvent for EventID 4769 (Kerberos service ticket request), then applies exact-match conditions on TicketOptions == "0x40810000" and TicketEncryptionType == "0x17" to identify RC4-encrypted, forwardable/renewable/canonicalize tickets typical of golden ticket attacks. It then summarizes counts by AccountName and returns the top 10, matching the requirement precisely.

Exam trap

SC-200 often tests event ID confusion — candidates must remember 4769 is for service ticket requests, while 4672 is for special logon, and must use exact match for hex values.

How to eliminate wrong answers

Option A is wrong because it omits the TicketEncryptionType filter, so it would include legitimate AES-encrypted tickets and produce false positives. Option C is wrong because it filters on EventID 4672 (Special Logon) instead of 4769, which is the wrong event for service ticket requests. Option D is wrong because it uses the contains operator instead of ==, which could match partial strings and is less precise; exact match is required for these specific hex values.

460
Multi-Selecthard

Which TWO remediation actions are available in Microsoft Defender for Endpoint when responding to a malware infection?

Select 2 answers
A.Run a full antivirus scan
B.Disable the user account
C.Reset the device to factory settings
D.Block the application in Defender for Cloud Apps
E.Isolate the device from the network
AnswersA, E

A full antivirus scan is a remediation action in Microsoft Defender for Endpoint, detecting and removing residual malware artefacts across the device after an infection. It satisfies the scenario by cleaning persistent threats that remain following initial detection and investigation.

Why this answer

Option A (Run a full antivirus scan) is correct because Microsoft Defender for Endpoint's device response actions include initiating a full Microsoft Defender Antivirus scan on the endpoint to detect and remediate residual malware artifacts beyond what was already found. Option E (Isolate the device from the network) is correct because device isolation is a core Defender for Endpoint live response action that cuts the endpoint off from the network (while optionally allowing Outlook/Teams communication) to contain the infection and prevent lateral movement. Option B is not a Defender for Endpoint remediation action; disabling user accounts is handled through identity services such as Active Directory or Entra ID, not the MDE device response console.

Option C is not offered as an MDE response action; factory reset is a device-management operation (e.g., Intune), not a Defender for Endpoint remediation. Option D is incorrect because blocking an application in Defender for Cloud Apps is a Cloud App Security (CASB) control for cloud app sessions, not a Defender for Endpoint endpoint remediation action.

Exam trap

SC-200 often tests the boundary between endpoint remediation (MDE), identity actions (Entra ID), and CASB actions (Defender for Cloud Apps) — candidates must pick only the endpoint-native actions.

461
MCQmedium

Your security team is investigating an incident in Microsoft Defender XDR where a user received multiple phishing emails. The team needs to create an automated response that blocks the sender's email address across all mailboxes in the organization. Which action should you configure in an automated investigation and response (AIR) playbook?

A.Add a 'Block IP address' action in Microsoft Defender for Cloud Apps.
B.Create a custom detection rule in Microsoft Sentinel.
C.Add a 'Block sender' action in Microsoft Defender for Office 365.
D.Deploy a configuration profile in Microsoft Intune.
AnswerC

In Microsoft Defender for Office 365, the 'Block sender' action directly adds the sender's email address to the tenant-level block list used by Exchange Online Protection, causing future messages from that address to be rejected during mail flow. This is the appropriate remediation when an email-based threat needs to be stopped at the messaging layer, and it can be executed from the email entity or threat explorer. It is therefore the correct action to block the sender across Exchange Online.

Why this answer

Blocking a sender's email address across all mailboxes is a native capability of Microsoft Defender for Office 365. The 'Block sender' action in an AIR playbook directly adds the sender to the tenant's block list, which is enforced at the transport layer for all inbound email, effectively preventing any further delivery from that address.

Exam trap

The trap here is that candidates confuse the scope of Microsoft Defender for Cloud Apps (Option A) with email security controls, mistakenly thinking IP blocking in MDCA can stop email from a specific sender, when in fact email transport blocking is handled exclusively by Defender for Office 365.

How to eliminate wrong answers

Option A is wrong because blocking an IP address in Microsoft Defender for Cloud Apps (MDCA) applies to cloud app sessions and API connections, not to email transport; it cannot block a sender's email address in Exchange Online. Option B is wrong because a custom detection rule in Microsoft Sentinel is for generating alerts from log data, not for executing remediation actions like blocking a sender in mail flow. Option D is wrong because a configuration profile in Microsoft Intune manages device settings and compliance policies, not email sender blocking, which is a mail flow control.

462
MCQhard

Your organization uses Microsoft Sentinel with UEBA (User and Entity Behavior Analytics). An alert indicates a user's sign-in from an unusual location, followed by a mass download of sensitive files from SharePoint. The user is a low-privilege employee. What is the most likely conclusion?

A.The user's account is compromised
B.The alert is a false positive due to user travel
C.The user is an insider threat
D.The user is conducting a ransomware attack
AnswerA

In Sentinel UEBA, this alert likely combines an impossible-travel event (source IP geolocation far from the user's normal base) with a mass-download anomaly such as copying hundreds of sensitive files from SharePoint Online or OneDrive within minutes. Because the location shift coincides with a sudden spike in data access that does not match the user's established behavioral baseline, the most probable scenario is an attacker using stolen credentials. UEBA also assigns a high risk score when the anomalous activity targets sensitive data categories, and the combination of geographic and volumetric deviations strongly indicates account compromise rather than benign behavior.

Why this answer

The combination of an unusual-location sign-in followed immediately by mass SharePoint downloads from a low-privilege account is the classic UEBA signature of credential compromise: an attacker authenticates with stolen credentials and exfiltrates data the account can reach. A low-privilege user has no legitimate business reason to suddenly download large volumes of sensitive files from a new geography, so the behavior deviates sharply from the account's established baseline. Microsoft Sentinel's UEBA correlates the anomalous sign-in with the abnormal data-access activity to surface this as a high-confidence compromise indicator.

Exam trap

SC-200 often tests the distinction between insider threat and external compromise — the trap is choosing 'insider threat' because the account is legitimate, ignoring that the anomalous geography points to stolen credentials rather than a trusted user acting maliciously.

How to eliminate wrong answers

Option B is wrong because legitimate travel would typically show a plausible travel pattern and the user's normal file-access behavior — a sudden mass download of sensitive files is not explained by travel alone. Option C is wrong because an insider threat implies the legitimate user is intentionally abusing their access; while possible, the unusual-location sign-in is a stronger indicator of external compromise than of an insider acting from their normal location. Option D is wrong because ransomware typically involves encryption, ransom notes, and lateral movement — mass downloading of files is exfiltration behavior, not the encryption/destruction pattern of ransomware.

463
Multi-Selecthard

Which THREE data sources should be included in a Microsoft Sentinel workspace to comprehensively monitor for lateral movement within an Azure environment?

Select 3 answers
A.Azure AD sign-in logs
B.Power BI audit logs
C.Azure Network Security Group flow logs
D.Azure DevOps audit logs
E.Azure Activity logs
AnswersA, C, E

Microsoft Entra ID sign-in logs record authentication events, including the originating IP, device and conditional access outcome. They satisfy the lateral movement requirement by exposing credential reuse or anomalous sign-ins from compromised accounts moving between Azure resources.

Why this answer

Azure AD sign-in logs (A) are correct because they record authentication events, including risky sign-ins, IP addresses, and conditional access results, which are essential for detecting credential-based lateral movement across Azure resources. Azure Network Security Group flow logs (C) are correct because they capture allowed and denied IP traffic flows through NSGs, enabling detection of east-west movement between subnets and VMs. Azure Activity logs (E) are correct because they record control-plane operations such as role assignments, resource creation, and management actions that attackers use to pivot and escalate privileges.

Power BI audit logs (B) and Azure DevOps audit logs (D) are not included because they focus on BI and DevOps activities, not on authentication, network, or Azure control-plane events relevant to lateral movement monitoring.

Exam trap

SC-200 often tests whether candidates can distinguish Azure runtime telemetry (sign-in, NSG flow, Activity logs) from SaaS/productivity audit logs (Power BI, DevOps) that do not reflect Azure infrastructure lateral movement.

464
MCQeasy

Your organization uses Microsoft Sentinel and wants to ensure that all incident-related data is retained for at least 90 days for compliance purposes. Which configuration should you check?

A.Log Analytics workspace retention settings
B.Watchlist settings
C.Analytics rule settings
D.Incident settings in Sentinel
AnswerA

In Microsoft Sentinel, all ingested telemetry resides in a designated Log Analytics workspace, and the workspace's retention settings determine how many days of raw logs are available for queries, analytics, and threat hunting. Adjusting table-level or workspace-level retention directly controls the lifespan of that data, including whether it moves to long-term retention or archive. Because Sentinel does not maintain a separate storage pool, the Log Analytics retention configuration is the authoritative mechanism for data retention.

Why this answer

Log Analytics workspace retention settings directly control how long raw data ingested into Microsoft Sentinel is stored. For compliance requiring 90-day retention of incident-related data, you must configure the workspace retention period to at least 90 days (or use archive policies for longer retention). Incident data in Sentinel is derived from this underlying workspace data, so retention settings at the workspace level ensure the data persists for the required duration.

Exam trap

The trap here is that candidates often confuse incident settings (which manage incident metadata and lifecycle) with data retention settings, assuming that configuring incident retention in Sentinel is sufficient, when in fact the underlying log data retention is controlled at the Log Analytics workspace level.

How to eliminate wrong answers

Option B is wrong because watchlist settings manage collections of external data (e.g., CSV files) used for correlation and enrichment, not the retention duration of incident-related data. Option C is wrong because analytics rule settings define detection logic, schedule, and alert creation, but do not control how long incident data is retained after ingestion. Option D is wrong because incident settings in Sentinel (e.g., status, classification, automation) manage incident lifecycle and response, not the underlying data retention period, which is governed by the Log Analytics workspace.

465
MCQhard

You are reviewing a hunting query. What is the primary purpose of this query?

A.List all users with any risk level during sign-in in the last 7 days
B.Detect users who have granted admin consent to malicious OAuth apps
C.Find users with medium-risk sign-ins that share IP addresses with service principal sign-ins, indicating possible token theft or lateral movement
D.Identify service principals that have been compromised and are performing high-risk sign-ins
AnswerC

This option correctly describes the query's purpose: it starts with medium-risk user sign-ins, joins those with service principal sign-ins on the same IP address, and uses a count threshold to identify repeated correlation. Such a pattern can reveal token theft or lateral movement where an attacker uses a stolen user token from an IP also associated with a service principal. The combination of the risk level on the user sign-in and the shared IP with a service principal is the key investigative signal.

Why this answer

The query filters for users with medium risk sign-ins and joins with service principal sign-ins on IP address, then counts occurrences per user exceeding 5, indicating potential compromise involving both user and service principal activity from the same IP. Option A is wrong because it does not focus on service principal compromise alone. Option B is wrong because it does not look for admin consent grants.

Option D is wrong because it uses only medium risk, not high.

466
MCQmedium

Match each Microsoft Defender for Cloud feature on the left with its primary purpose on the right.

A.Just-In-Time VM Access → Provides time-limited access to management ports via NSG rules; Adaptive Application Controls → Allowlists known safe applications to run on VMs; File Integrity Monitoring → Detects changes to sensitive registry keys and files; Regulatory Compliance Dashboard → Assesses Azure resources against industry standards
B.The first and second mappings are reversed; the remaining mappings are unchanged.
C.All features map to the same monitoring purpose.
D.The compliance and access-control mappings are swapped.
AnswerA

Just-In-Time (JIT) VM Access correctly describes time-limited opening of management ports (e.g., RDP/SSH) through NSG rules, while Adaptive Application Controls correctly describes an allowlist-based mechanism that uses machine learning to permit only known safe executables. File Integrity Monitoring (FIM) correctly targets changes to sensitive registry keys and files, and the Regulatory Compliance Dashboard correctly assesses Azure resources against industry standards such as CIS and PCI DSS. This alignment accurately captures each feature's core operational purpose without conflating network access, application control, integrity verification, or compliance assessment.

Why this answer

It accurately matches each Microsoft Defender for Cloud feature to its primary purpose. Just-In-Time (JIT) VM Access reduces the attack surface by locking down management ports (e.g., RDP 3389, SSH 22) and granting time-limited access via NSG rules only when requested. Adaptive Application Controls uses machine learning to create an allowlist of known safe applications, blocking unknown executables on VMs.

File Integrity Monitoring (FIM) tracks changes to sensitive registry keys, files, and certificates, alerting on unauthorized modifications. The Regulatory Compliance Dashboard continuously assesses Azure resources against built-in standards like CIS, NIST, and Azure Security Benchmark, providing a compliance score and recommendations.

Exam trap

The trap here is that candidates often confuse Just-In-Time VM Access with Adaptive Application Controls because both reduce attack surface, but JIT controls network-level access to management ports while Adaptive Application Controls controls which applications can execute at the OS level.

How to eliminate wrong answers

Option B is wrong because it claims the first two mappings are reversed, but JIT VM Access and Adaptive Application Controls are correctly paired in Option A; reversing them would incorrectly assign time-limited port access to application allowlisting and vice versa, which misrepresents their distinct security functions. Option C is wrong because it states all features map to the same monitoring purpose, which is false—each feature serves a unique purpose: JIT controls network access, Adaptive Application Controls controls software execution, FIM monitors file integrity, and the dashboard assesses compliance; they are not interchangeable. Option D is wrong because it swaps the compliance and access-control mappings, but the Regulatory Compliance Dashboard is correctly matched with assessing industry standards, and JIT VM Access is correctly matched with time-limited management port access; swapping them would inaccurately assign compliance assessment to JIT and access control to the dashboard.

467
MCQeasy

As a SOC analyst, you need to quickly identify if a specific user account has been involved in any incidents in the past week. Which feature in Microsoft Sentinel allows you to search for user-related incidents?

A.Incidents blade with time range filter
B.Hunting blade with user query
C.Entity behavior blade
D.Workbooks with KQL query
AnswerC

The Entity behavior blade is the correct feature because when you open a specific entity (user, device, or domain) in the Defender portal, the Entity behavior tab automatically renders a timeline of that entity's activities, associated alerts, and incident history. This direct entity-focused view lets an analyst immediately see whether that user was implicated in past incidents without writing any queries or building custom workbooks. Correct.

Why this answer

The Entity behavior blade in Microsoft Sentinel provides a user-centric view that aggregates all incidents, alerts, and activities associated with a specific user account. By selecting a user entity and navigating to the 'Incidents' tab within the blade, you can quickly filter incidents involving that user over a defined time range, such as the past week. This feature is designed specifically for investigating user-related security events without needing to write custom queries.

Exam trap

Microsoft often tests the misconception that the Incidents blade (Option A) is sufficient for user-specific searches, but the trap is that it lacks entity-level filtering, requiring analysts to manually correlate users across incidents, whereas the Entity behavior blade provides a consolidated user-centric view.

How to eliminate wrong answers

Option A is wrong because the Incidents blade with a time range filter shows all incidents across the workspace, but it does not allow you to search or filter by a specific user account directly; you would need to manually inspect each incident or use a KQL query to correlate user entities. Option B is wrong because the Hunting blade is used for proactive threat hunting with KQL queries to find potential threats, not for quickly identifying incidents already raised against a specific user; it requires writing and running custom queries, which is less efficient for this task. Option D is wrong because Workbooks with KQL queries are customizable dashboards for reporting and visualization, not a direct feature for searching user-related incidents; they require pre-built queries and are not designed for ad-hoc user lookups.

468
MCQmedium

A threat hunter is using Microsoft Defender for Endpoint advanced hunting to investigate a suspicious process that was observed launching from a temporary folder. The hunter wants to find all devices that have executed this specific process (with the same SHA256 hash) in the last 24 hours. Which table and column should be used in the query?

A.DeviceNetworkEvents table, SHA256 column
B.DeviceEvents table, SHA256 column
C.DeviceProcessEvents table, SHA256 column
D.DeviceFileEvents table, SHA256 column
AnswerC

DeviceProcessEvents records process creation events and exposes the SHA256 column, letting the hunter filter executions by the exact file hash observed. This satisfies the 24-hour scope via Timestamp filtering, returning every device that ran that specific binary regardless of filename or path.

Why this answer

DeviceProcessEvents table tracks process execution events and includes the SHA256 column for the file hash. Therefore, Option C is correct. Option A (DeviceNetworkEvents) is for network connections and does not include SHA256.

Option B (DeviceEvents) is a generic table that may not include process hash. Option D (DeviceFileEvents) is for file creation/modification, not execution.

469
Multi-Selecthard

Which THREE capabilities are provided by Microsoft Sentinel's UEBA (User and Entity Behavior Analytics)? (Select THREE.)

Select 3 answers
A.Identify users whose behavior deviates from their peers
B.Provide a timeline of a user's recent activities on the entity page
C.Automatically run playbooks when anomalies are detected
D.Detect anomalous sign-in locations and times
E.Create watchlists for high-value users
AnswersA, B, D

Microsoft Sentinel's UEBA engine leverages machine learning to establish a baseline of typical behavior for each user and their peer group. When a user's activities—such as access patterns, resource usage, or data exfiltration attempts—diverge significantly from that baseline, Sentinel surfaces an anomaly. This peer-to-peer comparison is a core UEBA capability that helps identify insider threats and compromised accounts, and it is distinct from simple rule-based alerting.

Why this answer

Microsoft Sentinel's UEBA uses machine learning models to establish a baseline of normal behavior for each user and then compares individual user activity against peer group behavior. When a user's actions deviate significantly from their peers, such as accessing unusual resources or performing atypical data transfers, an anomaly is generated, enabling security analysts to investigate potential insider threats or compromised accounts.

Exam trap

The trap here is that candidates may confuse UEBA's anomaly detection with the broader automation capabilities of Microsoft Sentinel, mistakenly thinking that UEBA itself automatically runs playbooks, when in fact playbook execution requires separate automation rules and is not a built-in UEBA feature.

470
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud Apps. You receive a high-severity incident indicating that a user's credentials were used to access a sensitive SharePoint site from an unmanaged device. The user, 'jdoe@contoso.com', is a senior executive. The IP address is from a public Wi-Fi hotspot. The incident includes a recommendation to apply session policy to block download of sensitive files. You need to create a policy in Microsoft Defender for Cloud Apps that blocks downloads from unmanaged devices for this specific user when accessing the sensitive site. The policy should trigger only when the user accesses the specific SharePoint site named 'ExecConfidential'. What should you do?

A.Create an app connector for SharePoint and a session policy that targets the user, site, and device tag 'Unmanaged' with the action 'Block download'.
B.Create a device compliance policy in Microsoft Intune to block unmanaged devices from accessing SharePoint.
C.Create a Conditional Access policy in Microsoft Entra ID to require compliant device for the SharePoint site.
D.Create a file policy in Defender for Cloud Apps to quarantine files downloaded from the site.
AnswerA

A SharePoint app connector enables Defender for Cloud Apps to proxy sessions, and a session policy scoped to jdoe, the ExecConfidential site and the Unmanaged device tag applies Block download in real time, satisfying the requirement to prevent sensitive file downloads from unmanaged devices.

Why this answer

Blocking downloads from unmanaged devices for a specific user and site requires a Defender for Cloud Apps session policy, which is enforced through Conditional Access app control and requires the SharePoint app connector to be configured. The session policy can be scoped to the user, the specific site 'ExecConfidential', and the 'Unmanaged' device tag, with the action set to block download. This is the only option that combines the app connector, session control, and the precise scoping the requirement demands.

Exam trap

The trap is choosing Conditional Access or Intune because they sound like the 'access control' answer, when the requirement is specifically session-level download blocking scoped to a site—a capability only Defender for Cloud Apps session policies provide.

How to eliminate wrong answers

Option B is wrong because an Intune device compliance policy governs device posture and conditional access eligibility but cannot selectively block file downloads from a specific SharePoint site for a specific user. Option C is wrong because a Conditional Access policy requiring a compliant device would block all access to the site from unmanaged devices rather than allowing access while blocking downloads, and it does not provide session-level download control. Option D is wrong because a file policy in Defender for Cloud Apps quarantines or governs files based on content/metadata after the fact and does not enforce real-time download blocking tied to device management state.

471
MCQhard

Your company deploys Microsoft Sentinel in a multi-workspace environment. You need to centralize incident management across workspaces while maintaining data residency. You configure Sentinel workspaces in each region. What additional configuration is required to view all incidents from a single pane?

A.Deploy the Microsoft Sentinel solution across workspaces.
B.Assign the same Azure RBAC roles to all users in each workspace.
C.Merge the workspaces into a single workspace.
D.Use an incident manager with a cross-workspace view.
AnswerD

Using an incident manager with a cross-workspace view is the correct approach because Microsoft Sentinel can aggregate incidents from multiple workspaces through Azure Lighthouse delegation. A central SOC workspace can then query and manage incidents across all listed workspaces from a single pane of glass, while each workspace retains its data residency and collection boundaries. This directly centralizes the incident lifecycle—triage, assignment, and closure—without duplicating configuration or merging data stores.

Why this answer

Microsoft Sentinel supports cross-workspace incident management through the incident manager, which can be configured to display incidents from multiple workspaces in a single view. This is achieved by using the 'cross-workspace view' feature, which leverages Azure Resource Graph to query incidents across workspaces without moving data, thus maintaining data residency requirements.

Exam trap

The trap here is that candidates often confuse deploying the Sentinel solution (Option A) with enabling cross-workspace views, but the solution deployment is a separate prerequisite and does not itself provide centralized incident management.

How to eliminate wrong answers

Option A is wrong because deploying the Microsoft Sentinel solution across workspaces is a prerequisite for enabling Sentinel in each workspace, but it does not provide a centralized incident view; it only installs the solution components. Option B is wrong because assigning the same Azure RBAC roles to all users in each workspace ensures consistent permissions but does not aggregate incidents into a single pane; RBAC controls access, not data aggregation. Option C is wrong because merging workspaces into a single workspace would violate data residency requirements by centralizing data in one region, and it is not a supported operation in Sentinel; workspaces are region-bound and cannot be merged.

472
MCQmedium

Your organization has Microsoft Defender for Endpoint deployed. A security analyst receives an alert about a suspicious PowerShell command executed on a device. The analyst needs to investigate the process tree. Which feature should the analyst use?

A.Device isolation
B.Live response
C.Timeline (process timeline)
D.Advanced hunting
AnswerC

The device timeline, also known as the process timeline, is the correct answer because it provides a chronological view of events and a visual representation of the process tree, including parent-child relationships. This allows an analyst to trace an attack chain from initial access to execution, observing how each process was spawned and what actions it performed. It is a core DFIR tool in Microsoft Defender for Endpoint for investigating a single device's historical activity.

Why this answer

The Timeline (process timeline) feature in Microsoft Defender for Endpoint allows analysts to view the full process tree, including parent-child relationships, command lines, and timestamps for events like PowerShell execution. This is the correct tool for investigating how a suspicious command was launched and what processes preceded it.

Exam trap

The trap here is that candidates often confuse Live response (a real-time interactive shell) with the Timeline feature (a historical, pre-built process tree), leading them to select Live response because they think it can be used to manually trace processes, but it lacks the automated, visual process tree view needed for efficient investigation.

How to eliminate wrong answers

Option A is wrong because Device isolation is a containment action that disconnects the device from the network to prevent lateral movement, not a forensic tool for viewing process trees. Option B is wrong because Live response provides a remote shell for real-time data collection and remediation (e.g., running scripts or collecting files), but it does not natively display a historical process tree; the process timeline is accessed via the portal. Option D is wrong because Advanced hunting is a Kusto Query Language (KQL)-based tool for querying raw data across multiple tables (e.g., DeviceProcessEvents), but it requires writing custom queries to reconstruct a process tree, whereas the Timeline feature provides a pre-built, visual process tree for a specific alert.

473
Multi-Selectmedium

Which TWO actions should you take to ensure that Microsoft Sentinel can detect and respond to threats across your multicloud environment, including AWS and GCP?

Select 2 answers
A.Use Azure Policy to deploy the connectors automatically.
B.Create analytics rules in Microsoft Sentinel to detect threats from the ingested multicloud logs.
C.Configure the AWS S3 and GCP Pub/Sub data connectors.
D.Enable the Microsoft Defender XDR connector for AWS and GCP.
E.Create a separate Microsoft Sentinel workspace for each cloud provider.
AnswersB, C

Analytics rules are the core detection mechanism in Microsoft Sentinel; without them, ingested logs remain dormant and never generate alerts or incidents. These rules use Kusto Query Language (KQL) to define detection logic, set alert thresholds, and trigger automated responses when suspicious activity matches. Enabling the AWS S3 and GCP Pub/Sub connectors supplies raw log data, but only analytics rules transform that data into actionable security incidents by performing correlation and pattern matching across the multicloud logs.

Why this answer

Analytics rules in Microsoft Sentinel define the conditions under which alerts are generated from ingested data. Without these rules, the raw logs from AWS S3 and GCP Pub/Sub would be stored but not evaluated for threats, rendering detection ineffective. Creating custom or built-in analytics rules is essential to transform ingested multicloud logs into actionable security incidents.

Exam trap

The trap here is that candidates often assume enabling a connector alone is sufficient for detection, forgetting that analytics rules are required to define what constitutes a threat; they also mistakenly think Microsoft Defender XDR can directly ingest AWS/GCP logs, when it only handles Microsoft 365 data.

474
Multi-Selecthard

Which THREE actions are recommended when conducting a threat hunting exercise in Microsoft Sentinel using the MITRE ATT&CK framework?

Select 3 answers
A.Focus only on techniques that have not been seen in your environment before.
B.Use the hunting queries from the Microsoft Sentinel Content hub as a starting point.
C.Rely exclusively on automated detection rules to identify threats.
D.Document your findings and update detection rules based on new patterns discovered.
E.Map your hunting hypotheses to specific MITRE ATT&CK tactics and techniques.
AnswersB, D, E

Content hub hunting queries map to MITRE ATT&CK tactics and techniques, giving you pre-built KQL aligned to the framework's structure. This satisfies the scenario's requirement to conduct hunting within ATT&CK, letting you pivot from known technique coverage rather than authoring detections from scratch.

Why this answer

Options B, D, and E are recommended actions. B: Using hunting queries from the Microsoft Sentinel Content hub provides a validated starting point. D: Documenting findings and updating detection rules helps improve future hunts.

E: Mapping hypotheses to MITRE ATT&CK tactics and techniques ensures comprehensive coverage. A is incorrect because focusing only on unseen techniques ignores known threats that may still be active. C is incorrect because relying exclusively on automated detection rules can miss advanced persistent threats that require manual hunting.

475
Multi-Selecteasy

Which TWO data connectors can be used to ingest Microsoft 365 audit logs into Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Microsoft Defender for Cloud Apps connector.
B.Microsoft 365 Defender connector.
C.Office 365 connector (Exchange, SharePoint, Teams).
D.Azure Activity connector.
E.Azure AD connector (sign-in logs).
AnswersB, C

This connector is a valid choice because it ingests unified audit logs from Microsoft 365, along with alerts and incidents from the Microsoft 365 Defender suite. It allows you to collect audit records related to user actions such as mailbox access, file shares, and Teams messages, which are critical for security investigations. By integrating with Microsoft 365 Defender, the connector provides a streamlined way to bring these logs into your SIEM, making it one of the two correct answers.

Why this answer

The Microsoft 365 Defender connector (Option B) ingests unified audit logs from Microsoft 365 Defender, which includes security-related events from Microsoft 365 services. The Office 365 connector (Option C) directly ingests audit logs from Exchange Online, SharePoint Online, and Microsoft Teams, which are part of the Microsoft 365 audit log. Both connectors are designed to bring Microsoft 365 audit log data into Microsoft Sentinel.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender connector with the Office 365 connector, thinking they are redundant, or they mistakenly select the Azure AD connector because they assume sign-in logs are part of Microsoft 365 audit logs, when in fact the Azure AD connector only captures Azure AD-specific events, not the full Microsoft 365 audit log.

476
MCQmedium

Your team is using Microsoft 365 Defender advanced hunting to investigate a possible data exfiltration incident. The security team suspects that an internal attacker used a compromised SharePoint Online account to download sensitive files from multiple sites. You need to build a hunting query that identifies all file download activities from SharePoint Online for a specific user account over the past 7 days, and then calculates the total size of downloaded files. Which KQL query should you use?

A.CloudAppEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownload' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)
B.CloudAppEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)
C.EmailEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)
D.FileEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)
AnswerB

This query is correct because it uses the CloudAppEvents table, the authoritative table in Microsoft 365 Defender advanced hunting for cloud app activities, and filters on ActionType == 'FileDownloaded', which is the exact event name for file downloads in SharePoint Online. The AccountDisplayName filter isolates the target user's actions within the last 7 days, and summarize TotalSize = sum(FileSize) correctly aggregates the FileSize numeric column to yield the total bytes downloaded. It is the only option that combines the right table, accurate action type, and proper aggregation.

Why this answer

Ly filters SharePoint file download events (FileDownloaded) and sums the FileSize. Option A uses wrong action; Option C uses wrong table; Option D is for email.

477
MCQeasy

Your company uses Microsoft Sentinel to monitor security events. You have configured a daily email report that summarizes the top 10 incidents from the past 24 hours. The report is sent using a Logic App playbook triggered by a scheduled query. Recently, the report has stopped being delivered. You check the Logic App run history and see that the last run failed with an HTTP 403 error when connecting to the Microsoft Sentinel API. The Logic App uses a managed identity for authentication. What is the most likely cause of the failure?

A.The managed identity does not have the required permissions on the Sentinel workspace.
B.The managed identity's client ID has changed.
C.The Logic App is not connected to Microsoft Entra ID.
D.The scheduled query is no longer running.
AnswerA

The managed identity must be assigned the Sentinel Reader RBAC role on the target Log Analytics workspace (or its resource group). Without this role, the Microsoft Sentinel connector in the Logic App returns an authorization error when attempting to read incidents or execute a query, even though the Logic App trigger ran successfully. Permissions are not automatically granted to the managed identity's service principal; they must be explicitly assigned via Azure RBAC.

Why this answer

The HTTP 403 error indicates a permissions failure when the Logic App attempted to call the Microsoft Sentinel API. Since the Logic App uses a managed identity for authentication, the most likely cause is that the managed identity lacks the necessary role assignments on the Sentinel workspace, such as 'Microsoft Sentinel Contributor' or 'Microsoft Sentinel Reader', which are required to query incidents via the API.

Exam trap

The trap here is that candidates may confuse an HTTP 403 (forbidden/permissions) with an HTTP 401 (unauthenticated) or assume the managed identity itself is broken, when in fact the identity is valid but lacks the required RBAC role on the Sentinel workspace.

How to eliminate wrong answers

Option B is wrong because a managed identity's client ID is immutable and does not change; if it did, the identity itself would be broken, not just the permissions. Option C is wrong because a Logic App using a managed identity is inherently connected to Microsoft Entra ID (formerly Azure AD) — the managed identity is a feature of Entra ID, so a missing connection would prevent authentication entirely, not cause a 403. Option D is wrong because the scheduled query not running would result in no data or a different error (e.g., empty report), not an HTTP 403 from the Sentinel API; the 403 specifically indicates an authorization failure during the API call.

478
MCQhard

A security analyst is configuring a Microsoft Sentinel playbook to automatically respond to phishing incidents. The playbook should only run when an incident of severity 'High' is created and the incident is not already assigned to a user. Which automation rule condition and trigger configuration should the analyst use?

A.Configure an automation rule with trigger 'When incident is created', conditions for severity equals High and 'Assigned to' is empty, and action to run the playbook.
B.Configure a playbook trigger 'When an incident is updated' and add a condition in the playbook logic app to check severity and assignment.
C.Schedule the playbook to run every 5 minutes and query for new incidents with required properties.
D.Configure an automation rule with trigger 'When incident is created' and only condition for severity equals High; the playbook will handle unassigned checks internally.
AnswerA

Configuring an automation rule with trigger 'When incident is created' and conditions for severity equals High and 'Assigned to' is empty ensures the playbook runs only for newly created High-severity incidents that are unassigned. This pre-filtering eliminates unnecessary playbook executions and allows the playbook to focus solely on the response actions, such as assigning an owner or initiating an investigation. Because the trigger fires on incident creation, the conditions are evaluated at the moment the incident is generated, which is the correct pattern for this scenario.

Why this answer

The automation rule trigger 'When incident is created' ensures the playbook runs immediately upon incident creation, and the conditions for severity equals 'High' and 'Assigned to' is empty filter incidents precisely as required. This configuration offloads the filtering to Sentinel's automation rule engine, which is more efficient and reliable than handling it inside the playbook logic.

Exam trap

The trap here is that candidates often think the playbook itself should handle all logic (like checking assignment) via conditions inside the Logic App, but the automation rule's condition engine is designed for this filtering and is more efficient, leading them to choose Option D instead of A.

How to eliminate wrong answers

Option B is wrong because using the trigger 'When an incident is updated' would cause the playbook to run on every update, not just creation, and adding conditions inside the Logic App is less efficient and can introduce latency or missed triggers. Option C is wrong because scheduling a playbook to run every 5 minutes with a query is a polling approach that introduces delay and is not event-driven, violating the requirement for immediate response. Option D is wrong because while the automation rule triggers on creation and filters severity, it does not include the 'Assigned to' condition; relying on the playbook to check assignment internally is less efficient and can cause the playbook to run unnecessarily for assigned incidents, consuming resources and potentially causing unintended actions.

479
Multi-Selecthard

Which TWO actions should be taken to respond to a potential data exfiltration incident detected by Microsoft Defender for Cloud Apps?

Select 2 answers
A.Block the IP address of the user's device at the firewall.
B.Suspend the user account in Microsoft Entra ID.
C.Report the user to Microsoft for investigation.
D.Revoke all active sessions for the user in Defender for Cloud Apps.
E.Run a full antivirus scan on the user's device.
AnswersB, D

Suspending the user account in Microsoft Entra ID immediately disables the account, preventing the user from authenticating and blocking issuance of new access tokens across all Entra ID-integrated cloud applications, including Exchange Online, SharePoint, and Teams. This is the most direct and comprehensive identity-centric containment action because it removes the attacker's ability to log in regardless of endpoint, IP, or session state. It also stops password-based and token-based access at the source, making it the preferred first step in responding to a compromised identity.

Why this answer

Suspending the user account in Microsoft Entra ID immediately revokes the user's ability to authenticate, preventing further access to cloud resources and stopping potential data exfiltration. This is a direct containment action that aligns with incident response best practices for compromised accounts.

Exam trap

The trap here is that candidates often confuse 'revoking sessions' (a temporary measure) with 'suspending the account' (a permanent containment action), and may incorrectly think that blocking an IP address or running an antivirus scan is a sufficient immediate response to data exfiltration.

480
MCQhard

A company has multiple Azure subscriptions managed by Microsoft Defender for Cloud with enhanced security features enabled. The security team wants to ensure that all Azure SQL Servers have Advanced Data Security (ADS) enabled, including Vulnerability Assessment. They decide to use Azure Policy to enforce this at scale. Which built-in policy initiative should they assign to achieve this?

A.Enable Azure Monitor for VMs
B.Azure Security Benchmark
C.Deploy Diagnostics Settings for SQL Databases
D.Enable Advanced Threat Protection for SQL servers
AnswerB

Azure Security Benchmark is a comprehensive policy initiative (policy set definition) that bundles multiple built-in policy definitions representing security best practices and compliance controls across services, including SQL servers. Specifically, it includes policies such as 'Advanced Data Security on SQL servers should be enabled' and 'Vulnerability assessment on SQL servers should be enabled', which together establish a baseline for SQL security. Assigning this initiative to the Azure subscription allows Microsoft Defender for Cloud to evaluate, audit, and automatically deploy the required SQL security settings, making it the correct choice for meeting the stated requirement.

Why this answer

The Azure Security Benchmark initiative includes built-in policies to enforce Advanced Data Security (ADS) and Vulnerability Assessment on Azure SQL Servers. Assigning this initiative at scale ensures compliance with security best practices across all subscriptions, as it contains the specific policy effect to enable ADS and VA automatically.

Exam trap

The trap here is that candidates often confuse a single policy (like 'Enable Advanced Threat Protection for SQL servers') with a policy initiative that bundles multiple related policies, leading them to select option D instead of the broader Azure Security Benchmark initiative that covers both ADS and Vulnerability Assessment enforcement.

How to eliminate wrong answers

Option A is wrong because 'Enable Azure Monitor for VMs' is an initiative focused on deploying the Log Analytics agent and VM insights, not on SQL Server security configurations. Option C is wrong because 'Deploy Diagnostics Settings for SQL Databases' only configures diagnostic logging to a Log Analytics workspace, but does not enable Advanced Data Security or Vulnerability Assessment. Option D is wrong because 'Enable Advanced Threat Protection for SQL servers' is a single policy, not a policy initiative; the question asks for a built-in policy initiative that enforces both ADS and Vulnerability Assessment at scale.

481
MCQmedium

During an incident investigation in Microsoft Sentinel, you need to gather related events from multiple data sources into a single view for analysis. Which feature should you use?

A.Workbooks
B.Investigation graph
C.Watchlists
D.Logs blade
E.Analytics rules
AnswerB

The Investigation graph is the correct tool for incident investigation because it presents an interactive, visual map of entities (such as hosts, IPs, and accounts) and their connections to alerts and activities. It allows analysts to expand nodes to explore related entities, assess blast radius, and pivot directly into other data sources, making it purpose-built for correlating and understanding a specific incident's scope.

Why this answer

The Investigation graph in Microsoft Sentinel is specifically designed to visually correlate and explore related entities and events across multiple data sources within a single investigation. It allows you to pivot from an alert or entity to see connected users, hosts, IP addresses, and other events, providing a unified view for analysis. This feature directly addresses the need to gather related events from disparate sources into one cohesive view during incident response.

Exam trap

The trap here is that candidates often confuse the Investigation graph with Workbooks or the Logs blade, mistakenly thinking that any visualization or query tool can serve the same purpose, but the Investigation graph is the only feature purpose-built for interactive, entity-centric incident exploration in Sentinel.

How to eliminate wrong answers

Option A is wrong because Workbooks are used for creating custom dashboards and reports for visualizing data trends, not for interactive, entity-based incident investigation. Option C is wrong because Watchlists are static collections of data (e.g., IP addresses or hashes) used for correlation or enrichment in queries, not for dynamic event gathering across sources. Option D is wrong because the Logs blade is a query interface for running KQL queries against raw log data, but it does not provide a built-in, visual entity relationship view for incident investigation.

Option E is wrong because Analytics rules are used to create detection logic that generates alerts, not to investigate or correlate events after an alert has been triggered.

482
MCQhard

A security analyst is investigating an advanced persistent threat campaign that involves lateral movement using RDP. The analyst suspects that an attacker uses RDP from DeviceA to DeviceB, and then within a few minutes executes a malicious PowerShell script on DeviceB. The analyst wants to create a custom detection rule in Microsoft 365 Defender that triggers when this pattern occurs. Which KQL query pattern should be used to correlate these events across devices?

A.Use a self-join: query DeviceProcessEvents for mstsc.exe, extract the target device (e.g., from command line), and then join with another query on DeviceProcessEvents for PowerShell on the target device where the time difference between the events is less than 10 minutes.
B.Query DeviceNetworkEvents for RDP connections (port 3389) and then join with DeviceProcessEvents for PowerShell on the same device.
C.Use the 'union' operator to combine all mstsc.exe and PowerShell events, then summarize by device and time.
D.Query DeviceLogonEvents for RDP logon type and then join with DeviceProcessEvents for PowerShell on the same device.
AnswerA

This approach correctly models the lateral movement sequence: the mstsc.exe process on the initiating host contains the target device's name or IP in its command line (e.g., mstsc /v:10.0.0.5), so extracting that value and self-joining DeviceProcessEvents back to the target device lets you pivot from the RDP client to the PowerShell process that ran after connection. Adding a time window of less than 10 minutes between the mstsc.exe event on the source and the PowerShell event on the target filters out unrelated script activity, producing a precise correlation that reflects the attack chain. Because both legs are process events from DeviceProcessEvents, the join uses consistent schema (DeviceName, Timestamp, CommandLine) and allows direct association regardless of network port or logon type.

Why this answer

It uses a self-join on DeviceProcessEvents to first detect the mstsc.exe process (RDP client) on DeviceA, extract the target device name from the command line, and then join with a second query on DeviceProcessEvents for PowerShell on DeviceB. The join condition includes a time difference of less than 10 minutes, which directly correlates the lateral movement (RDP) with the subsequent malicious script execution across devices, matching the described attack pattern.

Exam trap

The trap here is that candidates often choose options that only correlate events on a single device (like B or D) or use aggregation operators like 'union' (C) that lose the cross-device temporal sequence, failing to recognize that the self-join pattern is required to correlate events across different devices in a lateral movement scenario.

How to eliminate wrong answers

Option B is wrong because it queries DeviceNetworkEvents for RDP connections (port 3389) and joins with DeviceProcessEvents on the same device, which would only correlate events on a single device (e.g., DeviceB) and fails to capture the cross-device lateral movement from DeviceA to DeviceB. Option C is wrong because using the 'union' operator to combine all mstsc.exe and PowerShell events and then summarizing by device and time loses the critical sequence and cross-device correlation; it cannot enforce that the RDP connection from DeviceA precedes the PowerShell execution on DeviceB within a specific time window. Option D is wrong because querying DeviceLogonEvents for RDP logon type (type 10) and joining with DeviceProcessEvents on the same device only captures events on the target device (DeviceB) and does not identify the source device (DeviceA) or the specific RDP client process (mstsc.exe) used for lateral movement.

483
MCQeasy

You are reviewing the automation rule configuration shown in the exhibit. What is the purpose of this rule?

A.Automatically resolve incidents related to malware
B.Automatically close incidents with 'Malware' in the title
C.Run a playbook to isolate a device when an incident with 'Malware' in the alert title is created
D.Create a playbook for malware alerts
AnswerC

This automation rule is triggered when a new incident is created and its condition matches alert titles containing the word 'Malware.' The rule's action invokes a playbook—an Azure Logic Apps workflow—that is designed to isolate the affected device, typically through a Microsoft Defender for Endpoint connector. This correctly describes the two core parts of the rule: the condition (incident created + alert title contains 'Malware') and the action (run a playbook to isolate a device).

Why this answer

The automation rule is configured to trigger when an incident is created with 'Malware' in the alert title. The action specified is to run a playbook, which in Microsoft Sentinel can perform complex remediation steps such as isolating a device. Option C correctly identifies this combination of trigger condition and action.

Exam trap

The trap here is that candidates may confuse 'run a playbook' with 'resolve' or 'close' incidents, or think the rule itself creates the playbook, when in fact the rule only triggers an existing playbook.

How to eliminate wrong answers

Option A is wrong because the rule does not automatically resolve incidents; it runs a playbook, which may include resolution steps but is not the direct action of the rule. Option B is wrong because the rule does not close incidents; it triggers a playbook execution, not a closure action. Option D is wrong because the rule does not create a playbook; it runs an existing playbook when the condition is met.

484
Multi-Selecthard

Which THREE steps are part of the containment phase of incident response in Microsoft Sentinel? (Select THREE.)

Select 3 answers
A.Disable compromised user accounts in Microsoft Entra ID.
B.Isolate affected devices using Microsoft Defender for Endpoint.
C.Collect forensic data from affected endpoints.
D.Block malicious IP addresses and domains in Microsoft Defender for Cloud Apps.
E.Restore encrypted files from backup.
AnswersA, B, D

Disabling accounts stops further misuse.

Why this answer

Disabling compromised user accounts in Microsoft Entra ID is a containment step because it immediately revokes the account's access tokens and prevents further authentication, stopping an attacker from using that identity to move laterally or access resources. This aligns with the containment phase's goal of limiting the blast radius of an incident.

Exam trap

The trap here is confusing containment actions (stopping the attack) with investigation (collecting evidence) or recovery (restoring data), leading candidates to select forensic collection or backup restoration as containment steps.

485
MCQeasy

A security analyst reviews Microsoft Defender for Cloud recommendations for an Azure virtual machine. The VM has a recommendation titled 'Install endpoint protection solution on virtual machines'. The analyst clicks on the recommendation and sees affected resources. Which of the following best describes the purpose of this recommendation in the context of Defender for Cloud?

A.It identifies VMs that have an open network security group inbound rule that should be closed.
B.It suggests enabling Azure Firewall on the virtual network to protect the VM from external threats.
C.It recommends enabling disk encryption for the VM's OS and data disks.
D.It advises deploying a supported endpoint protection solution, such as Microsoft Defender Antivirus, to protect the VM from malware and other threats.
AnswerD

The correct recommendation prompts an analyst to deploy a supported endpoint protection solution, such as Microsoft Defender Antivirus or another integrated partner product, onto the VM. Defender for Cloud evaluates the VM's installed security agents and health state; if no solution is reported via the MMA/AMA or Microsoft Defender for Endpoint integration, it assigns the recommendation as 'unhealthy.' It can also detect a supported agent that is disabled, out-of-date, or reporting errors, and then direct the analyst to fix or provision the agent.

Why this answer

The recommendation 'Install endpoint protection solution on virtual machines' in Microsoft Defender for Cloud specifically identifies VMs that lack a supported endpoint protection solution (e.g., Microsoft Defender Antivirus, Trend Micro, Symantec). Its purpose is to ensure that VMs are protected against malware, viruses, and other threats by deploying an endpoint protection solution, which is a core security control in the cloud security posture management (CSPM) framework.

Exam trap

The trap here is that candidates confuse 'endpoint protection' with network-level controls (like NSG rules or Azure Firewall) or data-at-rest protections (like disk encryption), leading them to select options A, B, or C instead of recognizing the specific focus on malware protection at the OS level.

How to eliminate wrong answers

Option A is wrong because it describes a recommendation related to network security groups (NSGs) and open inbound rules, which is a separate recommendation (e.g., 'All network ports should be restricted') and not about endpoint protection. Option B is wrong because it suggests enabling Azure Firewall, which is a network-level security service, not an endpoint protection solution; Defender for Cloud has distinct recommendations for network security. Option C is wrong because it refers to disk encryption (e.g., Azure Disk Encryption), which protects data at rest, not endpoint protection against malware; these are different security controls in Defender for Cloud.

486
MCQeasy

A security operations analyst is creating a scheduled analytics rule in Microsoft Sentinel to detect brute force attempts on Microsoft Entra ID authentication. Which data source is most appropriate for this rule?

A.Azure Activity Logs
B.SigninLogs
C.Office Activity Logs
D.SecurityEvent
AnswerB

SigninLogs in Microsoft Entra ID records both successful and failed user sign-in attempts, including the user principal name, source IP, application, and failure reason. This is the authoritative identity-plane log for detecting brute-force behavior, because you can aggregate sign-in failures per account or IP and compare the count against a threshold, optionally looking for a subsequent success. For a scheduled analytics rule that detects brute-force attacks on cloud identities, SigninLogs is the correct data source.

Why this answer

SigninLogs captures user authentication attempts to Microsoft Entra ID, including failed sign-ins, which are essential for detecting brute force attacks. This data source provides detailed properties such as IP address, application, and status codes (e.g., 50076 for invalid password), enabling accurate detection of repeated failed attempts. Azure Activity Logs, Office Activity Logs, and SecurityEvent do not contain Entra ID authentication events.

Exam trap

The trap here is that candidates often confuse Azure Activity Logs (control plane) with SigninLogs (authentication plane), assuming all Azure-related logs are in Activity Logs, but Entra ID sign-in events are a separate data source.

How to eliminate wrong answers

Option A is wrong because Azure Activity Logs record control-plane operations (e.g., resource creation, role assignments) on Azure resources, not user authentication events to Entra ID. Option C is wrong because Office Activity Logs capture actions within Microsoft 365 services (e.g., SharePoint, Exchange), not Entra ID sign-in attempts. Option D is wrong because SecurityEvent logs Windows security events from on-premises or Azure VMs, such as logon type 3 for network logins, and does not include cloud-based Entra ID authentication.

487
MCQhard

A company uses Microsoft Sentinel with the Microsoft 365 Defender connector. The security team notices that alerts from Microsoft Defender for Endpoint (MDE) are not appearing in Sentinel. The MDE data connector status shows 'Connected'. Which step should you take to troubleshoot this issue?

A.Verify that the Microsoft 365 Defender connector is configured to ingest MDE alerts.
B.Check if the Microsoft Defender for Endpoint data connector is added.
C.Verify that the ingestion rules in Sentinel are not filtering out MDE alerts.
D.Check the Microsoft 365 Defender portal to ensure MDE alerts are being generated and forwarded to Microsoft 365 Defender.
AnswerD

Before troubleshooting Sentinel, verify that Microsoft Defender for Endpoint alerts are actually being produced and sent to Microsoft 365 Defender by reviewing the Microsoft 365 Defender portal. If no MDE alerts are visible there, they cannot propagate downstream to Sentinel, regardless of connector configuration. This is the root-cause check because the Microsoft 365 Defender connector only ingests what Microsoft 365 Defender itself has received and correlated; an empty source yields empty Sentinel tables.

Why this answer

The Microsoft 365 Defender connector in Microsoft Sentinel ingests alerts that have already been generated and forwarded by Microsoft Defender for Endpoint (MDE) to the Microsoft 365 Defender portal. Even if the connector status shows 'Connected', if MDE alerts are not being generated or forwarded to Microsoft 365 Defender (e.g., due to a licensing issue, misconfigured alert policy, or service health problem), they will never reach Sentinel. Therefore, the first troubleshooting step is to verify alert generation and forwarding at the source in the Microsoft 365 Defender portal.

Exam trap

The trap here is that candidates assume a 'Connected' status guarantees data flow, but the connector status only reflects the API connection to Microsoft 365 Defender, not the actual generation or forwarding of alerts from the underlying MDE service.

How to eliminate wrong answers

Option A is wrong because the Microsoft 365 Defender connector is specifically designed to ingest MDE alerts (along with other Microsoft 365 Defender signals) — there is no separate configuration toggle within the connector to enable or disable MDE alert ingestion; if the connector is connected, it ingests all available alerts from Microsoft 365 Defender. Option B is wrong because there is no separate 'Microsoft Defender for Endpoint data connector' in Sentinel; MDE alerts are ingested exclusively through the Microsoft 365 Defender connector, so adding a non-existent connector is not a valid troubleshooting step. Option C is wrong because ingestion rules in Sentinel filter data after it has been received by the connector; if alerts are not appearing, the issue is upstream (before ingestion rules apply), and checking ingestion rules would only be relevant if alerts were being dropped after arrival.

488
Multi-Selecteasy

Which TWO actions should be taken immediately when a compromised user account is detected in Microsoft Entra ID?

Select 2 answers
A.Revoke all current sessions.
B.Notify the user's manager.
C.Disable the user account.
D.Reset the user's password.
E.Block sign-ins from the user's IP address.
AnswersA, C

Revoking all current sessions immediately invalidates the access tokens, refresh tokens, and session cookies that have already been issued to the user, terminating any active attacker foothold in real time. This is a containment-first action because it stops ongoing malicious activity without waiting for password changes or conditional access checks. However, it only disrupts existing authentications; it does not prevent future sign-ins, so it must be paired with disabling the account to block new authentication attempts.

Why this answer

Revoking all current sessions (Option A) is a critical immediate action because it terminates all active authentication tokens and sessions for the compromised account, preventing the attacker from continuing to use existing tokens to access resources. This action leverages Microsoft Entra ID's token revocation capabilities, which invalidate refresh tokens and access tokens issued before the revocation, effectively cutting off the attacker's current access without waiting for password changes or other mitigations.

Exam trap

The trap here is that candidates often choose 'Reset the user's password' as the first action, overlooking that existing sessions remain valid until tokens expire, so session revocation must precede password reset to fully contain the compromise.

489
MCQeasy

You are a security operations analyst. You need to review all incidents from the past 24 hours that have a high severity and involve multiple users. In Microsoft Sentinel, which blade should you use?

A.Incidents
B.Hunting
C.Workbooks
D.Analytics
AnswerA

The Incidents blade in Microsoft Sentinel is the dedicated operational workspace for security analysts to triage, investigate, and manage security incidents. It aggregates related alerts into a single incident, provides filtering by status, severity, and product, and supports actions like assignment and closing. This is the correct place to review existing incidents as it centralizes all detection results requiring attention.

Why this answer

The Incidents blade in Microsoft Sentinel is the correct place to review all security incidents, including filtering by severity and the number of users involved. It provides a centralized view where you can apply filters for 'High' severity and 'Multiple users' to meet the requirement of reviewing incidents from the past 24 hours. The Hunting, Workbooks, and Analytics blades serve different purposes and do not offer the same incident review and filtering capabilities.

Exam trap

The trap here is that candidates might confuse the Hunting blade (used for proactive searches) with incident review, or think that Workbooks or Analytics can be used to filter incidents, when in fact only the Incidents blade provides the direct filtering and management interface for security incidents.

How to eliminate wrong answers

Option B is wrong because the Hunting blade is used for proactive threat hunting using KQL queries to find suspicious activities, not for reviewing already-created incidents. Option C is wrong because Workbooks are used for creating custom visualizations and reports from log data, not for directly reviewing or filtering incidents. Option D is wrong because the Analytics blade is used to create and manage analytics rules that generate alerts and incidents, not to review existing incidents.

490
MCQhard

Refer to the exhibit. A SOC analyst runs this Advanced Hunting query in Microsoft Defender XDR to detect potential living-off-the-land (LotL) attacks. An alert is triggered when a device shows multiple occurrences of 'mshta.exe' executing with a remote script. Which additional data source should the analyst check to confirm the attack?

A.DeviceFileEvents
B.DeviceNetworkEvents
C.DeviceLogonEvents
D.DeviceRegistryEvents
AnswerB

DeviceNetworkEvents supplies the outbound connection telemetry — remote IP, port, and URL — that mshta.exe generated when fetching the remote script. This directly confirms the LotL attack by correlating the process execution already surfaced in the hunting query with the actual command-and-control or payload download destination, satisfying the requirement to verify external network contact.

Why this answer

DeviceNetworkEvents would show network connections made by mshta.exe to remote hosts, confirming the LotL attack. The other options are not directly relevant or are redundant.

491
Multi-Selectmedium

Which TWO techniques are commonly used in threat hunting with Microsoft Sentinel to identify lateral movement? (Choose two.)

Select 2 answers
A.Detecting port scanning activity from internal IPs.
B.Searching for multiple failed logon attempts from a single IP.
C.Looking for mass file deletion events on file servers.
D.Correlating service account usage with anomalous network connections.
E.Identifying remote PowerShell execution across multiple machines.
AnswersD, E

Service accounts often have elevated privileges and allow remote connections (e.g., SMB, WinRM, RDP) to multiple systems for legitimate application workloads. When an attacker compromises a service account, correlating its historical baseline with anomalous outbound network connections—such as connections to previously unseen hosts or non-standard protocols—can reveal lateral movement attempts that would otherwise blend in with normal service traffic.

Why this answer

Option D is correct because correlating service account usage with anomalous network connections surfaces lateral movement: attackers frequently reuse service accounts (often over SMB/RPC or WinRM) to pivot between hosts, and Microsoft Sentinel can join identity logs (SecurityEvent 4624 logon type 3/9, Azure AD sign-in logs) with network telemetry (Syslog, CEF, or NSG flow logs) in KQL to flag a service account authenticating to hosts it never normally touches. Option E is correct because remote PowerShell execution across multiple machines is a classic lateral movement technique; Sentinel detects it via Event ID 4104 (PowerShell script block logging), 4688 process creation showing powershell.exe with -Command/-EncodedCommand, and WinRM operational logs (e.g., Microsoft-Windows-WinRM/Operational), especially when the same account spawns sessions on many hosts in a short window. Option A is not the best fit because port scanning is typically reconnaissance or discovery activity that precedes movement rather than lateral movement itself.

Option B describes brute-force or password-spray credential access, which is an earlier attack phase, not lateral movement. Option C, mass file deletion, indicates impact or ransomware behavior rather than host-to-host pivoting.

Exam trap

SC-200 often tests whether candidates can distinguish lateral movement from adjacent phases — brute force (credential access) and mass deletion (impact) are common distractors that sound related but belong to different ATT&CK tactics.

492
Multi-Selectmedium

Which TWO actions should an analyst take when triaging a Microsoft Sentinel incident that involves a user who clicked a malicious link in a phishing email? (Choose two.)

Select 2 answers
A.Reset the user's password immediately.
B.Block the sender's domain in the tenant's block list.
C.Run a KQL query on EmailEvents to identify the email and recipient.
D.Delete the email from the user's mailbox immediately.
E.Check the email's status in Microsoft Defender for Office 365 Threat Explorer.
AnswersC, E

Querying EmailEvents in Microsoft Sentinel's advanced hunting tables returns the specific email, recipient, delivery action and verdict, tying the phishing message to the affected user. This satisfies the stem's triage requirement by scoping the incident to concrete evidence before remediation.

Why this answer

Option C is correct because running a KQL query against the EmailEvents table in Microsoft Sentinel (or Advanced Hunting) lets the analyst locate the exact phishing message and confirm the recipient, delivery time, and network message ID, which is essential for scoping the incident. Option E is correct because Microsoft Defender for Office 365 Threat Explorer provides the email's current status (e.g., delivered, blocked, quarantined) and allows further investigation such as viewing the message header, URL detonation results, and related campaigns. Option A is not the right first triage action because a password reset is only warranted if credential compromise is confirmed, and doing it blindly can disrupt the user without addressing the email threat.

Option B is not appropriate during triage because blocking the sender's domain tenant-wide is a containment/remediation step that should follow confirmation of the malicious domain and may cause false positives. Option D is also not a triage action; deleting the email is remediation, and it should be performed after confirming the message is malicious and after preserving evidence for the investigation.

Exam trap

The trap is confusing triage with remediation; candidates may select actions like resetting passwords or deleting emails, which are remediation steps, rather than investigative steps like querying logs and checking threat explorer.

493
MCQmedium

Your Microsoft Sentinel workspace receives logs from multiple sources. You need to ensure that an incident response playbook is triggered automatically when a specific alert is generated. What should you create?

A.A data connector.
B.An analytics rule.
C.An automation rule.
D.A new Logic App.
AnswerC

Automation rules are the native Sentinel mechanism that runs on incident creation or alert creation and can perform actions like assigning ownership, changing status, or invoking a playbook (Logic App) via a trigger. When an automation rule is configured to run a playbook, it uses the alert trigger or incident trigger in the Logic App, passing the alert payload. This is the direct answer to the question because automation rules bridge detection to response. They are the correct trigger mechanism.

Why this answer

An automation rule in Microsoft Sentinel is specifically designed to trigger incident response playbooks automatically when an alert is generated. It allows you to define conditions based on alert properties and then invoke a Logic App playbook without manual intervention. This is the correct mechanism for automating incident response actions in Sentinel.

Exam trap

The trap here is that candidates often confuse analytics rules (which generate alerts) with automation rules (which respond to alerts), leading them to select analytics rules when the question asks for automatic playbook triggering.

How to eliminate wrong answers

Option A is wrong because a data connector is used to ingest logs from external sources into Sentinel, not to trigger playbooks on alerts. Option B is wrong because an analytics rule generates alerts based on query results, but it does not directly trigger playbooks; automation rules are required for that. Option D is wrong because a new Logic App is the playbook itself, but it must be associated with an automation rule to be triggered automatically by an alert; creating just a Logic App does not enable automatic triggering.

494
Multi-Selecthard

You are configuring Microsoft Sentinel to ingest data from multiple sources. Which TWO of the following are valid data connectors that can be used to ingest AWS CloudTrail logs?

Select 2 answers
A.Azure Functions connector
B.Office 365 connector
C.AWS S3 connector
D.Microsoft Defender for Cloud connector
E.Syslog connector
AnswersA, C

Azure Functions can be deployed to create a custom ingestion pipeline for AWS CloudTrail logs. This involves configuring an Azure Function to retrieve logs from the designated AWS S3 bucket where CloudTrail stores its data. The function then processes these logs and forwards them to the Microsoft Sentinel Log Analytics workspace, effectively satisfying the requirement to ingest AWS CloudTrail logs. This method offers flexibility for custom transformations or filtering before ingestion.

Why this answer

The AWS S3 connector (Option C) is a valid data connector for ingesting AWS CloudTrail logs into Microsoft Sentinel by reading the logs directly from an S3 bucket. The Azure Functions connector (Option A) is also valid because it can be configured to trigger on CloudTrail log delivery to S3, using a function app to parse and forward the logs to Sentinel via the Log Analytics HTTP Data Collector API.

Exam trap

The trap here is that candidates often assume only the AWS S3 connector is valid, forgetting that Azure Functions can also serve as a custom data connector for AWS CloudTrail logs when configured with the appropriate trigger and permissions.

495
MCQmedium

A security team uses Microsoft Defender for Cloud to protect Azure virtual machines. They notice that a VM is generating alerts for unusual outbound connections. The team wants to use a Defender for Cloud feature that learns the VM's typical network behavior and provides recommendations to tighten network security group rules, while also alerting on suspicious deviations. Which feature should they enable?

A.Adaptive network hardening
B.Just-In-Time VM access
C.File integrity monitoring
D.Vulnerability scanning
AnswerA

Adaptive network hardening continuously analyzes actual traffic flows to and from Azure resources, learning the legitimate patterns of communication. It then compares these learned flows against the current NSG rules and recommends—or can automatically apply—tightened rules that block traffic that does not match the baseline. When a deviation from the learned pattern is observed, such as an unexpected source IP or port combination, it raises an alert, making it the appropriate control for detecting anomalous network behavior.

Why this answer

Adaptive network hardening (ANH) is the correct feature because it uses machine learning to learn a VM's typical traffic patterns (including outbound connections), then analyzes the current Network Security Group (NSG) rules against those learned patterns. It provides recommendations to tighten NSG rules to allow only the traffic that is actually used, and it generates security alerts when it detects deviations from the learned baseline, such as unusual outbound connections.

Exam trap

The trap here is that candidates often confuse Just-In-Time VM access (which also deals with network security) with adaptive network hardening, but JIT only manages inbound port access, not outbound traffic analysis or rule tightening based on learned behavior.

How to eliminate wrong answers

Option B (Just-In-Time VM access) is wrong because it focuses on reducing the attack surface by locking down inbound RDP/SSH ports and granting temporary access, not on learning outbound network behavior or tightening NSG rules based on traffic patterns. Option C (File integrity monitoring) is wrong because it monitors changes to critical files, registries, and software, not network traffic or NSG rule recommendations. Option D (Vulnerability scanning) is wrong because it identifies missing patches and misconfigurations in the OS and applications, not network behavior or NSG rule hardening.

496
MCQeasy

You are hunting for signs of ransomware in your environment using Microsoft 365 Defender. Which advanced hunting table should you primarily query to detect file encryption events?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.DeviceFileEvents
D.DeviceRegistryEvents
AnswerC

DeviceFileEvents records file creation, modification and renaming activity from Defender for Endpoint, capturing the rapid, high-volume write and rename operations ransomware performs during encryption. This directly satisfies the stem's requirement to detect file encryption events, unlike tables covering process, network or registry activity.

Why this answer

DeviceFileEvents captures file creation, modification, and deletion events, which are typical for ransomware encryption. Option A (DeviceNetworkEvents) is wrong because it captures network connections, not file events. Option B (DeviceProcessEvents) is wrong because it captures process creation and termination, not file events.

Option D (DeviceRegistryEvents) is wrong because it captures registry modifications, not file events.

497
MCQmedium

Your organization uses Microsoft Sentinel. A security analyst receives an alert from a custom analytics rule that triggers on a specific sequence of failed logon attempts followed by a successful logon from an unusual location. The incident is generated but the analyst is not sure if the activity is malicious or a user error. What should the analyst do first to quickly gather additional context?

A.Run a KQL query across the entire workspace to find all related events
B.Create a new analytics rule to detect similar patterns
C.Use the Investigation graph to explore related entities and events
D.Modify the existing analytics rule to add more conditions
AnswerC

The Investigation graph maps the incident's entities—accounts, hosts, IPs—and their linked events, letting the analyst pivot across the failed-then-successful logon sequence and unusual location in one view, satisfying the need to rapidly gather context before deciding whether the activity is malicious.

Why this answer

The Investigation graph in Microsoft Sentinel is designed to let analysts visually explore an incident's related entities (users, hosts, IPs) and their connections, quickly surfacing additional context such as other alerts, sign-ins, and events tied to the same entities. It is the fastest first step to determine whether the activity is malicious or benign without writing queries.

Exam trap

SC-200 often tests the difference between investigation and detection-engineering actions, so the trap is choosing to modify or create analytics rules (a detection task) instead of using the Investigation graph to gather context on the current incident.

How to eliminate wrong answers

Option A is wrong because running a broad KQL query across the entire workspace is slower and less targeted than the graph, and it does not automatically correlate entities. Option B is wrong because creating a new analytics rule is a detection-engineering task, not an investigation step, and does nothing to gather context on the current incident. Option D is wrong because modifying the rule changes future detection behavior and does not help triage the existing incident.

498
MCQmedium

Your organization uses Microsoft Defender XDR. You need to configure automatic attack disruption for identity-related threats. The solution should automatically contain a compromised user by disabling their account. Which setting should you enable?

A.Configure Conditional Access policies to block the user.
B.Enable automatic attack disruption in the Microsoft Defender XDR settings.
C.Use Microsoft Sentinel automation rules to disable the user.
D.Create a custom detection rule to alert on suspicious sign-ins.
AnswerB

Enable automatic attack disruption in the Microsoft Defender XDR settings. This native capability automatically contains compromised identities by disabling user accounts or isolating devices when an active attack is detected, without manual intervention. It uses cross-domain signals to break the attack chain immediately, aligning exactly with the requirement to automatically respond in real time.

Why this answer

Microsoft Defender XDR's automatic attack disruption feature is specifically designed to contain identity-related threats by automatically disabling compromised user accounts. This setting, found in the Microsoft Defender XDR settings under 'Automated investigation and response', triggers when high-confidence identity attacks (e.g., password spray, lateral movement) are detected, without requiring manual intervention or additional infrastructure.

Exam trap

The trap here is that candidates often confuse 'blocking sign-ins' (Conditional Access) with 'disabling the account' (automatic attack disruption), failing to recognize that only the latter fully contains a compromised user by preventing all authentication attempts, including those from trusted devices or locations.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies block sign-in attempts but do not disable the user account; the account remains active and could be used from non-compliant devices or after policy bypass. Option C is wrong because Microsoft Sentinel automation rules can trigger playbooks to disable users, but this requires custom configuration and is not the built-in automatic attack disruption mechanism within Defender XDR for identity threats. Option D is wrong because custom detection rules only generate alerts and do not automatically contain the user; they lack the automated response capability to disable the account.

499
MCQeasy

You are reviewing an automation rule ARM template for Microsoft Sentinel. What is the result of deploying this automation rule?

A.The rule assigns the incident to SOC-Tier2 only if the severity is Medium.
B.The rule triggers when an incident is updated and resets the severity to High.
C.When a High severity incident is created, the rule changes its severity to Medium and assigns it to SOC-Tier2.
D.The rule triggers when a High severity incident is created but does not change the severity.
AnswerC

This option accurately reflects the ARM template's trigger and action configuration. On incident creation, when 'Severity' equals 'High', the rule executes an update action changing severity to 'Medium' and an assignment action setting the owner to the 'SOC-Tier2' group. Both actions run in sequence as part of that single rule instance, and no other conditions modify this behavior.

Why this answer

The ARM template defines an automation rule that triggers when an incident is created with a severity of High. The rule's actions change the severity to Medium and assign the incident to the SOC-Tier2 owner. This matches option C exactly.

Exam trap

The trap here is that candidates may misinterpret the trigger condition as 'on update' (option B) or overlook the severity change action (option D), focusing only on the assignment part of the rule.

How to eliminate wrong answers

Option A is wrong because the rule triggers on incident creation, not on assignment, and it changes severity from High to Medium, not assigning based on Medium severity. Option B is wrong because the rule triggers on creation, not update, and it changes severity from High to Medium, not resetting to High. Option D is wrong because the rule does change the severity from High to Medium, contradicting the 'does not change the severity' claim.

500
MCQmedium

You are a threat hunter using PowerShell on a Windows 10 device. The command returns no output for a known threat ID. What is the most likely reason?

A.The Get-MpThreat cmdlet is deprecated.
B.The threat ID format is incorrect.
C.The threat has already been remediated and is no longer in the active threats list.
D.PowerShell must be run as administrator.
AnswerC

The query targets the active threats collection, which only holds unresolved detections. Once remediation completes, the threat moves out of that list, so querying by that ID returns nothing even though the historical record may still exist elsewhere.

Why this answer

Get-MpThreat returns only currently active (unremediated) threats detected by Microsoft Defender Antivirus. If a known threat ID returns no output, the most likely explanation is that the threat was already remediated and removed from the active threats list, so the cmdlet has nothing to return.

Exam trap

SC-200 often tests that Get-MpThreat only shows active threats — candidates assume empty output means the cmdlet failed or the ID was wrong, rather than the threat being remediated.

How to eliminate wrong answers

Option A is wrong because Get-MpThreat is a current, supported Defender PowerShell cmdlet and is not deprecated. Option B is wrong because an incorrect threat ID format would typically produce a parameter/format error rather than silent empty output, and the question states the ID is 'known.' Option D is wrong because Get-MpThreat can be run without elevation for read operations; lack of admin rights would produce an access-denied error, not empty output.

501
Multi-Selecteasy

Which TWO data connectors are available in Microsoft Sentinel to ingest data from Microsoft 365 services?

Select 2 answers
A.Azure Active Directory
B.Microsoft Defender for Cloud
C.Amazon Web Services
D.Microsoft Entra ID
E.Office 365
AnswersD, E

Microsoft Entra ID is a correct connector because it ingests sign-in logs (including interactive and non-interactive sign-ins) and audit logs from Azure AD into Microsoft Sentinel. This data is essential for identity-based threat detection and investigation, allowing analysts to trace authentication attempts and directory changes.

Why this answer

Microsoft Entra ID (formerly Azure Active Directory) is a correct data connector because it ingests sign-in logs, audit logs, and provisioning events from Microsoft's identity service into Microsoft Sentinel. This connector uses the Microsoft Graph API to pull identity-related telemetry, which is essential for monitoring authentication anomalies and privilege escalation.

Exam trap

The trap here is that candidates confuse the legacy name 'Azure Active Directory' with the current product name 'Microsoft Entra ID', and may also mistakenly think Microsoft Defender for Cloud is a data source for M365 services rather than a security solution for cloud workloads.

502
MCQmedium

You are using Microsoft Sentinel to manage incidents. You want to automatically close incidents that are older than 90 days and have a status of 'New'. What is the most efficient way to achieve this?

A.Create a workbook that shows old incidents and manually close them.
B.Create a playbook that runs on a schedule (e.g., daily) and closes incidents that meet the criteria.
C.Modify the analytics rule to automatically close incidents after 90 days.
D.Create an automation rule that triggers on incident update and closes the incident if the created time is older than 90 days.
AnswerB

A scheduled playbook uses a recurrence trigger to query Microsoft Sentinel for incidents older than 90 days with status New, then closes them automatically. This satisfies the bulk-closure requirement without manual triage, unlike automation rules, which trigger on incident creation rather than elapsed age.

Why this answer

A scheduled playbook is the most efficient way to automatically close stale incidents because Microsoft Sentinel playbooks (Logic Apps) support recurrence triggers that can query the Sentinel incidents API on a schedule, filter by status 'New' and createdTime older than 90 days, and close them in bulk. This is a native, low-code automation path that doesn't require manual intervention or modifying detection logic.

Exam trap

SC-200 often tests the distinction between automation rules (event-triggered) and playbooks (which can be schedule-triggered) — candidates incorrectly assume automation rules can handle time-based conditions.

How to eliminate wrong answers

Option A is wrong because a workbook is only a visualization/reporting surface — it cannot close incidents and requires manual action, defeating the 'automatically' requirement. Option C is wrong because analytics rules generate incidents; they have no built-in 'auto-close after N days' setting, and modifying them would affect detection, not lifecycle management. Option D is wrong because automation rules trigger on incident creation/update events, not on a time schedule — an incident that simply ages past 90 days without any update will never fire the rule, so stale incidents would remain open.

503
MCQmedium

Refer to the exhibit. A security analyst runs this PowerShell script to query a Log Analytics workspace. What is the purpose of this query?

A.Count the number of unique devices
B.Identify all PowerShell executions in the last 7 days
C.List all processes run by a specific account
D.Detect suspicious PowerShell activity using encoded commands
E.Find devices that have not run PowerShell recently
AnswerD

This option is correct because the query explicitly examines command-line arguments for the '-EncodedCommand' parameter, which is a well-known PowerShell feature that attackers abuse to obfuscate malicious scripts. When an encoded command is present, the actual script is a Base64-encoded string, making static detection more difficult and justifying a suspicion review. Security analysts use such queries in advanced hunting to surface potentially hidden or obfuscated PowerShell activity.

Why this answer

The PowerShell script uses the `| where {$_ -match 'powershell.*-enc'} ` filter to search for command lines containing 'powershell' followed by '-enc', which is the alias for the `-EncodedCommand` parameter. This parameter is commonly used by attackers to obfuscate malicious PowerShell commands by passing them as a Base64-encoded string. The query is specifically designed to detect suspicious PowerShell executions that use encoded commands, making option D correct.

Exam trap

The SC-200 exam often tests the ability to recognize that the `-enc` parameter is a shorthand for `-EncodedCommand`, which is a key indicator of obfuscated PowerShell execution, and candidates may mistakenly think the query simply lists all PowerShell executions (option B) without noticing the specific filter.

How to eliminate wrong answers

Option A is wrong because the query does not include any `distinct` or `summarize` operators to count unique devices; it simply retrieves events without aggregation. Option B is wrong because the query filters for events where the command line matches 'powershell.*-enc', which is a subset of all PowerShell executions, not all PowerShell executions in the last 7 days. Option C is wrong because the query does not filter by a specific account; it searches across all accounts for the encoded command pattern.

Option E is wrong because the query looks for devices that have run PowerShell with encoded commands, not for devices that have not run PowerShell recently.

504
MCQeasy

A security administrator needs to view a list of all virtual machines that have a missing critical security update. Which Microsoft Defender for Cloud dashboard should they use?

A.Secure Score
B.Regulatory Compliance
C.Inventory
D.Recommendations
AnswerD

In Microsoft Defender for Cloud, the Recommendations blade aggregates all security assessments, including the built-in recommendation 'System updates should be installed on your machines' (assessment key 4ab39e73-6c9d-4c5e-a9e7-5f2f2b3b3b3b). This assessment evaluates each virtual machine for missing critical or security updates and lists the affected resources with their patch status directly in the recommendation's 'Affected resources' tab. Therefore, this is the correct place to view all VMs missing critical updates.

Why this answer

The Recommendations dashboard in Microsoft Defender for Cloud provides a prioritized list of security recommendations, including missing critical security updates for virtual machines. This dashboard aggregates findings from vulnerability assessments and update management, allowing administrators to identify and remediate specific missing patches across their VM fleet.

Exam trap

The trap here is that candidates confuse the Inventory dashboard (which lists all resources) with the Recommendations dashboard (which provides actionable security findings), leading them to select Inventory instead of the correct Recommendations option.

How to eliminate wrong answers

Option A is wrong because Secure Score measures overall security posture based on compliance with recommendations, but does not directly list VMs with missing updates. Option B is wrong because Regulatory Compliance focuses on adherence to compliance standards (e.g., ISO 27001, NIST) and does not surface specific missing security updates. Option C is wrong because Inventory provides a list of all resources (including VMs) but lacks the filtering and recommendation context needed to identify missing critical updates.

505
Multi-Selectmedium

Which TWO actions are appropriate when responding to a confirmed malware outbreak on multiple workstations identified by Microsoft Defender for Endpoint?

Select 2 answers
A.Collect investigation packages from the affected devices for analysis.
B.Add the malware hash to the custom threat indicator list.
C.Run a full antivirus scan on all workstations.
D.Reset passwords of all users who logged into the affected devices.
E.Isolate the affected devices from the network using Microsoft Defender for Endpoint.
AnswersA, E

Collecting investigation packages from affected devices is appropriate because it captures volatile forensic artifacts—such as running processes, active network connections, registry keys, and loaded drivers—in their current live state. This package enables analysts to identify Indicators of Compromise (IOCs), the initial access vector, and the full lateral movement scope without altering or destroying evidence. It is a non-disruptive collection action that complements containment, ensuring the investigation has the data needed to understand the outbreak before any cleanup begins.

Why this answer

Collecting investigation packages and isolating affected devices are appropriate response actions. Running a full scan is reactive and not immediate. Resetting passwords may be needed later but not first.

Blocking indicators is proactive but doesn't contain already infected devices.

506
MCQmedium

During a threat hunt in Microsoft Sentinel, you find a query that returns a high number of false positives. Which action should you take to refine the hunt?

A.Increase the query time range to gather more data
B.Create a scheduled alert rule based on the query
C.Remove columns from the result set to simplify analysis
D.Add additional filters to the query to exclude known benign activity
AnswerD

Adding filters that exclude known benign activity narrows the result set, directly reducing the false positives the hunt query returns. This refines the analytic without disabling it, satisfying the requirement to tune detection logic so genuine threats remain visible while routine noise is suppressed.

Why this answer

Adding filters to exclude known benign activity directly reduces false positives by narrowing the result set to only suspicious events. In Microsoft Sentinel, KQL queries are refined iteratively during threat hunts, and excluding known-good indicators (e.g., service accounts, approved IP ranges, signed binaries) is the standard tuning technique. This preserves the hunt's detection intent while improving signal-to-noise ratio.

Exam trap

SC-200 often tests the misconception that more data or more alerting equals better hunting — candidates pick 'increase time range' or 'create an alert rule' when the real fix is query-level tuning to suppress benign activity.

How to eliminate wrong answers

Option A is wrong because increasing the query time range returns even more data and typically amplifies false positives rather than reducing them. Option B is wrong because creating a scheduled alert rule from a noisy query would generate alert fatigue and is premature before tuning — analytics rules should be built only after the query is validated. Option C is wrong because removing columns only changes the display of results; it does not affect which rows match, so false positives remain in the result set.

507
Multi-Selectmedium

Which TWO data sources are essential for threat hunting in Microsoft Sentinel to detect lateral movement?

Select 2 answers
A.Microsoft Entra ID sign-in logs
B.DeviceNetworkEvents (Microsoft Defender for Endpoint)
C.SecurityEvent (Windows Event Logs)
D.CommonSecurityLog (Syslog)
E.DnsEvents
AnswersB, C

DeviceNetworkEvents is the workflow's core because it reveals each process's outbound and inbound network connections, including remote IP, remote port, protocol, and the initiating process image. Lateral movement requires a connection to another host via protocols like SMB (445), RDP (3389), or WinRM (5985), so hunting can simply look for unusual or repetitive connection patterns from a compromised host to internal addresses. This table also lets you join to process creation events, making it indispensable for reconstructing the full attack chain between systems.

Why this answer

DeviceNetworkEvents (Microsoft Defender for Endpoint) provides network connections between devices, which can reveal lateral movement attempts. SecurityEvent (Windows Event Logs) provides security-related events such as remote logons (Event ID 4624) and service creation (Event ID 7045), which are key indicators of lateral movement. Option A (Microsoft Entra ID sign-in logs) focuses on cloud identity and is not directly relevant for on-premises lateral movement.

Option D (CommonSecurityLog) typically comes from network perimeter devices and is not essential for internal lateral movement. Option E (DnsEvents) can provide insight into DNS queries but is less essential than the other two data sources for detecting lateral movement.

508
Multi-Selecthard

Your SOC is implementing a Microsoft Sentinel workspace with multiple content hub solutions. You need to ensure that only approved analytics rules are enabled and that any custom rules are reviewed before activation. Which THREE actions should you take?

Select 3 answers
A.Configure Threat Intelligence - Taxii connector to import rules from an external feed.
B.Use the Hunting blade to create custom hunting queries instead of analytics rules.
C.Use Microsoft Sentinel Repositories (CI/CD) to manage analytics rules via Azure DevOps or GitHub.
D.In Content hub, install only the solutions that contain approved analytics rules.
E.Create an automation rule that disables any newly created analytics rule that is not in an approved list.
AnswersC, D, E

Microsoft Sentinel Repositories (CI/CD) enables you to manage analytics rules as code in Azure DevOps or GitHub, with content deployed via ARM templates or Bicep. This enforces a formal approval workflow through pull requests and branch policies before any rule reaches the workspace, ensuring only reviewed and approved rules are deployed. It also provides version control and rollback capabilities, making it the most robust governance approach for rule lifecycle management.

Why this answer

Option C is correct because Microsoft Sentinel Repositories enable CI/CD-based deployment of analytics rules from Azure DevOps or GitHub, so every rule change goes through a pull request and review before activation, enforcing the approval workflow. Option D is correct because installing only Content hub solutions that contain approved analytics rules ensures that only vetted, Microsoft-published or approved rule templates are deployed into the workspace, preventing unapproved content from being enabled. Option E is correct because an automation rule triggered on analytics rule creation can immediately disable any rule not present in the approved list, providing a runtime guardrail that catches rules created outside the governed pipeline.

Option A is not correct because the Threat Intelligence - TAXII connector imports threat indicators, not analytics rules, so it does not govern rule enablement. Option B is not correct because hunting queries are separate from analytics rules and do not satisfy the requirement to control which analytics rules are enabled or reviewed.

Exam trap

The trap here is that candidates may confuse the purpose of the Threat Intelligence - TAXII connector (which imports threat indicators, not rules) or think that the Hunting blade can serve as a governance mechanism for analytics rules, when in fact it is only for ad-hoc threat hunting.

509
Multi-Selectmedium

Which TWO actions are valid ways to reduce the number of false positive incidents in Microsoft Sentinel without disabling analytics rules?

Select 2 answers
A.Configure the rule to group all alerts into a single incident per entity.
B.Increase the rule run frequency.
C.Change the incident severity to Informational.
D.Modify the rule's query to include additional filters.
E.Create an automation rule to close incidents that match certain criteria.
AnswersD, E

Modifying the rule's query to include additional filters, such as excluding known-safe IP addresses or requiring specific event attributes, directly increases precision by removing benign activity from the detection logic. This addresses the root cause of false positives because the KQL query is the decision engine that determines which raw events become alerts. Properly scoped filters reduce incident volume while preserving genuine threat detection.

Why this answer

Modifying the rule's query to include additional filters directly reduces false positives by narrowing the conditions that trigger an alert. This approach refines the detection logic without disabling the rule, ensuring only events that more precisely match the intended threat pattern generate incidents.

Exam trap

The trap here is that candidates confuse reducing incident volume (via grouping or severity changes) with reducing false positives, but only query modifications or automation rules that close specific false incidents actually address the root cause of inaccurate detections.

510
Matchingmedium

Match each Microsoft Sentinel data connector to its data source.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Subscription-level events from Azure Resource Manager

Sign-in logs and audit logs from Azure Active Directory

Security events from Windows machines

Events from Linux and network devices

Exchange Online and SharePoint Online logs

Why these pairings

Correct matches: Azure Activity → subscription logs, Office 365 → Exchange/SharePoint/Teams, Azure AD → sign-in/audit logs, AWS CloudTrail → API calls. Common confusions include swapping Azure Activity with Azure AD logs, and Office 365 with Azure subscription logs.

511
Multi-Selecthard

Which TWO features in Microsoft Sentinel can help reduce alert fatigue by grouping related alerts into incidents? (Select two.)

Select 2 answers
A.Incident merging
B.Entity behavior analytics
C.Automation rules that run playbooks
D.Analytics rules that create incidents
E.Threat intelligence indicators
AnswersA, D

Incident merging in Microsoft Sentinel combines multiple incidents that are part of the same attack campaign or share entities into a single incident. This directly reduces the number of incidents analysts must triage, lowering mean time to respond and preventing alert fatigue. By minimizing the chance that a critical alert is lost in a queue, it reduces the financial impact of a successful breach, thus lowering annualized loss expectancy.

Why this answer

Incident merging (Option A) is correct because it automatically combines multiple alerts that share common entities (such as IP addresses, hostnames, or user accounts) into a single incident. This reduces alert fatigue by preventing security analysts from having to triage dozens of separate alerts that are all part of the same attack chain, allowing them to focus on a single, consolidated incident.

Exam trap

The trap here is that candidates often confuse 'automation rules' (which automate responses) with 'incident creation' (which groups alerts), or they mistakenly think entity behavior analytics or threat intelligence indicators perform the grouping function, when in fact only incident merging and analytics rules with incident creation settings can consolidate related alerts.

512
MCQmedium

Your organization is using Microsoft Defender for Cloud Apps to protect cloud applications. The security team wants to be alerted when a user shares a sensitive file with an external user. What should you configure?

A.Activity policy
B.App discovery policy
C.Anomaly detection policy
D.File policy
AnswerD

File policies are purpose-built in Defender for Cloud Apps to monitor and govern files stored in connected cloud apps such as SharePoint, OneDrive, Box, and Google Drive. They evaluate conditions on file metadata, sharing permissions, file name, and content inspection, and can trigger alerts or automatic actions like quarantine or revoking access. This allows you to create a policy that specifically detects files shared with external users, thereby directly addressing the requirement to monitor file sharing.

Why this answer

File policies in Microsoft Defender for Cloud Apps are specifically designed to monitor and respond to events involving files stored in connected cloud apps, such as when a sensitive file is shared with an external user. You can configure a file policy with a filter for 'External' sharing and apply a content inspection rule to detect sensitive information types, triggering an alert when the condition is met.

Exam trap

The trap here is that candidates confuse activity policies (which monitor user actions) with file policies (which monitor file attributes and sharing permissions), leading them to choose Option A when the question explicitly mentions 'shares a sensitive file'—a file-centric event requiring content and sharing context.

How to eliminate wrong answers

Option A is wrong because an activity policy monitors user activities (e.g., login from unusual location, mass download) but does not natively inspect file content or sharing permissions for sensitivity. Option B is wrong because an app discovery policy analyzes traffic to identify shadow IT applications, not to monitor file sharing within already sanctioned cloud apps. Option C is wrong because an anomaly detection policy uses machine learning to detect unusual behavior patterns (e.g., impossible travel) but cannot enforce rules based on specific file sensitivity labels or external sharing status.

513
MCQmedium

A security operations team has Microsoft Defender for Cloud enabled on all subscriptions and wants to forward security alerts and recommendations to Microsoft Sentinel for analysis and automation. Which configuration should the team implement to enable this integration?

A.In Microsoft Sentinel, add the 'Microsoft Defender for Cloud' data connector and select the subscriptions to stream alerts and recommendations.
B.In Microsoft Defender for Cloud, create a continuous export to a Log Analytics workspace that is already connected to Sentinel.
C.Create an Azure Policy that deploys Azure Monitor Agent to all VMs and configures data collection rules to send data to Sentinel.
D.Enable the 'Enable integration with Microsoft Sentinel' option in the Defender for Cloud pricing & settings blade.
AnswerA

The Microsoft Defender for Cloud data connector in Microsoft Sentinel is the native integration path for streaming cloud security alerts and recommendations. When you add this connector and select your subscriptions, Sentinel automatically ingests the data into the SecurityAlert and SecurityRecommendation tables using the correct schema and entity mapping. This creates a direct, managed pipeline that allows the SOC to triage and respond to Defender for Cloud findings as Sentinel incidents without any additional configuration.

Why this answer

The 'Microsoft Defender for Cloud' data connector in Microsoft Sentinel is the native integration point that allows you to stream security alerts and recommendations from Defender for Cloud into Sentinel. By adding this connector and selecting the subscriptions, you enable a direct, bi-directional connection that ingests Defender for Cloud data into Sentinel's Log Analytics workspace for analysis and automation.

Exam trap

The trap here is that candidates confuse the direction of integration, thinking they must configure it from Defender for Cloud (Option D) or use continuous export (Option B), when in fact the integration is initiated from Microsoft Sentinel by adding the data connector.

How to eliminate wrong answers

Option B is wrong because continuous export in Defender for Cloud exports data to a Log Analytics workspace, but it does not automatically connect to Sentinel; you must still use the Sentinel data connector to ingest that data. Option C is wrong because Azure Policy deploying Azure Monitor Agent to VMs and configuring data collection rules sends VM-level telemetry, not Defender for Cloud security alerts and recommendations. Option D is wrong because the 'Enable integration with Microsoft Sentinel' option in Defender for Cloud's pricing & settings blade does not exist; the integration is configured from within Sentinel, not Defender for Cloud.

514
MCQmedium

Refer to the exhibit. You are investigating a user entity in Microsoft Sentinel. The entity details show a riskLevel of 'high' and riskState 'atRisk'. What does this indicate?

A.The user account has been disabled
B.The user account triggered a Sentinel analytics rule
C.The user account has been flagged by Microsoft Entra ID Protection as at risk
D.The user account has been confirmed compromised
AnswerC

The exhibit exposes riskLevel and riskState, which are populated by Microsoft Entra ID Protection when a user's risk score exceeds a threshold. These fields indicate that the identity has been flagged as at risk due to suspicious activity, such as atypical travel or leaked credentials. This is an automated risk assessment from Entra ID Protection, not a manual determination or a Sentinel analytics detection.

Why this answer

The riskLevel of 'high' and riskState of 'atRisk' are specific properties populated by Microsoft Entra ID Protection (formerly Azure AD Identity Protection). These values indicate that the user account has been flagged as risky based on real-time risk detections (e.g., leaked credentials, anonymous IP address, atypical travel). This is not a direct result of a Sentinel analytics rule, nor does it mean the account is disabled or confirmed compromised—it means the identity protection service has detected suspicious activity and assigned a risk level.

Exam trap

The trap here is that candidates often confuse the riskLevel and riskState fields from Microsoft Entra ID Protection with Sentinel analytics rule alerts, assuming any 'high risk' label must come from a detection rule, when in fact these fields are native identity protection properties that are enriched into the entity.

How to eliminate wrong answers

Option A is wrong because a disabled user account would show a different entity property (e.g., accountEnabled: false) and would not be reflected in the riskLevel or riskState fields, which are specific to identity risk detection. Option B is wrong because triggering a Sentinel analytics rule would generate an incident or alert, but the riskLevel and riskState fields on the user entity are populated by Microsoft Entra ID Protection, not by Sentinel analytics rules. Option D is wrong because a riskState of 'atRisk' indicates the account is suspected to be compromised but has not yet been confirmed; a confirmed compromise would show a riskState of 'confirmedCompromised'.

515
MCQeasy

Your organization uses Microsoft Sentinel. You need to ensure that an alert is created when a user accesses a sensitive SharePoint site from an unusual location. What should you create?

A.A watchlist
B.An analytics rule
C.A playbook
D.An automation rule
AnswerB

An analytics rule is the correct choice because Microsoft Sentinel uses analytics rules as its primary detection mechanism. A scheduled or Microsoft security analytics rule runs KQL queries on a recurring basis, evaluates results against thresholds or entity behavior, and can generate alerts and incidents for suspicious sign-in patterns or other anomalies, thereby satisfying the requirement to ensure detection and alerting.

Why this answer

An analytics rule in Microsoft Sentinel defines the conditions under which alerts are generated. To detect a user accessing a sensitive SharePoint site from an unusual location, you would create an analytics rule that queries the Office 365 activity logs (e.g., SharePoint operations) and uses the 'Unusual Geo-Location' anomaly detection or a custom KQL query comparing the user's location against a baseline of their typical access patterns. This rule will then generate an alert when the condition is met.

Exam trap

The trap here is that candidates often confuse the purpose of an analytics rule (alert creation) with automation rules (incident management) or playbooks (response actions), leading them to select a post-alert component instead of the rule that actually generates the alert.

How to eliminate wrong answers

Option A is wrong because a watchlist is a static collection of data (e.g., IP addresses or user accounts) used for correlation or enrichment in queries, not for generating alerts based on dynamic behavioral patterns like unusual location access. Option C is wrong because a playbook is an automated response workflow (based on Azure Logic Apps) triggered by an alert, not the mechanism that creates the alert itself. Option D is wrong because an automation rule manages the lifecycle of incidents (e.g., assigning, tagging, or closing) after an alert is generated, not the creation of the alert from raw log data.

516
MCQeasy

Your organization uses Microsoft Purview Data Loss Prevention (DLP) policies. You need to investigate an incident where sensitive data was shared externally. You want to view the details in Microsoft Sentinel. What should you ensure is configured?

A.The Microsoft 365 data connector in Microsoft Sentinel is enabled and configured to collect DLP alerts.
B.The SharePoint site is configured for external sharing.
C.The DLP policy must be set to 'Audit only' mode.
D.The unified audit log is enabled and the DLP events are being generated.
AnswerA

This connector is the explicit, required data ingestion path between Microsoft Purview DLP and Microsoft Sentinel. It calls the Office 365 Management API to pull DLP alert records and writes them into the SecurityAlert table, which is what Sentinel analytics rules actually query. Without this connector enabled and configured, no DLP alert—regardless of policy mode or audit logging—will appear in Sentinel. Therefore, it is the only condition that directly determines whether DLP alerts are ingested.

Why this answer

Microsoft Sentinel's Microsoft 365 data connector ingests unified audit logs from Microsoft Purview, including DLP alerts. When this connector is enabled and configured to collect DLP alerts, Sentinel can receive and surface the incident details, allowing investigation of externally shared sensitive data. Without this connector, DLP events remain in the Purview compliance portal and are not forwarded to Sentinel.

Exam trap

The trap here is that candidates often assume enabling the unified audit log (Option D) is sufficient for Sentinel to receive DLP alerts, but they overlook that the Microsoft 365 data connector must be specifically configured to collect DLP events, as the connector acts as the bridge between the audit log and Sentinel.

How to eliminate wrong answers

Option B is wrong because configuring a SharePoint site for external sharing is a prerequisite for external sharing to occur, but it does not enable Sentinel to ingest DLP alert details; it is a separate configuration unrelated to data collection. Option C is wrong because setting the DLP policy to 'Audit only' mode means the policy will only log events without blocking or alerting, but it does not affect whether Sentinel can receive DLP alerts; the connector must still be configured. Option D is wrong because while the unified audit log must be enabled and DLP events generated for any DLP alert to exist, this alone does not ensure that Sentinel receives those events; the Microsoft 365 data connector must be explicitly enabled and configured to collect DLP alerts.

517
MCQhard

Refer to the exhibit. A custom detection rule in Microsoft Sentinel uses this JSON definition. An analyst notices that the rule is generating alerts for legitimate administrative scripts launched from File Explorer. What is the best way to reduce false positives while retaining detection of malicious Office-based PowerShell launches?

A.Add an additional filter to exclude PowerShell executions from specific administrative user accounts
B.Increase the query time range to 30 days
C.Change the severity to Informational to suppress alerts
D.Remove the parent process filter and rely only on FileName == 'powershell.exe'
AnswerA

Excluding known admin accounts helps reduce noise while keeping detection for other users.

Why this answer

Adding conditions to exclude known administrative scenarios (e.g., specific user accounts) reduces false positives without removing the parent process filter entirely. Option B is wrong because removing the parent process filter would broaden detection, likely increasing false positives. Option C is wrong because lowering severity does not reduce false positives.

Option D is wrong because increasing time range does not help.

518
MCQhard

Your organization uses Microsoft Defender XDR incident queue. You want to automatically assign incidents related to a specific campaign to a dedicated SOC group. What should you create?

A.A standard rule in Microsoft Defender for Endpoint.
B.An automation rule in Microsoft Sentinel.
C.A custom detection rule in Microsoft Defender XDR that includes an incident assignment action.
D.A custom role in Microsoft Defender XDR.
AnswerC

A custom detection rule in Microsoft Defender XDR is the correct mechanism because it allows you to define a KQL-based query and, in the rule configuration, specify an incident assignment action. When the detection fires and generates an incident, that action automatically assigns the incident to a designated group (or in some cases an individual). This is the officially supported way to automate incident assignment in the Defender XDR incident queue, ensuring every generated incident has an owner from the outset.

Why this answer

Microsoft Defender XDR allows you to create custom detection rules that can include automated incident assignment actions. This enables you to automatically assign incidents related to a specific campaign to a dedicated SOC group directly within the Defender XDR incident queue, without relying on external tools or manual processes.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR's custom detection rules with Microsoft Sentinel's automation rules, but the question explicitly references the Defender XDR incident queue, not Sentinel.

How to eliminate wrong answers

Option A is wrong because standard rules in Microsoft Defender for Endpoint are used for alert suppression or tuning, not for incident assignment actions. Option B is wrong because automation rules in Microsoft Sentinel are designed for Azure Sentinel incidents, not for the Microsoft Defender XDR incident queue. Option D is wrong because custom roles in Microsoft Defender XDR control permissions and access, not automated incident assignment logic.

519
MCQeasy

Your organization uses Microsoft Sentinel. A security analyst reports a high number of false positives from a scheduled analytics rule that detects anomalous sign-ins. The rule uses the 'UserAgent' field in the SigninLogs table. What is the best practice to reduce false positives while maintaining detection coverage?

A.Increase the alert threshold to require more than one anomalous sign-in per hour.
B.Create a watchlist of legitimate IP addresses and reference it in the rule.
C.Disable the analytics rule and create a new one with different MITRE tactics.
D.Add a condition to the rule query to filter out known legitimate user agents.
AnswerD

Adding a condition to the rule query to filter out known legitimate user agents is the targeted fix because it directly removes the benign UserAgent strings from the anomaly-detection scope. In KQL, you can implement this with a `where UserAgent notin (~['LegitAgent1', 'LegitAgent2'])` clause or a regex pattern like `where UserAgent !matches regex @"(Chrome/120\.0|Edge/120\.0)"`, preserving the rule's ability to detect truly anomalous strings. This approach reduces false positives while maintaining full detection fidelity for other anomalous sign-in attributes such as geographic location, device compliance, or risk score, aligning with Sentinel best practices for rule tuning.

Why this answer

The high number of false positives is caused by legitimate user agents triggering the anomaly detection. By adding a condition to the KQL query that filters out known legitimate user agents (e.g., 'Mozilla/5.0' for standard browsers), you reduce noise without losing detection of truly anomalous sign-ins. This preserves the rule's coverage for unknown or malicious user agents while eliminating predictable false positives.

Exam trap

The trap here is that candidates may confuse the source of false positives (UserAgent field) with other common mitigation techniques like IP whitelisting (Option B) or threshold tuning (Option A), failing to realize that the most precise fix is to filter the specific noisy field directly in the query.

How to eliminate wrong answers

Option A is wrong because increasing the alert threshold to require more than one anomalous sign-in per hour would reduce sensitivity and could miss single, high-risk anomalous sign-ins, thus reducing detection coverage. Option B is wrong because creating a watchlist of legitimate IP addresses and referencing it in the rule addresses false positives from IP-based anomalies, not from the UserAgent field; the issue is specifically with user agents, not IP addresses. Option C is wrong because disabling the rule and creating a new one with different MITRE tactics does not address the root cause of false positives from the UserAgent field; it would lose existing detection logic and potentially introduce new gaps.

520
MCQmedium

An organization wants to enable vulnerability assessment for all Azure virtual machines, including future ones, using the integrated Qualys or Microsoft Defender Vulnerability Management solution. What is the recommended approach in Microsoft Defender for Cloud?

A.Enable the Defender for Servers plan and configure auto-provisioning of the vulnerability assessment solution.
B.Manually install the Log Analytics agent and then configure vulnerability assessment on each VM.
C.Use Azure Policy to assign the built-in initiative that deploys the vulnerability assessment solution and associates it with VMs.
D.Enable Azure Security Center's free tier and manually download the vulnerability assessment tool.
AnswerA

Enabling Defender for Servers activates the integrated vulnerability assessment capability (Microsoft Defender Vulnerability Management) and configuring auto-provisioning ensures the VA solution is automatically installed on all existing and future Azure VMs. This eliminates manual per-VM setup and provides continuous, centralized vulnerability findings in Defender for Cloud. It is the recommended, fully supported path for environment-wide coverage.

Why this answer

The recommended approach is to enable the Defender for Servers plan, which automatically provisions the integrated vulnerability assessment solution (Qualys or Microsoft Defender Vulnerability Management) on all existing and future Azure VMs. This ensures continuous scanning without manual intervention, leveraging auto-provisioning to deploy the necessary extension.

Exam trap

The trap here is that candidates often confuse Azure Policy with the primary deployment mechanism, but the correct approach requires enabling the Defender for Servers plan first, as the policy initiative is dependent on that plan being active.

How to eliminate wrong answers

Option B is wrong because manually installing the Log Analytics agent and configuring vulnerability assessment on each VM is not scalable and does not leverage the automated, integrated solution provided by Defender for Cloud. Option C is wrong because while Azure Policy can enforce compliance, the built-in initiative for vulnerability assessment requires the Defender for Servers plan to be enabled first; it is not a standalone deployment method. Option D is wrong because the free tier of Azure Security Center does not include vulnerability assessment capabilities; it only provides basic security recommendations without the integrated scanning solution.

521
MCQeasy

You are hunting for suspicious scheduled tasks that could be used for persistence. Which Microsoft 365 Defender advanced hunting table contains information about scheduled tasks?

A.IdentityLogonEvents
B.DeviceEvents
C.DeviceNetworkEvents
D.DeviceProcessEvents
AnswerB

DeviceEvents is the correct table because it contains a wide range of Windows security events, including Event ID 4698 which is specifically the creation of a scheduled task. This table ingests events from the Windows Event Log and is the primary place to hunt for persistence mechanisms like new scheduled tasks. You can also find related events like task updates (4702) and deletions (4699) here. So for identifying suspicious scheduled task creation, DeviceEvents is the authoritative source.

Why this answer

DeviceEvents in Microsoft 365 Defender advanced hunting is the correct table because it captures a wide range of system and security events, including scheduled task creation, modification, and deletion. Specifically, it logs events like 'ScheduledTaskCreated' and 'ScheduledTaskModified' under the ActionType column, which are essential for detecting persistence mechanisms. Other tables focus on different telemetry: IdentityLogonEvents for authentication, DeviceNetworkEvents for network connections, and DeviceProcessEvents for process creation.

Thus, DeviceEvents is the only table that directly contains scheduled task information.

Exam trap

SC-200 often tests the distinction between process execution and system event logging, causing candidates to mistakenly choose DeviceProcessEvents when asked about scheduled task creation, even though the actual task registration is recorded in DeviceEvents.

How to eliminate wrong answers

Option A is wrong because IdentityLogonEvents records logon and authentication events (e.g., interactive, network, and remote interactive logons) in Azure AD and on-premises systems, not scheduled task activities. Option C is wrong because DeviceNetworkEvents captures network connection events such as TCP/UDP traffic, DNS queries, and HTTP requests, not file system or task scheduler changes. Option D is wrong because DeviceProcessEvents logs process creation and termination events (e.g., ProcessCreate, ProcessTerminate), which may include the execution of schtasks.exe but does not contain the actual scheduled task creation or modification events themselves.

522
MCQmedium

A security team uses Microsoft Defender for Cloud with Defender for Servers enabled. They want to receive an alert whenever a new local user is added to the Administrators group on any Azure Windows virtual machine. Which data source must be configured in Defender for Cloud to capture this event?

A.Windows Security Events (Event ID 4732)
B.Windows Defender Antivirus logs
C.Azure Activity Logs
D.VM Insights
AnswerA

Event 4732 is generated by the Windows security audit policy whenever a user or group is added to a security-enabled local group, such as the Administrators group. Defender for Cloud collects Windows Security Events through the Log Analytics agent or Azure Monitor Agent, allowing custom alerts or the built-in 'Security event log' Analytics rule to detect these membership changes. This is the correct data source because it directly captures the OS-level audit trail of local group modification.

Why this answer

The addition of a user to the Administrators group on a Windows system generates Windows Security Event ID 4732. Defender for Cloud with Defender for Servers must have the 'Windows Security Events' data source configured to collect these audit events, which then triggers a security alert for the new local administrator.

Exam trap

The trap here is that candidates often confuse Azure Activity Logs (control-plane) with guest OS security events, assuming any Azure-level log will capture local user changes, but only the Windows Security Events data source collects the necessary Event ID 4732 from within the VM.

How to eliminate wrong answers

Option B is wrong because Windows Defender Antivirus logs contain malware detection and protection events, not user or group membership changes. Option C is wrong because Azure Activity Logs record control-plane operations on Azure resources (e.g., VM creation or deletion), not guest OS-level events like local group modifications. Option D is wrong because VM Insights collects performance metrics, process inventory, and network connections via the Log Analytics agent, but it does not natively capture Windows Security Event ID 4732 unless the Windows Security Events data source is explicitly configured.

523
MCQeasy

You are hunting for possible data exfiltration via email in Microsoft 365. Which data source in Microsoft Sentinel provides the most relevant telemetry for email forwarding rules?

A.Microsoft Defender for Cloud Apps logs
B.Windows Security Events
C.Azure AD sign-in logs
D.Office 365 audit logs (Exchange)
AnswerD

Office 365 audit logs, specifically the Exchange workload, are the authoritative source because they capture changes to mailbox forwarding and inbox rules. Operations like Set-Mailbox, which includes modifications to ForwardingSmtpAddress, and New-InboxRule or Set-InboxRule with RedirectTo are logged with the actor's UPN, the exact timestamp, and the target mailbox. These events are accessible via the Microsoft Purview compliance portal or the Search-UnifiedAuditLog cmdlet, making them the definitive evidence for a data exfiltration via email investigation.

Why this answer

Office 365 audit logs (Exchange) capture mailbox-level activity including the New-InboxRule, Set-InboxRule, and Set-Mailbox operations that create or modify forwarding rules (ForwardTo, RedirectTo, ForwardAsAttachmentTo). This is the authoritative telemetry source for detecting email-based exfiltration via auto-forwarding in Microsoft 365. Defender for Cloud Apps can surface anomalies but relies on the same underlying audit stream, making the native Office 365 audit log the most direct and complete source.

Exam trap

SC-200 often tests whether candidates confuse CASB-level anomaly detection (Defender for Cloud Apps) with the raw audit telemetry that actually records the malicious configuration change — the audit log is the source of truth, not the analytics layer.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps provides CASB-style anomaly detection and app governance signals but does not itself contain the raw Exchange mailbox rule creation events — it consumes them from the Office 365 audit pipeline. Option B is wrong because Windows Security Events cover on-premises host authentication, process, and object access activity (4624, 4688, 4663) and have no visibility into Exchange Online mailbox rules. Option C is wrong because Azure AD sign-in logs record authentication events (interactive and non-interactive sign-ins, conditional access results) and do not capture mailbox configuration changes such as forwarding rules.

524
MCQeasy

You need to grant a junior analyst the ability to view and investigate incidents in Microsoft Sentinel, but not make any changes. Which built-in role should you assign?

A.Microsoft Sentinel Responder
B.Microsoft Sentinel Contributor
C.Microsoft Sentinel Automation Contributor
D.Microsoft Sentinel Reader
AnswerD

Microsoft Sentinel Reader is the correct role because it grants read-only access to all Sentinel resources, including incidents, workbooks, hunting queries, and analytics rule templates. This allows the junior analyst to view and investigate security data without any risk of accidental modification, aligning perfectly with the principle of least privilege.

Why this answer

The Microsoft Sentinel Reader role provides read-only access to Sentinel resources, including incidents, workbooks, and analytics rules, without allowing any modifications. This aligns with the requirement to view and investigate incidents without making changes, as the role explicitly denies write, delete, or action permissions on Sentinel data.

Exam trap

The trap here is that candidates often confuse 'view and investigate' with the ability to update incident status or run playbooks, leading them to choose the Responder role, which actually allows changes.

How to eliminate wrong answers

Option A is wrong because the Microsoft Sentinel Responder role allows updating incidents (e.g., changing status, assigning ownership) and running playbooks, which includes making changes, not just viewing. Option B is wrong because the Microsoft Sentinel Contributor role grants full write access to Sentinel resources, including creating and modifying incidents, analytics rules, and automation rules, which exceeds the read-only requirement. Option C is wrong because the Microsoft Sentinel Automation Contributor role is specifically designed to manage automation rules and playbooks, not for viewing or investigating incidents, and it includes write permissions to automation components.

525
Multi-Selectmedium

Which TWO actions can be performed using automation rules in Microsoft Sentinel?

Select 2 answers
A.Run a playbook
B.Assign an incident to an owner
C.Create an incident
D.Modify an analytics rule
E.Delete an incident
AnswersA, B

Automation rules include a built-in 'Run playbook' action that invokes a Microsoft Sentinel playbook (an Azure Logic Apps workflow) automatically whenever the rule's trigger conditions are met, such as on incident creation or status change. This action allows security analysts to chain SOAR actions—like threat intelligence enrichment, quarantine, or email notification—directly from the incident workflow without manual intervention. The playbook must be registered with the incident trigger to appear in the automation rule.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook as an action when an incident is created or updated. Playbooks are automated workflows based on Azure Logic Apps, allowing for complex response actions such as threat containment, notification, or enrichment. This enables security teams to automate incident response without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rules, mistakenly thinking automation rules can create or modify analytics rules, when in fact automation rules only react to incidents and perform actions like assignment or playbook execution.

Page 6

Page 7 of 18

Page 8