Courseiva

CCNA Respond to security incidents Questions

75 of 375 questions · Page 2/5 · Respond to security incidents · Answers revealed

76
MCQeasy

A SOC analyst receives a phishing alert in Microsoft Defender for Office 365. The analyst needs to quickly determine if any users clicked the malicious link. Which action should the analyst take first?

A.Use Threat Explorer to search for the email subject
B.Open the user entity page for each recipient
C.Open the email entity page to view click details
D.Run a hunting query in Microsoft Sentinel
AnswerC

The email entity page is the correct destination because it consolidates the full message record from Microsoft Defender for Office 365, including delivery status, threat name, detection technology, and the recipient-specific URL click verdict. Its Click details section explicitly indicates whether each intended recipient clicked the link, whether the click was allowed or blocked, and the time of the click, which is exactly the evidence needed to assess the impact of a phishing alert. This page is purpose-built for single-message triage and provides near-instant visibility without requiring a custom query or cross-referencing multiple data sources.

Why this answer

The email entity page in Microsoft Defender for Office 365 provides detailed information about a specific email, including click verdicts for any URLs contained within. This allows the analyst to quickly see if any users clicked the malicious link. Option A (Threat Explorer) can also be used, but it requires more steps to filter for the specific email and then view click details.

Option B (user entity page) shows user-specific activities and alerts, but not email-specific click details. Option D (hunting query in Microsoft Sentinel) is effective but slower than directly viewing the email entity page in Defender for Office 365.

77
MCQeasy

You are investigating a brute force attack on a user account in Microsoft Entra ID. The sign-in logs show multiple failed attempts from different IP addresses. Which property in the sign-in logs indicates the type of authentication used?

A.riskEventTypes
B.conditionalAccessStatus
C.clientAppUsed
D.authenticationRequirement
AnswerD

authenticationRequirement is a sign-in log property that directly specifies the authentication strength required for the sign-in, such as singleFactorAuthentication or multiFactorAuthentication. In a brute force scenario, checking this field helps you determine whether the attacker only needed a valid password or whether they also had to satisfy an MFA challenge to succeed. This is the right field to inspect because it answers the exact question of which authentication type was used to access the account.

Why this answer

The `authenticationRequirement` property in Microsoft Entra ID sign-in logs specifies the type of authentication used for the sign-in attempt, such as single-factor authentication (password), multi-factor authentication, or passwordless authentication. In a brute force attack investigation, this property helps determine whether the failed attempts were against password-based authentication or a more secure method, providing critical context for the attack vector.

Exam trap

The trap here is that candidates confuse `clientAppUsed` (which describes the application or client type) with the authentication method, but `clientAppUsed` only indicates the client software (e.g., 'Browser' or 'Mobile Apps and Desktop clients') and not the underlying authentication protocol or factor.

How to eliminate wrong answers

Option A is wrong because `riskEventTypes` indicates the risk events detected during sign-in (e.g., impossible travel, anonymous IP) and does not specify the authentication type used. Option B is wrong because `conditionalAccessStatus` shows whether Conditional Access policies were applied or satisfied, not the authentication method. Option C is wrong because `clientAppUsed` identifies the client application (e.g., browser, mobile app, legacy authentication) but does not indicate the type of authentication (e.g., password, MFA, certificate).

78
MCQhard

Your organization uses Microsoft Sentinel as its SIEM and Microsoft Defender XDR for endpoint detection. A critical incident has been generated: 'Possible ransomware activity detected on multiple endpoints.' The incident includes alerts from Microsoft Defender for Endpoint (MDE) about file encryption behaviors and from Microsoft Defender for Identity (MDI) about anomalous service account logins. You have been assigned the incident and need to contain the threat effectively. You have Microsoft Sentinel automation rules that can trigger playbooks, and you have Microsoft Defender XDR actions available. The environment includes 500 Windows 10 devices managed by Microsoft Intune, and 50 servers on-premises. Some servers are domain controllers. Which of the following is the BEST first course of action?

A.Disable all compromised service accounts in Microsoft Entra ID and reset their passwords.
B.Reset passwords for all domain administrator accounts and enforce MFA.
C.Trigger a Microsoft Sentinel playbook to collect forensic evidence from affected endpoints before remediation.
D.Isolate the affected devices using Microsoft Defender for Endpoint device isolation.
AnswerD

Device isolation via Microsoft Defender for Endpoint immediately cuts network communication while preserving forensic evidence, halting ransomware spread across endpoints. It addresses the active encryption behaviour first, before investigating the MDI service account logins, containing the threat fastest.

Why this answer

For active ransomware encrypting files across multiple endpoints, the priority is to stop the spread immediately. Microsoft Defender for Endpoint device isolation cuts network communication while preserving the Defender sensor channel for investigation, containing the threat before lateral movement or further encryption. Forensic collection and account remediation are important but secondary to stopping active encryption.

Exam trap

SC-200 often tests the order of incident response phases — candidates pick forensic collection or account resets because they sound thorough, but containment (isolation) must come first to stop active encryption.

How to eliminate wrong answers

Option A is wrong because disabling service accounts is a remediation step that does not stop active file encryption on endpoints and may disrupt legitimate services. Option B is wrong because resetting domain admin passwords and enforcing MFA is a broad identity hardening step, not immediate containment of endpoint ransomware. Option C is wrong because collecting forensic evidence before remediation allows the ransomware to continue encrypting and spreading, violating containment-first incident response.

79
Multi-Selectmedium

Which TWO of the following are valid sources for creating incidents in Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Hunting query results
B.Microsoft 365 Defender alerts
C.Analytics rule triggering
D.Workbook creation
E.Playbook execution
AnswersB, C

Microsoft 365 Defender alerts are a legitimate incident source when you have the Microsoft 365 Defender data connector enabled in Sentinel. This connector automatically ingests high-fidelity alerts from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. The connector's incident creation setting then creates an incident each time one of these alerts is ingested, plus any related alerts are grouped into the same incident.

Why this answer

Microsoft 365 Defender alerts are a valid source for creating incidents in Microsoft Sentinel because Sentinel can ingest alerts from Microsoft 365 Defender (which includes Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps) via the Microsoft 365 Defender connector. When these alerts are ingested, Sentinel can automatically create incidents based on them, enabling unified incident management across the Microsoft security ecosystem.

Exam trap

The trap here is that candidates often confuse 'hunting query results' with analytics rule results, but hunting queries are ad-hoc investigations that do not automatically generate incidents, whereas analytics rules are scheduled detections that do.

80
MCQeasy

You are investigating an incident in Microsoft Sentinel where a user account was used to sign in from an unfamiliar location and then accessed multiple sensitive files. Which step is most important to perform first?

A.Block the IP address of the unfamiliar location.
B.Check firewall logs for related network traffic.
C.Review file permissions on the accessed files.
D.Disable the user account and reset the password.
AnswerD

Disabling the account and resetting the password immediately contains the active compromise, satisfying the stem's priority of stopping ongoing malicious access before deeper forensic scoping. This neutralises the attacker's session and credentials, preventing further sensitive file exfiltration while investigation continues in Microsoft Sentinel.

Why this answer

Confirming account compromise and immediately disabling the user account is the highest priority to stop further malicious activity. Resetting the password prevents the attacker from using the compromised credentials. Option A is incorrect because blocking the IP address alone may be ineffective if the attacker uses proxies, and it does not secure the account.

Option B is incorrect because checking firewall logs is a secondary forensic step that does not address the immediate threat. Option C is incorrect because reviewing file permissions should be done after securing the account.

81
MCQmedium

You are testing this analytics rule. It should detect encoded PowerShell commands not from System32, but it is generating false positives. What is the most likely cause?

A.The severity should be Informational
B.The rule should also include System32
C.The query syntax is incorrect
D.The rule does not exclude other legitimate paths like SysWOW64
AnswerD

The rule flags encoded PowerShell outside System32, but legitimate 32-bit processes launch from SysWOW64, which the path exclusion omits. Adding SysWOW64 to the exclusion list removes those benign executions, addressing the false positives described in the stem.

Why this answer

The rule is designed to detect encoded PowerShell commands not originating from System32, but it is generating false positives. The most likely cause is that the rule does not exclude other legitimate paths such as SysWOW64, which also contains legitimate PowerShell executables on 64-bit Windows. Adding an exclusion for SysWOW64 (and possibly other trusted paths) would reduce false positives while maintaining detection of suspicious executions.

Exam trap

The trap is assuming the rule is broken or misconfigured when the real issue is incomplete tuning — candidates may overlook that SysWOW64 is a legitimate path that must be excluded alongside System32.

How to eliminate wrong answers

Option A is wrong because changing severity to Informational does not address the false positives; it only changes the alert priority. Option B is wrong because including System32 would broaden the rule and likely increase false positives, not reduce them. Option C is wrong because if the query syntax were incorrect, the rule would fail to run or produce errors, not generate false positives.

82
MCQhard

Your organization uses Microsoft Defender for Cloud to monitor hybrid workloads. You receive an alert that a fileless malware attack was detected on an on-premises server connected via Azure Arc. The server is running Windows Server 2019. What is the BEST action to contain the threat?

A.Apply a security update using Azure Update Manager.
B.Run a script via Azure Arc to disable the network interfaces on the server.
C.Use Azure Automation runbook to restart the server.
D.Uninstall the Azure Arc agent from the server to isolate it.
AnswerB

Running a script via Azure Arc to disable the network interfaces is a network-based containment action that immediately cuts off all inbound and outbound traffic on the server. By using the Azure Arc 'Run Command' or a custom script extension, the server's NICs are brought down, which blocks data exfiltration, lateral movement, and command-and-control communication with the attacker's infrastructure. This preserves the machine in its current state for forensic analysis while the fileless malware is isolated from the rest of the network. It is an effective first response because it neutralizes the attacker's ability to communicate without disabling management channels.

Why this answer

Disabling the network interfaces via Azure Arc immediately cuts off the compromised server's network connectivity, preventing lateral movement or data exfiltration by the fileless malware. Since fileless malware operates in memory and may not leave persistent artifacts, containment via network isolation is the fastest and most effective initial response.

Exam trap

The trap here is that candidates confuse 'containment' with 'remediation' and choose a long-term fix like patching or restarting, rather than the immediate network isolation required to stop an active fileless attack.

How to eliminate wrong answers

Option A is wrong because applying a security update does not contain an active fileless malware attack; it only patches vulnerabilities for future prevention. Option C is wrong because restarting the server may temporarily disrupt the malware but does not prevent it from re-executing on reboot, and it could also destroy volatile evidence in memory. Option D is wrong because uninstalling the Azure Arc agent does not isolate the server; it only removes management connectivity, leaving the server still accessible on the network and the malware active.

83
Multi-Selectmedium

A security analyst is investigating a potential ransomware incident in Microsoft Defender XDR. The analyst needs to confirm the scope of the attack and halt further propagation. Which TWO actions should the analyst take first?

Select 2 answers
A.Initiate automated investigation on the affected devices
B.Reset passwords for all users in the organization
C.Collect forensic evidence from affected systems
D.Isolate the affected devices from the network
E.Run a full antivirus scan on all endpoints
AnswersA, D

Microsoft Defender for Endpoint's automated investigation leverages behavioral analytics and threat intelligence to immediately scope a ransomware incident, identifying all affected files, processes, and user accounts in parallel while containing the threat. Because it executes investigation playbooks automatically and can trigger containment actions such as device isolation or indicator blocking, it is faster than manual triage and preserves forensic context for the incident graph. Initiating automated investigation is the recommended first step in Defender for Endpoint because it converts a suspected outbreak into a scoped, machine-readable set of evidence.

Why this answer

Initiating automated investigation on affected devices (A) is correct because Microsoft Defender XDR's automated investigation uses built-in playbooks to automatically analyze alerts, determine the scope of compromise, and suggest remediation actions without manual intervention. This is the fastest way to confirm the attack scope while simultaneously halting propagation. Isolating affected devices (D) is correct because network isolation immediately cuts off communication between the compromised device and other systems, preventing lateral movement and further encryption of network shares.

Both actions are first-response steps in a ransomware incident.

Exam trap

The SC-200 exam often tests the distinction between containment-first vs. investigation-first; the trap here is that candidates may choose 'collect forensic evidence' (C) thinking it is necessary before isolation, but in a ransomware scenario, stopping propagation is the immediate priority, and forensic collection can be done after isolation.

84
MCQhard

An analyst creates a playbook in Microsoft Sentinel to automatically block an IP address when an alert fires. However, the playbook fails to block the IP. What is the most likely cause?

A.The IP address is being extracted from an incorrect field in the alert
B.The block duration is set to one day, which is too short
C.The playbook actions array has only one action, which is insufficient
D.The playbook is using the wrong trigger type; it should be on incident creation
AnswerA

The playbook is correctly triggered but fails because it references 'alertRuleId' as the IP address. In Sentinel alert payloads, alertRuleId is merely the identifier of the analytics rule that generated the alert, not a network entity. The IP address must be extracted from the 'Entities' collection of the incident, specifically from an entity with type 'IP' (e.g., Entities.IP.address). Passing a non-IP string to a block action causes input validation failure, so the playbook cannot block the address.

Why this answer

The most likely cause is that the playbook is extracting the IP address from an incorrect field in the alert. In Microsoft Sentinel, playbooks use the SecurityAlert schema, where the IP address may be stored in different fields (e.g., 'RemoteIP', 'SourceIP', 'DestinationIP') depending on the alert provider. If the playbook references the wrong field, it will pass a null or incorrect value to the block action, causing the automation to fail silently or target the wrong entity.

Exam trap

The trap here is that candidates assume the playbook trigger or action count is the problem, when the real issue is data extraction from the alert schema—a common oversight in automation workflows.

How to eliminate wrong answers

Option B is wrong because a block duration of one day is not inherently too short; the playbook would still execute the block action successfully for that duration, so duration does not cause the failure. Option C is wrong because a playbook actions array can contain a single action and still function correctly; there is no minimum number of actions required for execution. Option D is wrong because the playbook trigger type should be on alert creation (when the alert fires), not on incident creation; using incident creation would delay or miss the automated block, but the question states the playbook fails to block the IP, implying the trigger is not the root cause—the extraction logic is.

85
MCQeasy

You are reviewing an incident in Microsoft Sentinel. The incident is assigned to a user. What does the 'assignedTo' field indicate?

A.The incident was created by that user.
B.The incident was closed by that user.
C.The incident is assigned to that user for investigation.
D.The incident is assigned to a Microsoft Entra group.
AnswerC

In Microsoft Sentinel, the 'Owner' field (also displayed as 'Assigned to' in the incident details) identifies the single user who is currently responsible for investigating and managing the incident. When a user's name appears in this field, it means that user has been assigned the incident, either manually through the 'Assign owner' button or automatically via an automation rule. This assignment is used for tracking ownership, routing work, and reporting on investigation progress, and it is the direct answer to the question of who is handling the incident. Therefore, a user in that field indicates the incident is assigned to that user for investigation.

Why this answer

In Microsoft Sentinel, the 'assignedTo' field is used to track ownership of an incident during its lifecycle. When an incident is assigned to a user, it indicates that user is responsible for investigating and resolving the incident, not that they created or closed it. This field is set manually or via automation rules to ensure clear accountability for incident response.

Exam trap

The trap here is that candidates confuse 'assignedTo' with 'createdBy' or 'closedBy', assuming ownership implies creation or closure, but Sentinel separates these fields to track distinct stages of the incident lifecycle.

How to eliminate wrong answers

Option A is wrong because the 'assignedTo' field does not indicate who created the incident; the 'createdBy' field tracks the creator (e.g., an analytics rule or a user). Option B is wrong because the 'assignedTo' field does not indicate who closed the incident; the 'closedBy' field records the user who resolved it. Option D is wrong because the 'assignedTo' field in Sentinel incidents is a single user (a string value representing a user principal name), not a Microsoft Entra group; group assignment is not supported for incident ownership.

86
Multi-Selectmedium

Which TWO data sources should you enable in Microsoft Sentinel to improve detection of credential theft attacks?

Select 2 answers
A.Windows Security Events (via AMA)
B.DNS logs
C.Azure Active Directory Sign-in logs
D.Windows Firewall logs
E.Performance counters
AnswersA, C

Windows Security Events via AMA stream logon events such as 4624, 4625 and 4672, which expose brute-force, pass-the-hash and privilege-escalation patterns. Ingesting these satisfies the credential-theft detection requirement by feeding Sentinel analytics rules that correlate suspicious authentication behaviour on Windows hosts.

Why this answer

Option A, Windows Security Events (via AMA), is correct because it collects the Security event log through the Azure Monitor Agent and surfaces the exact events credential-theft detection relies on, such as 4624/4625 logons, 4648 explicit-credential use, 4672 special privileges, and 4768/4769 Kerberos TGT/TGS requests used to spot pass-the-hash, pass-the-ticket, and Kerberoasting. Option C, Azure Active Directory Sign-in logs, is correct because it captures Entra ID authentication telemetry — sign-in results, conditional access outcomes, MFA details, and risk detections — which Sentinel uses to detect password spray, brute force, impossible travel, and token/session theft against cloud identities. Option B, DNS logs, is not required here since DNS telemetry supports exfiltration, C2, and DGA detection rather than credential theft.

Option D, Windows Firewall logs, records allowed/blocked network connections and is irrelevant to authentication abuse. Option E, Performance counters, provides host resource metrics and has no bearing on detecting stolen credentials.

Exam trap

SC-200 often tests whether candidates confuse network-layer telemetry (DNS, firewall) with identity-layer telemetry, causing them to pick sources that detect lateral movement rather than credential theft.

87
MCQhard

During a ransomware incident, Microsoft Sentinel generated an incident with high severity. The incident includes alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Entra ID. Your team needs to automate the containment process. What is the best approach to automatically isolate affected devices and disable compromised accounts?

A.Use advanced hunting to find all affected devices and accounts
B.Create an automation rule in Microsoft Sentinel that runs a playbook to isolate devices and disable accounts
C.Create a custom detection rule in Microsoft Sentinel to trigger an incident
D.Configure automated investigation and response in Microsoft Defender for Endpoint
AnswerB

An automation rule triggers a playbook on incident creation, and the playbook calls Defender for Endpoint and Microsoft Entra ID actions to isolate devices and disable accounts. This satisfies the containment requirement without manual intervention.

Why this answer

The best approach is to create an automation rule in Microsoft Sentinel that triggers a playbook to isolate devices and disable accounts. Automation rules can be configured to run playbooks automatically when an incident is created, and the playbook can call Microsoft Defender for Endpoint to isolate devices and Microsoft Entra ID to disable accounts. This provides a centralized, automated containment workflow across multiple sources.

Exam trap

SC-200 often tests the difference between detection (creating incidents) and response (automation rules/playbooks), and candidates may incorrectly choose Defender for Endpoint AIR because it only covers endpoints, not the multi-domain incident.

How to eliminate wrong answers

Option A is wrong because advanced hunting is a manual query tool for investigation, not an automated containment mechanism; it does not isolate devices or disable accounts. Option C is wrong because creating a custom detection rule only generates incidents; it does not perform containment actions. Option D is wrong because configuring automated investigation and response in Defender for Endpoint only covers endpoint devices and does not disable Entra ID accounts, and it is limited to the Defender for Endpoint scope, not the multi-source incident in Sentinel.

88
MCQeasy

You are investigating a security incident in Microsoft Sentinel. You want to visualize the relationships between entities such as IP addresses, users, and hosts. Which tool should you use?

A.Investigation graph
B.Analytics rules
C.Automation rules
D.Workbooks
AnswerA

The investigation graph in Microsoft Sentinel renders entities such as IP addresses, users and hosts as connected nodes, exposing relationships and lateral movement paths visually. This satisfies the requirement to visualise entity relationships during incident investigation, unlike log queries or workbooks.

Why this answer

The Investigation graph in Microsoft Sentinel is specifically designed to visualize relationships between entities such as IP addresses, users, and hosts, making it the correct tool for this task. Analytics rules (B) are used for detection, automation rules (C) for automated responses, and workbooks (D) for dashboards and reporting, not for entity relationship visualization.

89
MCQeasy

An organization uses Microsoft Defender for Cloud Apps to detect anomalous behavior. An alert indicates that a user has signed in from an impossible travel scenario. The SOC analyst confirms the alert is a false positive due to a VPN. What should the analyst do to prevent future false positives for this user?

A.Change the user's location in Microsoft Entra ID.
B.Ignore the alert and continue monitoring.
C.Disable the impossible travel detection rule.
D.Add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps.
AnswerD

Adding the VPN IP range to Defender for Cloud Apps trusted IP addresses suppresses impossible-travel detections originating from those addresses, since the engine treats trusted ranges as known-good locations. This directly addresses the confirmed false positive caused by VPN egress, preventing recurrence for this user without disabling the detection policy itself.

Why this answer

The correct action is to add the VPN IP range to the trusted IP addresses in Defender for Cloud Apps (D). Trusted IP addresses are excluded from impossible travel and other anomalous location detections, so legitimate VPN egress IPs will not trigger false positives. This is a targeted, user-impacting fix that preserves detection for other scenarios.

Changing Entra ID location or disabling the rule are not appropriate.

Exam trap

SC-200 often tests the misconception that changing a user's location in Entra ID or disabling the detection rule is the right fix — the correct scoped remediation is adding the VPN IP range to trusted IP addresses in Defender for Cloud Apps.

How to eliminate wrong answers

Option A is wrong because changing the user's location in Microsoft Entra ID does not affect Defender for Cloud Apps impossible travel detection; that detection uses its own IP geolocation and does not rely on the Entra ID user location attribute. Option B is wrong because ignoring the alert and continuing to monitor does not prevent future false positives; the same VPN IP will keep triggering alerts, creating alert fatigue. Option C is wrong because disabling the impossible travel detection rule entirely would suppress all impossible travel alerts, including true positives, weakening security posture — the fix should be scoped to the trusted VPN IP range.

90
MCQmedium

You deploy this ARM template to a Microsoft Sentinel workspace. After deployment, you notice that the saved search does not appear as an analytics rule. What is the most likely reason?

A.The tags are incorrectly formatted.
B.The resource type is 'savedSearches', not 'scheduledQueryRules' or 'alertRules'.
C.The API version is incorrect.
D.The KQL query syntax is invalid.
AnswerB

A Microsoft Sentinel analytics rule must be deployed using either 'Microsoft.OperationalInsights/workspaces/scheduledQueryRules' (for scheduled rules) or 'Microsoft.SecurityInsights/alertRules' (the Sentinel-native provider). The template declares 'Microsoft.OperationalInsights/workspaces/savedSearches', which only stores a KQL query in the Log Analytics workspace and does not trigger any alert or incident logic. Because the resource type is wrong, nothing appears under the Analytics Rules blade in Sentinel; this is the root cause of the deployment's apparent failure.

Why this answer

In Azure Resource Manager, the resource type determines what kind of object is created. A 'savedSearches' resource creates a saved search query in Log Analytics/Sentinel, which is a reusable query definition — not an analytics rule. Analytics rules in Microsoft Sentinel are created using the 'scheduledQueryRules' resource type (or the older 'alertRules' type).

Therefore, even though the template deployed successfully, the saved search will never appear as an analytics rule because it is a fundamentally different resource type.

Exam trap

SC-200 often tests the distinction between saved searches and analytics rules in ARM templates, trapping candidates who assume any query resource will automatically become an analytics rule.

How to eliminate wrong answers

Option A is wrong because tags are metadata and do not affect the resource type or whether a saved search becomes an analytics rule; misformatted tags would not prevent the resource from being created as a saved search. Option C is wrong because an incorrect API version would typically cause a deployment error or use a different schema, but it would not change the fundamental resource type from savedSearches to scheduledQueryRules. Option D is wrong because invalid KQL syntax would cause the query to fail at runtime or during validation, but it would not change the resource type; the resource would still be a saved search, not an analytics rule.

91
MCQeasy

You are a Security Operations Analyst using Microsoft Sentinel. An incident has been created from an analytics rule. You need to assign the incident to a specific analyst and change its status to 'Active' so that it appears in their queue. Which action should you perform in the Microsoft Sentinel incident page?

A.Create a new automation rule to set the owner and status
B.Edit the incident's tags to include the analyst's name
C.Use the 'Assign to' field and set the status to 'Active'
D.Modify the analytics rule that generated the incident
AnswerC

The incident page in Microsoft Sentinel provides fields for owner (Assign to) and status (New, Active, Closed). Setting the owner to the specific analyst and changing the status to Active assigns the incident and moves it into the active workflow, making it appear in their queue. This directly fulfills the requirement to assign and activate the incident for the analyst.

Why this answer

In Microsoft Sentinel, incident assignment and status are managed directly on the incident page. The 'Assign to' field sets the owner, and the status field (New, Active, Closed) controls the workflow state. Setting both assigns the incident to the analyst and marks it Active, ensuring it appears in their queue.

Other actions like tagging or modifying rules do not achieve the required assignment and activation.

Exam trap

The trap here is thinking that tags or automation rules are needed for manual assignment; the incident page itself has direct fields for owner and status.

92
MCQmedium

Refer to the exhibit. The KQL query is used in a Microsoft Sentinel scheduled alert rule. What scenario does this query detect?

A.Multiple MFA denial events from a single user.
B.Brute force attacks against Azure AD accounts using invalid passwords.
C.Attempts to sign in with disabled user accounts.
D.Brute force attacks from a single IP address against multiple accounts.
AnswerC

This is correct because Azure AD returns ResultType 50057 specifically when a user attempts to sign in with an account that has been disabled by an administrator. The KQL query filtering on this ResultType will surface every such attempt, regardless of whether the provided password is accurate. Disabled accounts cannot authenticate at all, so these events represent a clear account-state failure rather than a credential mismatch.

Why this answer

The KQL query filters for `ResultType == 50057`, which specifically indicates a sign-in attempt by a disabled user account in Azure AD. This result type is unique to disabled accounts and does not cover MFA denials (53003), invalid password attempts (50126), or brute force patterns. Therefore, the query detects attempts to sign in with disabled user accounts.

Exam trap

The trap here is that candidates confuse the generic 'sign-in failure' concept with the specific `ResultType` code 50057, assuming any failure could indicate brute force or MFA issues, when in fact each code maps to a distinct Azure AD error condition.

How to eliminate wrong answers

Option A is wrong because MFA denial events are identified by `ResultType == 53003` (MFA challenge failed or denied), not 50057. Option B is wrong because brute force attacks using invalid passwords are detected by `ResultType == 50126` (invalid username or password), not 50057. Option D is wrong because brute force attacks from a single IP against multiple accounts would require aggregation on `IPAddress` and `UserPrincipalName` fields, not a simple filter on `ResultType == 50057`.

93
MCQeasy

Your organization uses Microsoft Sentinel for security operations. The SOC team receives an incident that was generated from a Microsoft Defender for Cloud Apps alert. The incident involves a user who is downloading a large number of files from SharePoint Online. The analyst needs to suspend the user's account immediately to stop the potential data exfiltration. The organization has a Microsoft Sentinel playbook that can suspend a user in Microsoft Entra ID. However, the playbook is not triggering automatically. You need to ensure that the playbook runs automatically whenever a Defender for Cloud Apps alert generates an incident in Sentinel. What should you configure?

A.Create an automation rule that triggers the playbook when an incident is created from Defender for Cloud Apps
B.Create a scheduled analytics rule that detects large file downloads
C.Enable the Microsoft Defender for Cloud Apps connector to sync alerts
D.Modify the playbook to run on alert creation
AnswerA

Automation rules in Microsoft Sentinel evaluate incident creation and can invoke a playbook conditionally. Scoping the trigger to incidents whose alert product is Defender for Cloud Apps ensures the suspend-user playbook runs automatically on those incidents.

Why this answer

An automation rule can be created to trigger a playbook on incident creation, specifically filtering for incidents from Defender for Cloud Apps. This enables automatic execution of the playbook to suspend the user. Option B is incorrect because a scheduled analytics rule is for generating alerts based on queries, not for triggering playbooks on existing incidents.

Option C is incorrect because enabling the connector only syncs alerts, but does not automatically run playbooks; an automation rule is required. Option D is incorrect because the playbook's trigger is configured in the automation rule, not by modifying the playbook itself.

94
Multi-Selecthard

Your organization uses Microsoft Sentinel. A new analytics rule is needed to detect brute-force attacks against your Azure SQL databases. The rule should minimize false positives and trigger only when multiple failed logins occur from a single IP address within a short time window. Which THREE components are essential for building this rule?

Select 3 answers
A.An alert threshold set to trigger when the count exceeds 10 failed attempts in 5 minutes.
B.A reference to the SQLInsights table for performance data.
C.A summarize operator in KQL to count failed login attempts per IP address within a timebin.
D.A KQL query against the AzureDiagnostics table filtering for failed login events.
E.A watchlist containing known malicious IP addresses.
AnswersA, C, D

This threshold is a critical component of the rule's alert trigger condition because requiring more than 10 failed sign-ins within a 5-minute window filters out isolated, routine authentication errors while still catching high-volume brute-force patterns. In Sentinel, this is configured in the Threshold field of the analytics rule, and it complements the KQL aggregation by determining when the query's aggregate results should actually generate an incident.

Why this answer

Setting an alert threshold to trigger when the count exceeds 10 failed attempts in 5 minutes directly reduces false positives by requiring a meaningful number of failures before alerting. This threshold aligns with common brute-force detection patterns, ensuring the rule only fires when there is a high likelihood of an actual attack rather than occasional user errors.

Exam trap

The trap here is that candidates may think a watchlist of known malicious IPs (option E) is necessary for detection, but brute-force rules should detect patterns from any IP, not just pre-listed ones, and the SQLInsights table (option B) is a distractor because its name sounds relevant but it lacks authentication event data.

95
MCQmedium

Your organization uses Microsoft Sentinel with Microsoft Defender XDR integration. You have a scheduled analytics rule that detects failed logon attempts across multiple on-premises domain controllers. The rule is configured to run every 5 minutes and create an incident when more than 10 failed attempts occur from a single IP address within 5 minutes. Recently, the SOC team noticed that the rule is generating a high volume of low-fidelity incidents, mostly from legitimate users mistyping passwords. You need to reduce the number of false positive incidents while still detecting real brute-force attacks. What should you do?

A.Increase the query frequency to every 1 minute and reduce the threshold to 5.
B.Modify the query to require at least 20 failed attempts from a single IP and include a condition that the attempts are against multiple user accounts.
C.Disable the rule and create a new rule based on successful logons followed by failed attempts.
D.Decrease the threshold to 5 and add a condition to exclude known good IP addresses.
AnswerB

Requiring at least 20 failed attempts from a single IP together with the condition that those attempts target multiple user accounts directly targets deterministic password-spray behavior while filtering out a single user's accidental mistypes. A single IP sending many failures against many distinct accounts is a strong signal for credential stuffing or password spraying, whereas failures against one account are commonly caused by a user forgetting a password. This tuning raises the confidence level of the alert without compromising detection of sustained attacks.

Why this answer

The correct approach is to tune the analytics rule to be more specific: raising the threshold to 20 failed attempts and requiring attempts against multiple user accounts filters out single-user password mistypes while still catching brute-force attacks that spray across accounts. This directly reduces false positives without losing detection fidelity.

Exam trap

SC-200 often tests the misconception that simply lowering thresholds or increasing frequency improves detection, when in fact it amplifies false positives; candidates must recognize that adding specificity (multi-account condition) is the correct tuning strategy.

How to eliminate wrong answers

Option A is wrong because increasing frequency to 1 minute and lowering the threshold to 5 would generate even more low-fidelity incidents, worsening the false positive problem. Option C is wrong because disabling the rule and switching to successful-then-failed logons misses the brute-force pattern entirely and creates a detection gap. Option D is wrong because lowering the threshold to 5 increases noise, and excluding known good IPs only partially helps while still missing the multi-account brute-force signal.

96
Multi-Selecthard

Your organization uses Microsoft Sentinel and has configured analytics rules for detecting ransomware. You receive an alert indicating possible ransomware activity on a server. Which THREE actions should you take to contain and investigate the incident? (Choose three.)

Select 3 answers
A.Create a new analytics rule to detect similar behavior.
B.Initiate a live response session to collect forensic artifacts.
C.Review the incident timeline in Microsoft 365 Defender.
D.Reset the password of the account that showed anomalous behavior.
E.Isolate the server from the network using Microsoft Defender for Endpoint.
AnswersB, C, E

Live response connects directly to the affected endpoint, allowing collection of volatile forensic artifacts such as memory, running processes and network connections before they are lost. This satisfies the investigation requirement, gathering evidence needed to determine ransomware scope and persistence mechanisms.

Why this answer

Option B is correct because initiating a live response session in Microsoft Defender for Endpoint lets you run forensic commands (e.g., getfile, analyze, run) on the affected server to collect volatile artifacts such as memory, running processes, and network connections for investigation. Option C is correct because Microsoft Sentinel incidents are integrated with Microsoft 365 Defender, so reviewing the incident timeline provides correlated alerts, entities, and investigation data across endpoints, identities, and email to understand the attack scope. Option E is correct because isolating the server via Microsoft Defender for Endpoint network isolation blocks inbound/outbound traffic (except for Defender communication) to stop ransomware propagation while preserving the ability to investigate.

Option A is not appropriate during containment/investigation because creating a new analytics rule is a detection-engineering task, not an incident response action. Option D is not appropriate because resetting the password of the anomalous account is a remediation step that may destroy evidence and does not contain the server-based ransomware activity.

Exam trap

The SC-200 exam often tests the distinction between detection tuning and incident response, and candidates may choose to create new analytics rules or reset passwords instead of taking immediate containment actions like isolation.

97
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR (including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps). You have an incident response team that operates 24/7. Recently, there have been multiple incidents involving users receiving phishing emails that lead to credential theft. The phishing emails are sophisticated and bypass Exchange Online Protection (EOP) and Defender for Office 365's built-in phishing filters. The emails contain links to fake login pages that harvest credentials. Once credentials are stolen, the attacker uses them to sign in from anonymous IP addresses and attempts to access sensitive data in SharePoint Online. You need to design a response strategy that includes automated containment and investigation. The solution must: - Automatically disable user accounts when a phishing incident is confirmed. - Automatically trigger an investigation into the user's activity in Microsoft Defender for Cloud Apps. - Send a notification to the incident response team with a summary of the incident. - Minimize manual effort. You have the following components available: - Microsoft Sentinel with automation rules and playbooks. - Microsoft Defender XDR with advanced hunting. - Microsoft Power Automate. What is the most efficient way to achieve these requirements?

A.Use Microsoft Defender XDR's automated investigation and response (AIR) to automatically disable the user account.
B.Create a playbook in Microsoft Sentinel that uses the Microsoft Graph API to disable the user account in Microsoft Entra ID, trigger an investigation in Microsoft Defender for Cloud Apps, and send an email notification. Associate the playbook with an automation rule that runs when the incident is created.
C.Create an automation rule in Microsoft Sentinel that triggers a webhook to a third-party system, which then disables the user account.
D.Configure a Playbook in Power Automate that monitors Microsoft Sentinel incidents and automatically disables the user account.
AnswerB

This fully automates containment, investigation, and notification.

Why this answer

Creating a playbook in Microsoft Sentinel that uses the Microsoft Graph API to disable the user in Microsoft Entra ID, triggers an investigation in Defender for Cloud Apps, and sends an email notification, then associating it with an automation rule that runs automatically when the incident is created, meets all requirements with minimal manual effort. Option B is correct because it enables automated containment and investigation without manual intervention. Option A is incorrect because Microsoft Defender XDR's automated investigation and response (AIR) does not automatically disable user accounts across all services; it focuses on endpoint remediation.

Option C is incorrect because relying on a third-party system via webhook introduces additional complexity and may not integrate seamlessly with Microsoft tools. Option D is incorrect because while Power Automate can be used, creating a playbook directly in Microsoft Sentinel is more tightly integrated and efficient for incident response workflows.

98
MCQhard

During a security incident, you need to create a custom detection rule in Microsoft Sentinel to alert on multiple failed logins followed by a successful login from the same IP within 10 minutes. Which KQL function should you use to group events by IP address and time window?

A.join
B.extend
C.project
D.summarize
AnswerD

The summarize operator aggregates rows into groups defined by your chosen dimensions, letting you bin events by IP address and a ten-minute time bucket, then apply count() and threshold logic to detect the failed-then-successful pattern within the required window.

Why this answer

The `summarize` operator is the correct choice because it groups events by one or more columns (e.g., IP address) and performs aggregations over a defined time window. In this scenario, you need to count failed logins and then check for a subsequent successful login within 10 minutes from the same IP, which requires grouping by IP and time. `summarize` allows you to use `bin()` on a timestamp to create time buckets, enabling the detection of multiple failed logins followed by a success within that window. This is the standard KQL approach for time-based correlation in Microsoft Sentinel.

Exam trap

SC-200 often tests the misconception that `join` is needed for correlating events, but the question specifically asks for grouping by IP and time window, which is the core purpose of `summarize`.

How to eliminate wrong answers

Option A is wrong because `join` combines rows from two tables based on a matching column, but it does not inherently group events by time window or perform aggregations; it would require additional operators to achieve the desired grouping. Option B is wrong because `extend` creates new calculated columns from existing data, but it does not group or aggregate events. Option C is wrong because `project` selects and renames columns, but it does not perform any grouping or aggregation.

99
Multi-Selecthard

You are a Microsoft Sentinel analyst handling an incident where a compromised user account is being used to access cloud applications. Your response plan requires you to both terminate the attacker's active sessions and review what the account accessed. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Use the Microsoft Entra ID user entity action to revoke sessions or reset the password so existing refresh tokens are invalidated.
B.Change the incident status to Closed and add a benign positive classification.
C.Disable the analytics rule that generated the incident so it does not retrigger.
D.Query the Microsoft Sentinel workspace logs, such as SigninLogs and AuditLogs, to review the account's recent activity during the compromise window.
E.Delete the user's mailbox to prevent further email-based data theft.
AnswersA, D

Revoking sessions or resetting the password invalidates existing refresh tokens, which forces reauthentication and cuts off the attacker's persistent access obtained through stolen tokens. This addresses the common gap where disabling or blocking sign-in does not immediately kill already-issued tokens. Performing this action directly from the incident's user entity keeps the response within the investigation workflow and satisfies the requirement to terminate active sessions.

Why this answer

Terminating an attacker's access requires invalidating tokens, not just blocking new sign-ins, so revoking sessions or resetting the password is essential. Reviewing sign-in and audit logs reconstructs what the account touched, which the response plan explicitly requires. Destroying the mailbox, disabling detection, or prematurely closing the incident would either damage evidence, create visibility gaps, or misrepresent the incident's severity.

Exam trap

The trap here is believing that disabling an account immediately ends the attacker's access, when already-issued refresh tokens can remain usable until revoked.

100
MCQhard

Refer to the exhibit. An alert in Microsoft Defender for Identity shows suspicious PowerCLI execution on an Exchange server. The service account 'svc_exchange' is used. What is the most likely true-positive scenario?

A.An attacker using a compromised service account to access mailboxes via remote PowerShell
B.A security tool scanning for vulnerabilities
C.A misconfigured backup application running from an external IP
D.A legitimate IT admin running Exchange management scripts
AnswerA

PowerCLI is a PowerShell-based module that an attacker can abuse to open a remote PowerShell session to Exchange's management and mailbox endpoints, despite being VMware's tooling. In this alert, the source is an internal service account that lacks the normal attributes of an approved admin account, and its remote PowerShell activity aligns with mailbox enumeration or data exfiltration via Exchange cmdlets. The use of PowerCLI as a launching point for these commands masks the attacker's intent while providing a shell for executing Get-Mailbox or Search-Mailbox queries.

Why this answer

PowerCLI execution on an Exchange server, especially using a service account like 'svc_exchange', is a strong indicator of an attacker leveraging compromised credentials to remotely access Exchange via PowerShell. Microsoft Defender for Identity detects this because PowerCLI is not a native Exchange management tool; it is typically used by attackers to interact with Exchange Web Services (EWS) or Remote PowerShell (WinRM) for mailbox access, data exfiltration, or persistence. The combination of a service account (often over-privileged and not monitored) and PowerCLI from an unusual source or time makes this a true-positive compromise scenario.

Exam trap

The trap here is that candidates assume any PowerShell on an Exchange server is legitimate admin activity, but the exam specifically tests that PowerCLI is a VMware tool, not an Exchange management tool, making its execution on an Exchange server a clear red flag for compromise.

How to eliminate wrong answers

Option B is wrong because vulnerability scanning tools do not use PowerCLI; they rely on network scanners (e.g., Nmap) or authenticated vulnerability assessment agents, not PowerShell cmdlets for Exchange. Option C is wrong because backup applications typically use native Exchange APIs (e.g., VSS writer or EWS impersonation) or dedicated backup agents, and they do not execute PowerCLI from an external IP; a misconfigured backup would generate different alerts (e.g., authentication failures, not suspicious script execution). Option D is wrong because a legitimate IT admin would use native Exchange Management Shell cmdlets (e.g., Get-Mailbox, Set-Mailbox) via Exchange Management Console or Remote PowerShell, not PowerCLI, which is a VMware tool; PowerCLI on an Exchange server is anomalous and indicates non-standard, likely malicious activity.

101
MCQmedium

Your organization uses Microsoft Defender for Endpoint. An endpoint is detected as infected with a trojan. The analyst needs to isolate the device from the network while preserving forensic data. What action should the analyst take?

A.Remove the device from the Active Directory domain.
B.Disable the network adapter on the device.
C.Initiate the 'Isolate device' action from the Microsoft Defender XDR portal.
D.Perform a full reimage of the device.
AnswerC

The 'Isolate device' action is the designed containment control in Microsoft Defender XDR; it enforces a network-level block on all inbound and outbound communications except for the trusted Defender for Endpoint cloud service, which remains available for management and forensic collection. This preserves your ability to run live response commands, gather evidence, and later release the device from isolation remotely. It is a reversible, evidence-preserving containment that does not require physical access.

Why this answer

The 'Isolate device' action in Microsoft Defender XDR (formerly Microsoft 365 Defender) disconnects the device from all network traffic except the Defender for Endpoint service, preserving forensic data on the device while preventing the trojan from communicating with command-and-control servers. This action uses a built-in network isolation mechanism that blocks inbound and outbound connections at the OS level, ensuring the device remains accessible for investigation and remediation.

Exam trap

The trap here is that candidates may confuse physical network disconnection (Option B) with the controlled, reversible isolation provided by Defender for Endpoint, failing to recognize that forensic preservation and remote management are key requirements in incident response.

How to eliminate wrong answers

Option A is wrong because removing the device from the Active Directory domain does not isolate it from the network; it only removes domain trust relationships, and the device can still communicate on the network, potentially spreading the trojan. Option B is wrong because disabling the network adapter physically cuts all network connectivity, but it also prevents remote management and forensic data collection via Defender for Endpoint, and it does not preserve the ability to monitor or remediate the device centrally. Option D is wrong because performing a full reimage destroys all forensic data on the device, including evidence of the trojan's origin and behavior, which is contrary to the requirement to preserve forensic data.

102
MCQmedium

Refer to the exhibit. You are configuring an automation rule in Microsoft Sentinel. The JSON snippet defines an automation rule. What is the expected behavior of this rule?

A.It creates an incident when a phishing email is detected
B.It sends an email to the security team when an incident is created
C.It runs a playbook to quarantine an email when a specific alert is generated
D.It modifies the incident severity when a playbook runs
AnswerC

The rule's trigger is set to a specific alert name and its action is to invoke a playbook, which is exactly how automated response works in Sentinel. When that alert fires, the rule automatically runs the Quarantine playbook, which likely uses a Microsoft 365 or Defender connector to isolate the offending email. This matches the exhibit: the automation rule reacts to the alert, not to an incident, by executing a playbook.

Why this answer

The automation rule is triggered when a specific alert is generated (as defined by the trigger condition), and it runs a playbook that contains logic to quarantine an email. In Microsoft Sentinel, automation rules can be configured to trigger on alert creation and execute a playbook, which in this case performs the quarantine action.

Exam trap

The trap here is that candidates often confuse the trigger condition (alert creation vs. incident creation) and assume the rule directly performs an action like sending an email or modifying severity, when in fact the rule only triggers a playbook that performs those actions.

How to eliminate wrong answers

Option A is wrong because the rule does not create an incident; it triggers on an existing alert and runs a playbook. Option B is wrong because the rule does not send an email; it runs a playbook, and the playbook itself could send an email, but the rule's action is to run the playbook, not directly send an email. Option D is wrong because the rule does not modify incident severity; it runs a playbook when an alert is generated, and severity modification would require a different trigger or action within the playbook itself.

103
MCQhard

Your organization uses Microsoft Purview Data Loss Prevention (DLP) and Microsoft Defender for Cloud Apps. During an incident, you discover that a user is exfiltrating sensitive data via a sanctioned cloud app. You need to block the user's ability to share files in that app immediately. What should you do?

A.Create a session policy in Microsoft Defender for Cloud Apps to block the user's file sharing activity.
B.Disable the app connector for that cloud app in Microsoft Defender for Cloud Apps.
C.Remove the user from the Microsoft Entra ID group that allows access to the cloud app.
D.Create a Microsoft Purview DLP policy to block sharing of sensitive content.
AnswerA

Session policies in Defender for Cloud Apps proxy the sanctioned app's traffic, allowing real-time control actions such as blocking file sharing for a specific user. This satisfies the requirement to stop exfiltration immediately without revoking the app's sanctioned status.

Why this answer

To immediately block a user's file-sharing activity in a sanctioned cloud app, create a session policy in Microsoft Defender for Cloud Apps. Session policies use Conditional Access App Control to proxy the session and apply real-time controls such as block download, block upload, or block sharing for specific users or groups. This is the fastest, most targeted control for the described scenario.

Exam trap

SC-200 often tests the difference between session policies (real-time, user-scoped, app-level control) and DLP policies (content-based, broader) — candidates pick DLP because it sounds like the data-protection tool, but the scenario demands immediate user-level blocking in a sanctioned app.

How to eliminate wrong answers

Option B is wrong because disabling the app connector would stop all monitoring and control for that app across the entire organization, not just the user — it is a blunt, org-wide action that also loses visibility. Option C is wrong because removing the user from an Entra ID group may revoke app access entirely but does not specifically block file sharing, and it may take time to propagate; it also does not address the immediate exfiltration if the user has other access paths. Option D is wrong because a Purview DLP policy blocks sharing of sensitive content based on content inspection, but it is not the immediate, user-scoped session control that Defender for Cloud Apps provides for sanctioned apps.

104
MCQeasy

Your organization uses Microsoft Sentinel. You receive a high-severity incident indicating a potential data exfiltration from an Azure Storage account. The incident contains entities such as IP addresses and user accounts. Which step should you perform first to contain the threat?

A.Contact the user associated with the storage account
B.Block the suspicious IP address in the Azure Firewall
C.Investigate the incident to confirm the activity is malicious
D.Disable the storage account
AnswerC

Confirming whether the flagged activity is genuinely malicious precedes containment, because isolating resources or disabling accounts on a false positive causes unnecessary disruption. Investigation validates the incident's entities and scope, ensuring subsequent containment actions target a real threat.

Why this answer

In Microsoft Sentinel, the first step after receiving a high-severity incident is to investigate and confirm whether the activity is truly malicious. This triage step prevents unnecessary containment actions that could disrupt legitimate business operations. Only after confirming the threat should you proceed with containment measures like blocking IPs or disabling accounts.

Exam trap

SC-200 often tests the principle of 'investigate before you contain' to ensure candidates understand the incident response lifecycle and avoid premature actions that could harm business operations or destroy evidence.

How to eliminate wrong answers

Option A is wrong because contacting the user is a communication step, not a containment action, and may alert an attacker if the user is compromised. Option B is wrong because blocking an IP in Azure Firewall is a containment action that should only be taken after confirming malicious activity; premature blocking can disrupt legitimate traffic. Option D is wrong because disabling the storage account is a drastic containment step that could cause significant downtime and should only be done after investigation confirms malicious exfiltration.

105
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You receive an alert that an administrator performed an unusual bulk download from SharePoint. What is the recommended first step to respond?

A.Report the activity to Microsoft for further analysis.
B.Suspend the administrator's account immediately.
C.Block the IP address of the administrator's device.
D.Review the activity log in Defender for Cloud Apps to determine the context.
AnswerD

Reviewing the activity log in Defender for Cloud Apps is the correct first step because it provides the full context of the risky action: the exact activity, affected application, source IP, geolocation, timestamp, and user agent. With this evidence, you can distinguish an expected administrative change from a sign of account compromise and then decide whether to apply adaptive protection, require reauthentication, or invoke a conditional access policy. This investigation-first approach aligns with Microsoft's incident response guidance and minimizes false-positive disruptions.

Why this answer

The recommended first step when investigating an alert in Microsoft Defender for Cloud Apps is to review the activity log to understand the context of the alert. This allows the analyst to determine whether the bulk download is legitimate (e.g., a scheduled backup or migration) or malicious (e.g., data exfiltration). Jumping to containment actions without context can disrupt business operations and potentially alert an attacker.

Exam trap

The trap here is that candidates often jump to immediate containment actions (like suspending the account or blocking the IP) without first gathering context, but Microsoft's recommended incident response process emphasizes 'investigate before contain' to avoid false positives and operational disruption.

How to eliminate wrong answers

Option A is wrong because reporting the activity to Microsoft for further analysis is not a first step; Microsoft does not perform initial triage for customer-specific alerts, and the organization is responsible for its own investigation. Option B is wrong because suspending the administrator's account immediately could be premature and disruptive if the activity is legitimate, and it may tip off a malicious insider. Option C is wrong because blocking the IP address of the administrator's device could be ineffective if the administrator uses a dynamic IP or VPN, and it does not address the root cause of the alert.

106
MCQmedium

You are investigating a security incident in Microsoft Sentinel where a user received a phishing email containing a link to a malicious domain. The link was clicked, but no further actions were observed. Which playbook action should you take immediately to prevent potential lateral movement?

A.Disable the user's account
B.Revoke the user's active sessions
C.Reset the user's password
D.Block the malicious domain on the firewall
AnswerD

Blocking the malicious domain at the firewall is a network-based containment action that stops all clients from resolving or connecting to the malicious site, effectively breaking the delivery chain for phishing or malware. It is a reversible, low-impact measure that addresses the root cause regardless of which user or device attempts access, and it aligns with security operations best practice to contain the threat at the earliest opportunity.

Why this answer

The user only clicked the link without performing any further actions (e.g., no credential entry or file download). Blocking the malicious domain on the firewall immediately prevents the user or any other host from reaching the domain, stopping potential lateral movement via subsequent connections. This aligns with the principle of containing the threat at the network layer before it can spread.

Exam trap

The trap here is that candidates often confuse a click-only incident with a credential compromise, leading them to choose password reset or session revocation, but the correct first step is to block the malicious domain to contain the network-based threat.

How to eliminate wrong answers

Option A is wrong because disabling the user's account is an overly aggressive step for a click-only incident with no observed lateral movement; it would disrupt legitimate access without addressing the network-level threat. Option B is wrong because revoking the user's active sessions only terminates current connections but does not prevent the user or other systems from reconnecting to the malicious domain later. Option C is wrong because resetting the user's password is irrelevant when no credentials were compromised; the attack vector is network-based, not credential-based.

107
MCQeasy

A SOC analyst is investigating a phishing campaign that targets Microsoft 365 users. The analyst needs to collect email message headers from multiple users' mailboxes. Which Microsoft 365 Defender action should the analyst use?

A.Use Microsoft 365 Defender > Actions & submissions to view email headers.
B.Use Microsoft 365 Defender > Threat hunters to search for email headers.
C.Use Microsoft 365 Defender > Attack simulation training to collect headers.
D.Use Microsoft 365 Defender > Email & collaboration > Explorer to query email headers.
AnswerD

Email & collaboration > Explorer (Threat Explorer) is the dedicated email investigation view that lets an analyst filter by phishing indicators (sender, subject, message ID, and more) and then select individual messages to view the full message header. It also provides an export option to save headers for offline analysis, making it the correct tool for this task.

Why this answer

Microsoft 365 Defender's Email & collaboration > Explorer (also known as Threat Explorer) is the dedicated tool for querying email message headers across multiple user mailboxes. It allows analysts to search for specific email messages by sender, recipient, subject, or other attributes, and then view the full internet message headers (RFC 5322) for forensic analysis. This is the standard workflow for investigating phishing campaigns in Microsoft 365 Defender.

Exam trap

The trap here is that candidates confuse Threat Explorer (a dedicated email investigation tool) with Advanced Hunting (a general-purpose query tool), leading them to incorrectly choose Option B, even though Advanced Hunting does not natively display raw email headers without custom KQL parsing.

How to eliminate wrong answers

Option A is wrong because Actions & submissions is used for submitting suspicious emails for analysis and reviewing submission results, not for querying or viewing email headers from multiple mailboxes. Option B is wrong because Threat hunters (Advanced Hunting) uses Kusto Query Language (KQL) to search for threat data across tables like EmailEvents, but it does not directly display raw email headers; headers must be extracted via additional queries. Option C is wrong because Attack simulation training is a tool for creating and managing simulated phishing attacks, not for collecting real email headers from user mailboxes.

108
MCQeasy

You run the above KQL query in Microsoft Sentinel to identify ransomware alerts from the last day. The result shows zero rows. Which is the most likely reason?

A.The table name 'SecurityAlert' is incorrect; it should be 'Alert'
B.No alerts with 'ransomware' in the name occurred in the last day
C.The user does not have permission to access the SecurityAlert table
D.The time filter of 1 day is too restrictive; need to increase range
AnswerB

The empty result set is a valid query result: within the last 24 hours, no SecurityAlert row had an alert name containing the case-insensitive substring 'ransomware' (assuming a standard `contains` operator). KQL processing filters every row in the time window; when none satisfy the predicate, Kusto returns zero rows without error. This means the query executed successfully and the absence of matching alerts is the most accurate explanation.

Why this answer

The KQL query filters for alerts where the name contains 'ransomware'. If no such alerts were generated in the last day, the query returns zero rows. This is the most likely reason because the query logic is correct, and the absence of data is a valid outcome, not an error.

Exam trap

The SC-200 exam often tests the candidate's ability to distinguish between a query returning zero rows due to a lack of matching data versus a query failing due to syntax or permission errors, leading candidates to incorrectly assume a configuration or permission issue.

How to eliminate wrong answers

Option A is wrong because 'SecurityAlert' is the correct table name in Microsoft Sentinel for storing security alerts; 'Alert' is not a valid table name. Option C is wrong because if the user lacked permission, the query would typically return an access denied error, not zero rows. Option D is wrong because the time filter of 1 day is not inherently too restrictive; the query is designed to check for alerts within that specific timeframe, and if none exist, zero rows is the expected result.

109
MCQmedium

A security analyst receives a Microsoft Defender for Cloud Apps alert about a suspicious sign-in from an IP address in a sanctioned app. The analyst needs to immediately prevent further access from that IP. What should the analyst do?

A.Create a mailbox rule to delete emails from that IP.
B.Create a Conditional Access policy in Microsoft Entra ID to block the IP.
C.Create an IP address-based access policy in Microsoft Defender for Cloud Apps.
D.Reset the user's password and require MFA re-registration.
AnswerC

From the Defender for Cloud Apps alert, you can create an IP address-based access policy that blocks the suspicious IP from all or selected cloud apps. This policy is enforced via the Cloud Apps conditional access proxy, providing real-time control over user access. It is the recommended, alert-specific remediation because it directly addresses the source IP identified in the threat, preventing further malicious activity.

Why this answer

Microsoft Defender for Cloud Apps provides native IP address-based access policies that can immediately block traffic from a specific IP address for a sanctioned app. This action is taken directly within Defender for Cloud Apps, without needing to modify Entra ID Conditional Access policies, and it applies in real time to the app session. The analyst can create a policy that blocks access from the suspicious IP, preventing further sign-ins from that address.

Exam trap

The trap here is that candidates often confuse the scope of Conditional Access in Entra ID (which is a broader identity-level control) with the app-specific, session-level control provided by Defender for Cloud Apps access policies, leading them to choose Option B instead of C.

How to eliminate wrong answers

Option A is wrong because a mailbox rule in Exchange Online can only filter or delete emails after delivery; it cannot block sign-in attempts or prevent access to a sanctioned app. Option B is wrong because creating a Conditional Access policy in Microsoft Entra ID would block the IP at the authentication layer, but this is a broader, slower approach that affects all apps and requires careful configuration; the question specifies the action should be taken immediately within Defender for Cloud Apps for a sanctioned app. Option D is wrong because resetting the user's password and requiring MFA re-registration does not block the specific IP address; the attacker could still attempt sign-ins from that IP with other credentials or after the user resets.

110
MCQeasy

During a security incident, you need to collect email messages associated with a phishing campaign from multiple mailboxes in Microsoft 365. Which tool should you use to search and export these emails?

A.Advanced Hunting in Microsoft Defender XDR.
B.Incident investigation in the Microsoft 365 Defender portal.
C.Mail Flow in the Exchange admin center.
D.Content Search in the Microsoft Purview compliance portal.
AnswerD

Content Search in Microsoft Purview queries multiple mailboxes simultaneously and exports matching messages to PST, satisfying the cross-mailbox collection requirement. Unlike eDiscovery holds or mailbox audit logging, it performs immediate, targeted searches across Exchange Online without placing mailboxes on hold, making it appropriate for rapid incident response collection.

Why this answer

Content Search in the Microsoft Purview compliance portal is the purpose-built tool for searching across Exchange mailboxes (and SharePoint/OneDrive) and exporting results to a PST or mailbox. It supports keyword queries, date ranges, sender/recipient filters, and bulk export across multiple mailboxes, which matches the phishing-campaign scenario.

Exam trap

The trap is confusing alert-triage tools (Defender XDR, incident investigation) with content-search tools — candidates must map 'search and export mailbox content' to Purview Content Search, not to Defender.

How to eliminate wrong answers

Option A is wrong because Advanced Hunting in Defender XDR is a KQL-based threat-hunting tool for telemetry and alerts — it does not export mailbox contents. Option B is wrong because incident investigation in the Defender portal is for triaging and correlating alerts, not for bulk email search and export. Option C is wrong because Mail Flow in Exchange admin center is for message trace and transport rule troubleshooting, not for content search or export of mailbox items.

111
MCQhard

Your organization uses Microsoft Sentinel with Fusion and Microsoft Security incident creation rules. You receive a high-severity incident from Microsoft Defender for Cloud Apps. The incident has a low confidence score. What should you do first?

A.Dismiss the incident as a false positive due to low confidence.
B.Suppress all future alerts from Defender for Cloud Apps with low confidence.
C.Escalate the incident to the SOC manager immediately.
D.Validate the alert by correlating with other logs.
AnswerD

Validating the alert by correlating it with other logs is the correct first step in incident triage. This involves checking user sign-in logs, Azure AD audit logs, Microsoft 365 audit logs, and endpoint/data loss prevention events for corroborating evidence of the same activity. Correlation helps confirm whether the Alert is a true positive, a false positive, or part of a bigger campaign, enabling proper prioritization and response.

Why this answer

A low confidence score indicates the alert may be a false positive, but it should not be dismissed without investigation. In Microsoft Sentinel, low confidence alerts from Defender for Cloud Apps require validation through correlation with other logs (e.g., Azure AD sign-ins, network logs) to confirm malicious activity before taking action. This aligns with the incident response process of triage and verification, not immediate dismissal or suppression.

Exam trap

The trap here is that candidates assume low confidence automatically means false positive, leading them to dismiss or suppress the alert, but the correct approach is to validate through correlation before making a decision.

How to eliminate wrong answers

Option A is wrong because dismissing an incident solely due to low confidence ignores the possibility of a true positive; low confidence means the detection logic is uncertain, not that the alert is definitively false. Option B is wrong because suppressing all future low-confidence alerts from Defender for Cloud Apps would create a blind spot, as low confidence can still indicate real threats that need correlation with other data. Option C is wrong because escalating to the SOC manager immediately bypasses the necessary triage step; the analyst should first validate the alert before escalating, as low confidence incidents often require initial investigation.

112
MCQmedium

Your organization uses Microsoft Sentinel. You have an incident that involves multiple alerts. You want to automatically assign the incident to the appropriate analyst based on the alert type. What should you use?

A.Create a playbook that assigns the incident.
B.Configure the analytics rule to set the incident owner.
C.Use a workbook to filter incidents by alert type.
D.Create an automation rule with an 'Assign incident to owner' action.
AnswerD

Automation rules in Microsoft Sentinel trigger on incident creation and can run the 'Assign incident to owner' action, routing incidents by alert type or other conditions. This satisfies the stem's requirement for automatic analyst assignment without manual triage.

Why this answer

An automation rule with an 'Assign incident to owner' action is the correct mechanism to automatically assign incidents based on alert type. Automation rules in Microsoft Sentinel support conditions on incident properties (including alert type/analytics rule) and can assign the incident to a specific owner or group. This directly fulfills the requirement.

Exam trap

SC-200 often tests the confusion between automation rules and playbooks, tricking candidates into selecting playbooks for simple assignment tasks that automation rules handle natively.

How to eliminate wrong answers

Option A is wrong because a playbook can assign incidents, but it is more complex and not the designed feature for simple assignment based on alert type; automation rules are the native, no-code solution. Option B is wrong because analytics rules can set incident owner at creation, but they cannot dynamically assign based on alert type across multiple alerts in the way automation rules can, and the question implies post-creation assignment logic. Option C is wrong because workbooks are for visualization and reporting, not for assigning incidents.

113
MCQmedium

A security analyst receives an alert in Microsoft Defender XDR indicating that a user account was compromised. The analyst needs to isolate the affected device to prevent lateral movement. Which action should the analyst take first?

A.Run a full antimalware scan on the device
B.Initiate device isolation from Microsoft Defender for Endpoint
C.Reset the user's password in Microsoft Entra ID
D.Create a custom detection rule in Microsoft Sentinel
AnswerB

Initiating device isolation from Microsoft Defender for Endpoint is the immediate containment action because it severs the compromised device's network connections—both wired and wireless—while preserving a secure channel to the Defender for Endpoint service for ongoing investigation and remediation. This prevents the attacker from moving laterally, exfiltrating data, or communicating with C2, effectively containing the breach at the endpoint.

Why this answer

Initiating device isolation in Microsoft Defender for Endpoint immediately contains the compromised device, preventing lateral movement. Option A is wrong because a full antimalware scan does not isolate the device and may not stop ongoing malicious activity. Option C is wrong because resetting the user's password does not isolate the device; it only revokes access to cloud resources.

Option D is wrong because creating a custom detection rule in Microsoft Sentinel does not take immediate action to contain the threat.

114
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft 365 Defender. You have a playbook that automatically isolates a device when a malware incident is confirmed. The playbook uses the Microsoft Defender for Endpoint connector. During a recent incident, the playbook failed to isolate a device because the device was not found in Defender for Endpoint. Upon investigation, you find that the device is onboarded to Microsoft Defender for Endpoint but the playbook is using an incorrect device ID format. What should you do to ensure the playbook works correctly?

A.Ensure the device is properly onboarded to Microsoft Defender for Endpoint by running the onboarding script again.
B.Reconfigure the Microsoft Defender for Endpoint connector in Sentinel to use a different API version.
C.Modify the playbook to use the device ID from the incident's entities instead of a manually entered ID.
D.Use the device name instead of the device ID in the playbook.
AnswerC

Using the incident entity's device ID guarantees the identifier matches Defender for Endpoint's onboarded record, because Sentinel incidents carry the exact machine ID surfaced by the connector. A manually entered ID risks format mismatches, such as Azure AD object ID versus Defender machine ID, which caused the lookup failure.

Why this answer

The playbook failed because it used an incorrect device ID format. The correct approach is to modify the playbook to dynamically retrieve the device ID from the incident's entities, which ensures the correct ID is used. This leverages the integration between Microsoft Sentinel and Microsoft 365 Defender, where incident entities include the proper device ID.

Exam trap

SC-200 often tests the integration between Sentinel and Defender, where candidates might focus on onboarding or connector configuration instead of the correct use of incident entities for dynamic values.

How to eliminate wrong answers

Option A is wrong because the device is already onboarded to Defender for Endpoint; re-running the onboarding script would not fix the incorrect device ID format used in the playbook. Option B is wrong because changing the API version of the connector is unlikely to resolve the issue; the problem is the device ID format, not the API version. Option D is wrong because using the device name instead of the device ID may not be supported by the isolation action, which typically requires the device ID; device names can be ambiguous or change.

115
MCQmedium

After a security incident, you need to collect forensic evidence from a Windows 10 machine. Which Microsoft tool should you use to create a memory dump?

A.Remote Desktop Protocol (RDP)
B.Microsoft Defender for Endpoint Live Response
C.Microsoft Crash Dump Tool (e.g., NotMyFault or Sysinternals tools)
D.Microsoft Defender for Cloud Apps
AnswerB

Live Response connects to the device through Microsoft Defender for Endpoint and can run the 'getfile' or memory-dump collection commands, capturing volatile memory without disrupting the host. This satisfies the forensic-evidence constraint by preserving RAM contents for offline analysis.

Why this answer

Microsoft Defender for Endpoint Live Response provides a `dump` command that can capture a full memory dump from a live Windows 10 system without causing a crash. This preserves volatile forensic evidence such as running processes, network connections, and encryption keys. In contrast, the Microsoft Crash Dump Tool (NotMyFault or Sysinternals) is designed to trigger a system crash (BSOD) for debugging purposes, which is destructive and not appropriate for forensic collection.

Therefore, for a security incident requiring a memory dump without system disruption, Live Response is the correct tool.

Exam trap

The trap is that candidates may assume Sysinternals tools (like NotMyFault) are the dedicated memory dump tools, but they create crash dumps by crashing the system, which destroys volatile evidence. In the context of forensic collection within Microsoft Defender XDR, Live Response is the correct method to capture a memory dump nondestructively.

How to eliminate wrong answers

Option A is wrong because Remote Desktop Protocol (RDP) is a network protocol for remote desktop access, not a tool for creating memory dumps; it provides no mechanism to capture volatile memory. Option B is wrong because Microsoft Defender for Endpoint Live Response can collect a memory dump using the `dump` command, but it is a remote investigation and response tool, not a dedicated crash dump tool; the question asks for a tool that creates a memory dump, and Live Response is a platform feature, not the specific tool referenced in the exam context. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) for monitoring cloud applications, not a tool for local forensic memory capture on a Windows 10 machine.

116
Multi-Selecthard

Which THREE elements are essential when creating a custom incident response playbook in Microsoft Sentinel? (Choose THREE.)

Select 3 answers
A.Appropriate permissions via managed identity or service principal for the playbook to execute actions.
B.A mandatory approval step before any action is taken.
C.One or more actions using connectors like Azure Automation or Logic Apps.
D.An analytics rule that generates the incident.
E.A trigger condition based on an incident creation or alert.
AnswersA, C, E

Every action in a playbook that interacts with Microsoft Sentinel or another resource must authenticate; without a managed identity or service principal, the Logic App will receive 401/403 errors and the automation fails. A managed identity (system-assigned or user-assigned) is the recommended option because it removes the need for client secrets and allows you to grant Microsoft Sentinel Responder or a custom role directly to the identity. This permission assignment is mandatory, not optional, because the playbook runs as a separate security principal in Azure AD.

Why this answer

A custom incident response playbook in Microsoft Sentinel requires appropriate permissions to execute actions against Azure resources. This is achieved by assigning a managed identity or configuring a service principal for the Logic App, which authenticates and authorizes the playbook to run actions such as blocking IPs, isolating machines, or querying threat intelligence. Without these permissions, the playbook would fail at runtime due to authentication errors, making it non-functional.

Exam trap

The trap here is that candidates confuse the components of a playbook (trigger, actions, permissions) with external dependencies like analytics rules or optional approval steps, leading them to select non-essential items that are not part of the playbook's core definition.

117
MCQhard

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspected Kerberoasting attack targeting a service account. You need to investigate the affected user and identify any related lateral movement. Which Microsoft Defender for Identity feature should you use to view the user's profile, including their activity timeline, associated alerts, and lateral movement paths?

A.The user's profile page in the Microsoft 365 Defender portal
B.The 'Advanced hunting' page in the Microsoft 365 Defender portal
C.The 'Users' page in the Microsoft Defender for Identity portal
D.The 'Health issues' page in the Microsoft Defender for Identity portal
AnswerA

In Microsoft 365 Defender, the user profile page aggregates identity signals from Defender for Identity, including the user's activity timeline, associated alerts, and lateral movement paths. This unified view allows you to investigate the Kerberoasting alert in context, see related activities, and identify potential lateral movement. It is the correct feature for deep investigation of an affected user across identity workloads.

Why this answer

The user profile page in Microsoft 365 Defender consolidates identity data from Defender for Identity, including the activity timeline, alerts, and lateral movement paths. It is designed for investigating a specific user and understanding their behavior and relationships. Other pages either list users, show health status, or provide raw query access, but none offer the integrated investigative profile needed here.

Exam trap

The trap here is assuming the Users page in the Defender for Identity portal provides the full investigation view; the richer, unified user profile is in the Microsoft 365 Defender portal.

118
MCQhard

Your company uses Microsoft Defender for Cloud Apps. You discover that a user's account is compromised and used to access a sensitive SharePoint site from an unfamiliar IP. You need to immediately revoke the user's session and force them to re-authenticate. Which action should you take?

A.Add the IP to the blocked IP addresses list.
B.Create a governance action to suspend the user.
C.Send a notification to the user to change their password.
D.Apply a policy with the 'Revoke session' action.
AnswerD

The 'Revoke session' action is the correct governance action because it is a targeted, corrective control that specifically terminates the user's active access to the cloud app without disabling the account. Defender for Cloud Apps works with Conditional Access App Control to remove the session cookie and force a fresh authentication with the identity provider. This immediately stops the attacker's access while preserving the user's ability to sign in again after the risk is mitigated.

Why this answer

The 'Revoke session' governance action in Defender for Cloud Apps invalidates the user's active sessions across connected SaaS apps (SharePoint, Exchange, Teams, etc.) and forces re-authentication, which is the correct immediate response to an active session hijack. It is applied via an access or session policy and works with Conditional Access App Control to terminate the session in real time.

Exam trap

SC-200 often tests the confusion between blocking an indicator (IP) and revoking the compromised credential/session — candidates pick the IP block because it feels like 'stopping the attacker', but the active session token is what actually needs to be killed.

How to eliminate wrong answers

Option A is wrong because blocking the IP only prevents future connections from that address — the attacker's already-authenticated session token remains valid and continues to access SharePoint. Option B is wrong because suspending the user disables the account but does not invalidate already-issued session cookies or OAuth tokens, so the attacker's active session persists until token expiry. Option C is wrong because notifying the user to change their password is a slow, manual remediation that leaves the attacker's session live and depends on user action.

119
MCQhard

The exhibit shows an automation rule in Microsoft Sentinel. The analyst reports that the playbook is not triggered for high-severity incidents. What is the most likely cause?

A.The playbook resource ID is invalid.
B.The condition syntax is incorrect.
C.The tenant ID is missing.
D.The rule triggers only on incident creation, not on updates.
AnswerD

The rule triggers only on incident creation, not on updates. The automation rule's trigger is set to 'When incident created', which means it evaluates only at the moment an incident is generated. If an existing incident is later modified to raise its severity to 'High', the rule will not run because it does not subscribe to incident update events. To handle such changes, the rule would need to use the 'When incident update' trigger or include both creation and update triggers.

Why this answer

The automation rule is configured to trigger 'When incident is created,' which means it only runs the playbook at the moment the incident is first generated. If the incident's severity is updated after creation (e.g., from medium to high), the rule does not re-trigger, so the playbook will not execute for that high-severity incident. This is the most likely cause because the analyst reports that high-severity incidents are not triggering the playbook, and the rule's trigger condition explicitly excludes updates.

Exam trap

The trap here is that candidates assume the rule will re-evaluate conditions whenever the incident changes, but Sentinel's automation rules only evaluate the trigger condition at the moment of incident creation or update, not continuously, so a severity change after creation will not fire a rule set to 'When incident is created.'

How to eliminate wrong answers

Option A is wrong because an invalid playbook resource ID would cause a persistent failure for all incidents, not just high-severity ones, and the error would appear in the automation rule's run history. Option B is wrong because the condition syntax (e.g., 'Severity equals High') is validated at rule creation time; an incorrect syntax would prevent the rule from being saved, not cause it to silently fail for specific incidents. Option C is wrong because the tenant ID is automatically populated by Sentinel when the rule is created and is not a configurable field; a missing tenant ID would prevent the rule from being created at all.

120
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. An alert indicates that an external IP address is downloading large amounts of data from a SharePoint site containing confidential documents. The activity is coming from a valid user account that appears to be compromised. What should you do first to stop the data exfiltration?

A.Delete the confidential documents from SharePoint
B.Suspend the user account in Microsoft Entra ID
C.Block the external IP address in Microsoft Defender for Cloud Apps
D.Change the SharePoint site permissions to deny access
AnswerB

Suspending the account in Microsoft Entra ID immediately blocks the compromised identity's authentication, halting the ongoing SharePoint download before further data leaves. Containment precedes investigation, so revoking the valid credentials stops exfiltration at its source rather than merely alerting on it.

Why this answer

The first priority is to immediately stop the ongoing data exfiltration by suspending the compromised user account in Microsoft Entra ID. This disables the attacker's access via that account, halting the download. Blocking the external IP address (Option C) is less effective because the attacker could switch IPs.

Changing SharePoint permissions (Option D) or deleting documents (Option A) would not stop the current download session as quickly as suspending the account.

121
MCQmedium

During an incident response, you need to collect email messages from a user's mailbox in Microsoft 365 for evidence. The user is suspected of phishing. Which Microsoft Purview solution should you use?

A.eDiscovery (Standard)
B.Data Loss Prevention
C.Records Management
D.Audit (Standard)
AnswerA

eDiscovery (Standard) supports searching, holding and exporting mailbox content for legal or investigative purposes, matching the need to collect email evidence. It preserves messages in place, so suspected phishing correspondence is captured without altering the user's mailbox.

Why this answer

Microsoft Purview eDiscovery (Standard) is designed for identifying, collecting, and preserving electronically stored information (ESI) such as email messages for legal or investigative purposes. It supports mailbox searches, holds, and export of evidence, making it the correct tool for collecting a user's mailbox during incident response.

Exam trap

SC-200 often tests the confusion between Audit (which shows activity logs) and eDiscovery (which collects content) — candidates pick Audit thinking it retrieves emails, but it only shows metadata about mailbox operations.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) is for preventing exfiltration of sensitive data in real time, not for collecting evidence after an incident. Option C is wrong because Records Management is for declaring and retaining content per compliance policies, not for investigative collection. Option D is wrong because Audit (Standard) provides activity logs and search, but it does not collect or export mailbox content as evidence — it shows what happened, not the messages themselves.

122
MCQhard

The analyst notices that the rule does not fire for a user who has 12 sign-ins from the same IP address, but all are low risk. The expected behavior is to alert when a single user has more than 10 sign-ins from the same IP with at least one high-risk sign-in. What is the issue?

A.The join should be on UserPrincipalName only, not IPAddress.
B.The join should be leftouter to include sign-ins without high risk.
C.The threshold is set to 10, but the user has 12 sign-ins, so it should fire.
D.The query requires a high-risk sign-in from the same IP, but none exist, so no match.
AnswerD

The default inner join in KQL returns only rows where both UserPrincipalName and IPAddress match between the sign-in dataset and the high-risk dataset. If this user has no high-risk sign-in that originated from the same IP, the join output is empty and the subsequent aggregation returns no result. Therefore the rule correctly does not fire, because the core condition—a high-risk event at the same source IP—is not satisfied.

Why this answer

The KQL query uses an inner join on UserPrincipalName and IPAddress, which only returns rows where a high-risk sign-in exists from the same IP. Since all 12 sign-ins from that IP are low risk, the join produces no matching rows, and the rule does not fire. The threshold of 10 is irrelevant when the join condition fails to produce any results.

Exam trap

The trap here is that candidates focus on the numeric threshold (10 vs. 12) and overlook the join logic, assuming the rule should fire because the count exceeds the threshold, when in fact the join condition is the root cause of the failure.

How to eliminate wrong answers

Option A is wrong because joining only on UserPrincipalName would incorrectly match sign-ins from different IPs, potentially firing the rule when a user has 10 sign-ins from one IP and a high-risk sign-in from a different IP. Option B is wrong because a leftouter join would include all sign-ins from the user even if no high-risk sign-in exists from that IP, causing the rule to fire when the threshold is met without any high-risk sign-in, violating the requirement. Option C is wrong because the threshold of 10 is not the issue; the rule does not fire due to the join condition failing, not because the count is below the threshold.

123
MCQeasy

In Microsoft Sentinel, an incident is created from a Fusion rule that correlates multiple alerts. The incident has a high severity. What should the analyst do first?

A.Run an automated playbook to contain the threat
B.Close the incident as false positive
C.Triage the incident by reviewing the evidence
D.Escalate the incident to senior management
AnswerC

Triage by reviewing the evidence is the mandatory first action for any Fusion-generated incident in Microsoft Sentinel, as it confirms whether the correlated alerts represent a genuine security threat and establishes the appropriate severity and priority. Analysts examine the incident's alerts, entities, and timeline to understand the attack chain and decide on next steps. This initial assessment ensures that subsequent actions—whether investigation, containment, or escalation—are based on accurate and complete information.

Why this answer

The first step in incident response within Microsoft Sentinel is to triage the incident by reviewing the evidence. A Fusion rule correlates multiple alerts into a single incident, and the analyst must examine the correlated alerts, entities, and timeline to validate the incident's legitimacy and understand the scope before taking any action. Automated playbooks or escalations should only occur after triage confirms the incident is a genuine threat.

Exam trap

The trap here is that candidates may assume a high-severity incident automatically requires immediate containment or escalation, but Microsoft Sentinel's incident response process mandates triage first to validate the correlation and avoid acting on false positives.

How to eliminate wrong answers

Option A is wrong because running an automated playbook to contain the threat should only occur after triage confirms the incident is a real threat; premature automation could disrupt legitimate operations or waste resources on a false positive. Option B is wrong because closing the incident as a false positive without reviewing the evidence violates the incident response process and could miss a genuine attack that the Fusion rule correctly identified. Option D is wrong because escalating to senior management is premature before triage; escalation should happen only after the analyst has assessed the incident's severity and impact.

124
MCQeasy

An incident in Microsoft Sentinel has been classified as a true positive. According to the incident response process, what should the analyst do next?

A.Contain the incident to prevent further damage.
B.Perform a root cause analysis.
C.Create a new analytic rule to detect similar activity.
D.Document the incident in a detailed report.
AnswerA

Once a Sentinel incident is confirmed as a true positive, the immediate objective is to stop the attacker's ability to cause additional harm. In the NIST 800-61 incident response lifecycle, containment follows detection and analysis, preceding eradication and recovery. In practice, this means initiating actions such as disabling the compromised account, isolating the asset via Microsoft Defender for Endpoint's device isolation, or blocking malicious IOCs in Microsoft Sentinel or Microsoft Defender. Delaying containment to perform deeper analysis risks lateral movement, data exfiltration, and destructive actions, which is why this is the unequivocal first step.

Why this answer

After classifying an incident as a true positive in Microsoft Sentinel, the immediate next step in the incident response process is to contain the incident to prevent further damage or lateral movement. This aligns with the NIST SP 800-61 incident response lifecycle, where containment follows identification and classification. In Sentinel, containment actions might involve disabling compromised accounts, blocking IPs via Azure Firewall, or isolating affected resources using Microsoft Defender for Cloud or Azure policies.

Exam trap

The trap here is that candidates often confuse the order of incident response phases, mistakenly thinking root cause analysis or documentation should come immediately after classification, when containment is the critical next step to stop active harm.

How to eliminate wrong answers

Option B is wrong because performing a root cause analysis is part of the eradication and recovery phases, which occur after containment has been completed. Option C is wrong because creating a new analytic rule to detect similar activity is a post-incident improvement task, not an immediate action after classification. Option D is wrong because documenting the incident in a detailed report is part of the lessons learned phase, which happens after containment, eradication, and recovery are finished.

125
MCQhard

An organization uses Microsoft Defender XDR. During an incident investigation, the security team needs to determine if a specific file was executed on any devices in the organization over the past 30 days. They have the file hash. What is the most efficient way to get this information?

A.Use the action center to search for the file
B.Use advanced hunting to query for file execution events
C.Review the incident timeline for the file
D.Check the device inventory for the file
AnswerB

Advanced hunting is the correct tool because it uses Kusto Query Language (KQL) to directly query raw telemetry tables such as DeviceProcessEvents and DeviceFileEvents across all onboarded devices. You can filter by SHA256 file hash to retrieve every execution event, including device, user, command line, and parent process details. This enables a comprehensive, time-bound search for file execution across the entire environment, which aligns with the need to locate all affected systems.

Why this answer

Advanced hunting in Microsoft Defender XDR provides a Kusto Query Language (KQL) interface to query raw event data across all workloads, including DeviceProcessEvents, DeviceFileEvents, and DeviceEvents. By querying for the specific file hash (e.g., SHA256) in process creation events over the past 30 days, the team can efficiently determine if and where the file executed. This is the most direct and scalable method for historical, organization-wide file execution searches.

Exam trap

SC-200 often tests the misconception that the action center or device inventory can be used for historical event searches, when in fact advanced hunting is the only tool designed for proactive, organization-wide threat hunting using raw telemetry.

How to eliminate wrong answers

Option A is wrong because the action center only shows remediation actions taken by Defender, not a searchable log of file executions. Option C is wrong because the incident timeline is limited to the scope of a specific incident and does not provide a global, 30-day execution history. Option D is wrong because device inventory lists installed software and devices, not execution events, and does not support searching by file hash for execution.

126
MCQhard

During an incident response, you need to collect a memory dump from a compromised Windows 10 device managed by Microsoft Defender for Endpoint. Which action should you take in the Microsoft Defender XDR portal?

A.Run a custom detection script
B.Initiate a Live Response session and run the 'memdump' command
C.Execute a Power Automate flow to collect memory
D.Start a full antivirus scan
E.Submit the device for automated investigation
AnswerB

Initiate a Live Response session in Microsoft Defender for Endpoint to get a remote shell on the device, allowing you to execute built-in commands such as memdump. The memdump command captures a full copy of the system's physical memory, which is essential for analyzing in-memory threats like process injection and credential theft. This is the correct method for on-demand memory acquisition.

Why this answer

To collect a memory dump from a compromised Windows 10 device managed by Microsoft Defender for Endpoint, you must initiate a Live Response session and run the 'memdump' command. Live Response provides a remote shell that allows forensic commands like 'memdump' to capture the full memory contents of the target machine, which is essential for analyzing volatile data during incident response. Other options, such as custom detection scripts or automated investigations, do not directly support memory acquisition.

Exam trap

The trap here is that candidates often confuse 'Live Response' with 'automated investigation' or 'custom detection scripts', assuming those can perform memory collection, when in fact only the explicit 'memdump' command within a Live Response session achieves this forensic task.

How to eliminate wrong answers

Option A is wrong because custom detection scripts are designed to run custom queries or actions based on detection logic, not to collect a full memory dump; they lack the direct memory capture capability. Option C is wrong because Power Automate flows can orchestrate actions but cannot natively execute a memory dump command on a remote endpoint; they would require a Live Response session as a prerequisite. Option D is wrong because a full antivirus scan only checks for malware signatures and does not capture volatile memory data needed for forensic analysis.

Option E is wrong because submitting the device for automated investigation triggers Microsoft's automated response playbooks, which may include memory collection only if specifically configured, but it is not a direct or guaranteed method to obtain a memory dump on demand.

127
Multi-Selectmedium

Which THREE features in Microsoft Sentinel allow an analyst to automate incident response actions?

Select 3 answers
A.Playbooks (Logic Apps)
B.Watchlists
C.Workbooks
D.Automation rules
E.Analytics rules with incident automation
AnswersA, D, E

Playbooks in Microsoft Sentinel are built on Azure Logic Apps and allow analysts to define complex, multi-step automated response workflows. They can connect to hundreds of external services, execute custom logic, and perform remediation actions such as blocking an IP, disabling a user, or opening a service desk ticket. Playbooks are the most flexible automation tool in Sentinel, often triggered by automation rules or directly from an incident, and are a correct answer for features that enable automated workflows.

Why this answer

Playbooks (Logic Apps) are correct because they provide a library of pre-built or custom workflows that can be triggered by automation rules or analytics rules to execute complex, multi-step incident response actions, such as blocking IPs, isolating hosts, or enriching alerts with threat intelligence. They integrate with Azure services and third-party APIs via connectors, enabling automated remediation without manual intervention.

Exam trap

The trap here is that candidates confuse Watchlists and Workbooks as active automation tools, when they are passive data stores and visualization tools, respectively, and fail to recognize that only Playbooks, Automation rules, and Analytics rules with incident automation can directly execute response actions.

128
MCQmedium

Your company uses Microsoft Sentinel as its SIEM. You are investigating an incident where a user reported receiving a phishing email that appeared to come from the CEO requesting a wire transfer. The user did not respond. However, the incident also contains alerts from Microsoft Defender for Office 365 indicating that other users clicked on a malicious link in a similar email. The email was sent to 100 users. The company has Microsoft Defender for Endpoint deployed on all devices. The incident requires immediate containment to prevent further compromise. What should you do first?

A.Run a threat hunting query to find all users who clicked the link.
B.Block the malicious URL using Microsoft Defender for Cloud Apps.
C.Isolate the device of the user who reported the email.
D.Delete the email from all users' mailboxes using Microsoft 365 Defender.
AnswerB

Blocking the URL in Microsoft Defender for Cloud Apps immediately prevents any user or device from reaching the phishing destination through the protected web traffic. Microsoft Defender for Cloud Apps uses app proxy and conditional access to enforce URL blocking at the cloud level, covering unmanaged devices and off-network users as well. This is the fastest way to stop the spread of compromise and aligns with the 'contain first' principle in incident response.

Why this answer

Blocking the malicious URL using Microsoft Defender for Cloud Apps (now part of Microsoft 365 Defender) immediately prevents all users from accessing the phishing link, stopping further compromise at the network level. This is the fastest containment action as it applies a URL block across the tenant without requiring individual mailbox or device actions. The incident involves multiple users clicking the link, so a URL block is the most efficient first step to halt the attack chain.

Exam trap

The trap here is that candidates confuse containment with investigation or remediation, often choosing to delete the email (D) or isolate a device (C) instead of recognizing that blocking the URL is the fastest way to stop all users from accessing the malicious link, which is the immediate containment priority.

How to eliminate wrong answers

Option A is wrong because running a threat hunting query is an investigative step that identifies affected users but does not contain the threat; containment requires an immediate blocking action, not analysis. Option C is wrong because isolating the device of the user who reported the email is unnecessary since that user did not respond to the phishing email, and the compromise is from other users who clicked the link; isolating a non-compromised device wastes time and resources. Option D is wrong because deleting the email from all mailboxes removes the phishing message but does not prevent users who already clicked the link from being compromised or block the malicious URL from being accessed again if the email is recovered or forwarded.

129
MCQhard

You are investigating a potential insider threat incident in Microsoft Sentinel. A user account has been flagged for downloading a large number of files from SharePoint Online. You need to determine if the user's activity is anomalous compared to their normal behavior. Which Microsoft Sentinel feature should you use to analyze this?

A.Workbooks with custom visualizations
B.User and Entity Behavior Analytics (UEBA)
C.Fusion incident detection
D.Microsoft Sentinel analytics rules with threshold-based detection
AnswerB

UEBA in Microsoft Sentinel uses machine learning to establish baselines of normal behavior for users and entities, then identifies anomalies. For a user downloading an unusually large number of files from SharePoint, UEBA can flag this as anomalous based on historical activity, helping you determine if it's an insider threat. This is the correct feature for behavioral analysis.

Why this answer

UEBA in Microsoft Sentinel is specifically designed to analyze user and entity behavior, establishing baselines and detecting anomalies. For a user downloading an unusually large number of SharePoint files, UEBA can identify this deviation from normal activity, aiding in insider threat investigations. Other features like Fusion, threshold rules, or workbooks do not provide behavioral baselining and anomaly detection.

Exam trap

The trap here is assuming that any detection feature can perform behavioral analysis, when in fact UEBA is the dedicated capability for baselining and anomaly detection.

130
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. During an incident, you need to automatically disable a compromised Azure VM from the network. Which playbook action should you use?

A.Apply an Azure Policy to deny network changes.
B.Create an Azure Firewall rule to block the VM's IP.
C.Add a rule to the VM's network security group to deny all traffic.
D.Remove the VM's role assignment from Azure RBAC.
AnswerC

Adding a deny-all rule to the VM's network security group (NSG) at the network interface level immediately blocks all inbound and outbound traffic to and from that interface, effectively isolating the VM from the rest of the network. NSG rules are evaluated in priority order, so a high-priority deny rule (e.g., priority 100) supersedes any permissive rules. This is the standard and most direct control for isolating a compromised Azure VM.

Why this answer

Adding a rule to the VM's network security group (NSG) to deny all traffic is the most direct and immediate way to isolate a compromised Azure VM at the network level. NSG rules are evaluated in order of priority, and a deny-all rule (e.g., denying any inbound and outbound traffic) effectively cuts off all network communication to and from the VM, which is a common containment step during incident response. This action can be automated via a Microsoft Sentinel playbook using the Azure Network Security Group connector.

Exam trap

The trap here is that candidates often confuse network-level isolation (NSG rules) with management-plane controls (RBAC) or perimeter-level filtering (Azure Firewall), leading them to choose options that do not actually block all traffic to the compromised VM.

How to eliminate wrong answers

Option A is wrong because applying an Azure Policy to deny network changes is a preventive governance control that blocks future modifications to network resources, but it does not actively block traffic to or from a compromised VM. Option B is wrong because creating an Azure Firewall rule to block the VM's IP would only filter traffic passing through the firewall; if the VM communicates within the same virtual network or uses other paths (e.g., VNet peering, VPN), the firewall rule may not apply, and the VM could still be reachable. Option D is wrong because removing the VM's role assignment from Azure RBAC revokes management-plane permissions (e.g., stopping or reconfiguring the VM) but does not affect network traffic; the VM would remain fully accessible over the network.

131
MCQmedium

During an incident response, a security analyst identifies that a user's account was used to access sensitive data from an anomalous location. The analyst needs to immediately prevent further access from that account while preserving forensic data. Which action should the analyst take?

A.Revoke the user's current sessions in Microsoft Entra ID.
B.Block the IP address of the anomalous location in the firewall.
C.Disable the user account in Microsoft Entra ID.
D.Enable multi-factor authentication (MFA) for the user.
AnswerC

Disabling the user account in Microsoft Entra ID is the correct containment action because it immediately prevents any new authentication attempts, including interactive and behind-the-scenes service account sign-ins. The user object, its assigned licenses, group memberships, and mailbox data are all preserved, so forensic analysis can continue without further compromise. This provides an unambiguous, identity-based kill switch that overrides every other access path relying on the user's credentials.

Why this answer

Disabling the user account in Microsoft Entra ID immediately prevents any further authentication or access to resources, including sensitive data, while preserving the account's forensic data (e.g., sign-in logs, audit events) for investigation. This action stops all current and future sessions without deleting the account or its associated data, which is critical for incident response.

Exam trap

The trap here is that candidates confuse 'revoke sessions' (which only ends current sessions but allows re-authentication) with 'disable account' (which permanently blocks all access), leading them to choose Option A as a quick fix without understanding that it does not prevent further access.

How to eliminate wrong answers

Option A is wrong because revoking the user's current sessions only terminates active sessions but does not prevent the user from re-authenticating and gaining access again, so it fails to stop further access. Option B is wrong because blocking the IP address in the firewall only addresses the specific anomalous location but does not prevent the user from accessing data from other locations, and it may block legitimate users sharing that IP. Option D is wrong because enabling MFA for the user does not immediately stop access; it only adds an additional authentication requirement for future logins, leaving the current sessions and potential re-authentication without MFA intact.

132
MCQmedium

Your organization uses Microsoft Defender for Endpoint. A user reports that their device is running slowly and exhibiting unusual network activity. You run a live response session and find a suspicious process running. Which action should you take first to contain the threat?

A.Collect a full memory dump for analysis.
B.Terminate the suspicious process.
C.Isolate the device from the network.
D.Add a firewall rule to block outbound traffic from the device.
AnswerC

Isolating the device cuts all network communication except the Defender for Endpoint service channel, immediately halting the suspicious process's command-and-control traffic and lateral movement. This satisfies the stem's containment requirement before further investigation, since live response alone leaves the threat active and the device still reachable.

Why this answer

The first containment action in a live response session should be to isolate the device from the network. Isolation stops lateral movement, command-and-control communication, and data exfiltration while preserving the device state for forensic investigation. Terminating the process or collecting a memory dump can wait until the device is contained, because the threat may respawn or the attacker may pivot.

Exam trap

SC-200 often tests the ordering of incident response steps — candidates pick 'terminate process' or 'collect memory' because they sound like immediate action, but containment (isolation) must precede eradication and forensic collection.

How to eliminate wrong answers

Option A is wrong because collecting a full memory dump is a forensic preservation step, not containment — it takes time and does not stop the threat from spreading. Option B is wrong because terminating the suspicious process may destroy evidence, and the process could be re-launched by a persistence mechanism; containment must come first. Option D is wrong because adding a firewall rule to block outbound traffic is a partial, manual mitigation that is slower and less complete than Defender for Endpoint's built-in device isolation, which blocks all network traffic except the Defender service.

133
MCQmedium

You are responding to a data exfiltration incident involving a user who copied sensitive files to a personal cloud storage service. The files were accessed from the user's managed device. Which Microsoft Defender for Cloud Apps activity policy should you create to detect similar future incidents?

A.An anomaly detection policy that flags impossible travel.
B.An activity policy that detects uploads to personal cloud storage services.
C.A file policy that detects files shared with external users.
D.An app discovery policy that identifies new cloud apps used in the organization.
AnswerB

An activity policy in Microsoft Defender for Cloud Apps is designed to monitor specific actions, such as file uploads, across cloud apps. You can configure policy filters based on app (e.g., personal cloud storage services) and the activity type (e.g., upload). This directly matches the incident by triggering an alert when a user uploads a file to a non-corporate cloud service, making it the correct response control.

Why this answer

The incident involves a user copying sensitive files to a personal cloud storage service from a managed device. An activity policy in Microsoft Defender for Cloud Apps can be configured to detect specific activities, such as uploads to personal cloud storage services (e.g., Dropbox, Google Drive), by monitoring the 'Upload' event for recognized cloud apps. This directly addresses the detection of similar future incidents by alerting on the exact action (upload) to the specific service category (personal storage).

Exam trap

The trap here is that candidates may confuse 'file policy' (which governs sharing and permissions) with 'activity policy' (which governs actions like uploads), leading them to incorrectly select Option C, which detects shared files rather than the act of uploading.

How to eliminate wrong answers

Option A is wrong because an anomaly detection policy for impossible travel detects geographically improbable logins, not file uploads to personal cloud storage. Option C is wrong because a file policy that detects files shared with external users focuses on sharing permissions (e.g., via a link), not the act of uploading files to a personal cloud storage service. Option D is wrong because an app discovery policy identifies new cloud apps being used in the organization via traffic logs, but it does not detect specific user activities like uploads to already-known personal storage services.

134
MCQeasy

You are investigating a ransomware incident in Microsoft Sentinel. The incident contains multiple alerts. You need to group related alerts under the same incident to reduce alert fatigue. What should you do?

A.Enable User and Entity Behavior Analytics (UEBA).
B.Create a new analytics rule to combine alerts.
C.Use an automation rule to merge incidents.
D.Configure incident creation rules in the analytics rule.
AnswerD

Configuring incident creation rules in the analytics rule is the correct way to combine related alerts into a single incident in Microsoft Sentinel. When editing an analytics rule, you can enable incident creation and set alert grouping to group up to 150 alerts into one incident based on matching entities (such as account or host) within a defined time window (up to 24 hours). This approach ensures that alerts from the same attack campaign are represented as a single incident, reducing alert fatigue and providing a unified scope for investigation.

Why this answer

In Microsoft Sentinel, incident creation is configured directly within the analytics rule. When you create or edit an analytics rule, the 'Incident creation' settings allow you to enable incident generation from alerts triggered by that rule. This ensures that all alerts from the same rule are grouped into a single incident, reducing alert fatigue by preventing multiple separate incidents for related alerts.

Exam trap

The trap here is that candidates often confuse automation rules (which handle incident actions) with incident creation settings within analytics rules, mistakenly thinking automation rules can merge incidents when they cannot.

How to eliminate wrong answers

Option A is wrong because UEBA (User and Entity Behavior Analytics) is used to detect anomalous behavior based on historical patterns, not to group related alerts under the same incident. Option B is wrong because creating a new analytics rule does not combine alerts; each analytics rule generates its own alerts, and you cannot merge alerts from different rules into one incident through rule creation alone. Option C is wrong because automation rules can trigger actions on incidents (e.g., assign, close, or run playbooks) but cannot merge separate incidents into one; merging incidents is not a supported action in automation rules.

135
Multi-Selectmedium

Which TWO of the following are valid response actions that can be taken on a device from Microsoft Defender for Endpoint? (Choose two.)

Select 2 answers
A.Quarantine email
B.Disable user account
C.Run antivirus scan
D.Reset user password
E.Isolate device from network
AnswersC, E

Running an antivirus scan is a native device response action in Microsoft Defender for Endpoint that initiates a Windows Defender scan directly on the endpoint. This action can be a quick or full scan, allowing security teams to detect and remediate malware without removing the device from the network. It is commonly used to assess a device's health after a potential compromise and is a valid response action for endpoint containment.

Why this answer

Microsoft Defender for Endpoint includes a 'Run antivirus scan' response action that initiates a Microsoft Defender Antivirus scan on the device. This action can be triggered from the Microsoft 365 Defender portal to detect and remediate malware or suspicious files without requiring user interaction.

Exam trap

The trap here is that candidates confuse response actions across different Microsoft security products (Defender for Endpoint vs. Defender for Office 365 vs. Azure AD) and mistakenly select identity-based or email-based actions as valid device-level responses.

136
Multi-Selecteasy

Which TWO are immediate containment actions in Microsoft Sentinel for a compromised Azure VM? (Choose two.)

Select 1 answer
A.Install anti-malware extension
B.Apply an NSG to block all inbound and outbound traffic
C.Reset the VM administrator password
D.Initiate a VM backup
E.Stop the VM using an automation rule
AnswersB

Attaching a network security group denies all inbound and outbound traffic to the VM, cutting command-and-control and lateral movement immediately. This satisfies the containment requirement by isolating the compromised host while investigation continues, without deleting evidence.

Why this answer

The correct answer is B (Apply an NSG to block all inbound and outbound traffic), an immediate containment action that isolates the compromised Azure VM by blocking network traffic. Option A (install anti-malware extension) is a remediation step, not immediate containment. Option C (reset password) does not stop an active attack and may interfere with investigation.

Option D (initiate VM backup) is not containment and could preserve compromised data. Option E (stop the VM using an automation rule) is not a valid Sentinel containment action; automation rules trigger playbooks and do not directly stop VMs, and stopping the VM can destroy volatile evidence.

Exam trap

Do not confuse remediation (installing anti-malware, resetting passwords, backups) with immediate containment (network isolation). Microsoft Sentinel automation rules trigger playbooks; they do not directly stop VMs.

137
MCQhard

A SOC team uses Microsoft Sentinel with Microsoft Defender XDR integration. An incident is created from a Defender for Endpoint alert. The analyst wants to run a KQL query across all affected devices without creating a new analytics rule. How can the analyst achieve this?

A.Modify the analytics rule that created the incident.
B.Use the incident's Logs blade to run a KQL query.
C.Use the Microsoft Sentinel Hunting blade.
D.Create a new workbook.
AnswerB

The incident's Logs blade opens a query environment scoped to the underlying Log Analytics workspace, allowing you to run KQL to pivot on entities, timestamps, or raw tables without creating or altering any rule. This ad-hoc query capability is the appropriate tool for investigating an existing incident because it gives immediate, context-aware access to the telemetry relevant to that incident.

Why this answer

The incident's Logs blade in Microsoft Sentinel allows analysts to run KQL queries directly against the data ingested into the workspace, scoped to the incident's context. This enables ad-hoc investigation across all affected devices without modifying or creating any analytics rules, which would require rule authoring and deployment.

Exam trap

The trap here is that candidates confuse the Hunting blade (which is for proactive, scheduled queries) with the incident-specific Logs blade (which is for reactive, ad-hoc investigation), leading them to choose option C incorrectly.

How to eliminate wrong answers

Option A is wrong because modifying the analytics rule that created the incident would change the rule's logic for future detections, not allow a one-time ad-hoc query across affected devices. Option C is wrong because the Hunting blade is designed for proactive threat hunting across historical data, not for running a query scoped to a specific incident's affected devices. Option D is wrong because creating a new workbook is for building visualizations and reports, not for running an immediate, incident-scoped KQL query.

138
MCQhard

An administrator creates a Microsoft Defender for Cloud Apps policy to block unsanctioned cloud storage apps. Despite the policy, users can still access these apps. What is the most likely cause?

A.The action type 'Block' is incorrect; it should be 'Alert'
B.The policy requires a 'Device' filter to apply to all users
C.The filter uses 'Unsanctioned' tag, but apps are tagged 'Sanctioned'
D.The policy mode is set to 'Monitor', which only alerts and does not block
AnswerD

The policy mode is indeed set to 'Monitor', which is why the 'Block' action does not work. In Defender for Cloud Apps, a policy in Monitor mode only records activity and creates alerts; it does not enforce any governance or blocking actions. To actually block app access, the policy mode must be set to an enforcement mode like 'Block' or 'Govern'. Therefore, this is the correct explanation because changing the mode from Monitor to an enforced setting is required for the Block action to take effect.

Why this answer

When a Microsoft Defender for Cloud Apps policy is set to 'Monitor' mode, it only generates alerts and does not enforce any blocking action. To actually block unsanctioned cloud storage apps, the policy must be configured with a 'Block' action type, typically in conjunction with a 'Governance' action that applies the block at the proxy or API level. The 'Monitor' mode is designed for detection and logging, not enforcement.

Exam trap

The trap here is that candidates often focus on the action type (e.g., 'Block' vs. 'Alert') or the app tagging, overlooking that the policy mode itself controls whether enforcement occurs, not just the action setting.

How to eliminate wrong answers

Option A is wrong because the 'Block' action type is correct for preventing access; changing it to 'Alert' would only notify administrators without blocking. Option B is wrong because a 'Device' filter is not required to apply a policy to all users; policies can target users, groups, or IP ranges without a device condition. Option C is wrong because if apps are tagged 'Sanctioned', they would be allowed, not blocked; the issue is that the policy is in 'Monitor' mode, which does not enforce the block regardless of the tag.

139
MCQmedium

You are reviewing an alert rule in Microsoft Sentinel created via ARM template. What is the primary purpose of this rule?

A.To send an alert when a sign-in with high risk level is detected.
B.To isolate the user's device from the network.
C.To automatically block the user from signing in.
D.To create an incident in Microsoft Sentinel.
AnswerA

This is the intended function of the analytics rule: it periodically runs a KQL query over SigninLogs where the risk level is 'high', and when the number of matching sign-ins exceeds the threshold, it generates a Sentinel alert and sends a notification through the configured action group (email, SMS, or ITSM). The action group is the delivery channel, so the rule's purpose is precisely to alert on high-risk sign-in events—not to take any direct remediation or downstream orchestration steps.

Why this answer

The primary purpose of an alert rule in Microsoft Sentinel created via ARM template is to generate an alert when a specific condition is met, such as a sign-in with a high risk level detected by Azure AD Identity Protection. This alert can then be used to trigger automated responses or create incidents, but the rule itself is designed to detect and alert on the defined condition, not to perform remediation actions like isolation or blocking.

Exam trap

The trap here is that candidates often confuse the purpose of an alert rule with the actions that can be triggered by it, such as automated remediation or incident creation, leading them to select options that describe downstream responses rather than the rule's primary detection function.

How to eliminate wrong answers

Option B is wrong because isolating a user's device from the network is a remediation action that would be performed by an automated response (e.g., a playbook or a Microsoft Defender for Endpoint action), not by the alert rule itself. Option C is wrong because automatically blocking a user from signing in is a conditional access policy action in Azure AD, not a function of a Sentinel alert rule; the rule only generates an alert based on risk detection. Option D is wrong because while an alert rule can be configured to automatically create an incident in Microsoft Sentinel, that is a secondary configuration setting (e.g., 'Create incident from alert' enabled), not the primary purpose of the rule; the rule's core function is to generate an alert when the detection condition is met.

140
MCQeasy

A SOC analyst needs to investigate a potential data exfiltration incident involving a user uploading files to an external cloud storage service. Which Microsoft Sentinel data source would provide the MOST relevant information?

A.SigninLogs
B.CommonSecurityLog
C.AzureActivity
D.OfficeActivity
AnswerD

OfficeActivity is the correct log because it captures detailed audit records from Microsoft 365, including SharePoint, OneDrive, Exchange, and Teams. It records data-plane events such as FileUploaded, FileDownloaded, and FileAccess, which are directly relevant to identifying data exfiltration. For instance, an analyst can search for a user downloading many documents from a sensitive SharePoint site or uploading content to an external location, making this the authoritative source for investigating file-based exfiltration.

Why this answer

OfficeActivity (D) is the correct data source because it captures audit logs from Microsoft 365 services, including SharePoint Online, OneDrive for Business, and Exchange Online. These logs record file uploads, downloads, and sharing events, making them the most relevant for investigating data exfiltration to external cloud storage services like OneDrive or SharePoint.

Exam trap

The trap here is that candidates often confuse AzureActivity (resource management logs) with user activity logs, or assume SigninLogs contain file-level actions, when in fact only OfficeActivity provides the granular file upload events needed for data exfiltration investigations.

How to eliminate wrong answers

Option A is wrong because SigninLogs only record authentication events (successful/failed logins) and do not contain file-level activity details. Option B is wrong because CommonSecurityLog is used for ingesting syslog or CEF-format logs from on-premises security appliances (e.g., firewalls, proxies) and does not natively capture Microsoft 365 cloud storage events. Option C is wrong because AzureActivity logs track resource management operations in Azure (e.g., creating VMs, modifying subscriptions) and do not include user file uploads to cloud storage services.

141
MCQmedium

Refer to the exhibit. You are reviewing a Microsoft Sentinel scheduled analytics rule configured as above. An incident was created for multiple alerts triggering within a 5-hour window. The SOC team needs to investigate each alert separately because they involve different user accounts. What should the analyst do to ensure each alert generates a separate incident?

A.Change the matchingMethod to 'AnyAlert'.
B.Set 'enabled' to false under groupingConfiguration.
C.Set 'reopenClosedIncident' to true.
D.Change the lookbackDuration to PT0H.
AnswerB

Setting enabled to false under groupingConfiguration completely disables the alert grouping engine for that analytics rule. With grouping disabled, Sentinel no longer applies entity-matching or lookback logic, and each individual alert will generate its own independent incident. This is the only direct way to guarantee a one-to-one mapping from alert to incident, which is exactly the desired behavior.

Why this answer

Setting 'enabled' to false under groupingConfiguration disables alert grouping entirely. When grouping is disabled, each individual alert that triggers the scheduled rule will generate its own separate incident, allowing the SOC team to investigate alerts involving different user accounts independently.

Exam trap

The trap here is that candidates often confuse disabling grouping with changing the matchingMethod or lookbackDuration, thinking those options separate alerts, when in fact only setting 'enabled' to false under groupingConfiguration achieves true per-alert incident creation.

How to eliminate wrong answers

Option A is wrong because changing the matchingMethod to 'AnyAlert' still groups alerts into a single incident if they fall within the same time window; it only changes how alerts are matched within the group, not whether grouping occurs. Option C is wrong because setting 'reopenClosedIncident' to true reopens a closed incident when a new alert matches it, but does not prevent grouping of multiple alerts into one incident. Option D is wrong because changing the lookbackDuration to PT0H (zero hours) would still group alerts that trigger at the exact same time, and does not disable the grouping mechanism; it only reduces the time window for grouping.

142
Multi-Selecthard

Which THREE data sources in Microsoft Sentinel can be used to detect lateral movement in a network? (Choose three.)

Select 3 answers
A.DNS logs
B.Microsoft Defender for Endpoint (device events)
C.Windows Event Logs (Event ID 5140)
D.Windows Security Events (Event ID 4624)
E.Microsoft Entra ID sign-in logs
AnswersB, C, D

Microsoft Defender for Endpoint's device events provide deep host telemetry, including process creation, command lines, network connections, and local account logon events. This enables detection of lateral movement techniques such as PsExec, SMB/WMI remote execution, and RDP sessions at the endpoint level. Because it correlates specific processes with network activity and the originating host, it is a powerful source for hunting lateral movement in Sentinel.

Why this answer

Microsoft Defender for Endpoint (MDE) provides detailed device-level events, including process creation, network connections, and logon sessions. These telemetry points are critical for detecting lateral movement because they reveal anomalous remote logins, service creation, or file execution on multiple endpoints, which are hallmarks of an attacker moving laterally.

Exam trap

The trap here is that candidates often select DNS logs (Option A) thinking they can detect lateral movement via unusual internal DNS queries, but DNS logs lack the authentication and process execution context required to confirm lateral movement, making them a supporting data source at best.

143
Multi-Selecthard

During a ransomware incident, Microsoft Defender for Cloud Apps alerts indicate that a user is uploading large volumes of data to an external cloud storage provider not approved by your organization. Which two actions should you take first? (Choose two.)

Select 2 answers
A.Block the unapproved cloud storage app
B.Suspend the user's account
C.Notify the user about the policy violation
D.Initiate a legal hold on the user's data
AnswersA, B

Blocking the unapproved cloud storage app in Microsoft Defender for Cloud Apps immediately enforces a block policy that prevents any session or upload to that app, cutting off the attacker's exfiltration channel. This is a direct containment action that stops ransomware from spreading via file uploads to shadow IT services. By applying a session policy or app governance control, you terminate the active data movement without waiting for user awareness.

Why this answer

Blocking the unapproved cloud storage app in Microsoft Defender for Cloud Apps immediately stops the ongoing data exfiltration by preventing further uploads to that external provider. This is a direct, real-time containment action that leverages Defender for Cloud Apps's app governance and conditional access controls to enforce organizational policies without disrupting the user's access to other resources.

Exam trap

The trap here is that candidates often choose only one containment action (e.g., blocking the app) and overlook the need to also suspend the user account, failing to recognize that the user may continue exfiltration via other unapproved apps or methods if only the app is blocked.

144
MCQmedium

An incident in Microsoft Defender XDR involves a device that is suspected to be infected with ransomware. The device is online and actively encrypting files. Which action should you take to contain the threat?

A.Isolate the device from the network
B.Disable the user's account
C.Run a full antivirus scan on the device
D.Collect a memory dump from the device
AnswerA

Device isolation in Microsoft Defender for Endpoint severs all external network connections while maintaining a secure channel to the MDE cloud so the security team can continue monitoring and issuing commands. This containment action immediately stops the attacker from using the compromised host to propagate over SMB, PsExec, or other protocols, and prevents ransomware from encrypting remote file shares. Isolation is reversible once forensic collection is complete, making it the correct first step in the incident response workflow.

Why this answer

Isolating the device from the network (Option A) is the correct immediate action because it stops the ransomware from communicating with its command-and-control (C2) server and prevents further lateral movement or encryption of network shares. In Microsoft Defender for Endpoint, device isolation blocks all inbound and outbound traffic at the OS kernel level, while still allowing the device to remain online for forensic analysis and remediation. This containment strategy is critical when the device is actively encrypting files, as it halts the attack's spread without losing the ability to investigate or remediate.

Exam trap

The trap here is that candidates often choose 'Run a full antivirus scan' (Option C) because they think detection must precede containment, but the SC-200 exam emphasizes that immediate containment (isolation) is the priority when active encryption is observed, not scanning.

How to eliminate wrong answers

Option B is wrong because disabling the user's account does not stop the ransomware process already running on the device; the malware will continue encrypting files under the system context or cached credentials. Option C is wrong because running a full antivirus scan takes significant time and may not stop the active encryption in progress, allowing the ransomware to complete its damage before detection. Option D is wrong because collecting a memory dump is a forensic step that does not contain the threat; it captures evidence but leaves the device online and actively encrypting, which worsens the incident.

145
MCQmedium

Based on the ARM template snippet, what is the purpose of this analytics rule?

A.To detect multiple failed logon attempts within a time window
B.To detect brute force attacks on user accounts
C.To detect successful logins by account
D.To detect account lockouts
AnswerB

Multiple failed logons indicate brute force.

Why this answer

The query counts failed logon events (EventID 4625) and triggers when the count exceeds a threshold (e.g., 5) within a time window, indicating multiple failed attempts. Option B is correct because a high count of failed logon attempts from the same account or IP is a classic sign of a brute force attack. Option C is incorrect because EventID 4625 is a failed logon, not a successful login.

Option D is incorrect because the query does not include EventID 4740 (account lockout) and does not check for lockouts.

146
MCQhard

During an incident response, a SOC analyst identifies that a malicious PowerShell script was executed on multiple endpoints. The analyst needs to collect relevant files from all affected endpoints for further analysis. What should the analyst use?

A.Microsoft Defender for Cloud Apps file investigation.
B.Microsoft Purview eDiscovery.
C.Microsoft Defender for Endpoint Live Response.
D.Microsoft Sentinel incident investigation graph.
AnswerC

Microsoft Defender for Endpoint Live Response is the correct tool because it provides a secure, remote shell session to an endpoint that is onboarded to Microsoft Defender for Endpoint. Analysts can use Live Response commands like 'collect' to retrieve specific files, run forensic scripts, and inspect system artifacts in real time. It also supports a managed library of commands and can be restricted through RBAC roles, making it purpose-built for incident response file collection.

Why this answer

Microsoft Defender for Endpoint Live Response allows analysts to remotely connect to endpoints and collect files, run scripts, and perform forensic actions in real time. This is the correct tool for gathering malicious PowerShell scripts from multiple affected endpoints during incident response.

Exam trap

The trap here is that candidates may confuse Microsoft Sentinel's investigation graph (which visualizes relationships) with a tool that can actually collect files, or they may think cloud app investigation or eDiscovery can be used for endpoint file collection, when neither supports live endpoint access.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps file investigation is designed for investigating files stored in cloud apps (e.g., SharePoint, OneDrive), not for collecting files from endpoints. Option B is wrong because Microsoft Purview eDiscovery is used for legal discovery and compliance searches across Microsoft 365 data, not for live forensic file collection from endpoints. Option D is wrong because Microsoft Sentinel incident investigation graph provides a visual map of entities and relationships in an incident but does not support direct file collection from endpoints.

147
MCQeasy

You receive an incident in Microsoft Sentinel that is a low-confidence alert from Microsoft Defender for Identity. What should be your first step?

A.Investigate the alert by reviewing related entities and logs.
B.Close the incident as a false positive.
C.Escalate to senior management.
D.Isolate the affected account immediately.
AnswerA

Investigating the alert by reviewing related entities (e.g., user, IP, host) and the underlying logs is the correct first step because it determines whether the detected activity is a true positive. Sentinel's incident investigation canvas allows you to track entity relationships, pivot to related events, and query KQL to confirm the alert's validity before any containment or remediation action is taken.

Why this answer

A low-confidence alert from Microsoft Defender for Identity indicates a potential but uncertain threat. The first step should always be to investigate the alert by reviewing related entities and logs to gather context and determine if the alert is a true positive or false positive. Prematurely closing, escalating, or isolating without investigation risks missing a real threat or causing unnecessary disruption.

Exam trap

The trap here is that candidates may assume low-confidence alerts are always false positives and close them immediately, but the correct triage process requires investigation first to avoid missing subtle attacks that manifest as low-confidence alerts.

How to eliminate wrong answers

Option B is wrong because closing a low-confidence alert as a false positive without investigation bypasses the triage process and could miss a real but subtle attack. Option C is wrong because escalating to senior management is premature before confirming the alert's validity through investigation. Option D is wrong because isolating the affected account immediately is an overreaction to a low-confidence alert and could disrupt legitimate user activity without evidence of compromise.

148
MCQeasy

You have been tasked with creating an automated response in Microsoft Sentinel for incidents involving lateral movement. Which Azure service allows you to run a playbook to automatically isolate a compromised VM?

A.Azure Logic Apps
B.Kusto Query Language (KQL)
C.Microsoft Defender XDR advanced hunting
D.Azure Event Hubs
AnswerA

Playbooks in Microsoft Sentinel are built on Azure Logic Apps, which provide a visual designer to automate incident response actions such as blocking IPs, resetting passwords, or opening tickets. Logic Apps connectors integrate with many services, allowing you to orchestrate a wide range of response workflows. Therefore, Azure Logic Apps is the correct choice for creating an automated response in Sentinel.

Why this answer

Azure Logic Apps is the correct answer because it provides the workflow automation engine that powers Microsoft Sentinel playbooks. When a lateral movement incident is detected, a Logic Apps-based playbook can execute automated actions such as isolating a compromised VM via Azure Network Security Groups (NSGs) or Azure Firewall rules, using connectors like the Azure VM or Azure Resource Manager. This enables a no-code or low-code response directly from Sentinel without manual intervention.

Exam trap

The trap here is that candidates often confuse 'automated response' with 'querying or hunting tools' (like KQL or advanced hunting) and overlook that only Logic Apps provides the actual workflow execution engine for playbooks in Sentinel.

How to eliminate wrong answers

Option B is wrong because Kusto Query Language (KQL) is a query language used to analyze data in Azure Data Explorer and Sentinel logs, not a service for running automated response actions like VM isolation. Option C is wrong because Microsoft Defender XDR advanced hunting is a threat-hunting and querying tool for cross-domain telemetry, not an automation platform capable of executing playbooks or isolating resources. Option D is wrong because Azure Event Hubs is a big data streaming platform and event ingestion service, not a workflow automation service; it cannot run playbooks or directly isolate a VM.

149
Multi-Selecthard

Which TWO remediation actions are available in Microsoft Defender for Endpoint when responding to a malware infection?

Select 2 answers
A.Run a full antivirus scan
B.Disable the user account
C.Reset the device to factory settings
D.Block the application in Defender for Cloud Apps
E.Isolate the device from the network
AnswersA, E

A full antivirus scan is a remediation action in Microsoft Defender for Endpoint, detecting and removing residual malware artefacts across the device after an infection. It satisfies the scenario by cleaning persistent threats that remain following initial detection and investigation.

Why this answer

Option A (Run a full antivirus scan) is correct because Microsoft Defender for Endpoint's device response actions include initiating a full Microsoft Defender Antivirus scan on the endpoint to detect and remediate residual malware artifacts beyond what was already found. Option E (Isolate the device from the network) is correct because device isolation is a core Defender for Endpoint live response action that cuts the endpoint off from the network (while optionally allowing Outlook/Teams communication) to contain the infection and prevent lateral movement. Option B is not a Defender for Endpoint remediation action; disabling user accounts is handled through identity services such as Active Directory or Entra ID, not the MDE device response console.

Option C is not offered as an MDE response action; factory reset is a device-management operation (e.g., Intune), not a Defender for Endpoint remediation. Option D is incorrect because blocking an application in Defender for Cloud Apps is a Cloud App Security (CASB) control for cloud app sessions, not a Defender for Endpoint endpoint remediation action.

Exam trap

SC-200 often tests the boundary between endpoint remediation (MDE), identity actions (Entra ID), and CASB actions (Defender for Cloud Apps) — candidates must pick only the endpoint-native actions.

150
MCQhard

Your organization uses Microsoft Sentinel with UEBA (User and Entity Behavior Analytics). An alert indicates a user's sign-in from an unusual location, followed by a mass download of sensitive files from SharePoint. The user is a low-privilege employee. What is the most likely conclusion?

A.The user's account is compromised
B.The alert is a false positive due to user travel
C.The user is an insider threat
D.The user is conducting a ransomware attack
AnswerA

In Sentinel UEBA, this alert likely combines an impossible-travel event (source IP geolocation far from the user's normal base) with a mass-download anomaly such as copying hundreds of sensitive files from SharePoint Online or OneDrive within minutes. Because the location shift coincides with a sudden spike in data access that does not match the user's established behavioral baseline, the most probable scenario is an attacker using stolen credentials. UEBA also assigns a high risk score when the anomalous activity targets sensitive data categories, and the combination of geographic and volumetric deviations strongly indicates account compromise rather than benign behavior.

Why this answer

The combination of an unusual-location sign-in followed immediately by mass SharePoint downloads from a low-privilege account is the classic UEBA signature of credential compromise: an attacker authenticates with stolen credentials and exfiltrates data the account can reach. A low-privilege user has no legitimate business reason to suddenly download large volumes of sensitive files from a new geography, so the behavior deviates sharply from the account's established baseline. Microsoft Sentinel's UEBA correlates the anomalous sign-in with the abnormal data-access activity to surface this as a high-confidence compromise indicator.

Exam trap

SC-200 often tests the distinction between insider threat and external compromise — the trap is choosing 'insider threat' because the account is legitimate, ignoring that the anomalous geography points to stolen credentials rather than a trusted user acting maliciously.

How to eliminate wrong answers

Option B is wrong because legitimate travel would typically show a plausible travel pattern and the user's normal file-access behavior — a sudden mass download of sensitive files is not explained by travel alone. Option C is wrong because an insider threat implies the legitimate user is intentionally abusing their access; while possible, the unusual-location sign-in is a stronger indicator of external compromise than of an insider acting from their normal location. Option D is wrong because ransomware typically involves encryption, ransom notes, and lateral movement — mass downloading of files is exfiltration behavior, not the encryption/destruction pattern of ransomware.

← PreviousPage 2 of 5 · 375 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Respond to security incidents questions.