Courseiva

SC-200 · domain

Respond to security incidents

This domain covers responding to security incidents using Microsoft Sentinel, Defender XDR, and related tools. It tests your ability to triage, investigate, contain, and remediate threats. You must know how to use incident management, automation rules, playbooks, and advanced hunting to resolve attacks like phishing, ransomware, and data exfiltration.

375 questions108 easy137 medium130 hard

Focused practice

Practice Respond to security incidents questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Respond to security incidents

You must be able to triage and remediate incidents using Microsoft Sentinel and Defender XDR. The most important thing is to correctly use automation rules and playbooks to contain threats without disrupting legitimate business operations.

Manage incidents in Microsoft 365 Defender and Microsoft Sentinel, including assignment, status, and classification.

Use advanced hunting with KQL to investigate incidents and identify affected entities.

Configure automation rules and playbooks to automate response actions like isolating devices or blocking users.

Perform remediation actions such as soft-deleting malicious emails, isolating endpoints, or revoking user sessions.

Watch out for

Common Respond to security incidents exam traps

  • ▸Confusing automation rules with playbooks: automation rules trigger playbooks but do not perform actions directly; playbooks contain the logic.
  • ▸Forgetting that Microsoft Sentinel incidents can include entities from multiple sources, requiring cross-workspace investigation.
  • ▸Assuming Defender for Office 365 automatically blocks all phishing emails; manual remediation may be needed for missed threats.

Question index

All Respond to security incidents questions (375)

Click any question to see the full explanation, or start a practice session above.

1

Your organization uses Microsoft Defender XDR. You receive an alert about a potentially unwanted application (PUA) being installed on a device. The PUA is not blocked by your current policy. You need to prevent future installations of this PUA without affecting other software. What should you do?

Easy
2

During a security incident response, you need to collect forensic evidence from a Windows 10 device that is suspected to be compromised. The device is not domain-joined and is located in a remote office. You have remote administrative access. Which Microsoft 365 tool should you use to acquire a memory dump of the device?

Easy
3

You are responding to a ransomware incident in Microsoft Defender XDR. You have identified that the malware encrypted files on several devices and then deleted the volume shadow copies. Which of the following actions should you take first to contain the incident?

Medium
4

Which THREE are valid investigation actions in Microsoft Sentinel? (Select THREE.)

Medium
5

An analyst in your SOC receives a Microsoft Defender for Cloud Apps alert indicating a suspicious Power Automate flow that is forwarding emails to an external domain. The analyst needs to disable the flow immediately. Which action should they take?

Easy
6

A SOC analyst is triaging an incident in Microsoft Sentinel and needs to assign it to a senior analyst for further investigation. What is the correct action?

Easy
7

A security analyst in Microsoft Sentinel receives an incident with a high severity alert from Microsoft Defender for Identity. The incident description mentions a suspected lateral movement pass-the-hash attack. What should the analyst do first?

Easy
8

You are a SOC analyst using Microsoft Defender for Endpoint. A device is flagged as compromised and you need to isolate it from the network while still allowing you to remotely investigate it. Which action should you take?

Medium
9

A Microsoft Defender for Endpoint alert indicates that a device has been communicating with a known command-and-control (C2) server. The device is critical for production. What is the most appropriate response?

Medium
10

An organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident is created when a user is detected as compromised. The incident severity is set to High. The SOC manager wants to ensure that all incidents with severity High or above are automatically assigned to the senior analyst tier. What should the analyst configure?

Medium
11

Your organization has Microsoft Sentinel and Microsoft Defender for Identity deployed. An incident is created for a user whose account was used to access a sensitive database from an unusual workstation. The user is a member of the 'Database Admins' group. The security team needs to prevent further unauthorized access and preserve evidence. What should you do first?

Hard
12

An organization uses Microsoft Sentinel for security operations. A security engineer needs to automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel. Which feature should the engineer use?

Easy
13

Your organization uses Microsoft Sentinel with Microsoft Defender XDR integrated. A critical incident has been raised involving a user account that was used to access a confidential SharePoint site from an unusual location at 2:00 AM. The incident includes alerts from Microsoft Defender for Cloud Apps, Microsoft Defender for Identity, and Microsoft Defender for Office 365. The analyst needs to contain the incident, investigate the scope, and begin remediation. The environment has the following: Microsoft Entra ID with conditional access policies, Microsoft Intune for device management, and Microsoft Defender for Endpoint on all devices. The analyst has identified the user account and the device used. Which course of action should the analyst take first?

Medium
14

Which TWO Microsoft Defender XDR entities can be managed during incident response?

Easy
15

A SOC analyst is using Microsoft Sentinel to respond to an incident involving multiple compromised user accounts. The analyst needs to quickly see the timeline of all related events. Which feature should the analyst use?

Easy
16

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. You receive an alert indicating that a user from the finance department accessed a sensitive SharePoint file from an IP address associated with a known malicious Tor exit node. The file contains payment information. The user's account has not been disabled. What should you do first to contain the incident?

Medium
17

Which THREE actions are part of the containment phase in the Microsoft Incident Response process?

Hard
18

Your organization uses Microsoft Sentinel with a workspace in the East US region. You need to respond to an incident involving data exfiltration from a virtual machine in West Europe. The incident was created from a custom analytics rule that queries the AzureActivity table. What should you do to ensure the incident contains all relevant evidence from the West Europe region?

Medium
19

Your company uses Microsoft Sentinel and Microsoft Defender for Cloud Apps (MCAS). A security analyst detects that a user is accessing a sanctioned cloud app from an unusual location. The analyst creates an incident in Sentinel. You need to automatically apply a session policy in MCAS to block downloads from that user for the next hour. You have an existing playbook that can apply session policies. What is the most efficient way to automate this response?

Hard
20

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. During a security incident involving a compromised Azure VM, which THREE actions are appropriate to contain and investigate the incident?

Hard
21

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You receive an alert in MDE about a suspicious PowerShell command executed on a device. You create an incident in Sentinel from this alert. You need to automatically collect a memory dump from the affected device for further analysis. You have a playbook that can initiate a memory dump collection via the MDE API. What is the best way to automate this?

Medium
22

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. During an incident investigation, you find that a device is exfiltrating data to an external IP. You need to isolate the device from the network using automated response. Which action should you configure in an automation rule?

Hard
23

Your organization uses Microsoft Defender for Cloud Apps. During an incident, you discover that a user is downloading large amounts of data from SharePoint to an unmanaged device. You need to automatically block further downloads from that device. What should you configure?

Hard
24

A company uses Microsoft Defender XDR and has enabled automatic attack disruption for human-operated ransomware. During an incident, the system automatically contains a compromised account. However, the SOC team wants to ensure that the containment action is reversible and that the account can be restored after investigation. What should the team do before restoring the account?

Medium
25

Your organization uses Microsoft Sentinel. A security incident is created, and the assigned analyst needs to perform initial triage. What is the first step the analyst should take according to Microsoft best practices for incident response?

Easy
26

Your organization uses Microsoft Sentinel. You need to implement a custom incident response process that requires approval before taking action on an incident. What should you use?

Hard
27

Your organization uses Microsoft Sentinel. You are investigating an incident and need to gather additional context about a suspicious IP address. Which TWO Microsoft Sentinel features can you use to enrich the investigation?

Easy
28

A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request. What is the first step the analyst should take?

Easy
29

You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different workloads. You need to view all related alerts in a single timeline. What should you use?

Easy
30

You are a security analyst investigating a detected phishing campaign targeting users in your organization. The Microsoft Defender for Office 365 alert indicates that several users clicked on a malicious link. Which action should you take first to prevent further compromise?

Medium
31

Your organization uses Microsoft Defender for Office 365. You detect a phishing email that was delivered to a user's inbox. You want to remove the email from all recipients. What should you do?

Easy
32

Your organization uses Microsoft Defender for Identity and Microsoft Defender XDR. You receive an alert about a suspicious LDAP query originating from a domain controller. The alert indicates potential use of the DCSync attack technique. What is the most effective immediate action to contain the attack?

Hard
33

During a ransomware incident, security team needs to prevent encryption while preserving forensic data. Which action best achieves this balance?

Hard
34

Refer to the exhibit. A security analyst creates a scheduled analytics rule in Microsoft Sentinel based on the JSON shown. After enabling the rule, the analyst notices that the rule generates alerts every hour for the same user accounts even after the incidents are resolved. What is the most likely cause?

Hard
35

Your organization uses Microsoft Sentinel. A security incident is generated by a scheduled analytics rule. You need to automatically assign the incident to the SOC team and set its severity. What should you create?

Medium
36

Your organization uses Microsoft Sentinel and has enabled the Microsoft 365 Defender connector. You want to automatically assign incidents to a specific analyst team based on the incident severity and type. Which component should you configure?

Hard
37

You are investigating a Microsoft Defender XDR incident where a user's device is showing signs of compromise. The incident includes alerts from Microsoft Defender for Endpoint and Microsoft Defender for Identity. You need to isolate the device from the network while preserving forensic evidence. Which action should you take?

Hard
38

A Microsoft Defender XDR incident shows a malicious email delivered to a user, and the analyst confirms the message contains a credential-harvesting link. Before the user clicks, you need to remove the message from all mailboxes in the tenant and block the sender and URL for the future. Which Microsoft Defender for Office 365 capability should you use from the incident?

Easy
39

A security analyst is investigating a Microsoft Defender for Cloud Apps alert about a suspicious OAuth app that has high permissions. The analyst needs to disable the app immediately. What is the correct action?

Medium
40

An analyst is investigating a potential data exfiltration incident involving a user who accessed sensitive files from a personal device. The analyst wants to gather evidence about the device's compliance status and recent activity. Which Microsoft Intune feature should the analyst use?

Medium
41

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel during an investigation. The analyst expects to see alerts related to malware from IP 10.0.0.5 but receives no results. The SecurityAlert table contains data from the last 24 hours. What is the most likely reason for no results?

Easy
42

You are a SOC analyst using Microsoft Defender XDR. An incident named "Multi-stage intrusion on FIN-PC01" contains alerts for a malicious PowerShell script, a suspicious outbound connection to a known C2 IP, and credential dumping activity. You need to perform an investigation that automatically shows the full attack story, including related entities, alerts, and timeline, without manually correlating each alert. What should you use?

Medium
43

Which TWO actions are appropriate when handling a confirmed ransomware incident in Microsoft 365?

Medium
44

Which TWO actions should you take when responding to a confirmed ransomware incident in Microsoft Defender XDR?

Medium
45

Your Microsoft Sentinel workspace ingests logs from Microsoft Defender for Cloud and Microsoft 365 Defender. You need to create an incident response playbook that automatically responds to high-severity incidents. Which THREE components are required? (Choose three.)

Medium
46

A security analyst receives a high-severity alert for a suspicious login from an unusual location. The alert was generated by Microsoft Sentinel from Microsoft Entra ID sign-in logs. The analyst needs to determine if the login was successful and if any data exfiltration occurred. What is the MOST efficient first step?

Medium
47

During a security incident, you need to isolate a compromised Windows device from the network while allowing communication with Microsoft Defender for Endpoint services. Which Microsoft Defender for Endpoint action should you use?

Hard
48

Your organization uses Microsoft Sentinel. You have been asked to configure automated responses to security incidents. Which TWO of the following can be used to automate responses in Microsoft Sentinel?

Medium
49

You have a Microsoft Sentinel analytical rule with the above configuration. During a security incident, multiple high-severity alerts are generated within a 5-minute window. How does the rule handle these alerts?

Medium
50

Your organization uses Microsoft Sentinel. A security analyst reports that an incident was automatically created for a sign-in from an unfamiliar location, but after investigation, it was determined to be a false positive. You need to reduce similar false positives in the future without affecting legitimate detections. What should you do?

Medium
51

A SOC analyst is investigating an incident where a user's credentials were compromised. The analyst uses Microsoft Sentinel to find all activities performed by the user in the last 24 hours. Which data source should the analyst query FIRST to get the most comprehensive view of the user's actions across Microsoft 365?

Easy
52

Your organization uses Microsoft Sentinel. You receive an incident that involves a potential lateral movement detected by Microsoft Defender for Identity. You need to investigate the timeline of the attack. Which Microsoft Sentinel feature should you use?

Medium
53

An incident response playbook in Microsoft Sentinel has a step: 'Investigate the user's recent activities using Microsoft 365 Defender.' Which data source would provide the most relevant information for this step?

Easy
54

You are investigating a suspicious sign-in to a privileged account. You need to determine if the sign-in was from a known malicious IP address. Which Microsoft Sentinel data source should you query?

Easy
55

During a ransomware incident, the security team needs to prevent the encryption of files while allowing the investigation to continue. Which feature in Microsoft Defender for Endpoint should be used to achieve this?

Hard
56

Refer to the exhibit. You are reviewing an alert in Microsoft Defender for Endpoint. The alert details are shown. Which of the following actions should you take first?

Easy
57

A SOC analyst is reviewing an incident in Microsoft Sentinel that involves a user receiving a phishing email with a malicious attachment. The attachment was opened on a device managed by Microsoft Intune. Which Microsoft Defender XDR component would have provided the earliest detection of the malicious file?

Easy
58

A security operations center (SOC) analyst is investigating an incident involving a user who received a phishing email with a malicious macro. The analyst needs to determine if any other users received the same email. Which Microsoft 365 Defender feature should the analyst use?

Medium
59

A SOC analyst is using Microsoft Sentinel to investigate an incident involving a user who accessed a sensitive database from an unusual location. The analyst wants to find all activities performed by this user within the last 24 hours from multiple data sources. Which KQL operator should the analyst use to combine the results of two queries that return different schemas?

Hard
60

Your organization uses Microsoft Sentinel. You have configured a data connector to ingest events from a third-party firewall. However, you notice that the logs are not appearing in Sentinel. What is the first thing you should check?

Easy
61

During an incident, an analyst finds that a user's account was compromised and used to send spam. The analyst needs to revoke all active sessions for that user. What should the analyst do?

Medium
62

Your organization uses Microsoft Defender for Cloud Apps. A security investigator discovers that a user's session token was stolen and used to access sensitive data in SharePoint Online from an anomalous IP address. You need to immediately revoke the attacker's access while minimizing impact on the legitimate user. What should you do?

Hard
63

Which THREE resources can be used as data sources for Microsoft Sentinel to detect security incidents? (Choose three.)

Medium
64

During an incident response, you need to collect forensic evidence from a compromised Azure virtual machine that is currently offline. What is the most efficient method to acquire a disk snapshot for analysis while preserving the integrity of the evidence?

Hard
65

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident has been generated from Microsoft Defender for Cloud indicating that a Linux VM in Azure is running a cryptocurrency miner. The VM is part of a production application and cannot be shut down immediately. The incident severity is High. You need to contain the threat while maintaining application availability, investigate the root cause, and prevent recurrence. The environment includes Azure Policy, Microsoft Defender for Endpoint on the VM, and a Log Analytics workspace. You must minimize manual steps. What course of action should you take?

Hard
66

During an incident, you need to isolate a compromised device from the network while allowing communication with Microsoft Defender for Endpoint cloud services. Which isolation type should you choose in Microsoft Defender XDR?

Hard
67

Which THREE are valid methods to collect forensic evidence from a compromised Windows machine during incident response in Microsoft Defender XDR? (Choose three.)

Hard
68

A security analyst detects a suspicious sign-in from an unfamiliar IP address for a user with high privileges. The analyst wants to immediately contain the threat while preserving the user's ability to work with proper approvals. What is the most effective first step?

Medium
69

Your organization is using Microsoft Defender for Office 365. A user reports receiving a suspicious email that appears to be from the CEO requesting an urgent wire transfer. You need to investigate the email and take immediate action. What should you do first?

Easy
70

You are responding to a ransomware incident where multiple devices are encrypted. The incident is captured in Microsoft Sentinel. Which TWO actions should you take first to contain the incident?

Hard
71

You receive an alert in Microsoft Sentinel indicating a potential privilege escalation using the 'AzureHound' tool. You need to determine if the alert is a true positive. What is the first step you should take?

Easy
72

Your organization uses Microsoft Sentinel and has enabled UEBA (User and Entity Behavior Analytics). You notice a series of incidents involving anomalous logon times for a privileged user. You want to automate the response to disable the user's account in Microsoft Entra ID when such incidents are created. What should you configure?

Hard
73

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You suspect a compromised on-premises admin account that has been used to modify security groups. You want to quickly contain the threat. What should you do first?

Hard
74

Your organization uses Microsoft Sentinel. An incident is created from an Azure Active Directory (now Microsoft Entra ID) sign-in alert. You need to determine if the sign-in was from a compromised token. What data source should you examine?

Easy
75

Which TWO are valid incident classification categories in Microsoft Sentinel?

Easy
76

A SOC analyst receives a phishing alert in Microsoft Defender for Office 365. The analyst needs to quickly determine if any users clicked the malicious link. Which action should the analyst take first?

Easy
77

You are investigating a brute force attack on a user account in Microsoft Entra ID. The sign-in logs show multiple failed attempts from different IP addresses. Which property in the sign-in logs indicates the type of authentication used?

Easy
78

Your organization uses Microsoft Sentinel as its SIEM and Microsoft Defender XDR for endpoint detection. A critical incident has been generated: 'Possible ransomware activity detected on multiple endpoints.' The incident includes alerts from Microsoft Defender for Endpoint (MDE) about file encryption behaviors and from Microsoft Defender for Identity (MDI) about anomalous service account logins. You have been assigned the incident and need to contain the threat effectively. You have Microsoft Sentinel automation rules that can trigger playbooks, and you have Microsoft Defender XDR actions available. The environment includes 500 Windows 10 devices managed by Microsoft Intune, and 50 servers on-premises. Some servers are domain controllers. Which of the following is the BEST first course of action?

Hard
79

Which TWO of the following are valid sources for creating incidents in Microsoft Sentinel? (Choose two.)

Medium
80

You are investigating an incident in Microsoft Sentinel where a user account was used to sign in from an unfamiliar location and then accessed multiple sensitive files. Which step is most important to perform first?

Easy
81

You are testing this analytics rule. It should detect encoded PowerShell commands not from System32, but it is generating false positives. What is the most likely cause?

Medium
82

Your organization uses Microsoft Defender for Cloud to monitor hybrid workloads. You receive an alert that a fileless malware attack was detected on an on-premises server connected via Azure Arc. The server is running Windows Server 2019. What is the BEST action to contain the threat?

Hard
83

A security analyst is investigating a potential ransomware incident in Microsoft Defender XDR. The analyst needs to confirm the scope of the attack and halt further propagation. Which TWO actions should the analyst take first?

Medium
84

An analyst creates a playbook in Microsoft Sentinel to automatically block an IP address when an alert fires. However, the playbook fails to block the IP. What is the most likely cause?

Hard
85

You are reviewing an incident in Microsoft Sentinel. The incident is assigned to a user. What does the 'assignedTo' field indicate?

Easy
86

Which TWO data sources should you enable in Microsoft Sentinel to improve detection of credential theft attacks?

Medium
87

During a ransomware incident, Microsoft Sentinel generated an incident with high severity. The incident includes alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Entra ID. Your team needs to automate the containment process. What is the best approach to automatically isolate affected devices and disable compromised accounts?

Hard
88

You are investigating a security incident in Microsoft Sentinel. You want to visualize the relationships between entities such as IP addresses, users, and hosts. Which tool should you use?

Easy
89

An organization uses Microsoft Defender for Cloud Apps to detect anomalous behavior. An alert indicates that a user has signed in from an impossible travel scenario. The SOC analyst confirms the alert is a false positive due to a VPN. What should the analyst do to prevent future false positives for this user?

Easy
90

You deploy this ARM template to a Microsoft Sentinel workspace. After deployment, you notice that the saved search does not appear as an analytics rule. What is the most likely reason?

Medium
91

You are a Security Operations Analyst using Microsoft Sentinel. An incident has been created from an analytics rule. You need to assign the incident to a specific analyst and change its status to 'Active' so that it appears in their queue. Which action should you perform in the Microsoft Sentinel incident page?

Easy
92

Refer to the exhibit. The KQL query is used in a Microsoft Sentinel scheduled alert rule. What scenario does this query detect?

Medium
93

Your organization uses Microsoft Sentinel for security operations. The SOC team receives an incident that was generated from a Microsoft Defender for Cloud Apps alert. The incident involves a user who is downloading a large number of files from SharePoint Online. The analyst needs to suspend the user's account immediately to stop the potential data exfiltration. The organization has a Microsoft Sentinel playbook that can suspend a user in Microsoft Entra ID. However, the playbook is not triggering automatically. You need to ensure that the playbook runs automatically whenever a Defender for Cloud Apps alert generates an incident in Sentinel. What should you configure?

Easy
94

Your organization uses Microsoft Sentinel. A new analytics rule is needed to detect brute-force attacks against your Azure SQL databases. The rule should minimize false positives and trigger only when multiple failed logins occur from a single IP address within a short time window. Which THREE components are essential for building this rule?

Hard
95

Your organization uses Microsoft Sentinel with Microsoft Defender XDR integration. You have a scheduled analytics rule that detects failed logon attempts across multiple on-premises domain controllers. The rule is configured to run every 5 minutes and create an incident when more than 10 failed attempts occur from a single IP address within 5 minutes. Recently, the SOC team noticed that the rule is generating a high volume of low-fidelity incidents, mostly from legitimate users mistyping passwords. You need to reduce the number of false positive incidents while still detecting real brute-force attacks. What should you do?

Medium
96

Your organization uses Microsoft Sentinel and has configured analytics rules for detecting ransomware. You receive an alert indicating possible ransomware activity on a server. Which THREE actions should you take to contain and investigate the incident? (Choose three.)

Hard
97

Your organization uses Microsoft Sentinel and Microsoft Defender XDR (including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps). You have an incident response team that operates 24/7. Recently, there have been multiple incidents involving users receiving phishing emails that lead to credential theft. The phishing emails are sophisticated and bypass Exchange Online Protection (EOP) and Defender for Office 365's built-in phishing filters. The emails contain links to fake login pages that harvest credentials. Once credentials are stolen, the attacker uses them to sign in from anonymous IP addresses and attempts to access sensitive data in SharePoint Online. You need to design a response strategy that includes automated containment and investigation. The solution must: - Automatically disable user accounts when a phishing incident is confirmed. - Automatically trigger an investigation into the user's activity in Microsoft Defender for Cloud Apps. - Send a notification to the incident response team with a summary of the incident. - Minimize manual effort. You have the following components available: - Microsoft Sentinel with automation rules and playbooks. - Microsoft Defender XDR with advanced hunting. - Microsoft Power Automate. What is the most efficient way to achieve these requirements?

Hard
98

During a security incident, you need to create a custom detection rule in Microsoft Sentinel to alert on multiple failed logins followed by a successful login from the same IP within 10 minutes. Which KQL function should you use to group events by IP address and time window?

Hard
99

You are a Microsoft Sentinel analyst handling an incident where a compromised user account is being used to access cloud applications. Your response plan requires you to both terminate the attacker's active sessions and review what the account accessed. Which two actions should you perform? (Choose two.)

Hard
100

Refer to the exhibit. An alert in Microsoft Defender for Identity shows suspicious PowerCLI execution on an Exchange server. The service account 'svc_exchange' is used. What is the most likely true-positive scenario?

Hard
101

Your organization uses Microsoft Defender for Endpoint. An endpoint is detected as infected with a trojan. The analyst needs to isolate the device from the network while preserving forensic data. What action should the analyst take?

Medium
102

Refer to the exhibit. You are configuring an automation rule in Microsoft Sentinel. The JSON snippet defines an automation rule. What is the expected behavior of this rule?

Medium
103

Your organization uses Microsoft Purview Data Loss Prevention (DLP) and Microsoft Defender for Cloud Apps. During an incident, you discover that a user is exfiltrating sensitive data via a sanctioned cloud app. You need to block the user's ability to share files in that app immediately. What should you do?

Hard
104

Your organization uses Microsoft Sentinel. You receive a high-severity incident indicating a potential data exfiltration from an Azure Storage account. The incident contains entities such as IP addresses and user accounts. Which step should you perform first to contain the threat?

Easy
105

Your organization uses Microsoft Defender for Cloud Apps. You receive an alert that an administrator performed an unusual bulk download from SharePoint. What is the recommended first step to respond?

Easy
106

You are investigating a security incident in Microsoft Sentinel where a user received a phishing email containing a link to a malicious domain. The link was clicked, but no further actions were observed. Which playbook action should you take immediately to prevent potential lateral movement?

Medium
107

A SOC analyst is investigating a phishing campaign that targets Microsoft 365 users. The analyst needs to collect email message headers from multiple users' mailboxes. Which Microsoft 365 Defender action should the analyst use?

Easy
108

You run the above KQL query in Microsoft Sentinel to identify ransomware alerts from the last day. The result shows zero rows. Which is the most likely reason?

Easy
109

A security analyst receives a Microsoft Defender for Cloud Apps alert about a suspicious sign-in from an IP address in a sanctioned app. The analyst needs to immediately prevent further access from that IP. What should the analyst do?

Medium
110

During a security incident, you need to collect email messages associated with a phishing campaign from multiple mailboxes in Microsoft 365. Which tool should you use to search and export these emails?

Easy
111

Your organization uses Microsoft Sentinel with Fusion and Microsoft Security incident creation rules. You receive a high-severity incident from Microsoft Defender for Cloud Apps. The incident has a low confidence score. What should you do first?

Hard
112

Your organization uses Microsoft Sentinel. You have an incident that involves multiple alerts. You want to automatically assign the incident to the appropriate analyst based on the alert type. What should you use?

Medium
113

A security analyst receives an alert in Microsoft Defender XDR indicating that a user account was compromised. The analyst needs to isolate the affected device to prevent lateral movement. Which action should the analyst take first?

Medium
114

Your organization uses Microsoft Sentinel and Microsoft 365 Defender. You have a playbook that automatically isolates a device when a malware incident is confirmed. The playbook uses the Microsoft Defender for Endpoint connector. During a recent incident, the playbook failed to isolate a device because the device was not found in Defender for Endpoint. Upon investigation, you find that the device is onboarded to Microsoft Defender for Endpoint but the playbook is using an incorrect device ID format. What should you do to ensure the playbook works correctly?

Easy
115

After a security incident, you need to collect forensic evidence from a Windows 10 machine. Which Microsoft tool should you use to create a memory dump?

Medium
116

Which THREE elements are essential when creating a custom incident response playbook in Microsoft Sentinel? (Choose THREE.)

Hard
117

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspected Kerberoasting attack targeting a service account. You need to investigate the affected user and identify any related lateral movement. Which Microsoft Defender for Identity feature should you use to view the user's profile, including their activity timeline, associated alerts, and lateral movement paths?

Hard
118

Your company uses Microsoft Defender for Cloud Apps. You discover that a user's account is compromised and used to access a sensitive SharePoint site from an unfamiliar IP. You need to immediately revoke the user's session and force them to re-authenticate. Which action should you take?

Hard
119

The exhibit shows an automation rule in Microsoft Sentinel. The analyst reports that the playbook is not triggered for high-severity incidents. What is the most likely cause?

Hard
120

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. An alert indicates that an external IP address is downloading large amounts of data from a SharePoint site containing confidential documents. The activity is coming from a valid user account that appears to be compromised. What should you do first to stop the data exfiltration?

Medium
121

During an incident response, you need to collect email messages from a user's mailbox in Microsoft 365 for evidence. The user is suspected of phishing. Which Microsoft Purview solution should you use?

Medium
122

The analyst notices that the rule does not fire for a user who has 12 sign-ins from the same IP address, but all are low risk. The expected behavior is to alert when a single user has more than 10 sign-ins from the same IP with at least one high-risk sign-in. What is the issue?

Hard
123

In Microsoft Sentinel, an incident is created from a Fusion rule that correlates multiple alerts. The incident has a high severity. What should the analyst do first?

Easy
124

An incident in Microsoft Sentinel has been classified as a true positive. According to the incident response process, what should the analyst do next?

Easy
125

An organization uses Microsoft Defender XDR. During an incident investigation, the security team needs to determine if a specific file was executed on any devices in the organization over the past 30 days. They have the file hash. What is the most efficient way to get this information?

Hard
126

During an incident response, you need to collect a memory dump from a compromised Windows 10 device managed by Microsoft Defender for Endpoint. Which action should you take in the Microsoft Defender XDR portal?

Hard
127

Which THREE features in Microsoft Sentinel allow an analyst to automate incident response actions?

Medium
128

Your company uses Microsoft Sentinel as its SIEM. You are investigating an incident where a user reported receiving a phishing email that appeared to come from the CEO requesting a wire transfer. The user did not respond. However, the incident also contains alerts from Microsoft Defender for Office 365 indicating that other users clicked on a malicious link in a similar email. The email was sent to 100 users. The company has Microsoft Defender for Endpoint deployed on all devices. The incident requires immediate containment to prevent further compromise. What should you do first?

Medium
129

You are investigating a potential insider threat incident in Microsoft Sentinel. A user account has been flagged for downloading a large number of files from SharePoint Online. You need to determine if the user's activity is anomalous compared to their normal behavior. Which Microsoft Sentinel feature should you use to analyze this?

Hard
130

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. During an incident, you need to automatically disable a compromised Azure VM from the network. Which playbook action should you use?

Hard
131

During an incident response, a security analyst identifies that a user's account was used to access sensitive data from an anomalous location. The analyst needs to immediately prevent further access from that account while preserving forensic data. Which action should the analyst take?

Medium
132

Your organization uses Microsoft Defender for Endpoint. A user reports that their device is running slowly and exhibiting unusual network activity. You run a live response session and find a suspicious process running. Which action should you take first to contain the threat?

Medium
133

You are responding to a data exfiltration incident involving a user who copied sensitive files to a personal cloud storage service. The files were accessed from the user's managed device. Which Microsoft Defender for Cloud Apps activity policy should you create to detect similar future incidents?

Medium
134

You are investigating a ransomware incident in Microsoft Sentinel. The incident contains multiple alerts. You need to group related alerts under the same incident to reduce alert fatigue. What should you do?

Easy
135

Which TWO of the following are valid response actions that can be taken on a device from Microsoft Defender for Endpoint? (Choose two.)

Medium
136

Which TWO are immediate containment actions in Microsoft Sentinel for a compromised Azure VM? (Choose two.)

Easy
137

A SOC team uses Microsoft Sentinel with Microsoft Defender XDR integration. An incident is created from a Defender for Endpoint alert. The analyst wants to run a KQL query across all affected devices without creating a new analytics rule. How can the analyst achieve this?

Hard
138

An administrator creates a Microsoft Defender for Cloud Apps policy to block unsanctioned cloud storage apps. Despite the policy, users can still access these apps. What is the most likely cause?

Hard
139

You are reviewing an alert rule in Microsoft Sentinel created via ARM template. What is the primary purpose of this rule?

Medium
140

A SOC analyst needs to investigate a potential data exfiltration incident involving a user uploading files to an external cloud storage service. Which Microsoft Sentinel data source would provide the MOST relevant information?

Easy
141

Refer to the exhibit. You are reviewing a Microsoft Sentinel scheduled analytics rule configured as above. An incident was created for multiple alerts triggering within a 5-hour window. The SOC team needs to investigate each alert separately because they involve different user accounts. What should the analyst do to ensure each alert generates a separate incident?

Medium
142

Which THREE data sources in Microsoft Sentinel can be used to detect lateral movement in a network? (Choose three.)

Hard
143

During a ransomware incident, Microsoft Defender for Cloud Apps alerts indicate that a user is uploading large volumes of data to an external cloud storage provider not approved by your organization. Which two actions should you take first? (Choose two.)

Hard
144

An incident in Microsoft Defender XDR involves a device that is suspected to be infected with ransomware. The device is online and actively encrypting files. Which action should you take to contain the threat?

Medium
145

Based on the ARM template snippet, what is the purpose of this analytics rule?

Medium
146

During an incident response, a SOC analyst identifies that a malicious PowerShell script was executed on multiple endpoints. The analyst needs to collect relevant files from all affected endpoints for further analysis. What should the analyst use?

Hard
147

You receive an incident in Microsoft Sentinel that is a low-confidence alert from Microsoft Defender for Identity. What should be your first step?

Easy
148

You have been tasked with creating an automated response in Microsoft Sentinel for incidents involving lateral movement. Which Azure service allows you to run a playbook to automatically isolate a compromised VM?

Easy
149

Which TWO remediation actions are available in Microsoft Defender for Endpoint when responding to a malware infection?

Hard
150

Your organization uses Microsoft Sentinel with UEBA (User and Entity Behavior Analytics). An alert indicates a user's sign-in from an unusual location, followed by a mass download of sensitive files from SharePoint. The user is a low-privilege employee. What is the most likely conclusion?

Hard
151

Which THREE data sources should be included in a Microsoft Sentinel workspace to comprehensively monitor for lateral movement within an Azure environment?

Hard
152

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud Apps. You receive a high-severity incident indicating that a user's credentials were used to access a sensitive SharePoint site from an unmanaged device. The user, 'jdoe@contoso.com', is a senior executive. The IP address is from a public Wi-Fi hotspot. The incident includes a recommendation to apply session policy to block download of sensitive files. You need to create a policy in Microsoft Defender for Cloud Apps that blocks downloads from unmanaged devices for this specific user when accessing the sensitive site. The policy should trigger only when the user accesses the specific SharePoint site named 'ExecConfidential'. What should you do?

Hard
153

Your organization has Microsoft Defender for Endpoint deployed. A security analyst receives an alert about a suspicious PowerShell command executed on a device. The analyst needs to investigate the process tree. Which feature should the analyst use?

Medium
154

Which TWO actions should be taken to respond to a potential data exfiltration incident detected by Microsoft Defender for Cloud Apps?

Hard
155

During an incident investigation in Microsoft Sentinel, you need to gather related events from multiple data sources into a single view for analysis. Which feature should you use?

Medium
156

Which THREE steps are part of the containment phase of incident response in Microsoft Sentinel? (Select THREE.)

Hard
157

Which TWO actions should be taken immediately when a compromised user account is detected in Microsoft Entra ID?

Easy
158

Refer to the exhibit. A SOC analyst runs this Advanced Hunting query in Microsoft Defender XDR to detect potential living-off-the-land (LotL) attacks. An alert is triggered when a device shows multiple occurrences of 'mshta.exe' executing with a remote script. Which additional data source should the analyst check to confirm the attack?

Hard
159

Which TWO actions should an analyst take when triaging a Microsoft Sentinel incident that involves a user who clicked a malicious link in a phishing email? (Choose two.)

Medium
160

Your Microsoft Sentinel workspace receives logs from multiple sources. You need to ensure that an incident response playbook is triggered automatically when a specific alert is generated. What should you create?

Medium
161

Your organization uses Microsoft Sentinel. A security analyst receives an alert from a custom analytics rule that triggers on a specific sequence of failed logon attempts followed by a successful logon from an unusual location. The incident is generated but the analyst is not sure if the activity is malicious or a user error. What should the analyst do first to quickly gather additional context?

Medium
162

Refer to the exhibit. A security analyst runs this PowerShell script to query a Log Analytics workspace. What is the purpose of this query?

Medium
163

Which TWO actions are appropriate when responding to a confirmed malware outbreak on multiple workstations identified by Microsoft Defender for Endpoint?

Medium
164

Your organization uses Microsoft Sentinel. A security analyst reports a high number of false positives from a scheduled analytics rule that detects anomalous sign-ins. The rule uses the 'UserAgent' field in the SigninLogs table. What is the best practice to reduce false positives while maintaining detection coverage?

Easy
165

Your company uses Microsoft Defender for Endpoint (MDE) on all Windows 10 devices. You are investigating a machine that is suspected of being part of a botnet. The machine is communicating with a known C2 server at IP 203.0.113.55. You have confirmed that the IP is malicious. You need to block all outbound traffic from the machine to that IP immediately, and also ensure that no other devices in the organization can communicate with that IP. The solution must be implemented without deploying additional network appliances. What should you do?

Hard
166

Your organization uses Microsoft 365 Defender. You are investigating a potential malware outbreak on several endpoints. Which TWO actions should you take to isolate affected devices and prevent lateral movement?

Medium
167

Which THREE indicators of compromise (IOCs) are commonly used in Microsoft Sentinel to detect advanced persistent threats (APTs)? (Choose THREE.)

Medium
168

Your organization has a hybrid identity environment with Microsoft Entra ID (Azure AD) and on-premises Active Directory. You are using Microsoft Defender for Identity (MDI) integrated with Microsoft Defender XDR. An incident is raised indicating that a user account has been compromised because of an anomaly in Kerberos protocol activity. The incident severity is High. You need to contain the incident immediately by disabling the user account across both on-premises and cloud. However, you also want to preserve the account for forensic analysis. What is the recommended course of action?

Hard
169

You are investigating a potential ransomware incident in Microsoft Defender XDR. The incident has a high severity alert indicating that a user installed a suspicious application. Which initial response action should you take to contain the threat while preserving evidence?

Medium
170

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You receive an alert from Defender for Cloud that a virtual machine has a high severity vulnerability: 'CVE-2023-XXXX' with a CVSS score of 9.8. The virtual machine is running a critical application for the finance department. You need to remediate the vulnerability as quickly as possible while minimizing downtime. The application vendor has not yet released a patch but has provided a workaround. What should you do?

Hard
171

Refer to the exhibit. You are investigating incidents related to suspicious process injection. The KQL query above is run in Microsoft Sentinel. What is the purpose of this query?

Hard
172

Your organization uses Microsoft Defender XDR. A security incident involving a compromised user account has been identified. Which THREE actions should you take to contain and remediate the incident?

Hard
173

You are a Security Operations Analyst investigating a potential insider threat. A user's account was flagged for downloading a large number of files from SharePoint Online. You need to review the user's activity and determine if the behavior is malicious. You have Microsoft Defender for Cloud Apps and Microsoft Sentinel configured. Which Microsoft Sentinel data source should you query to analyze the user's file download activities in SharePoint?

Hard
174

Your organization uses Microsoft Sentinel. A security analyst reports that an incident was automatically closed without investigation. You need to identify why the incident was closed automatically. Which Sentinel feature should you review?

Medium
175

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure subscriptions. You receive an alert that a critical vulnerability exists on a virtual machine. What is the BEST immediate action to validate the alert and contain the threat?

Medium
176

Your SOC uses Microsoft Defender for Cloud Apps. An alert indicates that a user is downloading a large number of files from SharePoint. Which action should you take to investigate and potentially block the activity?

Easy
177

Your organization uses Microsoft Sentinel and Microsoft Defender for Identity. An alert fires for a potential DCSync attack. The incident response team needs to immediately block the source account from performing directory replication. Which action should be taken?

Hard
178

A security analyst detects a suspicious login from an unusual location for a user in Microsoft Defender XDR. The analyst needs to investigate and contain the incident. Which TWO actions should be taken?

Easy
179

Refer to the exhibit. You run this KQL query in Microsoft Defender XDR to detect suspicious PowerShell activity. Why might this query generate many false positives?

Medium
180

Your organization has deployed Microsoft Sentinel with the Microsoft Defender XDR connector. A high-severity incident is created for a user who received a phishing email that contained a malicious link. The user clicked the link, and the attacker gained access to the user's mailbox. The security team needs to remove the attacker's access and prevent future occurrences. What should you do first?

Hard
181

Refer to the exhibit. You have created an automation rule in Microsoft Sentinel with the above configuration. The playbook isolates the device and disables the user account. After enabling the rule, you notice that a low-severity incident containing an alert titled 'Ransomware Behavior' did NOT trigger the automation. What is the most likely reason?

Hard
182

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You receive an alert from Defender for Cloud indicating that a virtual machine has a high severity vulnerability (CVE-2023-XXXX). You need to create an incident in Microsoft Sentinel and trigger a playbook to remediate the vulnerability. However, the incident is not being created automatically. What is the most likely cause?

Hard
183

During an incident, an analyst wants to use Microsoft Defender XDR's automatic attack disruption to contain an ongoing attack. What prerequisite must be met?

Easy
184

Your security operations center (SOC) uses Microsoft Sentinel. An incident is created from a fusion alert. What does Fusion technology do?

Easy
185

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You receive an alert about a suspicious sign-in from an IP address associated with a known malicious actor. The sign-in was for a privileged account. You need to immediately contain the incident. What should you do first?

Medium
186

You are investigating repeated SQL injection alerts. The KQL query returns IP addresses with more than 5 alerts in the last 7 days. What is the purpose of the `summarize` and `where AlertCount > 5` lines?

Medium
187

Your organization uses Microsoft Sentinel. An incident has been identified as a false positive. What is the recommended action to prevent similar false positives in the future?

Easy
188

A security analyst in your company uses Microsoft Defender XDR to investigate an incident involving a user who received a malicious email. The analyst needs to block the sender's email address across all tenants in the organization. What is the most efficient way to achieve this?

Hard
189

You are reviewing a scheduled analytics rule in Microsoft Sentinel. What does the suppressionDuration setting affect?

Hard
190

Your organization uses Microsoft Defender XDR. The incident queue shows multiple alerts related to a single endpoint: malware detected, suspicious PowerShell execution, and data exfiltration attempts. The analyst needs to investigate the incident. Which tool should the analyst use to correlate these events?

Medium
191

Which THREE actions should be taken when a phishing attack is detected in Microsoft Defender XDR?

Hard
192

The exhibit shows a partial playbook trigger configuration in Microsoft Sentinel. When will this playbook be triggered?

Medium
193

A security analyst receives an alert in Microsoft Defender XDR indicating a possible credential theft attempt from an external IP. The analyst wants to isolate the affected device immediately while preserving forensic data. What should the analyst do?

Medium
194

Refer to the exhibit. This JSON snippet is from an Azure Web Application Firewall (WAF) policy. What does this rule do?

Hard
195

A security analyst receives an alert from Microsoft Defender for Cloud Apps indicating that a user has signed in from a banned country. The analyst needs to block further access from that country for all users. What should the analyst configure?

Easy
196

You are responding to an incident where a user's credentials were stolen via a phishing email. The attacker used the credentials to access Microsoft Entra ID and then tried to perform privileged role escalation. Which Microsoft Sentinel solution should you use to detect this type of attack?

Medium
197

You are investigating a potential ransomware incident detected by Microsoft Defender XDR. The incident shows multiple machines with suspicious encryption activity. You need to contain the threat immediately. What should you do first?

Medium
198

After a security incident, you need to preserve evidence from a compromised Microsoft 365 tenant. What is the best method to preserve data?

Easy
199

A SOC analyst receives an alert from Microsoft Defender for Cloud Apps indicating that a user downloaded 500 GB of data from SharePoint to an unmanaged device. The user has no history of such behavior. What is the best first step in the incident response process?

Medium
200

Refer to the exhibit. An analyst runs Get-MpThreat on a device. Based on the output, what is the status of the threat?

Medium
201

Refer to the exhibit. A Microsoft Sentinel scheduled rule is configured as shown. The rule generates an alert, but the incident created contains only the first alert, and subsequent alerts do not update the incident. What is the most likely cause?

Medium
202

Your organization uses Microsoft Sentinel. You need to create an incident response playbook that automatically isolates a compromised device when a high-severity incident is created. The playbook should only run during business hours (9 AM - 5 PM local time). How should you configure this?

Medium
203

You are a Microsoft Sentinel analyst investigating an incident that contains several related alerts about a compromised user account. Your incident response runbook requires you to temporarily prevent the attacker from using the account while preserving the ability to restore access after remediation. You need to disable the account in Microsoft Entra ID directly from the incident investigation experience. What should you do?

Medium
204

Your company uses Microsoft Sentinel. A security analyst receives an incident that includes a large number of alerts from a single data source. The analyst needs to identify which alerts are duplicates or related so they can focus on unique threats. Which feature should the analyst use?

Medium
205

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos activity that may indicate a golden ticket attack. Which of the following actions should you take to investigate this alert?

Easy
206

During an incident investigation, you find that a compromised account was used to log into a virtual machine via RDP from an IP address in a sanctioned country. The VM has Microsoft Defender for Endpoint installed. Which data source in Microsoft Sentinel would you query to see the RDP connection events?

Hard
207

You are deploying Microsoft Sentinel using the above ARM template parameters. After deployment, you notice that Microsoft Defender for Cloud alerts are not being ingested. What is the MOST likely reason?

Hard
208

You are responding to a security incident involving a user who clicked on a malicious link in an email. The link led to a website that downloaded a file to the user's device. Microsoft Defender for Endpoint (MDE) detected the file as malware and blocked it. However, the user reports that the device is running slowly. You need to verify if there are any remnants of the malware. Which action should you take?

Easy
209

Your organization uses Microsoft Sentinel. You receive an alert for a suspicious sign-in from an unusual location. You want to automatically create an incident and assign it to the security team for investigation. What should you configure?

Easy
210

Your organization uses Microsoft 365 Defender. An incident is created for a user who received a phishing email that contained a link to a malicious website. The user clicked the link but did not enter any credentials. The incident includes the alert 'Phishing delivered' from Microsoft Defender for Office 365. You need to remediate the incident and prevent future occurrences. The user is in the Finance department and frequently receives emails from external vendors. What is the best course of action?

Hard
211

An analyst is investigating a phishing campaign that targeted multiple users. The analyst needs to identify if any users clicked a malicious link in the email. Which Microsoft Defender for Office 365 feature should be used?

Easy
212

Your organization uses Microsoft Sentinel. You receive an incident for a potential data exfiltration involving a sensitive blob storage container. You need to determine if the data was accessed from an unusual IP address. What should you do?

Medium
213

Your organization uses Microsoft Defender for Cloud Apps. You detect a suspicious app that has high data access and unusual API calls. You want to automatically block the app and notify the user. What should you implement?

Medium
214

During an incident response, you need to collect forensic data from Microsoft Defender for Endpoint (MDE) on a remote device that is currently offline. What is the best approach?

Hard
215

Your organization uses Microsoft Sentinel. A fusion incident was created involving multiple alerts from different sources. You need to investigate the incident to determine if it is a true positive. What is the first step you should take?

Medium
216

A company uses Microsoft Sentinel as its SIEM. The security team is investigating an incident that involves multiple alerts from different data sources. The team wants to see a timeline of all related activities across all data sources in one view. Which Microsoft Sentinel feature should they use?

Medium
217

Your company uses Microsoft Defender XDR. A critical server is exhibiting signs of a potential ransomware attack, with files being encrypted and a ransom note appearing. The incident has been escalated to the security operations center (SOC). What is the most immediate action to contain the threat and prevent further spread?

Hard
218

Which TWO actions should an analyst take when a user reports receiving a suspicious email with an attachment? (Select TWO.)

Medium
219

You are a SOC analyst in Microsoft Defender XDR. An incident has been created that includes alerts from Microsoft Defender for Endpoint and Microsoft Defender for Office 365. You need to assign the incident to a colleague and add a note about initial findings. What should you do?

Easy
220

An organization uses Microsoft Purview Communication Compliance to detect insider trading. An alert is generated for a user who sent a message containing sensitive financial data. The compliance officer needs to initiate a legal hold on the user's mailbox to preserve evidence. Which role must the officer have to perform this action?

Hard
221

Your company uses Microsoft Defender for Endpoint. A device shows signs of compromise with suspicious PowerShell execution. You need to collect forensic evidence before performing remediation. Which action should you use?

Hard
222

Your company uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the default policy. The email contains an external link to a credential harvesting site. You need to block similar emails in the future. What should you do?

Medium
223

A company uses Microsoft Sentinel with Microsoft Defender for Cloud Apps. An incident is created when a user downloads 500 GB from SharePoint in one hour. The analyst wants to create a playbook that automatically suspends the user in Microsoft Entra ID when such activity is detected. Which connector and action should the analyst use in the playbook?

Hard
224

Which THREE actions can you take in Microsoft Sentinel to respond to an incident?

Hard
225

You are a SOC analyst using Microsoft Defender XDR. An incident named 'Suspicious PowerShell download' is assigned to you. You need to quickly determine the initial entry point and the scope of affected devices. Which action should you perform first within the incident?

Medium
226

A security administrator receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request from a domain controller. The alert suggests a possible Golden Ticket attack. Which action should the administrator take to validate the alert?

Hard
227

A security analyst in your SOC receives an alert from Microsoft Defender for Cloud Apps indicating that a user downloaded a large number of files from SharePoint in a short time. What is the most likely classification of this activity?

Easy
228

A security operations center (SOC) team uses Microsoft Defender XDR and Microsoft Sentinel. An incident is created in Defender XDR that involves a malicious email and a compromised device. The team wants the incident to automatically sync to Sentinel. What is the minimum configuration required?

Medium
229

Your company uses Microsoft Sentinel with the Microsoft Defender for Cloud Apps connector. An incident is created when a user performs an unusual mass download from SharePoint Online. The playbook assigned to the incident automatically suspends the user account in Microsoft Entra ID. However, after investigation, the user's activity is determined to be legitimate (they were backing up data for a migration). You need to restore the user's account and ensure that the user can access all resources immediately. You also need to update the incident to reflect the findings. What should you do?

Easy
230

Which TWO are recommended first steps when responding to a confirmed ransomware incident in Microsoft Defender XDR?

Medium
231

Your organization uses Microsoft Defender for Cloud to protect hybrid cloud workloads. An alert indicates that a container in Azure Kubernetes Service (AKS) is running a privileged container. Which response action should you take first?

Easy
232

You are investigating a security incident in Microsoft Sentinel where a user reported receiving a phishing email with a malicious attachment. You need to identify all users who received the same email within the last 24 hours. Which KQL query should you use?

Medium
233

An incident in Microsoft Sentinel was assigned to you. After investigation, you determine it is a false positive. What should you do to resolve the incident?

Easy
234

You are investigating a phishing incident in Microsoft Defender XDR. The incident involves a user who clicked a malicious link in an email. Which data source would you use to trace the email's origin?

Easy
235

You are analyzing a firewall policy in Azure Firewall deployed via Azure Policy. What is the effect of this rule?

Medium
236

You are investigating a security incident involving a compromised user account. The attacker used the account to access sensitive data in SharePoint Online. Which TWO actions should you take to remediate the incident? (Choose two.)

Easy
237

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector. You have a critical incident that involves multiple alerts across different services. The incident is being updated with new alerts. You need to ensure that a specific playbook runs only when the incident severity is updated to High. How should you configure the automation rule?

Hard
238

A Microsoft Defender XDR incident shows that a user's device has been communicating with a known malicious C2 server. The device is online and the user is actively working. You need to contain the threat with minimal business disruption. What should you do?

Hard
239

You are responding to an incident where a user's device may be compromised. You need to collect forensic data from the device using Microsoft Defender for Endpoint. Which action should you take?

Easy
240

You are investigating a ransomware incident in Microsoft Sentinel. The incident contains multiple alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. You need to correlate the alerts and identify the initial entry point. Which KQL function should you use to combine the alerts?

Hard
241

You are responding to a phishing incident. The investigation reveals that a user clicked a link in a phishing email and entered credentials on a fake site. You need to contain the incident and prevent further compromise. What should you do first?

Medium
242

Your Microsoft 365 tenant is protected by Microsoft Defender for Office 365. A user reports receiving a suspicious email with a link. You need to investigate whether the link was malicious and if any other users clicked it. Which tool should you use first?

Medium
243

Your company uses Microsoft Defender XDR. During a ransomware incident, you need to isolate a compromised Windows 10 device from the network while allowing connectivity to the Microsoft Defender for Endpoint service. Which action should you take?

Hard
244

Your security team receives an alert from Microsoft Defender for Endpoint indicating a suspicious PowerShell command was executed on a device. The command attempted to download a payload from a known malicious IP. After confirming the alert is a true positive, what should be your first containment step?

Medium
245

Your organization uses Microsoft Sentinel. An incident is created for a possible data exfiltration via an unapproved external IP address. Which type of Microsoft Sentinel automation should you use to automatically block the IP address in the firewall?

Easy
246

Which TWO are valid methods to collect forensic evidence from a compromised Windows endpoint during an incident? (Choose TWO.)

Easy
247

A SOC analyst is investigating a Microsoft Sentinel incident involving a compromised service principal. The analyst needs to enrich the incident with information from an external threat intelligence platform that exposes a REST API and requires an API key. The enrichment must run automatically each time a matching incident is created and must not require manual steps. Which Microsoft Sentinel component should the analyst use to implement this enrichment?

Hard
248

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to automatically isolate a device when a high-severity incident is created. What is the most efficient way to achieve this?

Medium
249

A SOC team uses Microsoft Sentinel and wants to automatically enrich incidents with threat intelligence from a third-party feed. Which feature should they configure to ingest the threat intelligence and correlate it with alerts?

Medium
250

Refer to the exhibit. A security analyst runs the KQL query in Microsoft Defender XDR to find devices running encoded PowerShell commands in the last hour. The query returns results showing a device named 'DESKTOP-123' with account 'jdoe'. The analyst suspects malicious activity. Which immediate next step should the analyst take?

Medium
251

Which TWO actions are appropriate when responding to a confirmed data exfiltration incident via email?

Medium
252

Your organization uses Microsoft Defender XDR. A user reports that their device is behaving erratically, with unexpected pop-ups and high CPU usage. You suspect malware infection. You need to collect forensic data from the device for analysis. What should you do?

Medium
253

Your organization uses Microsoft Defender for Cloud Apps. An alert indicates that a user is downloading large amounts of data from SharePoint Online. What should you do first to investigate?

Medium
254

An incident is opened in Microsoft Sentinel for multiple sign-in failures from a single IP address targeting a privileged user account. Which action is most effective in automatically responding to this incident?

Easy
255

Your organization uses Microsoft Sentinel and has several analytics rules that generate incidents from various data sources. The SOC team is overwhelmed by the number of incidents. You need to implement a triage system that automatically assigns incidents to different analysts based on the incident's tactics and severity. You also want to send a notification to the assigned analyst via Teams. What should you do?

Hard
256

A Microsoft Defender XDR incident involves a compromised endpoint. Your containment policy requires isolating the device from the network while still allowing you to run live response commands to collect evidence. You need to choose the appropriate device isolation type in Microsoft Defender for Endpoint. Which isolation type should you select?

Medium
257

Refer to the exhibit. You run this KQL query in Microsoft 365 Defender advanced hunting to investigate an incident involving IP address 203.0.113.1. The query returns results, but you need to also see which devices communicated with this IP. How should you modify the query?

Hard
258

Which TWO playbook actions can be used to automatically contain a compromised user account in Microsoft Entra ID during an incident? (Choose TWO.)

Hard
259

You are a security analyst at Contoso. Microsoft Sentinel is deployed with the Microsoft Defender for Cloud Apps connector. An incident is generated for a high-risk sign-in from a user named JaneDoe@contoso.com. The incident severity is Medium. The incident details show that the sign-in originated from an IP address in a country where Contoso has no business presence, and the user recently changed their password. You suspect account compromise. You need to take immediate action to contain the threat and prevent further unauthorized access. The user is currently active in Microsoft Entra ID. You have the following options: A) Force the user to re-authenticate by revoking their sessions in Microsoft Entra ID. B) Disable the user account in Microsoft Entra ID. C) Block the IP address in Microsoft Defender for Cloud Apps. D) Create a Sentinel automation rule to automatically disable accounts on similar alerts. Which action should you take first to contain the current incident?

Hard
260

During a ransomware response in Microsoft Defender XDR, you identify that multiple devices are communicating with a known C2 server over port 443. You need to block this communication across all devices immediately. What is the most effective course of action?

Hard
261

A security analyst is investigating a phishing incident in Microsoft Defender XDR. The analyst wants to see the full email content and attachments. Where should the analyst look?

Easy
262

Your organization uses Microsoft Defender XDR. A security administrator reports that a user's device is showing high severity alerts for 'Tampering with Microsoft Defender Antivirus' but the device is not isolated. You need to ensure that when such alerts occur, the device is automatically isolated in Microsoft Defender for Endpoint. What should you do?

Hard
263

Refer to the exhibit. An analyst runs the command to install the Azure Monitor Agent on a VM. What is the primary purpose of installing this agent in the context of security incident response?

Easy
264

Your organization uses Microsoft Sentinel. You have a requirement to automatically add a tag to incidents that involve a specific user. The tag should be added when the incident is created. What should you configure?

Hard
265

Which TWO response actions are available in Microsoft Defender for Endpoint for a compromised device? (Choose two.)

Easy
266

An incident in Microsoft Sentinel involves multiple alerts indicating a potential data exfiltration via SharePoint Online. You need to respond and remediate. Which THREE actions should be taken?

Medium
267

Which THREE are valid incident classification categories in Microsoft Sentinel? (Select THREE.)

Easy
268

During an incident response, you need to collect forensic data from a compromised Linux server that is not managed by Microsoft Defender for Endpoint. You plan to use a manual collection script. Which tool should you use to securely upload the collected data to Azure for analysis?

Easy
269

You are investigating a lateral movement incident in Microsoft Defender for Endpoint. The timeline shows that a user's credentials were used from a compromised workstation to access a sensitive server. Which action should you take to contain the incident?

Hard
270

Which TWO actions can you perform in Microsoft Defender XDR as part of incident response?

Medium
271

Your organization uses Microsoft Sentinel. You receive an incident for a potential malware outbreak. You need to quickly see which entities are involved (e.g., IPs, hosts, accounts). Where should you look?

Easy
272

The KQL query above is used in a Microsoft Sentinel analytics rule. What is the purpose of this rule?

Hard
273

During an incident, you need to prevent a malicious process from running on all endpoints using Microsoft Defender for Endpoint. The process is not yet detected by antivirus signatures. Which action should you use?

Hard
274

A SOC analyst receives a Microsoft Defender for Cloud Apps alert about a mass download of files from a SharePoint site by a single user. The analyst needs to contain the incident. Which action should be taken first?

Easy
275

You have detected a suspicious PowerShell command running on several workstations. The command appears to be downloading a payload from a known malicious URL. What is the most effective immediate response using Microsoft Defender for Endpoint?

Medium
276

Your organization has Microsoft Defender XDR enabled. An incident is generated for a user who clicked a phishing link in an email. The analyst needs to automatically disable the user's mailbox for suspicious activity. Which automated action should the analyst configure in a Microsoft Sentinel automation rule?

Medium
277

During a ransomware incident, an analyst needs to identify which files were encrypted on an endpoint. The endpoint is running Windows and is managed by Microsoft Defender for Endpoint. Which data source should the analyst query in Advanced hunting?

Medium
278

A security analyst in your SOC is investigating a Microsoft Defender XDR incident. The analyst wants to see a visual representation of the attack timeline and related entities across emails, devices, and identities. Which feature should the analyst use?

Easy
279

You are a Security Operations Analyst at a company that uses Microsoft Defender XDR. An incident named 'Phishing campaign targeting finance' is assigned to you. The incident contains multiple alerts across Exchange Online and Microsoft Defender for Office 365. You need to perform a manual investigation and then take remediation actions. Which built-in incident management capability in the Microsoft 365 Defender portal allows you to view the attack story, evidence, and response actions for this incident in a single pane?

Medium
280

A security analyst receives a Microsoft Defender for Cloud Apps alert about a user performing unusual file downloads from SharePoint. The analyst needs to investigate the user's activity in the last 24 hours. Which log source should the analyst query first?

Easy
281

An incident in Microsoft Sentinel involves a phishing campaign that delivered a malicious macro-enabled document. The document was opened by 15 users. Which playbook action should be triggered automatically to contain the threat?

Medium
282

Your organization uses Microsoft Sentinel. You have a playbook that sends an email notification to the SOC team when a new incident is created. The playbook is currently triggered manually. You want the playbook to run automatically every time an incident of severity High is created. What should you do?

Easy
283

Your organization uses Microsoft Sentinel. A security analyst receives an alert for a suspicious sign-in from an unfamiliar IP address. The analyst wants to quickly check if the same IP address has been associated with any other alerts in the past 30 days. Which action should the analyst take?

Easy
284

Which TWO of the following are valid methods to retrieve data from Microsoft Sentinel for external analysis during an incident?

Hard
285

Your organization uses Microsoft Defender for Cloud. You need to remediate a security recommendation that indicates a virtual machine is missing critical security updates. Which TWO actions should you take to remediate this recommendation?

Easy
286

You are investigating a phishing incident in Microsoft Defender XDR. The user reported receiving an email with a malicious link. You need to identify all users who received the same email. Which feature should you use?

Easy
287

Your organization uses Microsoft Sentinel. You have a scheduled analytics rule that queries Windows Security Events to detect local admin group modifications. The rule runs every hour and looks back 1 hour. However, you are missing events that occur within the first few minutes of the hour. What is the most likely cause?

Hard
288

Your organization uses Microsoft Defender for Cloud. You receive a security alert about a suspicious process on a virtual machine. You want to investigate the process further. What should you do?

Easy
289

Which THREE of the following are key steps when containing a ransomware incident in Microsoft Defender XDR? (Select THREE.)

Hard
290

Your organization uses Microsoft Defender for Cloud Apps. You receive an alert about an impossible travel activity for a user. What is the best first step to validate if this is a true positive?

Hard
291

Which TWO are valid incident management actions in Microsoft Sentinel? (Choose two.)

Easy
292

Your organization uses Microsoft 365 Defender. During an incident, which TWO actions can be taken directly from the Microsoft 365 Defender portal to remediate a compromised email account?

Easy
293

You are a Security Operations Analyst using Microsoft Defender XDR. An incident named 'Phishing campaign targeting finance' has been automatically created from multiple alerts. The incident contains evidence for several users and mailboxes. You need to determine which users were affected by the campaign and the timeline of their interactions with the malicious emails. Which feature should you use?

Medium
294

Refer to the exhibit. The KQL query runs in Microsoft Sentinel and returns no results. The analyst expects to see failed logon attempts. What is the most likely reason?

Easy
295

The exhibit shows the output of a Microsoft Defender for Endpoint API call to get machine information. What does the isolationStatus value indicate?

Easy
296

During a security incident, you need to block a malicious IP address at the network level for all Azure resources in a subscription. You have Azure Firewall deployed. What is the MOST efficient method to implement the block?

Hard
297

Your security team is investigating a suspicious sign-in from an unfamiliar IP address. The user has Microsoft Entra ID P2 licenses and is assigned a Conditional Access policy that requires MFA for all cloud apps. During the incident response, you find that the sign-in succeeded despite the user not completing MFA. Which action should you take first to investigate the discrepancy?

Medium
298

Your organization uses Microsoft Defender XDR. You receive an automated investigation that found a malicious file on a device. The investigation recommends 'Block the file'. What does this action do?

Medium
299

You are investigating a compromised user account in Microsoft Sentinel. You have identified that the attacker used the account to send phishing emails internally. You need to contain the threat by disabling the account and revoking all active sessions. Which Microsoft Sentinel feature should you use to perform these actions directly from the incident?

Hard
300

Refer to the exhibit. An automation rule is configured as shown. When will the playbook be triggered?

Medium
301

A user reports that they cannot access their Microsoft 365 apps after clicking a link in an email. You suspect token theft. In Microsoft Defender XDR, which incident investigation action should you take first to verify the scope?

Hard
302

Your security team uses Microsoft Sentinel analytics rules to detect brute-force attacks. A rule triggers when more than 10 failed logins occur within 5 minutes from a single IP. An incident is generated. Which first step should the analyst take?

Easy
303

You are investigating a security incident in Microsoft Sentinel. You need to identify which user account was used to perform a suspicious Azure Resource Manager operation that deleted a virtual machine. The operation was logged in Azure Activity logs. Which Kusto Query Language (KQL) query should you use to find the user identity associated with the deletion?

Hard
304

Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. What will happen when a new incident with severity Medium is created?

Hard
305

Refer to the exhibit. You are reviewing a Microsoft Sentinel automation rule definition. The rule is intended to automatically change the severity to High, assign to tier2, and set status to Active for incidents triggered by alerts containing 'malware'. However, incidents are not being updated. What is the most likely cause?

Medium
306

You are investigating an incident in Microsoft Defender XDR that involves a user who clicked a link in a phishing email. The email was detected and blocked by Microsoft Defender for Office 365, but the user still clicked the link before it was blocked. The incident includes an alert for 'Malicious URL click'. What additional information should you check to determine if the user's credentials were compromised?

Medium
307

During an incident involving a compromised Azure VM, the security team wants to capture a memory dump for forensic analysis. The VM is running Windows Server 2022. What is the recommended approach?

Medium
308

During an incident response, a forensic investigator needs to collect a memory dump from a compromised Windows server that is still running. The server has Microsoft Defender for Endpoint installed but is not connected to the internet. Which method should the investigator use?

Hard
309

You are an incident responder for a company using Microsoft 365 Defender. A critical incident is assigned to you. What is the first action you should take according to best practices?

Easy
310

Your organization uses Microsoft Sentinel. A security incident related to a compromised user account has been fully investigated and remediated. Which THREE steps should you take to close the incident properly? (Choose three.)

Hard
311

Your Microsoft Sentinel workspace is receiving a high volume of false positive alerts from a specific analytics rule. You need to suppress these alerts without disabling the rule. Which feature should you use?

Hard
312

Your organization is responding to a ransomware incident. Which TWO actions should be taken first to contain the incident while preserving forensic evidence?

Medium
313

During an incident response, a SOC analyst needs to automatically collect relevant evidence from multiple Microsoft 365 services. Which Microsoft Sentinel playbook trigger should the analyst configure?

Easy
314

Which TWO actions should you perform to contain a ransomware incident in Microsoft Defender for Endpoint?

Medium
315

A security analyst receives a Microsoft Defender for Identity alert about a suspicious Kerberos attack. The analyst needs to contain the compromised account immediately. What should the analyst do?

Easy
316

Which TWO of the following are valid data connectors for Microsoft Sentinel? (Select TWO.)

Easy
317

During an investigation, you need to check if any user has been assigned privileged roles in Microsoft Entra ID outside of normal business hours. Which data source would provide this information?

Medium
318

Which THREE steps should be included in a Microsoft Sentinel playbook for automatic incident response when a high-severity alert fires?

Medium
319

You are responding to an incident where a user's credentials were used to access a federated SaaS application from an IP address associated with a known threat actor. The user's account is not disabled. Which action is most effective to prevent further unauthorized access?

Medium
320

Your organization uses Microsoft Defender for Cloud Apps. A security analyst receives an alert for a suspicious sign-in from an IP address in a sanctioned app. The analyst needs to immediately block the user from accessing the app. Which action should the analyst take?

Medium
321

You are responding to an incident where a malicious PowerShell script was executed on multiple endpoints. You need to collect the script content from the affected devices for analysis. What should you use?

Medium
322

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. A critical server in Azure was compromised by ransomware. The incident response team needs to ensure that no other resources in the same resource group are affected. What is the most immediate containment action?

Hard
323

Your SOC uses Microsoft Sentinel. An analytics rule produces an incident, and your runbook requires that when a specific high-severity incident is created, a playbook must automatically post a summary to a Microsoft Teams channel and create a tracking task. You need the playbook to run without a human clicking anything. What should you configure?

Hard
324

You are investigating a potential compromise of a service account in Microsoft Sentinel. You need to identify all actions performed by this account across Azure and Microsoft 365. Which Sentinel feature should you use?

Hard
325

Which TWO are legitimate sources of threat intelligence that can be ingested into Microsoft Sentinel?

Easy
326

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You have a custom analytics rule that triggers on a Defender for Endpoint alert. When the rule triggers, a playbook is executed that creates an incident in Microsoft Sentinel and sends a message to a Teams channel. The playbook fails to execute. Which permission should you verify first?

Easy
327

Your organization has deployed Microsoft Sentinel and uses the Microsoft 365 connector to ingest audit logs. You receive an alert from Microsoft Defender for Office 365 about a phishing email that was delivered to a user's inbox. You need to create an incident in Sentinel and automatically quarantine the email. What is the most efficient way to achieve this?

Hard
328

Your organization uses Microsoft Sentinel with the UEBA (User and Entity Behavior Analytics) feature enabled. A security analyst notices that a user account has been flagged with an anomaly indicating a possible compromised credential. Which entity type in Microsoft Sentinel's UEBA is most relevant for this alert?

Medium
329

An incident in Microsoft Defender XDR shows a device with high severity alert: 'Suspicious PowerShell command line.' The device is currently isolated from the network. What is the best next step to investigate the alert?

Easy
330

Which TWO actions should you take when responding to a confirmed ransomware incident in Microsoft Defender for Endpoint?

Hard
331

Your organization uses Microsoft Sentinel. A security analyst receives an alert indicating that a user account was used to sign in from an unfamiliar location. You need to investigate the incident using Microsoft Defender XDR. Which action should you take first?

Medium
332

During an incident response, you need to collect forensic evidence from a compromised Windows device using Microsoft Defender for Endpoint live response. Which command should you use to gather running processes?

Easy
333

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. An incident is generated for a user who received a phishing email that bypassed Exchange Online Protection. The user clicked the link and entered credentials on a fake login page. The incident includes alerts from Microsoft Defender for Office 365 and Microsoft Entra ID. You need to respond to the incident. The affected user has administrative privileges. Which of the following should you do FIRST?

Easy
334

You are a security analyst for a company using Microsoft Defender XDR. An incident is detected involving a device that has been communicating with a known command-and-control (C2) server. The device is currently online and the user is active. What should you do first to contain the threat?

Medium
335

Which TWO actions are valid containment steps for a compromised user account in Microsoft Defender XDR?

Hard
336

Your organization uses Microsoft Sentinel. An incident is created from a fusion detection that combines multiple signals. You need to ensure that when the incident is resolved, all related alerts are also resolved automatically. What should you do?

Hard
337

During an incident investigation, you discover that an attacker used a legitimate account to access sensitive data in Microsoft Purview Information Protection. You need to identify what data was accessed and by whom. Which log source should you query?

Medium
338

Which THREE steps are part of the containment phase of incident response in a hybrid environment using Microsoft Defender XDR?

Hard
339

A SOC analyst is responding to a ransomware incident. The analyst identifies that the ransomware encrypted files on a file share and left a ransom note. The analyst needs to prevent the ransomware from spreading to other shares. Which action should the analyst take first?

Hard
340

Which TWO actions should you take when responding to a confirmed data exfiltration incident involving Microsoft 365? (Choose two.)

Medium
341

Which THREE are valid data connectors in Microsoft Sentinel for ingesting security events from Microsoft 365 services? (Choose three.)

Hard
342

Which THREE actions are appropriate when investigating a potential data exfiltration incident in Microsoft Defender for Cloud Apps?

Hard
343

Your organization uses Microsoft Sentinel. A new incident is created from a fusion alert that combines multiple low-severity alerts. The analyst needs to determine the entities involved. What should the analyst review?

Medium
344

A security team is investigating a ransomware incident that encrypted files on several Windows servers. Microsoft Defender for Endpoint detected the ransomware but the initial infection vector is unknown. Which KQL query in Microsoft Sentinel would BEST identify the initial process that executed the ransomware?

Hard
345

Contoso uses Microsoft Sentinel with Microsoft Defender XDR connector. You receive an incident titled 'Malware detected on endpoint' from Microsoft Defender for Endpoint. The incident includes a detailed timeline showing that the malware was downloaded from a malicious URL. You need to respond to the incident using Microsoft Sentinel and Microsoft Defender XDR capabilities. The affected device is a Windows 10 workstation used by a standard user. You have been asked to contain the threat and prevent recurrence. The organization has a policy to preserve evidence for 90 days. Which action should you take FIRST?

Medium
346

Which THREE of the following are valid incident management capabilities in Microsoft Sentinel? (Choose three.)

Hard
347

An analyst runs this advanced hunting query to investigate suspicious command-line activity. Which type of activity is this query most likely detecting?

Hard
348

Which TWO actions should an analyst take when a confirmed ransomware incident is detected on multiple endpoints? (Choose TWO.)

Medium
349

You are handling an incident where a user's account was used to access sensitive data from an unusual location. Microsoft Entra ID Identity Protection flagged the sign-in as risky. You need to determine if the account is compromised. Which investigation step should you perform first?

Hard
350

Your organization is using Microsoft Defender for Cloud to protect Azure workloads. A critical vulnerability was discovered in a virtual machine that is part of a production application. The vulnerability has a high severity score and is actively being exploited in the wild. You need to respond quickly to mitigate the risk. What is the most effective immediate action?

Hard
351

Refer to the exhibit. You are deploying this analytics rule in Microsoft Sentinel. Which activity will trigger an alert?

Easy
352

During a ransomware incident, a security analyst needs to isolate an affected Windows 10 device managed by Microsoft Intune. The device is currently online and connected to the corporate network. Which remediation action should be taken from Microsoft Defender XDR to achieve this?

Hard
353

During an incident response, your team identifies a suspicious PowerShell command executed on multiple devices. Which Microsoft Defender XDR feature should you use to block the command across all endpoints immediately?

Easy
354

You are investigating a potential malicious PowerShell execution in Microsoft Defender for Endpoint using this KQL query in Advanced Hunting. The query returns no results. What is the most likely cause?

Medium
355

Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). During an incident investigation, you identify that a user account has been exhibiting anomalous behavior, such as logging in from multiple countries within a short time. You need to determine if the account is compromised and take appropriate action. What should you do first?

Medium
356

Your organization uses Microsoft Sentinel. You are responsible for responding to incidents. A new 'MFA Denied' incident is created from Microsoft Entra ID sign-in logs, indicating that a user in your organization had multiple MFA denials from a suspicious IP address (203.0.113.5). The user is a sales representative who frequently travels. The incident severity is Medium. The incident contains entities: user 'jsmith@contoso.com', IP address 203.0.113.5, and a device running Windows 11. You need to investigate and determine if this is a true positive. The user is currently on a business trip in Europe, but the sign-in attempts originated from an IP address in a different region. What should you do first?

Medium
357

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. An incident is triggered: 'Lateral movement detected - pass-the-hash attack.' The incident includes alerts from Microsoft Defender for Identity (MDI) showing anomalous NTLM authentication attempts from a compromised workstation to multiple servers. The compromised workstation is a Windows 10 device. You need to contain the incident. Which of the following actions should you take FIRST?

Medium
358

Your organization uses Microsoft Sentinel with the Microsoft 365 Defender connector. You receive an incident indicating that a user's account was used to sign in from an unusual location (Russia) while the user is in the United States. The sign-in was successful and no MFA challenge was prompted because the user had a valid session. The incident severity is High. You need to respond immediately. What should you do first?

Medium
359

Which TWO are valid sources of evidence in a Microsoft Sentinel incident? (Choose two.)

Medium
360

A security analyst needs to contain a compromised device that is spreading malware in the network. The device is enrolled in Microsoft Intune and managed by Microsoft Defender for Endpoint. What is the fastest way to isolate the device from the network?

Easy
361

Which TWO actions should a SOC analyst take immediately after confirming a ransomware incident in Microsoft Defender XDR?

Easy
362

Your organization's Microsoft Sentinel workspace ingests logs from multiple regions. During an incident, you need to search for a specific user's activity across all workspaces in a single query. What is the most efficient way to accomplish this?

Hard
363

You are investigating a Microsoft Sentinel incident involving a user who clicked a phishing link. The incident includes alerts from Microsoft Defender for Office 365. You need to identify if any other users received the same phishing email. What should you do?

Medium
364

During an incident response, you need to collect a forensic image of a Windows 10 device managed by Microsoft Intune. Which Microsoft Defender XDR feature should you use?

Easy
365

Your team uses Microsoft Sentinel to manage incidents. You want to automatically assign incidents with a severity of 'High' to the Tier 2 security team. Which feature should you configure?

Easy
366

A security analyst is investigating a potential data exfiltration incident in Microsoft Sentinel. The analyst needs to identify which users may have been compromised. Which THREE data sources should be queried to gather the most relevant evidence?

Hard
367

Which THREE steps are part of the incident response process when using Microsoft Sentinel?

Easy
368

Wide World Importers uses Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Purview for data loss prevention (DLP). An incident is generated: 'DLP policy violation - sensitive data shared externally.' The incident shows that a user shared a document containing credit card numbers via SharePoint Online with an external guest. The user is a finance department employee. You need to respond to the incident. The organization wants to minimize business disruption while protecting data. Which of the following is the BEST immediate action?

Hard
369

You are a SOC analyst at Contoso Ltd. The company uses Microsoft Sentinel and Microsoft Defender XDR. A high-severity incident is generated from a Sentinel analytics rule that detects multiple failed logins followed by a successful login from a geographically unusual location for a user. The incident includes an alert from Microsoft Defender for Identity indicating a possible brute-force attack. The user's account is a privileged administrator. Your organization has strict compliance requirements: any privileged account compromise must be contained within 15 minutes of detection. You have the following tools available: Microsoft Entra ID with Privileged Identity Management (PIM), Microsoft Defender for Cloud Apps, and Microsoft 365 Defender automation rules. The incident is now 5 minutes old. What should you do to meet the compliance requirement?

Hard
370

During a ransomware incident, you need to prevent the encryption of files in SharePoint Online and OneDrive for Business. You have already identified the compromised user account. What should you do?

Easy
371

You are investigating an incident where a user reported receiving a suspicious email with a malicious attachment. Microsoft Defender for Office 365 did not block it. The email originated from a known malicious sender domain. What configuration should you check first?

Hard
372

Refer to the exhibit. You are configuring a Microsoft Sentinel scheduled analytics rule with the above incident creation settings. What is the effect of setting 'groupingConfiguration.enabled' to false?

Easy
373

You are investigating a low-severity incident in Microsoft Sentinel where a user reported receiving a phishing email. The email was not blocked by the email security solution. The user did not click any links. What should you do first?

Easy
374

During a security incident, a Microsoft Sentinel analytics rule generated an alert for a suspicious sign-in from an unusual location. The incident involves a user whose account has been compromised. The security team needs to take immediate actions to remediate and prevent further damage. Which THREE actions should the security team prioritize?

Hard
375

Which TWO actions should you take when handling a confirmed ransomware incident in an environment protected by Microsoft Defender for Endpoint?

Medium

Frequently asked questions

What does the Respond to security incidents domain cover on the SC-200 exam?
You must be able to triage and remediate incidents using Microsoft Sentinel and Defender XDR. The most important thing is to correctly use automation rules and playbooks to contain threats without disrupting legitimate business operations.
How many questions are in this domain?
This page lists all 375 Respond to security incidents questions in the SC-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Respond to security incidents questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
sc-200 SC-200 respond security incidents Practice Questions