Courseiva

CCNA Respond to security incidents Questions

75 of 375 questions · Page 3/5 · Respond to security incidents · Answers revealed

151
Multi-Selecthard

Which THREE data sources should be included in a Microsoft Sentinel workspace to comprehensively monitor for lateral movement within an Azure environment?

Select 3 answers
A.Azure AD sign-in logs
B.Power BI audit logs
C.Azure Network Security Group flow logs
D.Azure DevOps audit logs
E.Azure Activity logs
AnswersA, C, E

Microsoft Entra ID sign-in logs record authentication events, including the originating IP, device and conditional access outcome. They satisfy the lateral movement requirement by exposing credential reuse or anomalous sign-ins from compromised accounts moving between Azure resources.

Why this answer

Azure AD sign-in logs (A) are correct because they record authentication events, including risky sign-ins, IP addresses, and conditional access results, which are essential for detecting credential-based lateral movement across Azure resources. Azure Network Security Group flow logs (C) are correct because they capture allowed and denied IP traffic flows through NSGs, enabling detection of east-west movement between subnets and VMs. Azure Activity logs (E) are correct because they record control-plane operations such as role assignments, resource creation, and management actions that attackers use to pivot and escalate privileges.

Power BI audit logs (B) and Azure DevOps audit logs (D) are not included because they focus on BI and DevOps activities, not on authentication, network, or Azure control-plane events relevant to lateral movement monitoring.

Exam trap

SC-200 often tests whether candidates can distinguish Azure runtime telemetry (sign-in, NSG flow, Activity logs) from SaaS/productivity audit logs (Power BI, DevOps) that do not reflect Azure infrastructure lateral movement.

152
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud Apps. You receive a high-severity incident indicating that a user's credentials were used to access a sensitive SharePoint site from an unmanaged device. The user, 'jdoe@contoso.com', is a senior executive. The IP address is from a public Wi-Fi hotspot. The incident includes a recommendation to apply session policy to block download of sensitive files. You need to create a policy in Microsoft Defender for Cloud Apps that blocks downloads from unmanaged devices for this specific user when accessing the sensitive site. The policy should trigger only when the user accesses the specific SharePoint site named 'ExecConfidential'. What should you do?

A.Create an app connector for SharePoint and a session policy that targets the user, site, and device tag 'Unmanaged' with the action 'Block download'.
B.Create a device compliance policy in Microsoft Intune to block unmanaged devices from accessing SharePoint.
C.Create a Conditional Access policy in Microsoft Entra ID to require compliant device for the SharePoint site.
D.Create a file policy in Defender for Cloud Apps to quarantine files downloaded from the site.
AnswerA

A SharePoint app connector enables Defender for Cloud Apps to proxy sessions, and a session policy scoped to jdoe, the ExecConfidential site and the Unmanaged device tag applies Block download in real time, satisfying the requirement to prevent sensitive file downloads from unmanaged devices.

Why this answer

Blocking downloads from unmanaged devices for a specific user and site requires a Defender for Cloud Apps session policy, which is enforced through Conditional Access app control and requires the SharePoint app connector to be configured. The session policy can be scoped to the user, the specific site 'ExecConfidential', and the 'Unmanaged' device tag, with the action set to block download. This is the only option that combines the app connector, session control, and the precise scoping the requirement demands.

Exam trap

The trap is choosing Conditional Access or Intune because they sound like the 'access control' answer, when the requirement is specifically session-level download blocking scoped to a site—a capability only Defender for Cloud Apps session policies provide.

How to eliminate wrong answers

Option B is wrong because an Intune device compliance policy governs device posture and conditional access eligibility but cannot selectively block file downloads from a specific SharePoint site for a specific user. Option C is wrong because a Conditional Access policy requiring a compliant device would block all access to the site from unmanaged devices rather than allowing access while blocking downloads, and it does not provide session-level download control. Option D is wrong because a file policy in Defender for Cloud Apps quarantines or governs files based on content/metadata after the fact and does not enforce real-time download blocking tied to device management state.

153
MCQmedium

Your organization has Microsoft Defender for Endpoint deployed. A security analyst receives an alert about a suspicious PowerShell command executed on a device. The analyst needs to investigate the process tree. Which feature should the analyst use?

A.Device isolation
B.Live response
C.Timeline (process timeline)
D.Advanced hunting
AnswerC

The device timeline, also known as the process timeline, is the correct answer because it provides a chronological view of events and a visual representation of the process tree, including parent-child relationships. This allows an analyst to trace an attack chain from initial access to execution, observing how each process was spawned and what actions it performed. It is a core DFIR tool in Microsoft Defender for Endpoint for investigating a single device's historical activity.

Why this answer

The Timeline (process timeline) feature in Microsoft Defender for Endpoint allows analysts to view the full process tree, including parent-child relationships, command lines, and timestamps for events like PowerShell execution. This is the correct tool for investigating how a suspicious command was launched and what processes preceded it.

Exam trap

The trap here is that candidates often confuse Live response (a real-time interactive shell) with the Timeline feature (a historical, pre-built process tree), leading them to select Live response because they think it can be used to manually trace processes, but it lacks the automated, visual process tree view needed for efficient investigation.

How to eliminate wrong answers

Option A is wrong because Device isolation is a containment action that disconnects the device from the network to prevent lateral movement, not a forensic tool for viewing process trees. Option B is wrong because Live response provides a remote shell for real-time data collection and remediation (e.g., running scripts or collecting files), but it does not natively display a historical process tree; the process timeline is accessed via the portal. Option D is wrong because Advanced hunting is a Kusto Query Language (KQL)-based tool for querying raw data across multiple tables (e.g., DeviceProcessEvents), but it requires writing custom queries to reconstruct a process tree, whereas the Timeline feature provides a pre-built, visual process tree for a specific alert.

154
Multi-Selecthard

Which TWO actions should be taken to respond to a potential data exfiltration incident detected by Microsoft Defender for Cloud Apps?

Select 2 answers
A.Block the IP address of the user's device at the firewall.
B.Suspend the user account in Microsoft Entra ID.
C.Report the user to Microsoft for investigation.
D.Revoke all active sessions for the user in Defender for Cloud Apps.
E.Run a full antivirus scan on the user's device.
AnswersB, D

Suspending the user account in Microsoft Entra ID immediately disables the account, preventing the user from authenticating and blocking issuance of new access tokens across all Entra ID-integrated cloud applications, including Exchange Online, SharePoint, and Teams. This is the most direct and comprehensive identity-centric containment action because it removes the attacker's ability to log in regardless of endpoint, IP, or session state. It also stops password-based and token-based access at the source, making it the preferred first step in responding to a compromised identity.

Why this answer

Suspending the user account in Microsoft Entra ID immediately revokes the user's ability to authenticate, preventing further access to cloud resources and stopping potential data exfiltration. This is a direct containment action that aligns with incident response best practices for compromised accounts.

Exam trap

The trap here is that candidates often confuse 'revoking sessions' (a temporary measure) with 'suspending the account' (a permanent containment action), and may incorrectly think that blocking an IP address or running an antivirus scan is a sufficient immediate response to data exfiltration.

155
MCQmedium

During an incident investigation in Microsoft Sentinel, you need to gather related events from multiple data sources into a single view for analysis. Which feature should you use?

A.Workbooks
B.Investigation graph
C.Watchlists
D.Logs blade
E.Analytics rules
AnswerB

The Investigation graph is the correct tool for incident investigation because it presents an interactive, visual map of entities (such as hosts, IPs, and accounts) and their connections to alerts and activities. It allows analysts to expand nodes to explore related entities, assess blast radius, and pivot directly into other data sources, making it purpose-built for correlating and understanding a specific incident's scope.

Why this answer

The Investigation graph in Microsoft Sentinel is specifically designed to visually correlate and explore related entities and events across multiple data sources within a single investigation. It allows you to pivot from an alert or entity to see connected users, hosts, IP addresses, and other events, providing a unified view for analysis. This feature directly addresses the need to gather related events from disparate sources into one cohesive view during incident response.

Exam trap

The trap here is that candidates often confuse the Investigation graph with Workbooks or the Logs blade, mistakenly thinking that any visualization or query tool can serve the same purpose, but the Investigation graph is the only feature purpose-built for interactive, entity-centric incident exploration in Sentinel.

How to eliminate wrong answers

Option A is wrong because Workbooks are used for creating custom dashboards and reports for visualizing data trends, not for interactive, entity-based incident investigation. Option C is wrong because Watchlists are static collections of data (e.g., IP addresses or hashes) used for correlation or enrichment in queries, not for dynamic event gathering across sources. Option D is wrong because the Logs blade is a query interface for running KQL queries against raw log data, but it does not provide a built-in, visual entity relationship view for incident investigation.

Option E is wrong because Analytics rules are used to create detection logic that generates alerts, not to investigate or correlate events after an alert has been triggered.

156
Multi-Selecthard

Which THREE steps are part of the containment phase of incident response in Microsoft Sentinel? (Select THREE.)

Select 3 answers
A.Disable compromised user accounts in Microsoft Entra ID.
B.Isolate affected devices using Microsoft Defender for Endpoint.
C.Collect forensic data from affected endpoints.
D.Block malicious IP addresses and domains in Microsoft Defender for Cloud Apps.
E.Restore encrypted files from backup.
AnswersA, B, D

Disabling accounts stops further misuse.

Why this answer

Disabling compromised user accounts in Microsoft Entra ID is a containment step because it immediately revokes the account's access tokens and prevents further authentication, stopping an attacker from using that identity to move laterally or access resources. This aligns with the containment phase's goal of limiting the blast radius of an incident.

Exam trap

The trap here is confusing containment actions (stopping the attack) with investigation (collecting evidence) or recovery (restoring data), leading candidates to select forensic collection or backup restoration as containment steps.

157
Multi-Selecteasy

Which TWO actions should be taken immediately when a compromised user account is detected in Microsoft Entra ID?

Select 2 answers
A.Revoke all current sessions.
B.Notify the user's manager.
C.Disable the user account.
D.Reset the user's password.
E.Block sign-ins from the user's IP address.
AnswersA, C

Revoking all current sessions immediately invalidates the access tokens, refresh tokens, and session cookies that have already been issued to the user, terminating any active attacker foothold in real time. This is a containment-first action because it stops ongoing malicious activity without waiting for password changes or conditional access checks. However, it only disrupts existing authentications; it does not prevent future sign-ins, so it must be paired with disabling the account to block new authentication attempts.

Why this answer

Revoking all current sessions (Option A) is a critical immediate action because it terminates all active authentication tokens and sessions for the compromised account, preventing the attacker from continuing to use existing tokens to access resources. This action leverages Microsoft Entra ID's token revocation capabilities, which invalidate refresh tokens and access tokens issued before the revocation, effectively cutting off the attacker's current access without waiting for password changes or other mitigations.

Exam trap

The trap here is that candidates often choose 'Reset the user's password' as the first action, overlooking that existing sessions remain valid until tokens expire, so session revocation must precede password reset to fully contain the compromise.

158
MCQhard

Refer to the exhibit. A SOC analyst runs this Advanced Hunting query in Microsoft Defender XDR to detect potential living-off-the-land (LotL) attacks. An alert is triggered when a device shows multiple occurrences of 'mshta.exe' executing with a remote script. Which additional data source should the analyst check to confirm the attack?

A.DeviceFileEvents
B.DeviceNetworkEvents
C.DeviceLogonEvents
D.DeviceRegistryEvents
AnswerB

DeviceNetworkEvents supplies the outbound connection telemetry — remote IP, port, and URL — that mshta.exe generated when fetching the remote script. This directly confirms the LotL attack by correlating the process execution already surfaced in the hunting query with the actual command-and-control or payload download destination, satisfying the requirement to verify external network contact.

Why this answer

DeviceNetworkEvents would show network connections made by mshta.exe to remote hosts, confirming the LotL attack. The other options are not directly relevant or are redundant.

159
Multi-Selectmedium

Which TWO actions should an analyst take when triaging a Microsoft Sentinel incident that involves a user who clicked a malicious link in a phishing email? (Choose two.)

Select 2 answers
A.Reset the user's password immediately.
B.Block the sender's domain in the tenant's block list.
C.Run a KQL query on EmailEvents to identify the email and recipient.
D.Delete the email from the user's mailbox immediately.
E.Check the email's status in Microsoft Defender for Office 365 Threat Explorer.
AnswersC, E

Querying EmailEvents in Microsoft Sentinel's advanced hunting tables returns the specific email, recipient, delivery action and verdict, tying the phishing message to the affected user. This satisfies the stem's triage requirement by scoping the incident to concrete evidence before remediation.

Why this answer

Option C is correct because running a KQL query against the EmailEvents table in Microsoft Sentinel (or Advanced Hunting) lets the analyst locate the exact phishing message and confirm the recipient, delivery time, and network message ID, which is essential for scoping the incident. Option E is correct because Microsoft Defender for Office 365 Threat Explorer provides the email's current status (e.g., delivered, blocked, quarantined) and allows further investigation such as viewing the message header, URL detonation results, and related campaigns. Option A is not the right first triage action because a password reset is only warranted if credential compromise is confirmed, and doing it blindly can disrupt the user without addressing the email threat.

Option B is not appropriate during triage because blocking the sender's domain tenant-wide is a containment/remediation step that should follow confirmation of the malicious domain and may cause false positives. Option D is also not a triage action; deleting the email is remediation, and it should be performed after confirming the message is malicious and after preserving evidence for the investigation.

Exam trap

The trap is confusing triage with remediation; candidates may select actions like resetting passwords or deleting emails, which are remediation steps, rather than investigative steps like querying logs and checking threat explorer.

160
MCQmedium

Your Microsoft Sentinel workspace receives logs from multiple sources. You need to ensure that an incident response playbook is triggered automatically when a specific alert is generated. What should you create?

A.A data connector.
B.An analytics rule.
C.An automation rule.
D.A new Logic App.
AnswerC

Automation rules are the native Sentinel mechanism that runs on incident creation or alert creation and can perform actions like assigning ownership, changing status, or invoking a playbook (Logic App) via a trigger. When an automation rule is configured to run a playbook, it uses the alert trigger or incident trigger in the Logic App, passing the alert payload. This is the direct answer to the question because automation rules bridge detection to response. They are the correct trigger mechanism.

Why this answer

An automation rule in Microsoft Sentinel is specifically designed to trigger incident response playbooks automatically when an alert is generated. It allows you to define conditions based on alert properties and then invoke a Logic App playbook without manual intervention. This is the correct mechanism for automating incident response actions in Sentinel.

Exam trap

The trap here is that candidates often confuse analytics rules (which generate alerts) with automation rules (which respond to alerts), leading them to select analytics rules when the question asks for automatic playbook triggering.

How to eliminate wrong answers

Option A is wrong because a data connector is used to ingest logs from external sources into Sentinel, not to trigger playbooks on alerts. Option B is wrong because an analytics rule generates alerts based on query results, but it does not directly trigger playbooks; automation rules are required for that. Option D is wrong because a new Logic App is the playbook itself, but it must be associated with an automation rule to be triggered automatically by an alert; creating just a Logic App does not enable automatic triggering.

161
MCQmedium

Your organization uses Microsoft Sentinel. A security analyst receives an alert from a custom analytics rule that triggers on a specific sequence of failed logon attempts followed by a successful logon from an unusual location. The incident is generated but the analyst is not sure if the activity is malicious or a user error. What should the analyst do first to quickly gather additional context?

A.Run a KQL query across the entire workspace to find all related events
B.Create a new analytics rule to detect similar patterns
C.Use the Investigation graph to explore related entities and events
D.Modify the existing analytics rule to add more conditions
AnswerC

The Investigation graph maps the incident's entities—accounts, hosts, IPs—and their linked events, letting the analyst pivot across the failed-then-successful logon sequence and unusual location in one view, satisfying the need to rapidly gather context before deciding whether the activity is malicious.

Why this answer

The Investigation graph in Microsoft Sentinel is designed to let analysts visually explore an incident's related entities (users, hosts, IPs) and their connections, quickly surfacing additional context such as other alerts, sign-ins, and events tied to the same entities. It is the fastest first step to determine whether the activity is malicious or benign without writing queries.

Exam trap

SC-200 often tests the difference between investigation and detection-engineering actions, so the trap is choosing to modify or create analytics rules (a detection task) instead of using the Investigation graph to gather context on the current incident.

How to eliminate wrong answers

Option A is wrong because running a broad KQL query across the entire workspace is slower and less targeted than the graph, and it does not automatically correlate entities. Option B is wrong because creating a new analytics rule is a detection-engineering task, not an investigation step, and does nothing to gather context on the current incident. Option D is wrong because modifying the rule changes future detection behavior and does not help triage the existing incident.

162
MCQmedium

Refer to the exhibit. A security analyst runs this PowerShell script to query a Log Analytics workspace. What is the purpose of this query?

A.Count the number of unique devices
B.Identify all PowerShell executions in the last 7 days
C.List all processes run by a specific account
D.Detect suspicious PowerShell activity using encoded commands
E.Find devices that have not run PowerShell recently
AnswerD

This option is correct because the query explicitly examines command-line arguments for the '-EncodedCommand' parameter, which is a well-known PowerShell feature that attackers abuse to obfuscate malicious scripts. When an encoded command is present, the actual script is a Base64-encoded string, making static detection more difficult and justifying a suspicion review. Security analysts use such queries in advanced hunting to surface potentially hidden or obfuscated PowerShell activity.

Why this answer

The PowerShell script uses the `| where {$_ -match 'powershell.*-enc'} ` filter to search for command lines containing 'powershell' followed by '-enc', which is the alias for the `-EncodedCommand` parameter. This parameter is commonly used by attackers to obfuscate malicious PowerShell commands by passing them as a Base64-encoded string. The query is specifically designed to detect suspicious PowerShell executions that use encoded commands, making option D correct.

Exam trap

The SC-200 exam often tests the ability to recognize that the `-enc` parameter is a shorthand for `-EncodedCommand`, which is a key indicator of obfuscated PowerShell execution, and candidates may mistakenly think the query simply lists all PowerShell executions (option B) without noticing the specific filter.

How to eliminate wrong answers

Option A is wrong because the query does not include any `distinct` or `summarize` operators to count unique devices; it simply retrieves events without aggregation. Option B is wrong because the query filters for events where the command line matches 'powershell.*-enc', which is a subset of all PowerShell executions, not all PowerShell executions in the last 7 days. Option C is wrong because the query does not filter by a specific account; it searches across all accounts for the encoded command pattern.

Option E is wrong because the query looks for devices that have run PowerShell with encoded commands, not for devices that have not run PowerShell recently.

163
Multi-Selectmedium

Which TWO actions are appropriate when responding to a confirmed malware outbreak on multiple workstations identified by Microsoft Defender for Endpoint?

Select 2 answers
A.Collect investigation packages from the affected devices for analysis.
B.Add the malware hash to the custom threat indicator list.
C.Run a full antivirus scan on all workstations.
D.Reset passwords of all users who logged into the affected devices.
E.Isolate the affected devices from the network using Microsoft Defender for Endpoint.
AnswersA, E

Collecting investigation packages from affected devices is appropriate because it captures volatile forensic artifacts—such as running processes, active network connections, registry keys, and loaded drivers—in their current live state. This package enables analysts to identify Indicators of Compromise (IOCs), the initial access vector, and the full lateral movement scope without altering or destroying evidence. It is a non-disruptive collection action that complements containment, ensuring the investigation has the data needed to understand the outbreak before any cleanup begins.

Why this answer

Collecting investigation packages and isolating affected devices are appropriate response actions. Running a full scan is reactive and not immediate. Resetting passwords may be needed later but not first.

Blocking indicators is proactive but doesn't contain already infected devices.

164
MCQeasy

Your organization uses Microsoft Sentinel. A security analyst reports a high number of false positives from a scheduled analytics rule that detects anomalous sign-ins. The rule uses the 'UserAgent' field in the SigninLogs table. What is the best practice to reduce false positives while maintaining detection coverage?

A.Increase the alert threshold to require more than one anomalous sign-in per hour.
B.Create a watchlist of legitimate IP addresses and reference it in the rule.
C.Disable the analytics rule and create a new one with different MITRE tactics.
D.Add a condition to the rule query to filter out known legitimate user agents.
AnswerD

Adding a condition to the rule query to filter out known legitimate user agents is the targeted fix because it directly removes the benign UserAgent strings from the anomaly-detection scope. In KQL, you can implement this with a `where UserAgent notin (~['LegitAgent1', 'LegitAgent2'])` clause or a regex pattern like `where UserAgent !matches regex @"(Chrome/120\.0|Edge/120\.0)"`, preserving the rule's ability to detect truly anomalous strings. This approach reduces false positives while maintaining full detection fidelity for other anomalous sign-in attributes such as geographic location, device compliance, or risk score, aligning with Sentinel best practices for rule tuning.

Why this answer

The high number of false positives is caused by legitimate user agents triggering the anomaly detection. By adding a condition to the KQL query that filters out known legitimate user agents (e.g., 'Mozilla/5.0' for standard browsers), you reduce noise without losing detection of truly anomalous sign-ins. This preserves the rule's coverage for unknown or malicious user agents while eliminating predictable false positives.

Exam trap

The trap here is that candidates may confuse the source of false positives (UserAgent field) with other common mitigation techniques like IP whitelisting (Option B) or threshold tuning (Option A), failing to realize that the most precise fix is to filter the specific noisy field directly in the query.

How to eliminate wrong answers

Option A is wrong because increasing the alert threshold to require more than one anomalous sign-in per hour would reduce sensitivity and could miss single, high-risk anomalous sign-ins, thus reducing detection coverage. Option B is wrong because creating a watchlist of legitimate IP addresses and referencing it in the rule addresses false positives from IP-based anomalies, not from the UserAgent field; the issue is specifically with user agents, not IP addresses. Option C is wrong because disabling the rule and creating a new one with different MITRE tactics does not address the root cause of false positives from the UserAgent field; it would lose existing detection logic and potentially introduce new gaps.

165
MCQhard

Your company uses Microsoft Defender for Endpoint (MDE) on all Windows 10 devices. You are investigating a machine that is suspected of being part of a botnet. The machine is communicating with a known C2 server at IP 203.0.113.55. You have confirmed that the IP is malicious. You need to block all outbound traffic from the machine to that IP immediately, and also ensure that no other devices in the organization can communicate with that IP. The solution must be implemented without deploying additional network appliances. What should you do?

A.Create a network protection policy in Microsoft Intune to block the IP
B.Create a custom network indicator in Microsoft Defender for Endpoint with action 'Alert and block'
C.Use the Microsoft Defender for Endpoint portal to block the IP globally
D.Create a firewall rule in Windows Defender Firewall to block outbound traffic to the IP, and deploy via Group Policy
AnswerB

Custom network indicators in Microsoft Defender for Endpoint let you block outbound traffic to a specified IP across all onboarded devices, using the existing agent rather than adding network appliances, satisfying both the immediate block and organisation-wide enforcement.

Why this answer

Custom network indicators in Microsoft Defender for Endpoint allow you to define IP addresses, URLs, or domains and assign an action of 'Alert and block' or 'Alert only'. When set to 'Alert and block', the indicator is enforced on all onboarded devices via the Defender for Endpoint network protection stack, blocking outbound connections to the specified IP without requiring any additional network appliances. This satisfies both requirements: immediate blocking on the affected machine and organization-wide enforcement across all MDE-onboarded Windows 10 devices.

Exam trap

SC-200 often tests the difference between Defender for Endpoint custom indicators (IOC-based, tenant-wide, no extra appliances) and Intune/Windows Firewall policies, tricking candidates into picking the more familiar firewall or Intune option when the question explicitly says 'no additional network appliances' and 'all devices'.

How to eliminate wrong answers

Option A is wrong because Intune network protection policies configure the Windows Defender SmartScreen/network protection feature but do not accept raw IP addresses as block entries — they rely on Defender for Endpoint indicators or web content filtering categories. Option C is wrong because there is no standalone 'block IP globally' button in the MDE portal; blocking is done through indicators (IOCs), not a generic portal toggle. Option D is wrong because a Windows Defender Firewall rule deployed via GPO only affects domain-joined Windows devices in scope of the GPO, does not integrate with MDE telemetry, and constitutes an additional management mechanism rather than using the existing MDE platform.

166
Multi-Selectmedium

Your organization uses Microsoft 365 Defender. You are investigating a potential malware outbreak on several endpoints. Which TWO actions should you take to isolate affected devices and prevent lateral movement?

Select 2 answers
A.Use Microsoft Defender for Endpoint to initiate device isolation on affected devices.
B.Run a full antivirus scan on all endpoints.
C.Reset the passwords of all users on the affected devices.
D.Delete the user accounts that logged into the affected devices.
E.Block the file hash of the malware in Microsoft Defender for Endpoint indicators.
AnswersA, E

Device isolation should be initiated from the Microsoft 365 Defender portal on each affected endpoint. This action immediately blocks all inbound and outbound network communications, except traffic to the Defender service, so the attacker loses the ability to move laterally, communicate with command-and-control servers, or exfiltrate data while the investigation continues. It is the first-line containment control when an active infection is confirmed.

Why this answer

Microsoft Defender for Endpoint's device isolation feature disconnects the device from the network while keeping the endpoint connected to the Defender service for monitoring and remediation. This prevents lateral movement by stopping all inbound and outbound communication, effectively containing the malware without losing visibility or control.

Exam trap

The trap here is that candidates often confuse reactive remediation actions (like scanning or password resets) with proactive containment actions, failing to recognize that only network-level isolation and indicator blocking directly prevent lateral movement.

167
Multi-Selectmedium

Which THREE indicators of compromise (IOCs) are commonly used in Microsoft Sentinel to detect advanced persistent threats (APTs)? (Choose THREE.)

Select 3 answers
A.Suspicious domains and URLs.
B.Vulnerability scan results.
C.File hashes (SHA256) of known malware.
D.Windows event IDs for successful logins.
E.IP addresses of known command and control servers.
AnswersA, C, E

Suspicious domains and URLs are network-based IOCs that Microsoft Sentinel matches against DNS, proxy, and firewall logs to surface command-and-control beaconing and phishing infrastructure. They satisfy the APT detection requirement because advanced persistent threats routinely rely on domain generation algorithms and compromised legitimate sites, making domain and URL indicators high-fidelity detection signals.

Why this answer

Option A is correct because suspicious domains and URLs are classic network-based IOCs that Microsoft Sentinel ingests via threat intelligence connectors and matches against DNS, proxy, and firewall logs to surface APT beaconing or phishing infrastructure. Option C is correct because SHA256 file hashes of known malware are high-fidelity, atomic IOCs that Sentinel uses in scheduled analytics rules and the Threat Intelligence matching rule to detect malicious binaries on endpoints and in file events. Option E is correct because IP addresses of known command-and-control servers are standard network IOCs that Sentinel correlates with CommonSecurityLog, Azure Firewall, and DNS data to identify active C2 communication.

Option B is not an IOC but a vulnerability assessment artifact describing exposure rather than evidence of compromise, and Option D is a normal operational event (e.g., Event ID 4624) that only becomes suspicious in context, not a standalone IOC.

Exam trap

The trap here is that candidates confuse vulnerability data (Option B) or routine operational events (Option D) with true IOCs, which must directly indicate a past or ongoing compromise rather than a potential risk or normal behavior.

168
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID (Azure AD) and on-premises Active Directory. You are using Microsoft Defender for Identity (MDI) integrated with Microsoft Defender XDR. An incident is raised indicating that a user account has been compromised because of an anomaly in Kerberos protocol activity. The incident severity is High. You need to contain the incident immediately by disabling the user account across both on-premises and cloud. However, you also want to preserve the account for forensic analysis. What is the recommended course of action?

A.Delete the user account from Microsoft Entra ID and on-premises AD immediately.
B.Reset the user's password in Microsoft Entra ID and force a password change at next logon on-premises.
C.Enable conditional access policy to require MFA for the user and revoke all refresh tokens.
D.From Microsoft Defender XDR incident, use the action to disable the user account in Microsoft Entra ID and also disable the on-premises account using a playbook that runs a PowerShell script.
AnswerD

Disabling the account in Microsoft Entra ID blocks cloud sign-in, while a playbook running PowerShell disables the on-premises Active Directory account, containing the Kerberos-based compromise across both environments. Disabling rather than deleting preserves the account for forensic analysis.

Why this answer

Microsoft Defender XDR provides a built-in action to disable a user account in Microsoft Entra ID directly from the incident. For on-premises AD, a playbook with a PowerShell script can disable the account, preserving it for forensic analysis. This approach contains the incident across both environments without deleting the account.

Exam trap

SC-200 often tests the need to disable accounts in both cloud and on-premises environments while preserving them for forensics, and candidates may choose password reset or deletion instead.

How to eliminate wrong answers

Option A is wrong because deleting the account destroys forensic evidence and is not recommended for containment. Option B is wrong because resetting the password does not disable the account and may not stop active Kerberos attacks. Option C is wrong because conditional access and token revocation do not disable the on-premises account, leaving it vulnerable.

169
MCQmedium

You are investigating a potential ransomware incident in Microsoft Defender XDR. The incident has a high severity alert indicating that a user installed a suspicious application. Which initial response action should you take to contain the threat while preserving evidence?

A.Isolate the device using Microsoft Defender for Endpoint.
B.Reset the user's password and enforce MFA.
C.Uninstall the suspicious application via Intune.
D.Disable the user account in Microsoft Entra ID.
AnswerA

Isolating the device via Microsoft Defender for Endpoint severs network communication while retaining the machine's live state, memory and forensic artefacts. This contains the ransomware's spread and preserves evidence, satisfying the requirement to contain the threat without destroying data needed for investigation.

Why this answer

Isolating the device using Microsoft Defender for Endpoint immediately stops lateral movement and data exfiltration while preserving forensic data. Option B is wrong because resetting the password and enforcing MFA does not contain the threat on the device itself. Option C is wrong because uninstalling the suspicious application may remove evidence needed for investigation.

Option D is wrong because disabling the user account does not stop malware already running on the device.

170
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You receive an alert from Defender for Cloud that a virtual machine has a high severity vulnerability: 'CVE-2023-XXXX' with a CVSS score of 9.8. The virtual machine is running a critical application for the finance department. You need to remediate the vulnerability as quickly as possible while minimizing downtime. The application vendor has not yet released a patch but has provided a workaround. What should you do?

A.Dismiss the alert as a false positive because no patch is available.
B.Shut down the virtual machine until a patch is available.
C.Implement the workaround provided by the vendor and create a custom remediation task in Defender for Cloud to track the issue.
D.Apply a network security group to block all inbound traffic to the VM.
AnswerC

Applying the vendor workaround mitigates the CVSS 9.8 exposure immediately without downtime, since no patch exists, and the custom remediation task tracks the risk until a permanent fix arrives. This satisfies the stem's requirement to remediate quickly while minimising downtime.

Why this answer

When no vendor patch exists but a workaround is available, applying the workaround immediately mitigates the risk while a custom remediation task in Defender for Cloud tracks the issue until a permanent patch arrives. This balances urgency (CVSS 9.8 is critical) with the business need to keep the finance application running.

Exam trap

SC-200 often tests whether candidates choose the most extreme action (shutdown, full network block) instead of the proportionate, tracked mitigation that keeps the business running.

How to eliminate wrong answers

Option A is wrong because dismissing a confirmed high-severity CVE as a false positive ignores a real, exploitable vulnerability and violates incident response best practice. Option B is wrong because shutting down a critical finance VM causes unacceptable downtime when a vendor workaround exists. Option D is wrong because blocking all inbound traffic with an NSG is a blunt instrument that would break legitimate application access, not a targeted remediation.

171
MCQhard

Refer to the exhibit. You are investigating incidents related to suspicious process injection. The KQL query above is run in Microsoft Sentinel. What is the purpose of this query?

A.To find alerts that occurred within a specific time range
B.To list all alerts of type 'Suspicious process injection' in the last 7 days
C.To get a count of 'Suspicious process injection' alerts grouped by compromised entity and severity, sorted by count
D.To identify the compromised entities with the highest severity alerts
AnswerC

The query first filters to only alerts where the title equals 'Suspicious process injection', then uses `summarize count() by CompromisedEntity, Severity` to compute how many alerts fall into each entity/severity bucket. Finally, it orders the aggregated results by the count in descending order, so the highest-frequency entity/severity combinations appear first. This exactly matches the stated purpose.

Why this answer

The query uses `summarize` with `count()` to aggregate alerts by `CompromisedEntity` and `Severity`, then sorts by the count in descending order. This directly produces a count of 'Suspicious process injection' alerts grouped by compromised entity and severity, sorted by count. The `where` clause filters for the specific alert name, and the time range is implicitly the last 7 days (as shown in the exhibit's query editor).

Exam trap

The trap here is that candidates often confuse 'listing alerts' (Option B) with 'aggregating and counting alerts' (Option C), overlooking the `summarize` and `count()` operators that transform the output from individual records to grouped counts.

How to eliminate wrong answers

Option A is wrong because the query does not filter by a specific time range; it relies on the default time range set in the query editor (last 7 days), but the purpose is not to find alerts within a range but to aggregate and count them. Option B is wrong because the query does not simply list all alerts; it uses `summarize` to group and count them, not to return individual alert records. Option D is wrong because the query groups by both `CompromisedEntity` and `Severity` and sorts by count, not by severity; it does not identify entities with the highest severity alerts—it identifies those with the highest count of alerts, regardless of severity.

172
Multi-Selecthard

Your organization uses Microsoft Defender XDR. A security incident involving a compromised user account has been identified. Which THREE actions should you take to contain and remediate the incident?

Select 3 answers
A.Disable the user account in Microsoft Entra ID.
B.Reset the user's password.
C.Block all IP addresses that the user has connected from.
D.Revoke all active sessions and tokens for the user.
E.Restore the user's mailbox from a backup.
AnswersA, B, D

Disabling the user account in Microsoft Entra ID is the most effective first containment step because it immediately blocks all authentication attempts, including the attacker's stolen credentials, and prevents access to all Microsoft 365 and cloud resources that depend on Entra ID. Even if the attacker holds a valid session token, disabling the account stops new sign-ins and is a strong, reversible measure that preserves the user profile and forensic data for investigation. In Microsoft Defender XDR incident response, this is the recommended manual action to halt attacker activity without deleting any evidence.

Why this answer

Disabling the user account in Microsoft Entra ID is a critical containment step because it immediately prevents the compromised account from authenticating to any Microsoft cloud services, including Exchange Online, SharePoint, and Teams. This action blocks further unauthorized access at the identity level, which is the foundation of the attack vector in a user account compromise. It is a direct and effective way to stop the attacker from using the account for lateral movement or data exfiltration.

Exam trap

The trap here is that candidates may think blocking IP addresses (Option C) is a valid containment action, but in Microsoft Defender XDR incidents, IP-based blocking is unreliable due to dynamic IPs and attacker evasion techniques, and the focus should be on identity-level controls like disabling the account and revoking tokens.

173
MCQhard

You are a Security Operations Analyst investigating a potential insider threat. A user's account was flagged for downloading a large number of files from SharePoint Online. You need to review the user's activity and determine if the behavior is malicious. You have Microsoft Defender for Cloud Apps and Microsoft Sentinel configured. Which Microsoft Sentinel data source should you query to analyze the user's file download activities in SharePoint?

A.AuditLogs table
B.OfficeActivity table
C.CloudAppEvents table
D.SigninLogs table
AnswerB

The OfficeActivity table in Microsoft Sentinel contains audit logs from Microsoft 365, including SharePoint Online and OneDrive for Business. It records events such as FileDownloaded, FileAccessed, and FileUploaded, along with user and file details. Querying this table allows you to analyze the user's file download activities and assess the volume and sensitivity of the files involved.

Why this answer

The OfficeActivity table is the correct data source for SharePoint Online file download activities. It captures detailed audit events such as FileDownloaded, including user, file name, and client IP, enabling you to assess the scale and nature of the downloads and determine if the behavior is suspicious.

Exam trap

The trap here is assuming that CloudAppEvents or AuditLogs contain SharePoint file download details, when in fact OfficeActivity is the dedicated table for Microsoft 365 audit events including SharePoint.

174
MCQmedium

Your organization uses Microsoft Sentinel. A security analyst reports that an incident was automatically closed without investigation. You need to identify why the incident was closed automatically. Which Sentinel feature should you review?

A.Analytics rules
B.Automation rules
C.Playbooks
D.Workbooks
E.Watchlists
AnswerB

Automation rules are Sentinel's native, rule-based engine for incident lifecycle automation, evaluated when an incident is created or updated. They support one or more conditions (e.g., severity, title, entity) and multiple actions, including setting the incident status to 'Resolved/Closed' and specifying a closure classification and comment. Because they are first-class components that directly execute incident-state changes without external dependencies, they are the definitive mechanism for automatically closing incidents.

Why this answer

Automation rules in Microsoft Sentinel allow you to define automated responses to incidents, including automatically closing them based on specific conditions (e.g., severity, title, or entity). If an incident was closed without investigation, an automation rule likely triggered a closure action, such as setting the status to 'Closed' with a specific classification. Reviewing the automation rules list and their trigger conditions will reveal which rule caused the automatic closure.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, thinking playbooks directly close incidents, but in Sentinel, playbooks are only triggered by automation rules and the closure action is defined in the automation rule itself, not in the playbook.

How to eliminate wrong answers

Option A is wrong because analytics rules generate alerts and incidents based on data queries, but they do not directly close incidents; they only create or suppress them. Option C is wrong because playbooks are workflows triggered by automation rules or analytics rules to perform complex actions (e.g., sending emails), but they are not the configuration that directly closes incidents—automation rules invoke playbooks, but the closure action is defined in the automation rule itself. Option D is wrong because workbooks are visualization dashboards for data analysis and do not perform any automated incident management actions.

Option E is wrong because watchlists are collections of data (e.g., IP addresses) used for correlation or filtering in analytics rules, not for automating incident closure.

175
MCQmedium

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure subscriptions. You receive an alert that a critical vulnerability exists on a virtual machine. What is the BEST immediate action to validate the alert and contain the threat?

A.Contact Microsoft support to request a vulnerability assessment.
B.Immediately apply the latest security patches to the VM using Azure Update Manager.
C.Isolate the VM from the network by applying a network security group rule.
D.Review the alert details in Microsoft Defender for Cloud to identify the vulnerability and follow the remediation steps.
AnswerD

Reviewing the alert details in Microsoft Defender for Cloud confirms the specific vulnerability and affected resource, then applying the documented remediation steps contains the threat. This validates before acting, satisfying the requirement for the best immediate action rather than unverified escalation or disabling the virtual machine.

Why this answer

The best immediate action is to review the alert details in Microsoft Defender for Cloud because it provides the specific vulnerability, affected resource, and recommended remediation steps. This validation step ensures you understand the threat before taking containment actions, which is critical for an effective and proportionate response. Defender for Cloud's alerts include contextual information such as severity, MITRE tactics, and remediation guidance, enabling informed decision-making.

Exam trap

SC-200 often tests the importance of validating alerts before taking action, as candidates may rush to containment or remediation without first reviewing the alert details, leading to unnecessary disruptions or ineffective responses.

How to eliminate wrong answers

Option A is wrong because Microsoft support does not perform vulnerability assessments on demand; Defender for Cloud already provides this capability. Option B is wrong because applying patches immediately without validating the alert could disrupt operations and may not address the specific vulnerability if the alert is a false positive. Option C is wrong because isolating the VM via NSG is a containment action that should be taken after validating the alert; doing so immediately could cause unnecessary downtime and may not be the appropriate response for a vulnerability that might not be actively exploited.

176
MCQeasy

Your SOC uses Microsoft Defender for Cloud Apps. An alert indicates that a user is downloading a large number of files from SharePoint. Which action should you take to investigate and potentially block the activity?

A.Create a Conditional Access policy to block the user
B.Block the IP address in Azure Firewall
C.Use Microsoft Intune to wipe the user's device
D.Suspend the user in Defender for Cloud Apps
AnswerD

Suspending the user in Defender for Cloud Apps is the correct immediate governance action because it directly targets the user account, revoking active sessions, invalidating access tokens, and blocking future sign-ins to connected cloud apps. This identity-level action is precise, affecting only the suspicious account without impacting other users who might share an IP address, and it stops the ongoing activity in real time. Defender for Cloud Apps can apply this action via the underlying app's API, ensuring that the suspension propagates across all managed cloud services as a consistent and immediate containment measure.

Why this answer

In Microsoft Defender for Cloud Apps, suspending a user is a direct response action that blocks the user from accessing cloud apps and can be used during investigation of suspicious activity like mass file downloads. This is the native remediation action within the CASB solution, allowing the SOC to contain the threat without disabling the identity across all of Azure AD.

Exam trap

SC-200 often tests the difference between native Defender for Cloud Apps remediation actions (suspend user) and broader identity controls (Conditional Access), so candidates may overreach with Azure AD tools.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies are configured in Azure AD/Entra ID and are broader identity controls, not the immediate investigative action within Defender for Cloud Apps for this alert. Option B is wrong because blocking an IP in Azure Firewall does not address a user-based cloud app activity and may not stop the user from other networks. Option C is wrong because wiping a device via Intune is a drastic endpoint action unrelated to cloud file downloads and would not directly stop the cloud app activity.

177
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Identity. An alert fires for a potential DCSync attack. The incident response team needs to immediately block the source account from performing directory replication. Which action should be taken?

A.Use Microsoft Defender for Identity to disable the account.
B.Reset the account password and enforce a sign-out.
C.Disable the account in Microsoft Entra ID (if synced) or Active Directory.
D.Remove the account from the Domain Admins group.
AnswerC

Disabling the account in Microsoft Entra ID (for cloud-only accounts) or Active Directory (for on-premises or hybrid accounts) is the definitive containment step. For a hybrid environment, you should disable the account on-premises first, as Azure AD Connect will synchronize the disabled state to Entra ID; for a cloud-only account, you can disable sign-in in Entra ID. This immediately prevents any new authentication attempts, including Kerberos, NTLM, or interactive logon, and blocks DCSync because the account can no longer request a TGT or authorize replication. This is the only option that fully neutralizes the compromised account.

Why this answer

Immediately disabling the account in Microsoft Entra ID (if synced) or Active Directory is the fastest way to stop the compromised account from performing any directory replication, including DCSync attacks. DCSync abuses the domain controller's replication protocol (MS-DRSR) to request password hashes, and disabling the account blocks all Kerberos and NTLM authentication, effectively halting the attack at the source.

Exam trap

The trap here is that candidates often assume resetting the password is sufficient to stop an attack, but they overlook that cached Kerberos tickets or active replication sessions can persist, making immediate account disablement the only surefire way to block DCSync in real time.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Identity does not have a built-in capability to disable an account; it can only trigger alerts or suggest remediation actions, but the actual disable must be performed in Active Directory or Entra ID. Option B is wrong because resetting the password and enforcing sign-out does not immediately stop an ongoing DCSync attack—the account may still have cached Kerberos tickets or active sessions that allow replication until they expire. Option D is wrong because removing the account from Domain Admins does not prevent it from performing DCSync if it still has the 'Replicate Directory Changes' permission assigned via other group memberships or direct delegation.

178
Multi-Selecteasy

A security analyst detects a suspicious login from an unusual location for a user in Microsoft Defender XDR. The analyst needs to investigate and contain the incident. Which TWO actions should be taken?

Select 2 answers
A.Disable the user account from Microsoft Entra ID.
B.Create a custom hunting query in Microsoft 365 Defender advanced hunting.
C.Review the user's sign-in logs and risk level in Microsoft Entra ID Identity Protection.
D.Run an automated investigation playbook.
E.Reset the user's password.
AnswersA, C

Disabling the account in Microsoft Entra ID immediately blocks further authentication and token issuance for the compromised identity, containing the incident while investigation continues. This directly satisfies the stem's requirement to contain a suspicious sign-in from an unusual location.

Why this answer

Option A is correct because disabling the user account in Microsoft Entra ID immediately blocks the compromised identity from authenticating, which is the fastest containment action to stop further unauthorized access during a suspicious-login incident. Option C is correct because reviewing the user's sign-in logs and Identity Protection risk level in Microsoft Entra ID provides the investigative context — source IP, location, device, and whether the sign-in was flagged as risky — needed to confirm compromise before or alongside containment. Option B is not the right primary action because advanced hunting is a proactive threat-hunting tool, not the standard investigative/containment step for a specific flagged sign-in.

Option D is not appropriate here because automated investigation playbooks are triggered by specific alerts or incidents and are not the analyst's direct manual containment action. Option E is not the best choice because a password reset alone does not immediately terminate active sessions or block the account, so it is weaker containment than disabling the account.

Exam trap

The trap is choosing password reset as containment — candidates assume resetting credentials stops the attacker, but without disabling the account or revoking sessions, an attacker with a valid token or persistence mechanism retains access.

179
MCQmedium

Refer to the exhibit. You run this KQL query in Microsoft Defender XDR to detect suspicious PowerShell activity. Why might this query generate many false positives?

A.The time range is too broad.
B.The query is too specific and misses many attacks.
C.Legitimate administrators often use encoded PowerShell commands.
D.The query does not filter by user.
AnswerC

Encoded PowerShell is a legitimate administrative technique, so a detection rule flagging encoded commands matches benign activity and inflates false positives. The query's logic keys on encoding itself, which is not inherently malicious, satisfying the stem's constraint that the rule triggers on common legitimate behaviour.

Why this answer

Legitimate administrators often use encoded PowerShell commands, which would match this query and generate false positives. Option A is wrong because the time range shown in the exhibit (e.g., 7 days) is not excessively broad for hunting. Option B is wrong because the query is specific to encoded commands, but it does not miss attacks; it targets a specific technique.

Option D is wrong because, while filtering by user could reduce noise, the main reason for false positives is that encoded commands are used legitimately, not because of the absence of user filtering.

180
MCQhard

Your organization has deployed Microsoft Sentinel with the Microsoft Defender XDR connector. A high-severity incident is created for a user who received a phishing email that contained a malicious link. The user clicked the link, and the attacker gained access to the user's mailbox. The security team needs to remove the attacker's access and prevent future occurrences. What should you do first?

A.Run a full antivirus scan on the user's device
B.Reset the user's password immediately
C.Report the incident to Microsoft for further investigation
D.Remove any mailbox forwarding rules and delegated access
AnswerD

Attackers persist by creating hidden inbox forwarding rules and granting delegated mailbox access, so removing these first severs the attacker's ongoing access to the compromised mailbox. Containment precedes broader remediation such as password resets or investigation, satisfying the requirement to remove access immediately.

Why this answer

The first step should be to remove any mailbox forwarding rules and delegated access because attackers often set up persistence mechanisms to maintain access even after password resets. Removing these ensures the attacker cannot continue to receive emails or access the mailbox. This is a critical containment step before other remediation actions.

Exam trap

SC-200 often tests the order of incident response actions; the trap is focusing on password reset or antivirus scans while missing the attacker's persistence mechanisms like forwarding rules.

How to eliminate wrong answers

Option A is wrong because a full antivirus scan on the user's device addresses malware but does not remove attacker access from the mailbox, which is the immediate concern. Option B is wrong because resetting the password alone may not remove forwarding rules or delegated access, allowing the attacker to persist. Option C is wrong because reporting to Microsoft is not the first step; containment and remediation should be prioritized.

181
MCQhard

Refer to the exhibit. You have created an automation rule in Microsoft Sentinel with the above configuration. The playbook isolates the device and disables the user account. After enabling the rule, you notice that a low-severity incident containing an alert titled 'Ransomware Behavior' did NOT trigger the automation. What is the most likely reason?

A.The 'ContainsAny' operator does not match single values
B.The automation rule does not have permission to run the playbook
C.The playbook ID is invalid
D.The incident severity is Low, but the rule only triggers on High severity
AnswerD

The rule's condition filters on High severity, so a Low-severity incident falls outside its trigger scope entirely. Microsoft Sentinel evaluates automation rule conditions against incident properties at creation; severity mismatch prevents any playbook run, regardless of the alert title. Raising the incident's severity or broadening the rule condition would allow execution.

Why this answer

Microsoft Sentinel automation rules have a condition set that includes severity; if the rule is configured to trigger only on High-severity incidents, a Low-severity incident will never fire the rule regardless of the alert title. The exhibit shows the rule's conditions, and the most likely mismatch is the severity filter. The playbook itself is not the issue because the rule simply never evaluated to true for this incident.

Exam trap

The trap is assuming the playbook or operator is at fault when the real issue is a condition mismatch — always check the rule's severity/status filters against the incident that failed to trigger.

How to eliminate wrong answers

Option A is wrong because the `ContainsAny` operator in Sentinel automation conditions is designed to match against a list of values and works fine with single values — it is not the cause of the non-trigger. Option B is wrong because a permissions problem with the playbook would surface as a failed playbook run (visible in the automation rule's run history), not as the rule silently not triggering. Option C is wrong because an invalid playbook ID would typically produce a configuration error or a failed action, not a clean 'rule did not run' outcome; the rule would still fire and then fail at the playbook step.

182
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You receive an alert from Defender for Cloud indicating that a virtual machine has a high severity vulnerability (CVE-2023-XXXX). You need to create an incident in Microsoft Sentinel and trigger a playbook to remediate the vulnerability. However, the incident is not being created automatically. What is the most likely cause?

A.The Microsoft Defender for Cloud connector in Microsoft Sentinel is not enabled or misconfigured
B.An analytics rule with a matching severity threshold has not been created
C.The free trial of Microsoft Sentinel has expired
D.The playbook does not have the correct permissions on the target VM
AnswerA

The Microsoft Defender for Cloud connector is the data ingestion pipeline that brings security alerts from Defender for Cloud into Microsoft Sentinel. If this connector is disabled, not connected to the correct subscription, or has misconfigured diagnostic settings, no Defender for Cloud alerts reach the Sentinel workspace, so no incidents can be generated from them. Without this connector enabled, all other components—analytics rules, automation, and playbooks—have no alert data to act upon.

Why this answer

The Microsoft Defender for Cloud connector in Microsoft Sentinel is the bridge that forwards security alerts from Defender for Cloud to Sentinel. If this connector is not enabled or is misconfigured, Defender for Cloud alerts—including vulnerability alerts for VMs—will never reach Sentinel, so no incident can be created automatically. Without the connector, the data source is disconnected, and Sentinel has no trigger to generate an incident or invoke a playbook.

Exam trap

The trap here is that candidates often assume Defender for Cloud alerts automatically create incidents in Sentinel without needing a connector, or they confuse the connector with an analytics rule, thinking a custom rule is required to match severity thresholds.

How to eliminate wrong answers

Option B is wrong because an analytics rule with a matching severity threshold is not required for Defender for Cloud alerts; these alerts are automatically ingested as incidents via the connector, not through custom analytics rules. Option C is wrong because if the Sentinel free trial had expired, the entire Sentinel workspace would be disabled, not just the incident creation for a specific alert; the question states Sentinel is still operational. Option D is wrong because playbook permissions on the target VM are irrelevant to incident creation; they only matter when the playbook attempts to execute remediation actions after the incident is already created.

183
MCQeasy

During an incident, an analyst wants to use Microsoft Defender XDR's automatic attack disruption to contain an ongoing attack. What prerequisite must be met?

A.Devices must be onboarded to Microsoft Defender for Endpoint.
B.Microsoft Purview compliance portal must be configured.
C.Users must have Azure AD Premium P2 licenses.
D.Microsoft Sentinel must be enabled and connected to Defender XDR.
AnswerA

Automatic attack disruption in Microsoft Defender XDR executes active containment responses—such as isolating devices or blocking indicators—based on real-time endpoint signals. These signals only exist when devices are onboarded to Microsoft Defender for Endpoint, which deploys the sensor and enables EDR in active mode. Without onboarded endpoints, the service has no telemetry to trigger or apply disruption actions.

Why this answer

Microsoft Defender XDR's automatic attack disruption relies on Microsoft Defender for Endpoint (MDE) signals to automatically contain compromised devices or user accounts. Devices must be onboarded to MDE so that the high-confidence alerts (e.g., from ransomware or lateral movement) can trigger automated containment actions like device isolation or blocking an IP. Without MDE onboarding, the attack disruption engine has no endpoint telemetry or remediation capability to act upon.

Exam trap

The trap here is that candidates often confuse the broader Microsoft security ecosystem (Purview, Sentinel, Azure AD P2) as prerequisites for Defender XDR's automated response, when in fact the core requirement is simply having devices onboarded to Microsoft Defender for Endpoint.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview compliance portal is focused on data governance, eDiscovery, and compliance (e.g., DLP, retention), not on real-time attack disruption or endpoint containment. Option C is wrong because Azure AD Premium P2 licenses are required for Identity Protection and risk-based conditional access, but automatic attack disruption in Defender XDR does not depend on Azure AD P2; it requires MDE licenses (e.g., Microsoft 365 E5 or standalone MDE). Option D is wrong because Microsoft Sentinel is a SIEM/SOAR that can ingest alerts from Defender XDR, but it is not a prerequisite for Defender XDR's own automatic attack disruption; the disruption logic runs natively within Defender XDR using MDE data.

184
MCQeasy

Your security operations center (SOC) uses Microsoft Sentinel. An incident is created from a fusion alert. What does Fusion technology do?

A.Uses machine learning to detect suspicious user behavior
B.Runs queries at scheduled intervals to detect threats
C.Detects unusual patterns in Azure activity logs
D.Correlates alerts from different products to detect multi-stage attacks
AnswerD

Fusion correlation in Microsoft Sentinel links low-fidelity alerts and anomalies across multiple products into a single incident, identifying multi-stage attack progressions that individual detections miss. This directly satisfies the stem's fusion alert scenario, where the SOC receives one consolidated incident rather than separate, unrelated alerts.

Why this answer

Microsoft Sentinel's Fusion technology is a correlation engine that stitches together low-fidelity alerts and signals from multiple sources (Microsoft and third-party products) into high-fidelity incidents representing multi-stage attacks. It uses machine learning models built on attack kill-chain patterns to detect sequences like a suspicious sign-in followed by anomalous resource creation. This is why Fusion incidents are typically high severity and span multiple products.

Exam trap

The trap is confusing Fusion with UEBA or scheduled analytics rules — Fusion is specifically the cross-product, multi-stage attack correlation engine, not a behaviour-analytics or query-scheduling feature.

How to eliminate wrong answers

Option A is wrong because UEBA (User and Entity Behavior Analytics) is the Sentinel feature that uses machine learning to detect suspicious user behaviour — Fusion is about cross-product correlation, not behavioural baselining. Option B is wrong because scheduled analytics rules run KQL queries at intervals to detect threats; that is the standard analytics rule mechanism, not Fusion. Option C is wrong because detecting unusual patterns in Azure Activity logs is a specific data-source analytics scenario, not the definition of Fusion, which spans many sources and products.

185
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You receive an alert about a suspicious sign-in from an IP address associated with a known malicious actor. The sign-in was for a privileged account. You need to immediately contain the incident. What should you do first?

A.Reset the user's password.
B.Disable the user account in Microsoft Entra ID.
C.Create a custom analytics rule in Sentinel to detect similar sign-ins.
D.Block the IP address in the firewall.
AnswerB

Disabling the account in Microsoft Entra ID immediately blocks further sign-ins and revokes the compromised privileged identity's access, containing the incident before deeper investigation. It directly addresses the need to contain a suspicious privileged sign-in fastest.

Why this answer

Disabling the user account in Microsoft Entra ID immediately stops the attacker from using the compromised credentials. Option A is wrong because resetting the password might not be fast enough if the attacker has an active session. Option C is wrong because creating an analytics rule does not contain the incident immediately; it only helps detect similar sign-ins in the future.

Option D is wrong because blocking the IP address in the firewall is reactive and may not be effective if the attacker uses a different IP.

186
MCQmedium

You are investigating repeated SQL injection alerts. The KQL query returns IP addresses with more than 5 alerts in the last 7 days. What is the purpose of the `summarize` and `where AlertCount > 5` lines?

A.To identify IPs with a high number of alerts, indicating a possible attack.
B.To correlate alerts with other data sources.
C.To remove duplicate alerts from the same IP.
D.To count the number of distinct IP addresses.
AnswerA

This query aggregates SQL injection alerts by source IP and ranks them by count, so the primary purpose is to surface the IP addresses that trigger the most alert activity. High counts over the selected time range are a strong indicator of an ongoing or repeated attack campaign, and this output directly supports triage, investigation, and potential blocking. The query does not need additional context to fulfill this goal because the aggregation itself is the intended result.

Why this answer

The `summarize` operator in KQL aggregates data by grouping on the IP address field and counting the number of alerts per IP. The `where AlertCount > 5` filter then retains only those IP addresses whose aggregated count exceeds 5. This combination directly serves to identify IPs that have triggered a high volume of SQL injection alerts within the 7-day window, which is a strong indicator of a sustained or automated attack attempt.

Exam trap

The trap here is that candidates may confuse `summarize` with `distinct` or think the `where` clause removes duplicates, when in fact the query is designed to surface high-frequency IPs as potential attack sources, not to deduplicate or count unique IPs.

How to eliminate wrong answers

Option B is wrong because the query does not join or correlate with any other data sources; it only filters and aggregates a single alert table. Option C is wrong because `summarize` with a count does not remove duplicates—it counts occurrences, and the `where` clause filters on that count, not on duplicate removal. Option D is wrong because the query counts alerts per IP, not the number of distinct IPs; a distinct count would use `dcount(IP)` or `distinct` without grouping by IP.

187
MCQeasy

Your organization uses Microsoft Sentinel. An incident has been identified as a false positive. What is the recommended action to prevent similar false positives in the future?

A.Delete the analytics rule
B.Close the incident and set the classification to 'False positive'
C.Modify the analytics rule to reduce false positives
D.Mark the incident as 'False positive' and add a comment
AnswerC

Modifying the analytics rule is the correct action because it directly addresses the root cause of the false positives by adjusting the rule's query logic, threshold, or entity-specific filters. For example, you can add exclusions for known benign IP addresses, increase the aggregation window count, or refine the KQL query to be more context-aware. This persistent tuning prevents recurrence, reduces alert noise, and maintains security coverage for real threats.

Why this answer

Modifying the analytics rule addresses the root cause of the false positive by adjusting the rule's query logic, thresholds, or entity mappings to reduce noise. In Microsoft Sentinel, analytics rules define the conditions that generate incidents; tuning these rules (e.g., changing frequency, lookback period, or adding exclusion filters) directly prevents similar false positives from recurring. Simply closing or classifying incidents does not prevent future occurrences, and deleting the rule would remove all detection capability.

Exam trap

The trap here is that candidates confuse incident management actions (closing/classifying) with rule optimization, assuming that marking an incident as false positive automatically suppresses future similar alerts, when in fact it only affects the current incident's audit trail.

How to eliminate wrong answers

Option A is wrong because deleting the analytics rule removes all detection for that scenario, which is overly aggressive and could miss real threats; the goal is to reduce false positives, not eliminate detection entirely. Option B is wrong because closing an incident with classification 'False positive' only documents the current incident and does not modify the underlying rule to prevent future false positives. Option D is wrong because marking the incident as 'False positive' and adding a comment is a manual documentation step that has no effect on the analytics rule's behavior or future incident generation.

188
MCQhard

A security analyst in your company uses Microsoft Defender XDR to investigate an incident involving a user who received a malicious email. The analyst needs to block the sender's email address across all tenants in the organization. What is the most efficient way to achieve this?

A.In the Microsoft 365 Defender portal, use the action center to block the sender's email address across all tenants.
B.From the Microsoft 365 Defender portal, go to Email & collaboration > Exchange admin center and block the sender.
C.In Microsoft Purview, create a data loss prevention policy to block the sender.
D.In Microsoft Entra ID admin center, create a conditional access policy to block the sender.
AnswerA

The Microsoft 365 Defender action center aggregates manual and automated remediation actions across Defender for Office 365 and other workloads, and in multi-tenant environments it allows a global operation such as blocking a sender’s email address to be applied to all affected tenants simultaneously. This action is enforced at the transport layer, ensuring malicious mail is intercepted before delivery. It is the designed workspace for centralized threat containment, unlike per-tenant management portals.

Why this answer

Microsoft Defender XDR allows you to take action on entities like email senders. Using the action center, you can block the sender's email address globally, which applies to all tenants. Option C is correct.

Option A is wrong because Exchange admin center works per tenant and is not as efficient for cross-tenant blocking. Option B is wrong because Microsoft Entra ID admin center manages identities, not email blocking. Option D is wrong because Microsoft Purview is for compliance, not email threat protection.

189
MCQhard

You are reviewing a scheduled analytics rule in Microsoft Sentinel. What does the suppressionDuration setting affect?

A.It groups alerts into a single incident within that time window.
B.It delays the execution of the query by that amount of time.
C.It determines how often the query runs.
D.It stops the rule from creating new alerts for that duration after an alert is generated.
AnswerD

When suppression is enabled, after the rule successfully generates an alert, Sentinel will not create any new alerts for the configured duration, even if subsequent query executions return matching results. This is a post-detection quiet period designed to avoid alert fatigue from repeated identical findings. The suppression timer resets only when a new alert is actually created, and the rule continues to run queries but suppresses their alerts until the duration lapses.

Why this answer

The suppressionDuration setting in a Microsoft Sentinel scheduled analytics rule stops the rule from creating new alerts for a specified period after an alert is generated. This prevents alert fatigue by suppressing duplicate alerts from the same rule when the same conditions persist, allowing analysts to focus on unique incidents.

Exam trap

The trap here is confusing suppressionDuration with incident grouping or query frequency settings, as candidates often think it controls how alerts are merged or how often the rule runs, rather than its actual purpose of temporarily halting alert creation after an alert fires.

How to eliminate wrong answers

Option A is wrong because grouping alerts into a single incident within a time window is controlled by the 'Grouping' settings (e.g., 'Group all events into a single alert' and 'Group alerts into a single incident'), not by suppressionDuration. Option B is wrong because delaying the execution of the query is not a function of suppressionDuration; query execution timing is determined by the 'Run query every' and 'Lookup data from the last' settings. Option C is wrong because how often the query runs is set by the 'Run query every' interval, not by suppressionDuration, which only affects alert creation after an alert is generated.

190
MCQmedium

Your organization uses Microsoft Defender XDR. The incident queue shows multiple alerts related to a single endpoint: malware detected, suspicious PowerShell execution, and data exfiltration attempts. The analyst needs to investigate the incident. Which tool should the analyst use to correlate these events?

A.Microsoft Defender for Office 365 Explorer.
B.Microsoft Defender for Cloud Apps activity log.
C.Advanced hunting in Microsoft Defender XDR.
D.Microsoft Sentinel incident workspace.
AnswerC

Advanced hunting in Microsoft Defender XDR lets you query raw telemetry across the entire Microsoft ecosystem—endpoints, emails, cloud apps, identities, and more—using Kusto Query Language (KQL). You can perform multi-table joins to correlate low-level events, like a suspicious PowerShell process on one device that contacted a malicious URL previously phished in an email. This unified schema is built specifically for proactive and reactive incident hunting and is the correct native tool for a cross-domain Defender XDR incident.

Why this answer

Advanced hunting in Microsoft Defender XDR allows the analyst to query across multiple data sources—including endpoint detection and response (EDR), identity, email, and cloud app data—using Kusto Query Language (KQL). This enables correlation of the malware detection, suspicious PowerShell execution, and data exfiltration alerts on the same device by joining tables such as DeviceEvents, DeviceProcessEvents, and DeviceNetworkEvents, providing a unified timeline of the attack chain.

Exam trap

The trap here is that candidates often confuse the purpose of Advanced hunting (a cross-domain query engine) with Microsoft Sentinel’s incident workspace (a SIEM incident management interface), leading them to choose Option D because they think a SIEM is always the best correlation tool, even though the question specifically asks for correlation within Defender XDR.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 Explorer is designed for investigating email-based threats (phishing, malware in attachments/links) and does not ingest endpoint process or network events from Defender for Endpoint. Option B is wrong because Microsoft Defender for Cloud Apps activity log focuses on user and app activities in cloud applications (e.g., SharePoint, OneDrive, Azure AD sign-ins) and lacks endpoint-level process execution and network connection data. Option D is wrong because Microsoft Sentinel incident workspace is a SIEM/SOAR platform that aggregates alerts from multiple sources, but it is not the primary tool for performing cross-table endpoint event correlation within Defender XDR; Advanced hunting is the native query engine for that purpose.

191
Multi-Selecthard

Which THREE actions should be taken when a phishing attack is detected in Microsoft Defender XDR?

Select 3 answers
A.Run a full antivirus scan on the user's device
B.Report the email as phishing in Microsoft Defender for Office 365
C.Reset the user's password
D.Block the sender's email address or domain
E.Delete the phishing email from the user's mailbox
AnswersB, D, E

Reporting submits the email to Microsoft for analysis, which updates the threat intelligence and improves automated detection for the whole organization. In MDO, this can be done via the User-reported messages report or the built-in Report Message add-in. This action also allows the security team to investigate the incident and potentially automate remediation policies.

Why this answer

Reporting the email as phishing in Microsoft Defender for Office 365 triggers automated investigation and remediation workflows, including tenant-level block actions and threat intelligence updates. This action directly supports the incident response process by enabling the security team to analyze the phishing attempt and prevent further delivery to other users.

Exam trap

The trap here is that candidates often confuse the immediate containment actions (block sender, delete email) with post-compromise remediation steps (password reset, antivirus scan), leading them to select options that are appropriate only after a confirmed credential theft or malware infection.

192
MCQmedium

The exhibit shows a partial playbook trigger configuration in Microsoft Sentinel. When will this playbook be triggered?

A.When an incident is updated with severity High.
B.When an alert is generated with severity High.
C.When an incident of severity High is created.
D.When any incident is created.
AnswerC

This is correct because the trigger explicitly references an incident creation event and includes a condition that checks the incident's severity equals High. Only new incidents that meet this severity requirement will activate the playbook; all other incidents will be ignored by this trigger. The condition is evaluated as part of the incident creation flow, so the playbook runs immediately when a High-severity incident is born.

Why this answer

The playbook trigger configuration shown in the exhibit specifies that the playbook runs when an incident is created, and it includes a condition that filters for incidents with a severity of High. In Microsoft Sentinel, playbook triggers can be set on incident creation or alert creation, and conditions like severity are evaluated at the time of the trigger event. Here, the trigger is explicitly set to 'When an incident is created' with a severity condition of 'High', so the playbook only fires when a new incident with High severity is created.

Exam trap

The trap here is that candidates often confuse the trigger event (creation vs. update) or overlook the severity condition, assuming the playbook runs on any incident creation when the exhibit clearly shows a filter for High severity.

How to eliminate wrong answers

Option A is wrong because the trigger is set to fire on incident creation, not on incident update; the condition 'When an incident is updated' would require a different trigger type in Sentinel. Option B is wrong because the trigger is configured for incidents, not alerts; alert triggers are separate and would use 'When an alert is generated' as the trigger type. Option D is wrong because the playbook includes a severity condition of 'High', so it does not trigger on all incidents—only those with High severity.

193
MCQmedium

A security analyst receives an alert in Microsoft Defender XDR indicating a possible credential theft attempt from an external IP. The analyst wants to isolate the affected device immediately while preserving forensic data. What should the analyst do?

A.Use Microsoft Defender for Endpoint to 'contain device' from the device inventory.
B.Disable the user account in Microsoft Entra ID.
C.Initiate a live response session on the device and run the 'isolate device' command.
D.Reset the user's password and enforce sign-out.
AnswerC

Initiating a live response session and running the 'isolate device' command is the correct action because live response gives the analyst a remote shell on the endpoint, enabling collection of volatile evidence (processes, network connections, persistence artifacts) before the environment changes. The 'isolate device' command disconnects the device from the network and blocks inbound and outbound communication except for the connection to the Microsoft Defender for Endpoint service, which keeps management and forensic collection channels open. This combination contains the immediate threat by cutting off the attacker's network access while preserving forensically sound data needed for deeper investigation.

Why this answer

Initiating a live response session and running the 'isolate device' command in Microsoft Defender for Endpoint immediately disconnects the device from the network (both internal and external) while preserving forensic data on the endpoint. This action stops the ongoing credential theft attempt without destroying volatile evidence, which is critical for subsequent investigation.

Exam trap

The trap here is that candidates confuse 'contain device' (which only restricts communication with other managed devices) with full network isolation, leading them to choose Option A instead of the correct live response isolation command.

How to eliminate wrong answers

Option A is wrong because 'contain device' in Microsoft Defender for Endpoint only blocks communication with the device from other managed devices but does not fully isolate it from the network or external IPs, leaving the attack vector open. Option B is wrong because disabling the user account in Microsoft Entra ID prevents further authentication but does not stop the attacker from using an already established session or cached credentials on the device, and it does not preserve forensic data. Option D is wrong because resetting the user's password and enforcing sign-out does not isolate the device; the attacker may still have persistence mechanisms (e.g., scheduled tasks, backdoors) running on the endpoint, and it does not preserve volatile forensic data.

194
MCQhard

Refer to the exhibit. This JSON snippet is from an Azure Web Application Firewall (WAF) policy. What does this rule do?

A.Blocks traffic from the entire 10.0.0.0/24 subnet.
B.Blocks traffic originating from IP address 10.0.0.1.
C.Logs traffic from IP address 10.0.0.1 without blocking.
D.Allows traffic from IP address 10.0.0.1.
AnswerB

The rule's match condition uses RemoteAddr as the source operand, IPMatch as the operator, and the literal value '10.0.0.1', meaning it matches requests whose client IP is exactly 10.0.0.1. The action specified is 'Block', so any request from that source IP is denied. Consequently, it correctly blocks traffic originating from that single IP address.

Why this answer

The JSON snippet defines a WAF rule with a match condition that checks if the client IP address equals 10.0.0.1. The action is set to 'Block', meaning any request from that specific IP address will be denied. Option B correctly identifies this behavior.

Exam trap

The trap here is that candidates often confuse an exact IP match with a subnet match, assuming '10.0.0.1' implies the entire /24 range, or they misread the 'Block' action as 'Allow' or 'Log' due to familiarity with other WAF rule types.

How to eliminate wrong answers

Option A is wrong because the rule uses an exact IP match ('10.0.0.1'), not a CIDR range ('10.0.0.0/24'), so it does not block the entire subnet. Option C is wrong because the action is 'Block', not 'Log' (which would require an action like 'Log' or 'Allow' with logging enabled). Option D is wrong because the action is 'Block', not 'Allow', so traffic from 10.0.0.1 is denied, not permitted.

195
MCQeasy

A security analyst receives an alert from Microsoft Defender for Cloud Apps indicating that a user has signed in from a banned country. The analyst needs to block further access from that country for all users. What should the analyst configure?

A.Modify the device compliance policy in Microsoft Intune.
B.Configure a data loss prevention (DLP) policy in Microsoft Purview.
C.Create an IP range group for the country and configure a session policy to block it.
D.Create a conditional access policy in Microsoft Entra ID to block the country.
AnswerC

In Microsoft Defender for Cloud Apps, the correct approach is to create an IP address group that represents the country in question, using Defender for Cloud Apps' built-in country-based IP classification or by uploading custom ranges. Then, you configure a session policy with an access-control action set to 'Block' and a filter that matches the 'IP group' to the newly created group. When a session policy is active, Defender for Cloud Apps intercepts the session in real time and denies access from that country, providing granular, app-specific enforcement.

Why this answer

Microsoft Defender for Cloud Apps session policies can block access based on IP address geolocation. By creating an IP range group for the banned country and configuring a session policy to block traffic from that group, the analyst can enforce real-time blocking of all user sessions originating from that country, leveraging the reverse proxy architecture of Defender for Cloud Apps.

Exam trap

The trap here is that candidates often confuse the scope of conditional access policies (which block at the authentication level) with the session-level control provided by Defender for Cloud Apps, leading them to select option D instead of C.

How to eliminate wrong answers

Option A is wrong because device compliance policies in Microsoft Intune control device health and configuration (e.g., encryption, jailbreak detection) and cannot block access based on geographic location. Option B is wrong because data loss prevention (DLP) policies in Microsoft Purview are designed to prevent sensitive data from being shared or leaked, not to block sign-ins or sessions based on country of origin. Option D is wrong because while a conditional access policy in Microsoft Entra ID can block access from specific countries, it operates at the authentication level and does not provide the granular session-level control (e.g., monitoring or blocking specific app actions) that Defender for Cloud Apps session policies offer for cloud app usage.

196
MCQmedium

You are responding to an incident where a user's credentials were stolen via a phishing email. The attacker used the credentials to access Microsoft Entra ID and then tried to perform privileged role escalation. Which Microsoft Sentinel solution should you use to detect this type of attack?

A.Network Security Group flow logs
B.Syslog data connector
C.Threat intelligence connectors
D.UEBA (User and Entity Behavior Analytics)
AnswerD

UEBA (User and Entity Behavior Analytics) in Microsoft Sentinel builds individual baselines from historical sign-in patterns, role assignments, and user activities, then applies machine learning to detect anomalies such as unusual privilege escalation or impossible travel. Because it focuses on behavioral deviations rather than static rules, UEBA is specifically designed to surface the kind of account misuse associated with compromised credentials.

Why this answer

UEBA (User and Entity Behavior Analytics) is the correct solution because it uses machine learning to establish baseline behavioral patterns for users and entities, then detects anomalies such as a user logging in from an unusual location and immediately attempting privileged role escalation. This directly identifies the credential theft and privilege escalation chain described in the incident, whereas other options focus on network traffic, generic syslog ingestion, or threat intelligence matching, which would not catch the behavioral anomaly of a stolen credential being used for role escalation.

Exam trap

The trap here is that candidates often confuse UEBA with threat intelligence or network logs, mistakenly thinking that detecting credential theft requires matching known malicious IPs or analyzing raw network traffic, when in fact the attack relies on behavioral anomalies that only UEBA can identify.

How to eliminate wrong answers

Option A is wrong because Network Security Group flow logs capture IP traffic metadata (source/destination, ports, protocols) but do not analyze user authentication behavior or Entra ID role escalation attempts; they are designed for network-level troubleshooting and security group rule monitoring, not identity-based attack detection. Option B is wrong because the Syslog data connector ingests log data from on-premises or third-party devices (e.g., firewalls, Linux servers) in syslog format, but it does not natively parse Microsoft Entra ID audit logs or apply behavioral analytics to detect anomalous role escalation; it is a generic log ingestion pipeline, not a detection solution. Option C is wrong because Threat intelligence connectors ingest indicators of compromise (IOCs) like malicious IPs, domains, or hashes from external feeds, but the attack described uses a legitimate user's stolen credentials from a phishing email—there is no malicious IOC to match against; the detection relies on behavioral deviation, not known threat signatures.

197
MCQmedium

You are investigating a potential ransomware incident detected by Microsoft Defender XDR. The incident shows multiple machines with suspicious encryption activity. You need to contain the threat immediately. What should you do first?

A.Reset the passwords of all users on the affected machines
B.Run a full antivirus scan on all endpoints
C.Initiate device isolation on affected machines from Microsoft Defender XDR
D.Disable the user accounts associated with the affected machines
AnswerC

Device isolation severs network connectivity while preserving Microsoft Defender XDR communication, immediately halting lateral spread and further encryption across affected endpoints. This containment satisfies the requirement to stop the threat first, before investigation or remediation, and is executed directly from the incident view.

Why this answer

In Microsoft Defender XDR, device isolation is the fastest containment action that stops lateral movement and further encryption while preserving the machine for investigation. Isolating affected devices immediately cuts off network communication except for the Defender connection, preventing ransomware from spreading. This is the recommended first step in the incident response containment phase for active ransomware.

Exam trap

SC-200 often tests the order of incident response actions, tricking candidates into choosing identity-based actions (password reset, disable account) instead of immediate endpoint containment.

How to eliminate wrong answers

Option A is wrong because resetting passwords does not stop active encryption or lateral movement and is a recovery/identity action, not containment. Option B is wrong because a full antivirus scan is a detection/remediation step that takes time and does not immediately stop an ongoing ransomware attack. Option D is wrong because disabling user accounts does not stop malware already running on the machines and may disrupt legitimate response efforts.

198
MCQeasy

After a security incident, you need to preserve evidence from a compromised Microsoft 365 tenant. What is the best method to preserve data?

A.Take a backup of the entire tenant
B.Use Microsoft Purview eDiscovery to search and export
C.Export the data to a PST file and delete the original
D.Place the user's mailbox and OneDrive on litigation hold
AnswerD

Placing the mailbox and OneDrive on litigation hold preserves all existing and future content immutably, preventing deletion or alteration during investigation, which satisfies the evidence-preservation requirement. This retention mechanism operates independently of the user, unlike simple export or backup copies.

Why this answer

Placing the user's mailbox and OneDrive on litigation hold is the best method for preserving evidence because it preserves all data in its original state, preventing deletion or modification. Option A (backup of entire tenant) is excessive and not immediate. Option B (eDiscovery) is for search and export, not preservation.

Option C (export to PST and delete) destroys the original evidence, which is inadvisable.

199
MCQmedium

A SOC analyst receives an alert from Microsoft Defender for Cloud Apps indicating that a user downloaded 500 GB of data from SharePoint to an unmanaged device. The user has no history of such behavior. What is the best first step in the incident response process?

A.Run a full antivirus scan on the unmanaged device.
B.Contact the user to verify if the download was intentional.
C.Disable the user account in Microsoft Entra ID.
D.Create a detection rule for similar behavior in Microsoft Sentinel.
AnswerC

Disabling the user account in Microsoft Entra ID is the correct immediate containment action because it sets AccountEnabled to false, blocking the compromised identity from authenticating to Microsoft 365 and Defender services that host the data. This action directly interrupts the active download session and prevents the entity from initiating new requests, regardless of whether the device itself is managed, and it does so quickly enough to limit data loss. As a side benefit, it preserves the unmanaged device's source IP and activity logs for later forensic analysis without giving the attacker a warning.

Why this answer

The immediate priority in an incident response process for a potential data exfiltration scenario is to contain the threat. Disabling the user account in Microsoft Entra ID (formerly Azure AD) is the fastest way to revoke access to SharePoint and other cloud resources, preventing further unauthorized data transfer. This aligns with the 'containment' phase of the NIST incident response lifecycle, before any investigation or remediation steps.

Exam trap

The trap here is that candidates often choose 'Contact the user' (Option B) as a first step, confusing the 'identification' or 'verification' phase with the immediate containment priority required in a potential data exfiltration incident.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan on the unmanaged device is a remediation step that assumes malware is the cause, but the alert indicates a large download to an unmanaged device, which is a behavioral anomaly; scanning the device does not stop the ongoing exfiltration and may be impossible if the device is not under organizational control. Option B is wrong because contacting the user to verify if the download was intentional introduces a delay and risks tipping off a potential attacker if the account is compromised; the first step must be containment, not verification. Option D is wrong because creating a detection rule in Microsoft Sentinel is a proactive improvement step that should occur after the incident is contained and analyzed, not as the first response to an active alert.

200
MCQmedium

Refer to the exhibit. An analyst runs Get-MpThreat on a device. Based on the output, what is the status of the threat?

A.The threat executed and is now inactive.
B.The threat was quarantined and is still active.
C.The threat is currently active on the device.
D.The threat was blocked and did not execute.
AnswerD

This is the correct conclusion because the Get-MpThreat output shows both DidThreatExecute is False and IsActive is False. DidThreatExecute=False confirms that the threat did not run, while IsActive=False confirms it is not currently present or running, which aligns with a blocked state. In Microsoft Defender, a threat that was blocked before execution typically has these exact field values, indicating the attack was prevented.

Why this answer

The output of Get-MpThreat shows the threat's state as 'Blocked' and its execution status as 'Not Executed'. This indicates that Microsoft Defender Antivirus successfully prevented the threat from running on the device. Therefore, the threat was blocked and did not execute, making D the correct answer.

Exam trap

The trap here is that candidates often confuse 'Blocked' with 'Quarantined' or assume any threat listed must have executed, but the 'ExecutionStatus' field explicitly clarifies whether the threat ran or was stopped pre-execution.

How to eliminate wrong answers

Option A is wrong because the threat's execution status is 'Not Executed', meaning it did not execute and become inactive. Option B is wrong because the threat was not quarantined; its state is 'Blocked', and it is not active. Option C is wrong because the threat is not currently active; it was blocked before execution.

201
MCQmedium

Refer to the exhibit. A Microsoft Sentinel scheduled rule is configured as shown. The rule generates an alert, but the incident created contains only the first alert, and subsequent alerts do not update the incident. What is the most likely cause?

A.The triggerOperator and triggerThreshold are misconfigured.
B.The KQL query is missing a join to include more data.
C.The severity is set to High, which prevents incident updates.
D.The rule does not have incident grouping enabled.
AnswerD

The rule does not have incident grouping enabled, which means each time the scheduled query fires and creates an alert, Sentinel provisions a brand-new incident instead of attaching the alert to an already open incident. In the analytics rule's Incident settings, the 'Group related alerts into a single incident' option is either unchecked or set to 'do not group,' resulting in a one-to-one alert-to-incident relationship. Consequently, the second brute-force attempt generates a new incident rather than updating the existing one, exactly as described in the exhibit. Enabling grouping with an appropriate entity (e.g., target username) and time window would cause subsequent alerts to update the original incident.

Why this answer

The exhibit shows the rule is configured to create a single incident from alerts grouped by entities, but the 'Grouping' settings are not enabled. Without incident grouping enabled, each alert generates a separate incident, and subsequent alerts do not update the existing incident. Enabling incident grouping allows alerts matching the same grouping criteria to be merged into the same incident, ensuring updates occur.

Exam trap

The trap here is that candidates often confuse alert grouping (which controls incident creation) with query logic or severity, assuming that a high severity or a missing join would cause the incident not to update, when in fact the root cause is the disabled grouping setting.

How to eliminate wrong answers

Option A is wrong because triggerOperator and triggerThreshold control the alert generation frequency (e.g., how many query results trigger an alert), not how alerts are grouped into incidents. Option B is wrong because the KQL query's structure does not affect incident grouping; the query only defines the data that generates alerts. Option C is wrong because severity settings do not prevent incident updates; severity is a property of the incident, not a grouping or update mechanism.

202
MCQmedium

Your organization uses Microsoft Sentinel. You need to create an incident response playbook that automatically isolates a compromised device when a high-severity incident is created. The playbook should only run during business hours (9 AM - 5 PM local time). How should you configure this?

A.Configure the analytics rule to only create incidents during business hours
B.Add a condition in the playbook to check the current time
C.Use a workbook to schedule the playbook
D.Create an automation rule with a condition on the incident creation time
AnswerB

A time-based condition inside the playbook logic evaluates the current time before triggering isolation, satisfying the business-hours constraint. However, Microsoft Sentinel playbooks are Logic Apps, so this check must use a built-in date/time expression or condition action, and the recurrence trigger still fires around the clock.

Why this answer

Microsoft Sentinel automation rules cannot evaluate conditions based on the time of day (e.g., creation hour). The appropriate method is to add a condition in the playbook itself (Azure Logic Apps) to check the current time and proceed only during business hours. This approach gives you full control over the playbook's execution schedule without relying on unsupported automation rule conditions.

Exam trap

The trap here is that candidates may assume automation rules can filter by time of day, similar to conditions on other incident fields. However, automation rules cannot evaluate temporal conditions like 'created between 9 AM and 5 PM'. The correct approach is to embed a time condition directly in the playbook logic.

How to eliminate wrong answers

Option A is wrong because analytics rules create incidents based on detection logic, not time windows; configuring an analytics rule to only create incidents during business hours would miss threats detected outside those hours, which is not a supported or intended configuration. Option B is wrong because adding a condition in the playbook to check the current time would still trigger the playbook for every incident, wasting resources and potentially causing unintended actions if the time check fails; the playbook should not be invoked at all outside business hours. Option C is wrong because workbooks are visualization tools, not scheduling or automation mechanisms; they cannot trigger playbooks or enforce time-based execution.

203
MCQmedium

You are a Microsoft Sentinel analyst investigating an incident that contains several related alerts about a compromised user account. Your incident response runbook requires you to temporarily prevent the attacker from using the account while preserving the ability to restore access after remediation. You need to disable the account in Microsoft Entra ID directly from the incident investigation experience. What should you do?

A.Open the user entity page in the incident, select the Disable user account action, and confirm the operation.
B.Delete the user object in Microsoft Entra ID and restore it from the deleted users list after remediation.
C.Add the user entity to a watchlist, then configure an automation rule that disables accounts on the watchlist.
D.Assign the user a Conditional Access policy that blocks all cloud apps, then close the incident.
AnswerA

From an incident, expanding the user entity in Microsoft Sentinel exposes entity actions, and Disable user account performs the Microsoft Entra ID account disablement in place. This satisfies the runbook requirement to stop the attacker from authenticating while keeping the object recoverable, because disabling blocks sign-in but does not delete or alter the account's data, so access can be restored after remediation completes.

Why this answer

Microsoft Sentinel surfaces user entities inside incidents and provides entity actions that reach into Microsoft Entra ID. Disabling the account immediately blocks authentication for the compromised identity while leaving the object intact, so it can be re-enabled once containment and remediation are verified. Watchlists, Conditional Access, and deletion either do not change account state directly or introduce unnecessary disruption and recovery complexity.

Exam trap

The trap here is assuming any containment control, such as a blocking Conditional Access policy, is equivalent to disabling the account itself.

204
MCQmedium

Your company uses Microsoft Sentinel. A security analyst receives an incident that includes a large number of alerts from a single data source. The analyst needs to identify which alerts are duplicates or related so they can focus on unique threats. Which feature should the analyst use?

A.Alert grouping
B.Investigation graph
C.Entity mapping
D.Automation rules
AnswerA

Alert grouping is a built-in setting in Sentinel analytics rules that determines when a new incident should be created versus when an alert should be added to an existing incident. You can group by entity, by alert attributes, or within a specified time window, and you can also set the incident title. This directly reduces alert fatigue by consolidating related alerts, making it the correct answer.

Why this answer

Alert grouping in Microsoft Sentinel automatically combines related alerts into a single incident, reducing noise so analysts can focus on unique threats. It uses machine learning to correlate alerts that share entities, timing, or patterns, directly addressing the need to identify duplicates or related alerts.

Exam trap

SC-200 often tests the confusion between alert grouping (deduplication/correlation at incident creation) and entity mapping (field mapping for correlation), causing candidates to pick entity mapping when the question asks about reducing duplicate alerts.

How to eliminate wrong answers

Option B is wrong because the investigation graph is a visual tool for exploring entity relationships during an investigation, not for deduplicating or grouping alerts at ingestion. Option C is wrong because entity mapping defines how alert fields map to entities (accounts, hosts, IPs) in analytics rules — it enables correlation but does not itself group alerts. Option D is wrong because automation rules trigger playbooks or actions based on incident creation, not alert deduplication.

205
MCQeasy

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos activity that may indicate a golden ticket attack. Which of the following actions should you take to investigate this alert?

A.Immediately reset the krbtgt account password twice
B.Export the Active Directory event logs to Microsoft Sentinel for analysis
C.Review the alert details in the Microsoft Defender for Identity portal and analyze related events
D.Disable the user account that triggered the alert
AnswerC

Reviewing the alert details in the Microsoft Defender for Identity portal is the correct first step because the portal aggregates the pertinent events, users, devices, and related alerts into an investigation experience. From the alert page, you can access the full timeline, examine the underlying activities, and pivot to entity profiles, which lets you validate whether the alert is a true positive and understand the attack chain. This analysis provides the context needed to decide on any subsequent containment or remediation.

Why this answer

The first step in investigating a golden ticket attack alert from Microsoft Defender for Identity is to review the alert details and analyze the related events within the Defender for Identity portal. This allows you to understand the scope of the suspicious Kerberos activity, identify the affected accounts, and correlate the alert with other security signals before taking any remediation actions.

Exam trap

The trap here is that candidates often jump to remediation actions like resetting the krbtgt password or disabling accounts without first investigating the alert details, which can lead to unnecessary disruption or missed context about the attack's scope.

How to eliminate wrong answers

Option A is wrong because immediately resetting the krbtgt account password twice is a remediation step that should only be performed after thorough investigation and confirmation of a golden ticket attack; premature reset can cause Kerberos authentication failures across the domain. Option B is wrong because exporting Active Directory event logs to Microsoft Sentinel for analysis is a secondary step that may be useful for long-term hunting or correlation, but the immediate investigation should start within the Defender for Identity portal where the alert originated. Option D is wrong because disabling the user account that triggered the alert is premature and could be a false positive; the alert may be triggered by legitimate activity or a compromised account that needs further analysis before taking disruptive action.

206
MCQhard

During an incident investigation, you find that a compromised account was used to log into a virtual machine via RDP from an IP address in a sanctioned country. The VM has Microsoft Defender for Endpoint installed. Which data source in Microsoft Sentinel would you query to see the RDP connection events?

A.DeviceLogonEvents (Microsoft Defender XDR)
B.CommonSecurityLog
C.SigninLogs (Microsoft Entra ID)
D.SecurityEvent
AnswerD

SecurityEvent is the correct table because it contains Windows Security event logs, including Event ID 4624 (successful logon) and 4625 (failed logon), which are essential for RDP investigations. When an RDP session is established on a Windows VM, the local Security channel generates a 4624 with LogonType 10 (RemoteInteractive), and this data is sent to Sentinel via the Windows Security Events data connector (using either the legacy Log Analytics agent or the Azure Monitor Agent). From this table you can query the source IP, source port, and account that performed the RDP logon to identify indicators of compromise. Thus, SecurityEvent is the authoritative and most direct source for RDP logon activity in Microsoft Sentinel.

Why this answer

The SecurityEvent table in Microsoft Sentinel collects Windows security events from machines with the Log Analytics agent or Azure Monitor Agent, including Event ID 4625 (failed logon) and Event ID 4624 (successful logon). Since the compromised account used RDP to log into a VM with Defender for Endpoint installed, the RDP connection events are captured as Windows security log events and stored in the SecurityEvent table. This is the correct data source for querying local authentication events on the VM itself.

Exam trap

The trap here is that candidates confuse cloud sign-in logs (SigninLogs) with local OS logon events, or assume Defender for Endpoint's DeviceLogonEvents is the primary Sentinel table, when in fact SecurityEvent is the correct source for Windows security events collected via the Log Analytics agent.

How to eliminate wrong answers

Option A is wrong because DeviceLogonEvents (Microsoft Defender XDR) captures device-level logon events from Microsoft Defender for Endpoint sensors, but it is designed for advanced hunting in the Microsoft 365 Defender portal, not directly in Microsoft Sentinel's workspace tables; while it can be accessed via cross-resource queries, the question asks for a data source in Microsoft Sentinel, and SecurityEvent is the native table for Windows security events. Option B is wrong because CommonSecurityLog is used for syslog-style logs from third-party security appliances (e.g., firewalls, proxies), not for Windows RDP logon events from a VM. Option C is wrong because SigninLogs (Microsoft Entra ID) records cloud-based authentication to Microsoft Entra ID (formerly Azure AD), such as user sign-ins to Azure portal or Office 365, not local RDP logons to a virtual machine.

207
MCQhard

You are deploying Microsoft Sentinel using the above ARM template parameters. After deployment, you notice that Microsoft Defender for Cloud alerts are not being ingested. What is the MOST likely reason?

A.UEBA is enabled, which conflicts with Defender for Cloud data ingestion.
B.The workspace location (eastus) does not support Defender for Cloud connector.
C.The 'MicrosoftThreatProtection' connector only ingests Microsoft Defender XDR signals, not Defender for Cloud alerts.
D.The workspace name 'sentinel-workspace' is reserved for internal use.
AnswerC

The 'MicrosoftThreatProtection' connector (also known as the Microsoft 365 Defender connector) exclusively ingests incident and alert data from Microsoft Defender XDR components such as Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. Defender for Cloud alerts are delivered via the 'AzureSecurityCenter' (now 'Microsoft Defender for Cloud') connector, which is a separate data source with its own connector type. Because the ARM template only includes the MicrosoftThreatProtection connector, Defender for Cloud alerts would never appear in Sentinel, making this the correct explanation for the issue.

Why this answer

The 'MicrosoftThreatProtection' connector is specifically designed to ingest signals from Microsoft Defender XDR (formerly Microsoft 365 Defender), which includes Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. It does not ingest Microsoft Defender for Cloud alerts. To ingest Defender for Cloud alerts, you must use the dedicated 'Defender for Cloud' data connector in Microsoft Sentinel.

Therefore, deploying only the 'MicrosoftThreatProtection' connector will result in Defender for Cloud alerts not being ingested.

Exam trap

The trap here is that candidates assume the 'MicrosoftThreatProtection' connector ingests all Microsoft security alerts, including Defender for Cloud, because of the broad 'Threat Protection' naming, but in reality it only covers Microsoft Defender XDR signals.

How to eliminate wrong answers

Option A is wrong because UEBA (User and Entity Behavior Analytics) is a feature within Microsoft Sentinel that analyzes patterns and anomalies; it does not conflict with or block data ingestion from Defender for Cloud. Option B is wrong because the 'eastus' region fully supports the Defender for Cloud connector; all Azure public regions support this connector. Option D is wrong because 'sentinel-workspace' is not a reserved name; workspace names must be globally unique within a resource group but are not reserved by Microsoft for internal use.

208
MCQeasy

You are responding to a security incident involving a user who clicked on a malicious link in an email. The link led to a website that downloaded a file to the user's device. Microsoft Defender for Endpoint (MDE) detected the file as malware and blocked it. However, the user reports that the device is running slowly. You need to verify if there are any remnants of the malware. Which action should you take?

A.Re-onboard the device to MDE to ensure it's fully managed.
B.Run a full antivirus scan using Microsoft Defender Antivirus.
C.Initiate a live response session and run a PowerShell script to check for persistence mechanisms.
D.Perform a full OS reinstall to ensure the device is clean.
AnswerC

Initiating a live response session on the endpoint and executing a PowerShell script is the correct action because it provides a remote, audited shell that can directly interrogate the system's persistence mechanisms. The script can enumerate Services, Run keys, scheduled tasks, WMI event subscriptions, and other autostart locations to determine whether the attacker left behind a way to re-enter. This aligns with MDE's incident response workflow, allowing you to collect evidence and remediate instantly without taking the device offline.

Why this answer

A live response session in Microsoft Defender for Endpoint lets you run remote investigative commands — including PowerShell scripts — directly on the device to enumerate persistence mechanisms such as Run keys, scheduled tasks, services, and WMI subscriptions. Since MDE already blocked the malware, the goal is to verify no remnants or persistence artifacts remain, and live response is the purpose-built tool for that forensic check.

Exam trap

SC-200 often tests the instinct to 'nuke and pave' or run a generic AV scan — candidates overlook that live response is the targeted forensic tool for verifying remnants after a blocked infection.

How to eliminate wrong answers

Option A is wrong because re-onboarding the device only re-establishes the MDE agent connection and does not investigate or remove any malware remnants. Option B is wrong because a full Defender Antivirus scan may detect known signatures but will not reveal fileless persistence, registry artifacts, or scheduled tasks that a targeted live-response script can enumerate. Option D is wrong because a full OS reinstall is a destructive, disproportionate response when the malware was already blocked and only verification of remnants is required.

209
MCQeasy

Your organization uses Microsoft Sentinel. You receive an alert for a suspicious sign-in from an unusual location. You want to automatically create an incident and assign it to the security team for investigation. What should you configure?

A.Add the user to a watchlist and configure a fusion rule.
B.Create a playbook that triggers on the alert and creates an incident manually.
C.Modify the analytics rule to set the incident creation setting to 'Create incident from alert'.
D.Configure an automation rule that runs when the alert is generated, creates an incident, and sets the owner to the security team.
AnswerD

Automation rules are Sentinel's native orchestration mechanism that can trigger on alert creation and perform actions such as creating an incident, assigning an owner, changing severity, and running playbooks. By configuring a rule that runs when the alert is generated, you ensure the incident is created with the security team as the owner in one atomic step. This approach centralizes lifecycle management and is recommended over manual playbook or analytics-rule-only configurations for consistent ownership.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically create incidents from alerts and assign them to specific teams or owners. This is the native, efficient method to handle the scenario without manual intervention or custom playbooks.

Exam trap

The trap here is that candidates may think a playbook is required for incident creation, but automation rules provide a simpler, native mechanism that can both create incidents and assign ownership without custom code.

How to eliminate wrong answers

Option A is wrong because watchlists are used for correlation and enrichment, not for automatic incident creation; fusion rules combine multiple alerts but do not assign incidents. Option B is wrong because creating a playbook to manually create an incident is unnecessary overhead; automation rules can directly create incidents without a playbook. Option C is wrong because the 'Create incident from alert' setting is already enabled by default for analytics rules; the question requires assigning the incident to the security team, which is not achieved by this setting alone.

210
MCQhard

Your organization uses Microsoft 365 Defender. An incident is created for a user who received a phishing email that contained a link to a malicious website. The user clicked the link but did not enter any credentials. The incident includes the alert 'Phishing delivered' from Microsoft Defender for Office 365. You need to remediate the incident and prevent future occurrences. The user is in the Finance department and frequently receives emails from external vendors. What is the best course of action?

A.Use Threat Explorer to delete the email from the user's mailbox and create a Safe Links policy to block the malicious URL.
B.Report the email to Microsoft for analysis and block the sender domain.
C.Provide security awareness training to the user and mark the incident as resolved.
D.Add the sender's domain to the Tenant Allow/Block List as allowed to avoid future false positives.
AnswerA

Threat Explorer permits soft-deleting the delivered phishing message from the mailbox, removing the threat, while a Safe Links policy rewrites and blocks the malicious URL at click time for all users, addressing the recurring external-vendor vector. Together they remediate the current incident and prevent recurrence.

Why this answer

The best remediation combines immediate containment with prevention: Threat Explorer (or the unified action center) lets you soft-delete or hard-delete the phishing email from the user's mailbox, and a Safe Links policy blocks the malicious URL so future clicks are neutralized. This addresses both the current incident and the recurring risk from external vendors, which is the correct incident-response sequence of contain, eradicate, and prevent.

Exam trap

SC-200 often tests the difference between reactive reporting and active remediation—candidates pick 'report to Microsoft' or 'train the user' because they sound responsible, but the exam rewards the option that removes the threat and blocks the vector.

How to eliminate wrong answers

Option B is wrong because reporting to Microsoft and blocking the sender domain is reactive and incomplete—it does not remove the already-delivered email from the mailbox, and blocking a domain can cause false positives for legitimate vendors. Option C is wrong because awareness training and closing the incident does nothing to remove the malicious email or block the URL, leaving the user and others exposed to the same link. Option D is wrong because adding the sender's domain to the allow list is the opposite of remediation—it would permit future phishing from that domain and defeat the Tenant Allow/Block List's protective purpose.

211
MCQeasy

An analyst is investigating a phishing campaign that targeted multiple users. The analyst needs to identify if any users clicked a malicious link in the email. Which Microsoft Defender for Office 365 feature should be used?

A.Safe Attachments
B.Threat Explorer
C.Attack Simulator
D.Safe Links
AnswerB

Threat Explorer in Microsoft Defender for Office 365 provides real-time, detailed reporting on email threats, letting analysts filter by URL clicks and identify exactly which recipients interacted with the malicious link during the phishing campaign investigation.

Why this answer

Threat Explorer (also known as Explorer) in Microsoft Defender for Office 365 provides a real-time, interactive view of threat data, including email delivery status and user actions such as clicks on malicious links. It allows analysts to filter by 'Click action' to identify users who clicked a URL that was determined to be malicious, making it the correct tool for this investigation.

Exam trap

The trap here is that candidates often confuse the protection features (Safe Links and Safe Attachments) with the investigation tool (Threat Explorer), assuming that because Safe Links blocks malicious clicks, it also provides historical click reports, when in fact Threat Explorer is the dedicated hunting and investigation tool for analyzing user actions.

How to eliminate wrong answers

Option A is wrong because Safe Attachments is a protection feature that detonates email attachments in a sandbox environment to detect malware, but it does not track or report user clicks on links. Option C is wrong because Attack Simulator is a training and simulation tool used to launch simulated phishing attacks to test user awareness, not to investigate past real-world phishing campaigns. Option D is wrong because Safe Links is a protection feature that rewrites URLs and checks them at time of click to block malicious destinations, but it does not provide a historical log or report of which users clicked a specific malicious link in a past campaign.

212
MCQmedium

Your organization uses Microsoft Sentinel. You receive an incident for a potential data exfiltration involving a sensitive blob storage container. You need to determine if the data was accessed from an unusual IP address. What should you do?

A.Modify the analytics rule that triggered the incident.
B.Run a playbook to collect IP information.
C.Open the Sentinel workbook for storage monitoring.
D.Use the Incident details pane to review the entity timeline.
AnswerD

The Incident details pane includes an Entities tab where the entity timeline displays a chronological sequence of activities associated with entities such as IP addresses, hosts, and accounts. This view aggregates data from multiple sources—including alerts, events, and logs—allowing the analyst to see what an IP did before, during, and after the incident. It requires no additional configuration and directly supports the investigation by revealing behavioral patterns and attack paths.

Why this answer

The Incident details pane in Microsoft Sentinel includes an entity timeline that shows activities and events associated with entities (such as IP addresses, accounts, hosts) tied to the incident. Reviewing the entity timeline lets you see whether the blob storage was accessed from an unusual IP and correlate that IP with other activity. This is the direct investigative step for the question.

Exam trap

SC-200 often tests the distinction between investigation actions (reviewing entity timelines, running KQL) and response/automation actions (playbooks) or configuration actions (editing analytics rules) — the trap is picking a response or config action when the question asks how to investigate.

How to eliminate wrong answers

Option A is wrong because modifying the analytics rule changes detection logic going forward; it does not help investigate the current incident's IP access. Option B is wrong because running a playbook is a response automation action (e.g., block IP, notify), not an investigation step to determine whether an unusual IP accessed the data — and playbooks do not inherently 'collect IP information' for analysis. Option C is wrong because a workbook is a visualization/reporting tool; it may show aggregate storage metrics but does not provide the entity-level timeline needed to determine if a specific unusual IP accessed the container.

213
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. You detect a suspicious app that has high data access and unusual API calls. You want to automatically block the app and notify the user. What should you implement?

A.Create an access policy that blocks the app based on the risk level.
B.Create an app governance policy that automatically blocks the app and sends a notification to the user.
C.Create a session policy to monitor the app's API calls.
D.Create a DLP policy to prevent data exfiltration from the app.
AnswerB

App governance policies in Defender for Cloud Apps are specifically designed to govern OAuth apps and can perform automated actions such as disabling or blocking an app when suspicious behavior is detected. When a policy triggers, it can block the app from accessing resources and send notification emails to the configured recipients, including the user or admin. This directly matches the stated requirement, making it the correct choice.

Why this answer

App governance policies in Microsoft Defender for Cloud Apps are specifically designed to govern OAuth-enabled apps that have been granted permissions to access organizational data. When an app exhibits suspicious behavior like high data access and unusual API calls, an app governance policy can automatically block the app and send a notification to the user, directly addressing the requirement to both block and notify.

Exam trap

The trap here is that candidates confuse 'blocking an app' (which requires an app governance policy) with 'blocking user access to an app' (which is done via an access policy), leading them to choose the access policy option even though it does not block the app itself or notify the user.

How to eliminate wrong answers

Option A is wrong because an access policy controls user access to apps based on risk level (e.g., blocking access from risky IPs), but it does not block the app itself or send notifications to the user about the app's behavior. Option C is wrong because a session policy monitors and controls user sessions in real-time (e.g., preventing download of sensitive data), but it does not block the app or notify the user about the app's suspicious activity. Option D is wrong because a DLP policy prevents data exfiltration by scanning content in transit or at rest, but it does not block an app or notify the user about the app's API calls or data access patterns.

214
MCQhard

During an incident response, you need to collect forensic data from Microsoft Defender for Endpoint (MDE) on a remote device that is currently offline. What is the best approach?

A.Initiate a live response session when the device comes online
B.Wait until the device is online and then collect manually
C.Run a remotely scheduled antivirus scan
D.Collect the data from the device's cloud store
AnswerA

Live response in Microsoft Defender for Endpoint is the correct forensic data collection method because it provides an interactive, audited remote shell on the device. Once the device is online, you can run built-in commands such as 'collect' to capture evidence like running processes, registry data, event logs, and sensitive files in a structured package. Unlike manual methods, this session uses Microsoft's authorized API and records all commands for chain of custody, making it the preferred incident-response approach.

Why this answer

When a device is offline, Microsoft Defender for Endpoint cannot establish a live response session because the device must be connected to the MDE service to execute commands. Initiating a live response session when the device comes online is the best approach because it allows you to run forensic collection commands (e.g., 'getfile', 'run') directly on the device via the MDE API, without requiring manual intervention or additional infrastructure.

Exam trap

The trap here is that candidates assume MDE can collect forensic data from a cloud store or via scheduled scans, but MDE's live response is the only native method for on-demand forensic collection from a remote device, and it requires the device to be online.

How to eliminate wrong answers

Option B is wrong because waiting until the device is online and then collecting manually is inefficient and error-prone; it lacks the structured, auditable, and remote execution capabilities that live response provides, and manual collection may miss critical artifacts. Option C is wrong because running a remotely scheduled antivirus scan only checks for malware and does not collect forensic data such as memory dumps, registry hives, or event logs. Option D is wrong because MDE does not maintain a 'cloud store' of raw forensic data from offline devices; the cloud store contains telemetry and alerts, not full disk or memory images that can be collected on demand.

215
MCQmedium

Your organization uses Microsoft Sentinel. A fusion incident was created involving multiple alerts from different sources. You need to investigate the incident to determine if it is a true positive. What is the first step you should take?

A.Run a KQL query on the raw logs to see if the alerts are connected.
B.Assign the incident to a senior analyst for further investigation.
C.Review the incident timeline and entity mapping in the incident details.
D.Close the incident as a false positive if the alerts seem unrelated.
AnswerC

Opening the incident details and examining the timeline and entity mapping is the correct first step because it shows the sequential events of the attack and the relationships between involved entities such as users, hosts, and IP addresses. Sentinel's fusion engine generates this correlation by combining multiple low-fidelity alerts across the attack chain, and the timeline helps you see if the alerts are sequentially connected. The entity mapping directly reveals shared indicators that might otherwise look disconnected when reading alert titles alone.

Why this answer

The first step in investigating a Fusion incident in Microsoft Sentinel is to review the incident timeline and entity mapping. This provides a consolidated view of all correlated alerts, their timestamps, and the entities involved (e.g., IP addresses, user accounts), enabling you to quickly assess whether the alerts are logically connected and indicative of a true positive attack chain. Starting with this high-level overview is efficient before diving into raw logs.

Exam trap

The trap here is that candidates often jump to running KQL queries (Option A) because they associate investigation with raw log analysis, but the correct first step is to use Sentinel's built-in incident visualization to understand the correlation before querying.

How to eliminate wrong answers

Option A is wrong because running a KQL query on raw logs is a later investigative step; you should first use the built-in incident details to understand the correlation before querying underlying data. Option B is wrong because assigning the incident to a senior analyst bypasses the initial triage responsibility of the current analyst, who should first review the incident details to determine if escalation is necessary. Option D is wrong because closing an incident as a false positive without reviewing the timeline and entity mapping violates proper incident response procedures and could miss a real threat.

216
MCQmedium

A company uses Microsoft Sentinel as its SIEM. The security team is investigating an incident that involves multiple alerts from different data sources. The team wants to see a timeline of all related activities across all data sources in one view. Which Microsoft Sentinel feature should they use?

A.Workbooks
B.Incident timeline
C.Investigation graph
D.Hunting page
AnswerB

The incident timeline aggregates alerts, bookmarks and entities from every connected data source into a single chronological view, satisfying the requirement to correlate related activities across sources during an investigation. Unlike hunting queries, which return raw results per query, it presents the whole incident's progression in one pane.

Why this answer

The Incident timeline in Microsoft Sentinel provides a unified chronological view of all alerts and events related to an incident. Option A is wrong because Workbooks are for custom dashboards and reporting, not for viewing incident timelines. Option C is wrong because the Investigation graph focuses on entity relationships, not a chronological timeline.

Option D is wrong because the Hunting page is for proactive threat hunting, not incident investigation.

217
MCQhard

Your company uses Microsoft Defender XDR. A critical server is exhibiting signs of a potential ransomware attack, with files being encrypted and a ransom note appearing. The incident has been escalated to the security operations center (SOC). What is the most immediate action to contain the threat and prevent further spread?

A.Collect an investigation package for analysis
B.Disable the user account that was logged on
C.Initiate the 'Contain device' action from Microsoft Defender XDR
D.Run a full antivirus scan on the server
AnswerC

Contain device isolates the server from the network via Microsoft Defender XDR while preserving the live session for investigation, immediately halting encryption and lateral spread. This satisfies the stem's requirement for the most immediate containment action against active ransomware.

Why this answer

Initiate the 'Contain device' action from Microsoft Defender XDR. This action immediately isolates the compromised device from the network, preventing the ransomware from spreading to other systems. Option A is incorrect because collecting an investigation package is for forensic analysis, not containment.

Option B is incorrect because disabling the user account does not stop the ransomware process that is already running on the server. Option D is incorrect because running a full antivirus scan takes time and does not contain the threat; containment must happen first.

218
Multi-Selectmedium

Which TWO actions should an analyst take when a user reports receiving a suspicious email with an attachment? (Select TWO.)

Select 2 answers
A.Submit the email to Microsoft for analysis using the Submissions page in Microsoft 365 Defender.
B.Run a PowerShell script to automatically forward the email to IT.
C.Delete the email from the user's mailbox using Microsoft 365 Defender.
D.Open the attachment to verify if it is malicious.
E.Block the sender in the user's Outlook settings.
AnswersA, C

Submitting the suspicious email via the Submissions page sends the original message and attachments to Microsoft for detonation and signature analysis, satisfying the need to report and analyse the threat. This enables Microsoft to tune detection and block similar messages across the tenant.

Why this answer

Option A is correct because submitting the suspicious email via the Submissions page in Microsoft 365 Defender sends the message, including its attachment, to Microsoft for analysis, allowing the service to detonate and inspect it and then update its threat intelligence and filtering. Option C is correct because an analyst can use Microsoft 365 Defender (for example, via Threat Explorer or the Email entity page) to soft-delete or hard-delete the malicious message from the user's mailbox, removing the threat and preventing further user interaction. Option B is wrong because automatically forwarding a potentially malicious email with a live attachment to IT spreads the threat and is not a standard containment action.

Option D is wrong because opening the attachment could execute malicious code and compromise the analyst's workstation. Option E is wrong because blocking the sender only in the user's Outlook settings is a weak, local action that does not remove the message or protect the organization, and sender addresses are easily spoofed.

Exam trap

SC-200 often tests the correct incident response actions for suspicious emails. The trap is choosing actions that are either dangerous (opening attachment) or ineffective (blocking sender locally) instead of the proper submission and deletion procedures.

219
MCQeasy

You are a SOC analyst in Microsoft Defender XDR. An incident has been created that includes alerts from Microsoft Defender for Endpoint and Microsoft Defender for Office 365. You need to assign the incident to a colleague and add a note about initial findings. What should you do?

A.Export the incident to a CSV file and email it to your colleague, then close the incident.
B.Open the incident, use the 'Assign to' option to select your colleague, and add a comment in the incident's activity log.
C.Use the 'Manage incident' option to change the status to 'In progress' and set the 'Assigned to' field to your colleague's email address.
D.Create a new incident manually and copy the alerts from the original incident, then assign the new incident to your colleague.
AnswerB

In Microsoft Defender XDR, you can assign an incident to a specific user directly from the incident page, and you can add comments to the incident timeline. This action notifies the assignee and records your findings for collaboration. It is the standard way to hand off an incident while preserving context.

Why this answer

Microsoft Defender XDR provides built-in incident assignment and commenting. Assigning the incident to a colleague from the incident page ensures they are notified and can take ownership. Adding a comment in the activity log documents initial findings without altering the incident's alert correlation.

This maintains a clear audit trail and supports efficient collaboration.

Exam trap

The trap here is assuming you must export or recreate the incident to share it, rather than using the native assignment and commenting features.

220
MCQhard

An organization uses Microsoft Purview Communication Compliance to detect insider trading. An alert is generated for a user who sent a message containing sensitive financial data. The compliance officer needs to initiate a legal hold on the user's mailbox to preserve evidence. Which role must the officer have to perform this action?

A.Communication Compliance admin
B.Compliance Administrator (Global)
C.eDiscovery Manager (Legal Hold)
D.Exchange Online Mailbox Search role
AnswerC

The eDiscovery Manager role group has a sub-role for Legal Hold that specifically allows managing holds on mailboxes and sites. This is the required identity to place a mailbox on hold in the Microsoft Purview compliance portal. Without this sub-role, even other eDiscovery roles cannot place holds.

Why this answer

Legal hold requires the 'Legal Hold' role in Microsoft Purview (eDiscovery). Communication Compliance roles alone do not include hold capabilities. Exchange Online roles may not have cross-functional hold.

221
MCQhard

Your company uses Microsoft Defender for Endpoint. A device shows signs of compromise with suspicious PowerShell execution. You need to collect forensic evidence before performing remediation. Which action should you use?

A.Isolate the device from the network.
B.Run a full antivirus scan.
C.Collect investigation package.
D.Initiate a live response session.
AnswerC

Collecting the investigation package gathers volatile forensic artefacts — running processes, scheduled tasks, network connections and autorun entries — from the compromised device before remediation alters them. This satisfies the stem's requirement to preserve evidence first, whereas isolating or remediating the device would destroy the volatile data needed for later analysis.

Why this answer

In Microsoft Defender for Endpoint, the 'Collect investigation package' action gathers a forensic snapshot of the device — including running processes, network connections, autoruns, scheduled tasks, and recent files — without altering the system state. This is the correct first step when you need to preserve evidence before remediation, because it captures volatile data that would be lost if you isolated or remediated the device. Isolation and live response are separate actions that serve different purposes.

Exam trap

SC-200 often tests the order of incident response actions — candidates pick 'Isolate the device' because it sounds like the most urgent step, but the question specifically asks for evidence collection before remediation, making 'Collect investigation package' the correct choice.

How to eliminate wrong answers

Option A is wrong because isolating the device from the network stops the attack but does not collect forensic evidence — it actually prevents further live data collection from the network and is a containment action, not an evidence-gathering one. Option B is wrong because running a full antivirus scan may quarantine or delete malicious files, destroying evidence, and it does not produce a forensic package. Option D is wrong because a live response session gives you a remote shell to run commands on the device, but it is an interactive tool — it does not automatically collect and package forensic artifacts the way 'Collect investigation package' does.

222
MCQmedium

Your company uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the default policy. The email contains an external link to a credential harvesting site. You need to block similar emails in the future. What should you do?

A.Create an anti-spam policy to block the sender's domain.
B.Create a Safe Links policy and add the malicious domain to the blocked URLs list.
C.Create an anti-malware policy to block the attachment type.
D.Add the sender's domain to the Tenant Allow/Block List.
AnswerB

Safe Links policies are specifically designed to protect users from malicious hyperlinks by rewriting URLs and checking them against Microsoft's threat intelligence plus your custom block list. Adding the malicious domain to the blocked URLs list causes any link containing that domain to be blocked or to trigger a warning when clicked, even if the email's sender appears benign. This directly addresses the attack vector—the embedded URL—rather than the email's origin, making it the correct control.

Why this answer

The phishing email contains a link to a credential harvesting site, so the most direct way to block similar emails in the future is to use a Safe Links policy. Safe Links proactively scans and blocks URLs at time of click, and you can add the malicious domain to the blocked URLs list to prevent users from accessing that site. This addresses the specific threat vector (malicious URL) rather than the sender's domain or attachment type.

Exam trap

The trap here is that candidates confuse the Tenant Allow/Block List (which is for sender/domain/IP blocking) with the Safe Links blocked URLs list (which is for URL-level blocking), leading them to choose option D instead of B.

How to eliminate wrong answers

Option A is wrong because an anti-spam policy blocks emails based on sender or domain reputation, but the email already bypassed the default policy, and blocking the sender's domain is reactive and easily circumvented by attackers using new domains. Option C is wrong because an anti-malware policy blocks attachments, but the threat here is a URL link, not an attachment, so it would not prevent the phishing email. Option D is wrong because the Tenant Allow/Block List is used to override filtering decisions for specific senders or domains, but adding the sender's domain would block all emails from that domain, which is too broad and does not address the URL-based threat; also, the email already bypassed the default policy, so a block list entry might not be effective if the email is already being delivered.

223
MCQhard

A company uses Microsoft Sentinel with Microsoft Defender for Cloud Apps. An incident is created when a user downloads 500 GB from SharePoint in one hour. The analyst wants to create a playbook that automatically suspends the user in Microsoft Entra ID when such activity is detected. Which connector and action should the analyst use in the playbook?

A.Microsoft Teams connector with 'Post message' action to notify admin.
B.Microsoft Entra ID connector with 'Update user' action to set accountEnabled to false.
C.Microsoft 365 Defender connector with 'Run advanced hunting' action.
D.Exchange Online connector with 'Set mailbox' action.
AnswerB

The Microsoft Entra ID connector's 'Update user' action writes directly to the directory object, letting the playbook set accountEnabled to false and immediately block sign-in. This satisfies the requirement to suspend the user automatically upon the Defender for Cloud Apps incident trigger.

Why this answer

The Microsoft Entra ID connector provides the 'Update user' action, which can set the 'accountEnabled' property to false, effectively suspending the user in Microsoft Entra ID. This directly addresses the requirement to automatically disable a user account when a high-volume SharePoint download incident is detected in Microsoft Sentinel. The playbook can be triggered by the incident and use this action to perform the suspension without manual intervention.

Exam trap

The SC-200 exam often tests the distinction between notification actions (like Teams posts) and remediation actions (like disabling a user account), and the trap here is that candidates may choose a notification option (A) because it seems proactive, but the question explicitly requires automatic suspension, not just alerting.

How to eliminate wrong answers

Option A is wrong because the Microsoft Teams connector with 'Post message' action only sends a notification to an admin; it does not suspend the user or perform any account modification, so it fails to meet the requirement of automatically suspending the user. Option C is wrong because the Microsoft 365 Defender connector with 'Run advanced hunting' action is used to query threat data for investigation, not to modify user account status; it cannot suspend a user in Microsoft Entra ID. Option D is wrong because the Exchange Online connector with 'Set mailbox' action modifies mailbox settings (e.g., forwarding, quotas) but does not disable the user account in Microsoft Entra ID; suspending a user requires disabling the identity, not just the mailbox.

224
Multi-Selecthard

Which THREE actions can you take in Microsoft Sentinel to respond to an incident?

Select 3 answers
A.Assign the incident to a user
B.Create an automation rule
C.Run a playbook
D.Modify a KQL query in an analytics rule
E.Export logs to Azure Storage
AnswersA, B, C

Assigning an incident to a user is a valid incident management action that designates an owner responsible for investigation and resolution. It establishes accountability, enables tracking of workload, and allows metrics to be based on individual or team performance, all within the Microsoft Sentinel incident workspace.

Why this answer

Assigning an incident to a user is a core incident response action in Microsoft Sentinel. It establishes ownership, ensuring a specific analyst is responsible for investigation and remediation. This action is performed directly from the incident details pane and is a fundamental step in managing the incident lifecycle.

Exam trap

The trap here is that candidates confuse actions that configure detection (like modifying analytics rules) or manage data (like exporting logs) with direct incident response actions, which are limited to triage, investigation, and remediation steps within the incident interface.

225
MCQmedium

You are a SOC analyst using Microsoft Defender XDR. An incident named 'Suspicious PowerShell download' is assigned to you. You need to quickly determine the initial entry point and the scope of affected devices. Which action should you perform first within the incident?

A.Export the incident details to a CSV file for offline analysis.
B.Initiate an automated investigation to remediate the threat.
C.Run an advanced hunting query to list all devices with PowerShell events.
D.Review the incident timeline to identify the first alert and related entities.
AnswerD

The incident timeline in Microsoft Defender XDR aggregates alerts and activities chronologically, helping you pinpoint the initial alert and affected entities. This provides the entry point and scope, enabling efficient triage. Other options may be useful later but do not directly answer the immediate need.

Why this answer

The incident timeline in Microsoft Defender XDR provides a chronological view of alerts and activities, allowing analysts to quickly identify the initial alert and affected entities. This is critical for understanding the entry point and scope before taking further action. Other options, while valid later, do not directly address the immediate need for triage.

Exam trap

The trap here is assuming that advanced hunting or automated investigation should be the first step, when in fact the timeline provides the quickest contextual overview.

← PreviousPage 3 of 5 · 375 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Respond to security incidents questions.