Courseiva

CCNA Respond to security incidents Questions

75 of 375 questions · Page 4/5 · Respond to security incidents · Answers revealed

226
MCQhard

A security administrator receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request from a domain controller. The alert suggests a possible Golden Ticket attack. Which action should the administrator take to validate the alert?

A.Review Microsoft Defender for Identity alerts for brute force attempts.
B.Check the domain controller's Security event log for Event ID 4769 with suspicious attributes.
C.Reset the krbtgt account password twice.
D.Verify if the user account associated with the ticket is disabled.
AnswerB

Checking the domain controller's Security event log for Event ID 4769 is the correct validation step because this event records every Kerberos service ticket request. In a Golden Ticket attack, the attacker uses a forged TGT to request service tickets, so Event ID 4769 entries will show anomalies such as unusual encryption types (e.g., RC4 when AES is expected), unexpected service names, or client IP addresses that don't align with normal behavior. These anomalies confirm that a forged ticket is being presented.

Why this answer

Event ID 4769 (Kerberos Service Ticket Request) on a domain controller is the authoritative source for validating suspicious ticket requests. In a Golden Ticket attack, the forged ticket often exhibits anomalous attributes such as an unusually long lifetime, a non-existent or disabled user account, or encryption type mismatches (e.g., RC4 when AES is expected). Reviewing this log directly confirms whether the ticket characteristics deviate from normal Kerberos behavior, providing definitive evidence for the alert.

Exam trap

The trap here is that candidates confuse validation steps with remediation actions, specifically choosing to reset the krbtgt password (Option C) before confirming the attack through log analysis, which would destroy forensic evidence and fail to validate the alert.

How to eliminate wrong answers

Option A is wrong because brute force attempts relate to password guessing or credential stuffing, not the validation of a forged Kerberos ticket; Golden Ticket attacks involve forged TGTs, not repeated authentication failures. Option C is wrong because resetting the krbtgt account password twice is a remediation step to invalidate existing Golden Tickets after an attack is confirmed, not a validation action to determine if the alert is legitimate. Option D is wrong because while a disabled user account might be a clue, it is not a definitive validation step; the ticket could be forged for an enabled account, and the primary validation requires examining the Kerberos service ticket request details in Event ID 4769.

227
MCQeasy

A security analyst in your SOC receives an alert from Microsoft Defender for Cloud Apps indicating that a user downloaded a large number of files from SharePoint in a short time. What is the most likely classification of this activity?

A.Ransomware
B.Lateral movement
C.Data exfiltration
D.Privilege escalation
AnswerC

Bulk downloading many files from a host, especially under a security alert, strongly indicates that an attacker is collecting and removing sensitive data. This aligns with the MITRE ATT&CK exfiltration technique (TA0010), where data is transferred out of the environment via HTTP/S, cloud storage, email, or removable media. The volume and pattern of file downloads make data exfiltration the most reasonable and supported conclusion.

Why this answer

A sudden, large-volume download of files from SharePoint within a short time window is a classic indicator of data exfiltration. Microsoft Defender for Cloud Apps uses anomaly detection policies to flag such activity based on user baseline behavior, download velocity, and the total number of files accessed, which aligns with the exfiltration phase of the cyber kill chain.

Exam trap

The trap here is that candidates may confuse bulk file downloads with ransomware activity (Option A) because both involve unusual file operations, but ransomware focuses on encryption/modification, not exfiltration, and Defender for Cloud Apps has separate detections for each behavior.

How to eliminate wrong answers

Option A is wrong because ransomware typically manifests as file encryption, renaming, or mass deletion, not simply bulk downloads; Defender for Cloud Apps would detect ransomware via file modification patterns or encryption alerts. Option B is wrong because lateral movement involves an attacker moving between hosts or accounts within the network (e.g., using RDP, SMB, or pass-the-hash), not downloading files from a cloud app. Option D is wrong because privilege escalation refers to gaining higher-level permissions (e.g., from user to admin), whereas the described activity is a data access pattern that does not inherently involve permission changes.

228
MCQmedium

A security operations center (SOC) team uses Microsoft Defender XDR and Microsoft Sentinel. An incident is created in Defender XDR that involves a malicious email and a compromised device. The team wants the incident to automatically sync to Sentinel. What is the minimum configuration required?

A.Configure the Microsoft Defender for Office 365 connector in Sentinel
B.Configure the Azure AD Identity Protection connector in Sentinel
C.Configure the Microsoft Defender XDR connector in Sentinel
D.Configure the Microsoft 365 Defender connector in Sentinel
AnswerC

The Microsoft Defender XDR connector streams incidents and alerts from Defender XDR into Microsoft Sentinel, automatically creating matching incidents. Enabling it is the minimum configuration; analytics rules or playbooks are unnecessary for the sync itself.

Why this answer

The Microsoft Defender XDR connector in Microsoft Sentinel is the dedicated connector that ingests incidents and advanced hunting events from all Defender XDR workloads (Defender for Endpoint, Office 365, Identity, Cloud Apps) and syncs them into Sentinel. Because the incident spans email and device, only the unified Defender XDR connector provides the cross-workload incident stream required for automatic synchronization.

Exam trap

SC-200 often tests the distinction between individual workload connectors and the unified Microsoft Defender XDR connector, tricking candidates into choosing a workload-specific connector for a cross-domain incident.

How to eliminate wrong answers

Option A is wrong because the Defender for Office 365 connector only brings email-related signals and does not sync the full cross-domain incident. Option B is wrong because Azure AD Identity Protection only covers identity risk detections, not email or device incidents. Option D is wrong because 'Microsoft 365 Defender' is the former name of the suite; the current connector in Sentinel is named 'Microsoft Defender XDR', and selecting the legacy name does not provide the unified incident sync.

229
MCQeasy

Your company uses Microsoft Sentinel with the Microsoft Defender for Cloud Apps connector. An incident is created when a user performs an unusual mass download from SharePoint Online. The playbook assigned to the incident automatically suspends the user account in Microsoft Entra ID. However, after investigation, the user's activity is determined to be legitimate (they were backing up data for a migration). You need to restore the user's account and ensure that the user can access all resources immediately. You also need to update the incident to reflect the findings. What should you do?

A.Send a new invitation to the user via Microsoft Entra ID and close the incident as resolved.
B.Reset the user's password in Microsoft Entra ID and force a password change at next sign-in.
C.Edit the playbook to remove the suspend action and re-run it for the incident.
D.Re-enable the user account in Microsoft Entra ID and set the incident status to Closed with classification 'False positive'.
AnswerD

Once the analyst determines the alert is a false positive, the correct remediation is to re-enable the user account by setting accountEnabled back to true in Microsoft Entra ID, restoring the user's access to Entra ID-protected resources. After making that change, the incident should be closed with classification 'False positive' and a comment documenting that the suspension was erroneous. These two steps together restore service and provide accurate reporting for tuning the analytics rule that caused the false trigger.

Why this answer

The user account was suspended by the playbook, so you must manually re-enable it in Microsoft Entra ID to restore access immediately. Setting the incident status to 'Closed' with classification 'False positive' accurately reflects that the alert was triggered by legitimate activity, which is the proper way to close a false positive in Microsoft Sentinel.

Exam trap

The trap here is that candidates may think re-running the playbook (Option C) will undo the suspension, but playbooks are not idempotent for reversing actions; they only execute the defined steps at trigger time and cannot retroactively modify past state.

How to eliminate wrong answers

Option A is wrong because sending a new invitation is used for inviting external users or resetting B2B collaboration, not for re-enabling a suspended internal user account. Option B is wrong because resetting the password does not re-enable a suspended account; the account remains disabled until explicitly enabled, and forcing a password change does not restore access. Option C is wrong because editing the playbook and re-running it for the incident would not retroactively unsuspend the user; playbooks execute actions at the time of incident creation and cannot reverse past actions on the same incident.

230
Multi-Selectmedium

Which TWO are recommended first steps when responding to a confirmed ransomware incident in Microsoft Defender XDR?

Select 2 answers
A.Assess the financial impact of the incident
B.Disable all user accounts
C.Run a full antivirus scan on all devices
D.Isolate affected devices using Microsoft Defender for Endpoint
E.Revoke user sessions and require reauthentication
AnswersD, E

Isolation severs the endpoint's network connectivity while preserving its volatile memory and forensic artefacts, immediately halting lateral spread and encryption across the estate. This containment step directly satisfies the stem's requirement for a recommended first response action in Microsoft Defender XDR before eradication or recovery begins.

Why this answer

The correct answers are D and E. Isolating affected devices using Microsoft Defender for Endpoint (D) and revoking user sessions to require reauthentication (E) are immediate containment steps to prevent further spread. Assessing financial impact (A) is part of investigation, not first response.

Disabling all user accounts (B) is too disruptive and not recommended as a first step. Running a full antivirus scan (C) may alert the attacker and is not a containment measure.

231
MCQeasy

Your organization uses Microsoft Defender for Cloud to protect hybrid cloud workloads. An alert indicates that a container in Azure Kubernetes Service (AKS) is running a privileged container. Which response action should you take first?

A.Investigate the alert details in Microsoft Defender for Cloud
B.Disable the container immediately
C.Restart the AKS cluster
D.Delete the container and its image
AnswerA

Investigation is the mandatory first step because Microsoft Defender for Cloud enriches AKS container alerts with the full attack story, affected pod and container identities, MITRE ATT&CK tactics, and associated entities. Opening the alert details lets you confirm whether the activity is a true positive, determine its severity and blast radius, and identify which subsequent containment or remediation action is safe. Proceeding before reviewing these details risks an incorrect response, which is why all other options are premature.

Why this answer

When a Microsoft Defender for Cloud alert indicates a privileged container in AKS, the first response action should be to investigate the alert details within Defender for Cloud. This allows you to assess the scope, impact, and context of the alert—such as which container, namespace, and pod is involved, and whether it is a false positive—before taking any disruptive remediation steps. Prematurely disabling, deleting, or restarting resources could destroy forensic evidence and escalate the incident unnecessarily.

Exam trap

The trap here is that candidates may think immediate containment (disabling or deleting) is always the correct first step, but Microsoft's incident response guidance emphasizes 'investigate first' to avoid destroying evidence and to ensure the response is proportional to the threat.

How to eliminate wrong answers

Option B is wrong because disabling the container immediately without investigation may remove critical forensic data and could disrupt legitimate workloads if the alert is a false positive. Option C is wrong because restarting the entire AKS cluster is an overly aggressive and disruptive action that does not address the specific privileged container and could cause widespread service downtime. Option D is wrong because deleting the container and its image prematurely destroys evidence needed for root cause analysis and may violate incident response procedures that require preservation of artifacts.

232
MCQmedium

You are investigating a security incident in Microsoft Sentinel where a user reported receiving a phishing email with a malicious attachment. You need to identify all users who received the same email within the last 24 hours. Which KQL query should you use?

A.EmailEvents | where RecipientEmailAddress == 'user@contoso.com' and Timestamp > ago(24h) | project SenderFromAddress, Subject
B.EmailUrlInfo | where Url == 'http://malicious.com' | project RecipientEmailAddress
C.EmailAttachmentInfo | where FileName == 'malicious.doc' | project RecipientEmailAddress
D.EmailEvents | where SenderFromAddress == 'attacker@example.com' and Subject == 'Invoice' and Timestamp > ago(24h) | project RecipientEmailAddress
AnswerD

This retrieves all recipients who received the same email from the same sender and subject.

Why this answer

To find all users who received the same phishing email, you must pivot on the email's identifying attributes — sender and subject — rather than the reported recipient. Querying EmailEvents filtered by SenderFromAddress, Subject, and a 24-hour window, then projecting RecipientEmailAddress, returns every recipient of that campaign.

Exam trap

The trap is anchoring on the reported victim's email address — the exam tests whether you pivot on campaign identifiers (sender/subject) to find all recipients, not just query the one user who reported it.

How to eliminate wrong answers

Option A is wrong because filtering on the single reported recipient's address only returns that user's emails and cannot identify other recipients. Option B is wrong because EmailUrlInfo contains URL click/URL data and does not reliably enumerate all recipients of the email; it is keyed to URLs, not the campaign. Option C is wrong because EmailAttachmentInfo focuses on attachment metadata and, while it has recipient fields, it does not filter by sender/subject/time to scope the campaign and may miss recipients if the attachment name varies.

233
MCQeasy

An incident in Microsoft Sentinel was assigned to you. After investigation, you determine it is a false positive. What should you do to resolve the incident?

A.Add a comment and leave it open
B.Close the incident with classification 'FalsePositive'
C.Delete the incident
D.Reassign to another analyst
E.Change the status to 'Active'
AnswerB

Closing the incident with the classification 'FalsePositive' is the correct remediation because it formally resolves the incident, records that the detected activity was not malicious, and preserves the audit trail. In Microsoft Sentinel, this action updates the incident status to 'Resolved', stores the classification and closing reason in the incident record, and can trigger automation or analytics rule tuning to reduce future false positives.

Why this answer

In Microsoft Sentinel, when an incident is determined to be a false positive, the correct resolution is to close it with the classification 'FalsePositive'. This action properly documents the outcome, updates the incident status to 'Closed', and ensures the incident is tracked for reporting and analytics. Leaving it open or changing status to 'Active' does not resolve it, while deleting is not supported and reassignment does not address the determination.

Exam trap

The trap here is that candidates may think they can delete an incident to remove it from the queue, but Microsoft Sentinel does not allow deletion—only closure with a proper classification is supported.

How to eliminate wrong answers

Option A is wrong because adding a comment and leaving the incident open does not resolve it; incidents must be closed to indicate completion. Option C is wrong because Microsoft Sentinel does not support deleting incidents; they can only be closed or archived. Option D is wrong because reassigning to another analyst does not resolve the incident; it merely changes ownership without addressing the false positive determination.

Option E is wrong because changing the status to 'Active' would indicate the incident is still under investigation, which contradicts the conclusion that it is a false positive.

234
MCQeasy

You are investigating a phishing incident in Microsoft Defender XDR. The incident involves a user who clicked a malicious link in an email. Which data source would you use to trace the email's origin?

A.Microsoft Defender for Endpoint
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud Apps
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Office 365 is the correct tool because it natively monitors email flow and protects Exchange Online through threat policies, URL detonation, and attachment sandboxing. It exposes rich hunting telemetry in Threat Explorer, such as email delivery outcomes, URL click verdicts, and user-reported phishing submissions, along with the ability to trace a message's complete path. This direct visibility into the phishing email's origin, targeting, and verdicts makes it the proper investigative surface for a phishing incident. It may later inform pivots to other Defender workloads, but initial triage belongs here.

Why this answer

Microsoft Defender for Office 365 (MDO) is the correct data source because it provides email-specific telemetry, including SMTP headers, sender IP addresses, and authentication results (SPF, DKIM, DMARC). This data is essential for tracing the origin of a phishing email that a user clicked. MDO's Threat Explorer and Email Entity page allow you to reconstruct the email's path from the sending server to the recipient's inbox.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Endpoint's network-level visibility (e.g., URL click events) with the email-specific origin data that only Microsoft Defender for Office 365 can provide.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint focuses on endpoint-level threats (processes, files, network connections) and does not store email headers or SMTP transaction logs needed to trace an email's origin. Option C is wrong because Microsoft Defender for Cloud Apps is designed for cloud application usage and shadow IT discovery, not for email transport analysis or header inspection. Option D is wrong because Microsoft Defender for Identity monitors on-premises Active Directory signals (Kerberos, NTLM, LDAP) for identity-based attacks, not email routing or SMTP metadata.

235
MCQmedium

You are analyzing a firewall policy in Azure Firewall deployed via Azure Policy. What is the effect of this rule?

A.Allows outbound traffic from any source to IP 10.0.0.5.
B.Allows inbound traffic from IP 10.0.0.5 to any destination.
C.Denies inbound traffic from IP 10.0.0.5 to any destination.
D.Denies outbound traffic from any source to IP 10.0.0.5.
AnswerC

This option is correct because it exactly matches the rule's configuration: Access is Deny, Direction is Inbound, Source is 10.0.0.5, and Destination is Any. When the Azure Firewall processes inbound packets, any traffic with a source IP of 10.0.0.5 will be dropped before reaching any internal resource. The 'Any' destination ensures the denial applies to all internal IP addresses, ports, and protocols, making this the accurate interpretation of the rule's intent.

Why this answer

The rule in Azure Firewall deployed via Azure Policy uses a default deny approach for inbound traffic. Since the rule explicitly denies inbound traffic from IP 10.0.0.5 to any destination, option C is correct. Azure Firewall processes rules in a priority order, and a deny rule for inbound traffic from a specific source IP overrides any allow rules that might match the same traffic.

Exam trap

The trap here is that candidates often confuse the direction of traffic (inbound vs outbound) and the action (allow vs deny), leading them to select options that reverse the source/destination or misinterpret the rule's effect.

How to eliminate wrong answers

Option A is wrong because the rule specifies 'Deny' action, not 'Allow', and it targets inbound traffic from a specific source IP, not outbound traffic to any source. Option B is wrong because the rule denies inbound traffic from IP 10.0.0.5, not allows inbound traffic from that IP. Option D is wrong because the rule is for inbound traffic (source IP 10.0.0.5 to destination), not outbound traffic from any source to that IP.

236
Multi-Selecteasy

You are investigating a security incident involving a compromised user account. The attacker used the account to access sensitive data in SharePoint Online. Which TWO actions should you take to remediate the incident? (Choose two.)

Select 2 answers
A.Reset the user's password.
B.Revoke all refresh tokens for the user.
C.Disable the user account in Microsoft Entra ID.
D.Review the sign-in logs to determine the extent of the breach.
E.Create a Conditional Access policy to require MFA for the user.
AnswersB, C

Revoking refresh tokens immediately invalidates the attacker's existing sessions, preventing token renewal and further access to SharePoint Online. This satisfies the containment constraint by cutting off persistent access tied to the compromised account, since access tokens alone expire quickly but refresh tokens sustain the intrusion.

Why this answer

Option B is correct because revoking all refresh tokens for the compromised user immediately invalidates the OAuth 2.0 refresh tokens that the attacker could use to silently obtain new access tokens for SharePoint Online and other Microsoft 365 resources, cutting off their persistent access. Option C is correct because disabling the user account in Microsoft Entra ID blocks any further authentication attempts with that identity, preventing the attacker from signing in again while the incident is contained. Option A is not the best remediation action here because resetting the password alone does not invalidate existing refresh tokens, so the attacker could retain access until those tokens expire.

Option D is a detection/investigation step rather than a remediation action, and Option E is a preventive control that does not immediately stop an active compromise.

Exam trap

Distinguish between investigative actions (reviewing logs) and remediation actions (revoking tokens, disabling account). Immediate remediation stops the breach; investigation follows.

237
MCQhard

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector. You have a critical incident that involves multiple alerts across different services. The incident is being updated with new alerts. You need to ensure that a specific playbook runs only when the incident severity is updated to High. How should you configure the automation rule?

A.Set the trigger to 'When an alert is created' and filter for alerts with High severity.
B.Set the trigger to 'When incident is updated' and add a condition on severity equals High.
C.Set the trigger to 'When incident is created' and add a condition on severity equals High.
D.Configure the condition inside the playbook to check severity and exit if not High.
AnswerB

The 'When incident is updated' trigger is the correct lifecycle hook because it fires on any change to an incident's properties, including a severity change. Adding a condition that severity equals High ensures the playbook only proceeds for incidents that are or have been set to High, satisfying the requirement. This is the recommended pattern: keep the condition in the automation rule so the playbook is only invoked when the condition is true.

Why this answer

The requirement is to run the playbook only when the incident severity is updated to High, so the automation rule must trigger on 'When incident is updated' and include a condition that severity equals High. This ensures the playbook fires on the severity change event rather than on creation or alert events.

Exam trap

SC-200 often tests whether candidates confuse incident-level triggers with alert-level triggers, and whether they place conditions in the automation rule versus inside the playbook, leading to unnecessary executions or missed events.

How to eliminate wrong answers

Option A is wrong because triggering on alert creation and filtering for High severity would fire on new alerts, not on an incident severity update, and would not reflect the incident-level change. Option C is wrong because triggering on incident creation only fires once at creation and would miss later severity updates. Option D is wrong because putting the severity check inside the playbook means the playbook still runs (and consumes resources) on every trigger, and it does not address the trigger condition itself; the requirement is to run only when severity is updated to High.

238
MCQhard

A Microsoft Defender XDR incident shows that a user's device has been communicating with a known malicious C2 server. The device is online and the user is actively working. You need to contain the threat with minimal business disruption. What should you do?

A.Remove the device from the network by disabling the switch port
B.Shut down the device remotely
C.Run a full antivirus scan on the device
D.Initiate device isolation from Microsoft Defender XDR
AnswerD

Initiating device isolation from Microsoft Defender XDR contains the threat while the device stays online, satisfying the minimal-disruption constraint. Network isolation blocks all traffic except Defender XDR communication, so the user's session persists and the C2 channel is severed without wiping or powering off the endpoint.

Why this answer

Initiating device isolation in Microsoft Defender XDR stops all network communication to and from the device while allowing the user to continue working locally, thus containing the threat with minimal business disruption. Option A is incorrect because disabling the switch port would require physical access to the network infrastructure and may not be feasible remotely. Option B is incorrect because shutting down the device remotely causes immediate disruption and loss of user productivity.

Option C is incorrect because a full antivirus scan does not stop ongoing C2 communication and may allow the threat to continue spreading.

239
MCQeasy

You are responding to an incident where a user's device may be compromised. You need to collect forensic data from the device using Microsoft Defender for Endpoint. Which action should you take?

A.Isolate device
B.Initiate Live Response
C.Collect investigation package
D.Run antivirus scan
AnswerC

The 'Collect investigation package' action in Microsoft Defender for Endpoint is the correct choice because it automatically assembles a ZIP file containing forensic data from the device, including registry entries, event logs, loaded modules, network connections, and running processes. This artifact is specifically designed for deep investigation and can be downloaded by the analyst for offline analysis. It is a built-in response action that captures the full evidentiary picture needed to determine the scope and origin of the incident.

Why this answer

The 'Collect investigation package' action in Microsoft Defender for Endpoint is specifically designed to gather forensic data—such as registry hives, event logs, memory dumps, and disk images—from a device for offline analysis. This is the correct choice because the question explicitly asks to collect forensic data, and this action packages all relevant artifacts into a single .zip file for detailed examination.

Exam trap

The trap here is that candidates often confuse 'Initiate Live Response' with forensic data collection because it offers interactive access, but the question specifically asks for a method to 'collect forensic data' in a packaged format, which only 'Collect investigation package' provides.

How to eliminate wrong answers

Option A is wrong because 'Isolate device' disconnects the device from the network to contain a threat but does not collect forensic data; it prevents further spread but provides no artifacts for analysis. Option B is wrong because 'Initiate Live Response' provides a real-time remote shell for interactive investigation and remediation, but it is not a one-click collection of a comprehensive forensic package; it requires manual commands to gather data. Option D is wrong because 'Run antivirus scan' only performs a malware scan and removal, which does not capture the full forensic evidence needed for incident response, such as memory or registry artifacts.

240
MCQhard

You are investigating a ransomware incident in Microsoft Sentinel. The incident contains multiple alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. You need to correlate the alerts and identify the initial entry point. Which KQL function should you use to combine the alerts?

A.materialize()
B.union
C.mv-expand
D.make_set()
AnswerD

make_set() is a KQL aggregation function that constructs an array of unique values from a specified column, grouped by one or more key columns. When correlating alerts in a ransomware investigation, you can use make_set(AlertTitle) with a summarize by Account or Hostname to gather all distinct alert names that fired for that entity. This creates a concise, ordered set of alert titles that reveals the sequence or combination of malicious activities, such as initial access and data encryption. It is therefore the correct choice for aggregating alert titles to support correlation analysis.

Why this answer

D is correct because `make_set()` is used with `summarize` to create a distinct list of values from a column across multiple rows, which is essential for correlating alerts from different data sources (e.g., DeviceEvents, EmailEvents, IdentityLogonEvents) by a common identifier like `DeviceName` or `AccountUpn`. This allows you to group alerts from Defender for Endpoint, Office 365, and Identity into a single row per entity, making it easier to trace the initial entry point by analyzing the timeline of distinct alert types.

Exam trap

The trap here is that candidates confuse `union` (which simply appends rows) with the need to correlate alerts by a common entity, leading them to overlook `make_set()` as the correct aggregation function for grouping distinct alert data from multiple sources.

How to eliminate wrong answers

Option A is wrong because `materialize()` is used to cache the result of a subquery for performance optimization in complex queries, not to combine or correlate alerts from different tables. Option B is wrong because `union` merges rows from multiple tables into a single result set but does not aggregate or correlate alerts by a common entity; it simply appends rows, which would not help identify the initial entry point without further summarization. Option C is wrong because `mv-expand` is used to expand multi-value arrays or dynamic fields into multiple rows, not to combine alerts from different sources; it would break apart existing data rather than correlate it.

241
MCQmedium

You are responding to a phishing incident. The investigation reveals that a user clicked a link in a phishing email and entered credentials on a fake site. You need to contain the incident and prevent further compromise. What should you do first?

A.Report the phishing site to Microsoft.
B.Block the phishing URL in Microsoft Defender for Office 365.
C.Reset the user's password and revoke sessions.
D.Delete the phishing email from the user's mailbox.
AnswerC

Resetting the user's password changes the credential so the stolen password is no longer valid for authentication, while revoking sessions through Microsoft Entra ID invalidates any refresh tokens and access tokens the attacker may have obtained. This directly severs the attacker's ability to continue using the compromised account, including mailbox access and other applications. It is the proper immediate containment action for a credential-phishing incident.

Why this answer

The immediate priority when credentials have been compromised is to invalidate them, preventing the attacker from using them for further access. Resetting the password and revoking sessions (e.g., via Azure AD 'Revoke-AzureADUserAllRefreshToken' or 'Revoke-MgUserSignInSession') ensures the attacker cannot authenticate again, even if they have the password hash or active tokens. This aligns with the NIST SP 800-61 incident response containment phase.

Exam trap

The trap here is that candidates focus on blocking the phishing URL or deleting the email (technical controls for the attack vector) instead of recognizing that the core containment priority is neutralizing the compromised credentials (the attacker's foothold).

How to eliminate wrong answers

Option A is wrong because reporting the phishing site to Microsoft is a post-containment reporting step that does not stop the attacker from using the stolen credentials or accessing resources. Option B is wrong because blocking the phishing URL in Defender for Office 365 prevents future clicks but does not remediate the already-compromised credentials or active sessions. Option D is wrong because deleting the phishing email from the user's mailbox removes evidence but does not invalidate the stolen credentials or prevent the attacker from using them to log in.

242
MCQmedium

Your Microsoft 365 tenant is protected by Microsoft Defender for Office 365. A user reports receiving a suspicious email with a link. You need to investigate whether the link was malicious and if any other users clicked it. Which tool should you use first?

A.Microsoft Entra ID sign-in logs
B.Microsoft Purview compliance portal
C.Email Entity page in Microsoft Defender XDR
D.Threat Explorer
E.Attack Simulation Training
AnswerD

Threat Explorer is the correct tool because it is a security hunting and investigation engine built into Microsoft Defender for Office 365 that provides queryable access to email message data and user click activities. It includes a dedicated URL view that reports each click on a Safe Links-protected URL, the identity of the user who clicked it, the verdict applied, and the client app used, with the ability to filter by time, user, and threat type. This makes it ideal for investigating a potential phishing click and correlating it with email delivery and threat intelligence.

Why this answer

Threat Explorer (Option D) is the correct first tool because it provides a centralized view of email threats, including malicious links and clicks. You can filter by URL or sender to identify if the specific link was detected as malicious and then use the 'Click to allow/block' feature or the 'URL clicks' view to see which users clicked it. This aligns with the incident response workflow for investigating phishing campaigns in Defender for Office 365.

Exam trap

The trap here is that candidates often confuse the Email Entity page (which shows details for a single email) with Threat Explorer (which provides aggregated, searchable data across all emails and clicks), leading them to pick Option C instead of the correct tool for multi-user investigation.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID sign-in logs track authentication events, not email content or link clicks; they would not show whether a link in an email was malicious or clicked. Option B is wrong because the Microsoft Purview compliance portal focuses on data governance, eDiscovery, and compliance policies, not real-time email threat investigation or link click analysis. Option C is wrong because the Email Entity page in Microsoft Defender XDR provides details about a single email message but does not natively aggregate click data across multiple users or allow bulk investigation of link clicks; Threat Explorer is the dedicated tool for that.

Option E is wrong because Attack Simulation Training is used to create and run simulated phishing campaigns for user training, not to investigate real-world suspicious emails or link clicks.

243
MCQhard

Your company uses Microsoft Defender XDR. During a ransomware incident, you need to isolate a compromised Windows 10 device from the network while allowing connectivity to the Microsoft Defender for Endpoint service. Which action should you take?

A.Initiate a Full isolation from the device's action menu.
B.Contain the device from the Microsoft Defender XDR portal.
C.Apply a firewall rule to block all outbound traffic.
D.Run a selective isolation to block only external connections.
AnswerA

Initiating Full isolation from the device's action menu in Microsoft Defender XDR is the correct response because it immediately blocks all network traffic to and from the compromised device except for communication with the Defender for Endpoint service. This keeps the sensor and cloud command channel alive, allowing remediation actions like antivirus scans and collected forensic packages to be delivered. It is a policy-driven, reversible action that prevents ransomware from spreading laterally or reaching command-and-control while preserving your ability to investigate and respond.

Why this answer

Full isolation from the device's action menu is correct because in Microsoft Defender XDR, full isolation blocks all network traffic to and from the device except for the Defender for Endpoint service communication channel. This allows the security team to contain ransomware spread while still managing the device and running remediation actions through the Defender portal. Selective isolation, by contrast, only blocks external connections and permits internal ones, which is insufficient for ransomware containment.

Exam trap

SC-200 often tests the difference between full and selective isolation; the trap is choosing selective isolation thinking it blocks external threats while allowing internal management, when ransomware containment requires full isolation.

How to eliminate wrong answers

Option B is wrong because 'Contain the device' is not the correct action name in Defender XDR for network isolation; containment is a broader concept and does not match the specific isolation action. Option C is wrong because a firewall rule blocking all outbound traffic would also block the Defender for Endpoint service, breaking management and remediation. Option D is wrong because selective isolation allows internal network connectivity, which would not stop ransomware from spreading laterally.

244
MCQmedium

Your security team receives an alert from Microsoft Defender for Endpoint indicating a suspicious PowerShell command was executed on a device. The command attempted to download a payload from a known malicious IP. After confirming the alert is a true positive, what should be your first containment step?

A.Search for similar commands across all devices using advanced hunting
B.Disable the user account in Microsoft Entra ID
C.Isolate the device from the network using Microsoft Defender for Endpoint
D.Reset the user's password
AnswerC

Isolation immediately cuts the device's network connectivity, halting any further command-and-control communication or payload download from the malicious IP. This contains the true-positive compromise before lateral movement or additional payloads occur, satisfying the requirement for a first containment step.

Why this answer

Isolating the device via Microsoft Defender for Endpoint is the correct first containment step because it immediately cuts the endpoint off from the network while preserving the Defender agent's communication channel for further investigation and remediation. This stops lateral movement and C2 traffic from the compromised host without destroying forensic evidence. It is the standard 'contain first, investigate second' playbook for confirmed endpoint compromise.

Exam trap

The trap is choosing an investigative or identity-focused action (hunting, disabling account, resetting password) as the 'first' step when the question asks for containment — candidates conflate investigation with containment and miss that stopping the active threat takes priority.

How to eliminate wrong answers

Option A is wrong as a first step because advanced hunting is a threat-hunting/investigation activity, not containment — the malicious process is still running and could spread while you hunt. Option B is wrong because disabling the Entra ID account addresses identity compromise, but the endpoint is already executing malicious code; disabling the account does not stop the running payload or its network activity. Option D is wrong because resetting the user's password is a remediation step for credential compromise and does nothing to halt the active malware on the device.

245
MCQeasy

Your organization uses Microsoft Sentinel. An incident is created for a possible data exfiltration via an unapproved external IP address. Which type of Microsoft Sentinel automation should you use to automatically block the IP address in the firewall?

A.Data connector.
B.Analytics rule.
C.Watchlist.
D.Playbook.
AnswerD

Playbooks are Logic Apps triggered by Microsoft Sentinel automation rules, enabling an automated response that calls firewall APIs to block the IP. This satisfies the requirement to block the unapproved external address automatically upon incident creation.

Why this answer

Playbooks in Microsoft Sentinel are automated workflows based on Azure Logic Apps that can perform response actions, such as blocking an IP address in a firewall. When an incident indicates data exfiltration via an unapproved external IP, a playbook can be triggered automatically or manually to execute the block action via integration with firewall APIs or management tools.

Exam trap

The SC-200 exam often tests the distinction between detection (analytics rules) and response (playbooks), so candidates may confuse an analytics rule's ability to generate alerts with the capability to perform automated remediation actions.

How to eliminate wrong answers

Option A is wrong because a data connector is used to ingest logs and events from various sources into Sentinel, not to perform automated response actions like blocking an IP. Option B is wrong because an analytics rule generates alerts or incidents based on query logic; it does not execute remediation actions such as firewall changes. Option C is wrong because a watchlist is a collection of data (e.g., known malicious IPs) for correlation in queries, but it cannot directly trigger a block action in a firewall.

246
Multi-Selecteasy

Which TWO are valid methods to collect forensic evidence from a compromised Windows endpoint during an incident? (Choose TWO.)

Select 2 answers
A.Run Windows Update to fix vulnerabilities.
B.Reboot the system and boot from a forensic USB drive.
C.Use FTK Imager to create a forensically sound image of the hard drive.
D.Run KAPE (Kroll Artifact Parser and Extractor) to collect artifacts.
E.Take a memory dump using DumpIt or similar tool.
AnswersD, E

KAPE is specifically designed for live incident response: it collects targeted artifacts such as browser history, prefetch files, registry hives, and recently accessed documents directly from the running system while preserving their timestamps and metadata. Its output is organized and can be processed with timelines, and its operation avoids installing persistent software or altering core system files, so the evidence collection is faster and less intrusive than full disk imaging. By running KAPE during the incident, you capture volatile and semi-volatile evidence that would be lost after a reboot or shutdown, which is why it is a valid live collection method.

Why this answer

KAPE (Kroll Artifact Parser and Extractor) is a purpose-built tool for collecting and parsing forensic artifacts from live Windows endpoints during incident response. It efficiently gathers critical evidence such as prefetch files, registry hives, event logs, and browser history without altering the system state, making it a valid method for forensic collection.

Exam trap

The SC-200 exam often tests the distinction between live forensic collection tools (like KAPE and DumpIt) and traditional forensic imaging tools (like FTK Imager) that require a dead-box approach, leading candidates to incorrectly select FTK Imager for live collection.

247
MCQhard

A SOC analyst is investigating a Microsoft Sentinel incident involving a compromised service principal. The analyst needs to enrich the incident with information from an external threat intelligence platform that exposes a REST API and requires an API key. The enrichment must run automatically each time a matching incident is created and must not require manual steps. Which Microsoft Sentinel component should the analyst use to implement this enrichment?

A.A data connector for the threat intelligence platform
B.A workbook with a custom parameter
C.A scheduled analytics rule with entity mapping
D.A Microsoft Sentinel playbook triggered by an automation rule
AnswerD

Playbooks are Logic Apps workflows that can call external REST APIs, handle API keys via secure inputs, and post results back to the incident as comments, tags, or entities. Automation rules can trigger a playbook automatically when an incident is created, matching the requirement for automatic enrichment on matching incidents. This combination provides the required no-touch, repeatable enrichment using the external threat intelligence platform.

Why this answer

Automated enrichment using an external API with an API key requires a Logic Apps-based playbook, which can securely store secrets, make HTTP calls, and write results back to the incident. Automation rules provide the trigger mechanism when an incident is created, ensuring the playbook runs without manual intervention. Analytics rules, workbooks, and data connectors serve different purposes and cannot fulfill the automated external enrichment requirement.

Exam trap

The trap here is assuming a data connector or analytics rule can call an external API; only playbooks (Logic Apps) can perform outbound API calls with secrets and write enrichment back to the incident.

248
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to automatically isolate a device when a high-severity incident is created. What is the most efficient way to achieve this?

A.Manually isolate the device from the Microsoft Defender for Endpoint console after the incident is created.
B.Create an automation rule in Microsoft Sentinel that runs a PowerShell script to isolate the device.
C.Create a custom detection rule in Microsoft Defender XDR that triggers device isolation.
D.Create an automation rule in Microsoft Sentinel that triggers a playbook, which uses the Microsoft Defender for Endpoint connector to isolate the device.
AnswerD

This is the correct approach because an automation rule in Microsoft Sentinel can be configured to trigger immediately upon incident creation and invoke a playbook. The playbook, built in Azure Logic Apps, uses the Microsoft Defender for Endpoint connector's 'Isolate machine' action to send an isolation command to the device. This provides a fully integrated, automated response that directly ties Sentinel's incident detection to the prescribed containment action, without manual intervention or custom script execution.

Why this answer

It leverages Microsoft Sentinel's automation rules to trigger a playbook that uses the Microsoft Defender for Endpoint connector, enabling automated device isolation in response to a high-severity incident. This approach is the most efficient as it combines Sentinel's incident-driven automation with Defender for Endpoint's native isolation action, eliminating manual intervention and ensuring rapid response.

Exam trap

The trap here is that candidates may confuse automation rules with direct script execution or assume that Defender XDR detection rules can natively perform response actions like isolation, when in fact isolation requires a playbook or automated response configuration outside the detection rule.

How to eliminate wrong answers

Option A is wrong because manual isolation from the Microsoft Defender for Endpoint console is not automated and contradicts the requirement for efficiency, as it requires human action after incident creation. Option B is wrong because automation rules in Microsoft Sentinel cannot directly run PowerShell scripts; they trigger playbooks (Logic Apps) or other actions, and running a script natively is not supported. Option C is wrong because custom detection rules in Microsoft Defender XDR can trigger alerts but cannot directly execute device isolation actions; isolation is an automated response action that must be configured via automation rules or playbooks, not within the detection rule itself.

249
MCQmedium

A SOC team uses Microsoft Sentinel and wants to automatically enrich incidents with threat intelligence from a third-party feed. Which feature should they configure to ingest the threat intelligence and correlate it with alerts?

A.Analytics rules
B.Threat intelligence connectors
C.Data connectors
D.Watchlists
AnswerB

Threat intelligence connectors are purpose-built data connectors that pull indicators from external sources—such as TAXII feeds, Microsoft Defender Threat Intelligence, or third-party platforms—directly into the normalized ThreatIntelligenceIndicator table. Once ingested, Sentinel automatically enables matching and correlation across analytics rules and detections. This is the correct mechanism for automatically importing and operationalizing TI feeds.

Why this answer

Threat intelligence connectors in Microsoft Sentinel allow ingestion of TI feeds and enable correlation with alerts. The other options do not provide this capability.

250
MCQmedium

Refer to the exhibit. A security analyst runs the KQL query in Microsoft Defender XDR to find devices running encoded PowerShell commands in the last hour. The query returns results showing a device named 'DESKTOP-123' with account 'jdoe'. The analyst suspects malicious activity. Which immediate next step should the analyst take?

A.Delete the query because it returned results
B.Modify the query to increase the time range to 24 hours
C.Click on the result to open the full device timeline and analyze the process tree
D.Isolate the device 'DESKTOP-123' from the network
AnswerC

Opening the device timeline reveals the full process tree, parent-child relationships and command lines behind the encoded PowerShell. This lets the analyst confirm whether the activity is genuinely malicious before containment, satisfying the need for immediate triage evidence.

Why this answer

When a KQL query in Microsoft Defender XDR returns suspicious results — such as encoded PowerShell commands on a device — the immediate next step is to investigate by clicking the result to open the full device timeline and analyze the process tree. This provides context on parent processes, command-line arguments, and related events to determine whether the activity is truly malicious before taking disruptive action.

Exam trap

SC-200 often tests the incident response sequence, tricking candidates into choosing immediate containment (isolation) when the correct first step is investigation to confirm the threat — a classic 'respond vs. investigate' trap.

How to eliminate wrong answers

Option A is wrong because deleting the query does not address the potential threat and would destroy the detection logic. Option B is wrong because expanding the time range to 24 hours is a broader search, not an immediate investigative step on the specific suspicious device — it delays triage and may return excessive noise. Option D is wrong because isolating the device is a containment action that should follow confirmation of malicious activity; isolating prematurely can disrupt business operations and should not be the immediate first step without investigation.

251
Multi-Selectmedium

Which TWO actions are appropriate when responding to a confirmed data exfiltration incident via email?

Select 2 answers
A.Block the recipient domain on the email gateway
B.Place a legal hold on the user's mailbox
C.Disable the user's account immediately
D.Delete all sent items from the user's mailbox
E.Run a full antivirus scan on the user's device
AnswersA, B

Blocking the recipient domain on the email gateway is an appropriate containment action because it immediately halts the active data exfiltration channel by rejecting any further outbound messages destined for that domain. This measure is applied at the transport layer, so it stops the bleeding without deleting any previously sent evidence, and it preserves the ability to later analyze the full extent of the breach while preventing additional data loss.

Why this answer

Blocking the recipient domain on the email gateway (A) is appropriate because it immediately prevents further data exfiltration to that external domain by rejecting all outbound emails to that domain at the transport layer. Placing a legal hold on the user's mailbox (B) preserves all mailbox content, including deleted items, as an immutable copy for forensic investigation and potential legal proceedings, ensuring evidence is not lost during the incident response.

Exam trap

The trap here is that candidates often confuse immediate containment (disabling the account) with proper forensic preservation, forgetting that disabling the account can destroy volatile evidence and alert the adversary, while blocking the recipient domain is a more precise containment action.

252
MCQmedium

Your organization uses Microsoft Defender XDR. A user reports that their device is behaving erratically, with unexpected pop-ups and high CPU usage. You suspect malware infection. You need to collect forensic data from the device for analysis. What should you do?

A.Create a custom detection rule in Microsoft Defender for Endpoint to capture the behavior.
B.Offboard the device and re-onboard it to trigger a fresh investigation.
C.Initiate a live response session on the device from the Microsoft 365 Defender portal.
D.Run a full antivirus scan using Microsoft Defender Antivirus.
AnswerC

Initiating a live response session from the Microsoft 365 Defender portal opens a secure, interactive remote shell to the device, allowing an analyst to execute built-in and custom commands to collect registry keys, running processes, network connections, and specific files into an evidence package. It is the correct choice for immediate forensic triage because it provides direct, time-sensitive access to volatile artifacts without relying on automated detection. The session is fully audited and can be used to run live response scripts or collect suspicious binaries for further analysis.

Why this answer

Initiating a live response session from the Microsoft 365 Defender portal allows you to remotely connect to the device and perform real-time forensic data collection, such as running scripts, capturing memory dumps, and collecting files, without disrupting the device's state. This is the appropriate method for gathering forensic evidence when malware is suspected, as it provides deep, interactive access for analysis.

Exam trap

The trap here is that candidates often confuse remediation actions (like running a scan or re-onboarding) with forensic data collection, failing to recognize that live response is the only option that provides interactive, real-time access for gathering evidence without altering the system state.

How to eliminate wrong answers

Option A is wrong because creating a custom detection rule in Microsoft Defender for Endpoint is used to detect future occurrences of specific behaviors, not to collect forensic data from an already compromised device. Option B is wrong because offboarding and re-onboarding a device does not trigger a fresh investigation; it simply reconnects the device to the service and may destroy existing forensic evidence by resetting the device's state. Option D is wrong because running a full antivirus scan using Microsoft Defender Antivirus is a remediation step that may alter or delete malware artifacts, making forensic analysis impossible, and it does not provide the interactive data collection capabilities needed for in-depth investigation.

253
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. An alert indicates that a user is downloading large amounts of data from SharePoint Online. What should you do first to investigate?

A.Govern the user by suspending their account.
B.Review the user's activity log in Defender for Cloud Apps.
C.Create a new IP address range for the organization.
D.Block the SharePoint Online app for all users in Defender for Cloud Apps.
AnswerB

Reviewing the user's activity log in Defender for Cloud Apps is the foundational step for incident investigation. It provides forensic detail such as exact timestamps, source IP addresses, user agents, and the number of files downloaded, allowing you to compare this behavior against the user's baseline and organizational anomalies. This evidence is required to determine whether the downloads constitute a real exfiltration threat or are an outlier caused by a legitimate business task.

Why this answer

The first step in investigating a potential data exfiltration alert is to review the user's activity log in Defender for Cloud Apps. This log provides granular details about the specific files downloaded, the volume of data, the time frame, and the source IP address, allowing you to validate whether the activity is anomalous or legitimate before taking any restrictive action.

Exam trap

The trap here is that candidates may confuse immediate governance actions (like suspending or blocking) with the proper investigative first step, failing to recognize that Defender for Cloud Apps requires log review to confirm the alert's validity before applying any automated or manual response.

How to eliminate wrong answers

Option A is wrong because suspending the user account is a reactive governance action that should only be taken after confirming malicious intent through investigation; prematurely suspending could disrupt legitimate business operations. Option C is wrong because creating a new IP address range is a configuration for defining trusted locations or policies, not an investigative step to analyze a specific alert. Option D is wrong because blocking SharePoint Online for all users is an overly broad and disruptive action that would halt all SharePoint access across the organization, which is not warranted for a single user alert and bypasses the necessary investigation.

254
MCQeasy

An incident is opened in Microsoft Sentinel for multiple sign-in failures from a single IP address targeting a privileged user account. Which action is most effective in automatically responding to this incident?

A.Create a playbook to block the IP address in the firewall.
B.Enable conditional access policy to require MFA for the user.
C.Create a playbook to automatically disable the user account.
D.Report the IP address to Microsoft for threat intelligence.
AnswerA

Creating a playbook that invokes a firewall API (via Azure Logic Apps) to block the offending IP is a direct containment action. It severs the attacker's communication path to your environment at the network boundary, without affecting the legitimate user's ability to sign in. This is the immediate, low-disruption response that stops the ongoing brute-force attempts from that source.

Why this answer

The most effective automated response is to block the IP address in the firewall via a playbook, as it directly stops the attack source. Disabling the user account is too broad and may affect legitimate access. Enabling MFA does not stop the current attack.

Reporting the IP is not immediate.

255
MCQhard

Your organization uses Microsoft Sentinel and has several analytics rules that generate incidents from various data sources. The SOC team is overwhelmed by the number of incidents. You need to implement a triage system that automatically assigns incidents to different analysts based on the incident's tactics and severity. You also want to send a notification to the assigned analyst via Teams. What should you do?

A.Create multiple automation rules that trigger on incident creation, each with conditions for specific tactics and severity, and then run a playbook that assigns the incident to an analyst and sends a Teams notification.
B.Use a workbook to create a triage dashboard and instruct analysts to manually claim incidents from the dashboard.
C.Modify each analytics rule to include a custom details field that specifies the analyst, and use a playbook to send Teams notification based on that field.
D.Create a single playbook that checks the incident's tactics and severity, assigns it to the appropriate analyst, and sends a Teams notification, then configure that playbook to run automatically on all new incidents.
AnswerA

Automation rules trigger on incident creation and can filter by tactics and severity, then invoke a playbook. The playbook performs the assignment and posts the Teams notification, satisfying both the triage routing and alerting requirements without manual intervention.

Why this answer

Automation rules in Microsoft Sentinel trigger on incident creation and support conditions based on incident properties such as tactics and severity, and they can invoke a playbook. Creating multiple automation rules with tactic/severity conditions that each run an assignment-and-notification playbook delivers the required automatic triage and Teams alerting. This is the native, supported pattern for conditional incident routing.

Exam trap

The trap is choosing a single catch-all playbook or a manual dashboard instead of using automation rules with tactic/severity conditions — the exam tests whether you know automation rules are the conditional trigger layer and playbooks are the action layer.

How to eliminate wrong answers

Option B is wrong because a workbook is a visualization/reporting tool; it cannot automatically assign incidents or send notifications, and manual claiming does not meet the 'automatically assigns' requirement. Option C is wrong because custom details fields are static metadata set by analytics rules and cannot dynamically determine the correct analyst based on tactics/severity at incident time. Option D is wrong because a single playbook triggered on all incidents lacks the conditional routing logic at the automation-rule layer; while a playbook can branch internally, the question's requirement for tactic/severity-based assignment is best met with automation rules that filter and trigger, and a blanket playbook on every incident is less precise and not the recommended design.

256
MCQmedium

A Microsoft Defender XDR incident involves a compromised endpoint. Your containment policy requires isolating the device from the network while still allowing you to run live response commands to collect evidence. You need to choose the appropriate device isolation type in Microsoft Defender for Endpoint. Which isolation type should you select?

A.Selective isolation, which blocks most network traffic but permits the Defender for Endpoint service and live response.
B.Device containment via a firewall rule that blocks the device's IP address at the perimeter.
C.Full isolation, which blocks all network traffic to and from the device.
D.App execution restriction via an indicator that blocks the malicious process hash.
AnswerA

Selective isolation limits outbound and inbound communication to the Defender for Endpoint service channel and permits live response, so you can still run commands to gather forensic artifacts while the attacker is cut off from command-and-control and lateral movement. This matches the requirement to isolate the device yet retain live response capability. You can later release the device from isolation once remediation is verified.

Why this answer

Selective isolation in Microsoft Defender for Endpoint cuts the device off from normal network communication while allowing the Defender for Endpoint service channel and live response. That preserves the analyst's ability to collect evidence through live response commands during containment. Full isolation, perimeter firewall rules, and hash-based indicators either over-restrict, fail to contain roaming devices, or address only a single artifact instead of the host.

Exam trap

The trap here is assuming full isolation is always the safest choice, when it can remove the management path needed for live response evidence collection.

257
MCQhard

Refer to the exhibit. You run this KQL query in Microsoft 365 Defender advanced hunting to investigate an incident involving IP address 203.0.113.1. The query returns results, but you need to also see which devices communicated with this IP. How should you modify the query?

A.Join with IdentityLogonEvents on AccountUpn
B.Join with DeviceNetworkEvents on DeviceId where RemoteIP == "203.0.113.1"
C.Join with DeviceInfo on DeviceId
D.Join with EmailEvents on AlertId
AnswerB

Joining DeviceNetworkEvents on DeviceId and filtering RemoteIP to 203.0.113.1 correlates the existing results with endpoint network telemetry, satisfying the requirement to identify which devices communicated with that IP. DeviceNetworkEvents records inbound and outbound connections per device, so the join surfaces the missing device context.

Why this answer

The goal is to find which devices communicated with the suspicious IP 203.0.113.1. DeviceNetworkEvents is the advanced hunting table that records network connections from devices, including the RemoteIP field. Joining on DeviceId and filtering where RemoteIP equals the target IP directly surfaces the devices that contacted it.

Exam trap

SC-200 often tests whether candidates know which advanced hunting table holds which telemetry type, so the trap is choosing a table that sounds related (like DeviceInfo or IdentityLogonEvents) instead of the one that actually records network connections.

How to eliminate wrong answers

Option A is wrong because IdentityLogonEvents tracks authentication events keyed on AccountUpn, not device-to-IP network communications, so it cannot reveal which devices talked to the IP. Option C is wrong because DeviceInfo only provides device inventory and configuration metadata; it contains no remote IP connection data to correlate. Option D is wrong because EmailEvents deals with email message metadata and AlertId linkage, which is unrelated to identifying devices that communicated with an external IP.

258
Multi-Selecthard

Which TWO playbook actions can be used to automatically contain a compromised user account in Microsoft Entra ID during an incident? (Choose TWO.)

Select 2 answers
A.Reset the user's password.
B.Send a notification email to the user.
C.Disable the user account via Microsoft Graph API.
D.Add the user to a group that has access to critical resources.
E.Revoke all refresh tokens and sessions for the user.
AnswersC, E

Disabling the user account via the Microsoft Graph API (PATCH /users/{id} with accountEnabled set to false) immediately prevents the user from authenticating and blocks new token issuance. This identity-level control stops the attacker from accessing any Microsoft 365 resources and is a strong containment measure. Because it also prevents legitimate use, it is often reserved for confirmed compromises and is followed by investigation and remediation.

Why this answer

Disabling a user account via Microsoft Graph API is a direct containment action that immediately prevents the compromised account from authenticating and accessing resources. This is a standard automated response in Microsoft Sentinel or Microsoft 365 Defender playbooks to stop an active incident.

Exam trap

The trap here is that candidates often confuse 'password reset' (a remediation step) with 'containment,' or they think 'sending a notification' is an automated response, when in fact only actions that immediately block access (disable account, revoke tokens) qualify as containment in Microsoft 365 Defender playbooks.

259
MCQhard

You are a security analyst at Contoso. Microsoft Sentinel is deployed with the Microsoft Defender for Cloud Apps connector. An incident is generated for a high-risk sign-in from a user named JaneDoe@contoso.com. The incident severity is Medium. The incident details show that the sign-in originated from an IP address in a country where Contoso has no business presence, and the user recently changed their password. You suspect account compromise. You need to take immediate action to contain the threat and prevent further unauthorized access. The user is currently active in Microsoft Entra ID. You have the following options: A) Force the user to re-authenticate by revoking their sessions in Microsoft Entra ID. B) Disable the user account in Microsoft Entra ID. C) Block the IP address in Microsoft Defender for Cloud Apps. D) Create a Sentinel automation rule to automatically disable accounts on similar alerts. Which action should you take first to contain the current incident?

A.Force the user to re-authenticate by revoking their sessions.
B.Disable the user account in Microsoft Entra ID.
C.Block the IP address in Microsoft Defender for Cloud Apps.
D.Create a Sentinel automation rule to automatically disable accounts on similar alerts.
AnswerB

Disabling the user account in Microsoft Entra ID is the most effective immediate containment step because it blocks all new token issuance and denies sign-in for every application that trusts Entra ID as the identity provider. This cuts off the attacker's access to Microsoft 365, Azure, and any federated SaaS apps using the account. You should also reset the user's password and revoke tokens after disabling, but the disable itself stops the attack in progress.

Why this answer

Disabling the user account immediately stops any further access using that account, which is the most direct containment action. Option A (Revoke sessions) would end current sessions but the user could still authenticate again if credentials are compromised. Option C (Block IP) is less effective as the attacker may use other IPs.

Option D (Create automation rule) is a long-term solution, not immediate containment.

260
MCQhard

During a ransomware response in Microsoft Defender XDR, you identify that multiple devices are communicating with a known C2 server over port 443. You need to block this communication across all devices immediately. What is the most effective course of action?

A.Add the C2 server domain to the Microsoft Defender for Office 365 Tenant Allow/Block List
B.Create a firewall rule to block outbound traffic to the C2 server IP address
C.Create an indicator of compromise (IoC) in Microsoft Defender for Endpoint with action 'Block'
D.Add the C2 server URL to the custom indicator list in Microsoft Defender for Cloud Apps
AnswerC

A Defender for Endpoint indicator with action 'Block' blocks the malicious IP or domain on all onboarded endpoints immediately through Network Protection, regardless of where the devices connect.

Why this answer

Creating an indicator of compromise in Microsoft Defender for Endpoint with action 'Block' is the most effective immediate action. The indicator is enforced by the Defender for Endpoint sensor and blocks the known C2 IP or domain across all onboarded devices, regardless of network location. Option A applies only to email and collaboration content.

Option B only blocks traffic that passes through the firewall and may miss remote devices or non-firewall paths. Option D applies only to cloud app sessions, not general C2 network traffic.

261
MCQeasy

A security analyst is investigating a phishing incident in Microsoft Defender XDR. The analyst wants to see the full email content and attachments. Where should the analyst look?

A.The incident timeline
B.The action center
C.The email entity page
D.The user entity page
AnswerC

The email entity page in Microsoft Defender XDR aggregates the full message body, headers, attachments and related alerts for a specific email, giving the analyst the complete content needed for phishing triage. It is reached from the incident graph or Explorer, unlike the summary views that only show metadata.

Why this answer

The Email entity page in Microsoft Defender XDR provides detailed information about an email, including content and attachments. Option A is wrong because the incident timeline shows events related to the incident, not full email content. Option B is wrong because the action center is for managing response actions, not viewing email details.

Option D is wrong because the user entity page shows user information, not email content.

262
MCQhard

Your organization uses Microsoft Defender XDR. A security administrator reports that a user's device is showing high severity alerts for 'Tampering with Microsoft Defender Antivirus' but the device is not isolated. You need to ensure that when such alerts occur, the device is automatically isolated in Microsoft Defender for Endpoint. What should you do?

A.Create an automation rule in Microsoft Sentinel
B.Create an endpoint detection and response policy in Microsoft Intune
C.Create a custom detection rule in Microsoft Defender XDR
D.Configure an attack surface reduction rule
AnswerC

Custom detection rules in Microsoft Defender XDR are built with KQL queries over the advanced hunting schema (such as DeviceProcessEvents or DeviceNetworkEvents) and allow you to set automatic response actions directly, including 'Isolate device' as a triggered action. When the query matches a device, the rule natively instructs the Defender for Endpoint sensor to isolate that machine immediately, which is exactly the capability the scenario requires. This is the only option that both detects a suspicious behavior and executes a device-level containment action without relying on external automation.

Why this answer

Microsoft Defender XDR's custom detection rules allow you to create automated actions based on specific alert triggers, such as 'Tampering with Microsoft Defender Antivirus'. By configuring a custom detection rule with an automated response action (e.g., 'Isolate device'), you can ensure the device is automatically isolated in Microsoft Defender for Endpoint when the alert occurs, without requiring manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules in Microsoft Sentinel (which handle incidents) with custom detection rules in Defender XDR (which handle raw alerts and can trigger direct automated actions), leading them to choose Option A despite Sentinel not being the native tool for this specific Defender-for-Endpoint isolation requirement.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel automation rules operate on incidents ingested into Sentinel, not directly on Defender XDR alerts; they would require Sentinel to be connected and the alert to be forwarded, adding latency and complexity. Option B is wrong because endpoint detection and response (EDR) policies in Microsoft Intune are used to configure device compliance and security baselines, not to define automated response actions triggered by specific alerts. Option D is wrong because attack surface reduction (ASR) rules are designed to block malicious behaviors (e.g., script execution), not to trigger automated isolation actions in response to specific high-severity alerts like tampering.

263
MCQeasy

Refer to the exhibit. An analyst runs the command to install the Azure Monitor Agent on a VM. What is the primary purpose of installing this agent in the context of security incident response?

A.To collect security events and performance data for analysis in Microsoft Sentinel.
B.To integrate the VM with Microsoft Defender for Cloud.
C.To scan the VM for vulnerabilities.
D.To enable real-time malware protection on the VM.
AnswerA

The Azure Monitor Agent uses data collection rules to gather Windows or Linux security events and performance counters from the VM, forwarding them to the Log Analytics workspace that Microsoft Sentinel ingests. This supplies the telemetry analysts need during incident response.

Why this answer

The Azure Monitor Agent (AMA) is the modern replacement for the Log Analytics agent (MMA/OMS) and is used to collect security events, Windows Event Logs, Syslog, and performance counters from VMs and forward them to a Log Analytics workspace. In Microsoft Sentinel, that workspace is the data lake that powers analytics rules, hunting queries, and workbooks — so AMA's primary purpose in incident response is feeding telemetry into Sentinel for detection and investigation.

Exam trap

The trap is conflating the telemetry-collection agent with the endpoint-protection agent — candidates pick 'real-time malware protection' or 'vulnerability scanning' because those sound like security agent functions, but AMA only ships logs and metrics.

How to eliminate wrong answers

Option B is wrong because Defender for Cloud integration is achieved through the Defender for Cloud auto-provisioning of the agent, but the agent's purpose is data collection, not 'integration' — and Defender for Cloud is a separate posture/protection service. Option C is wrong because vulnerability scanning is performed by Defender for Servers' integrated Qualys scanner or by Defender Vulnerability Management, not by AMA itself. Option D is wrong because real-time malware protection is provided by Microsoft Defender for Endpoint (MDE), which is a separate agent/onboarding, not AMA.

264
MCQhard

Your organization uses Microsoft Sentinel. You have a requirement to automatically add a tag to incidents that involve a specific user. The tag should be added when the incident is created. What should you configure?

A.Add the user to a watchlist and create a fusion rule.
B.Create an automation rule that triggers on incident creation and runs a playbook with the 'Add tag' action.
C.Modify the analytics rule to include a tag in the incident configuration.
D.Enable entity behavior analytics to automatically tag incidents.
AnswerB

Automation rules in Microsoft Sentinel are the native orchestration mechanism that can trigger on incident creation (or status change) and execute a playbook. A playbook built in Azure Logic Apps can include the 'Add tag' action from the Sentinel connector, which appends the desired tag to the incident. This directly satisfies the requirement by applying the tag automatically, and it is the documented method for enriching incidents with custom labels because analytics rules and watchlists lack this capability.

Why this answer

Automation rules in Microsoft Sentinel can be configured to trigger when an incident is created, and they can run a playbook that includes the 'Add tag' action. This allows you to automatically tag incidents involving a specific user by incorporating logic within the playbook to check for that user's presence in the incident entities.

Exam trap

The trap here is that candidates may confuse the ability to configure tags directly in an analytics rule (which is not supported) with the correct method of using automation rules and playbooks to add tags after incident creation.

How to eliminate wrong answers

Option A is wrong because a watchlist is a data source for matching and enrichment, but a fusion rule is designed to detect multi-stage attacks by correlating alerts, not to add tags to incidents. Option C is wrong because analytics rules can define incident properties like severity or tactics, but they do not support adding tags directly; tags must be added post-creation via automation rules or playbooks. Option D is wrong because entity behavior analytics (UEBA) profiles entity behavior and generates anomalies, but it does not automatically tag incidents; it relies on analytics rules to create incidents from those anomalies.

265
Multi-Selecteasy

Which TWO response actions are available in Microsoft Defender for Endpoint for a compromised device? (Choose two.)

Select 2 answers
A.Disable the user account
B.Run a full antivirus scan
C.Change the Windows Firewall rules
D.Isolate the device from the network
E.Reset the device to factory defaults
AnswersB, D

A full antivirus scan is an available device response action in Microsoft Defender for Endpoint, running alongside quick scan to detect and remediate malware on the compromised endpoint. It supports containment and eradication without isolating the device or requiring manual intervention.

Why this answer

Options B and D are correct because Microsoft Defender for Endpoint includes predefined response actions such as running a full antivirus scan and isolating a device from the network. Option A is incorrect because disabling the user account is an identity mitigation action in Azure AD, not a device response in Defender for Endpoint. Option C is incorrect because changing Windows Firewall rules is not a standard response action in Defender for Endpoint.

Option E is incorrect because resetting a device to factory defaults is not a supported response action.

266
Multi-Selectmedium

An incident in Microsoft Sentinel involves multiple alerts indicating a potential data exfiltration via SharePoint Online. You need to respond and remediate. Which THREE actions should be taken?

Select 3 answers
A.Remove external sharing permissions on SharePoint sites.
B.Block the user account in Microsoft Entra ID.
C.Reset the user's password and enforce MFA.
D.Isolate the user's device using Microsoft Defender for Endpoint.
E.Create a custom detection rule for similar activity.
AnswersA, B, D

In the context of a Sentinel incident, external sharing on SharePoint sites is a common data exfiltration vector when accounts are compromised. Removing external sharing permissions—via the SharePoint admin center or PowerShell cmdlets like Set-SPOTenant -SharingCapability—immediately revokes external users' ability to access shared links, cutting off the attacker's current path to exfiltrate data. This is a direct containment action at the data plane, and it is crucial to perform before or alongside user-level blocking to stop exfiltration that has already been enabled.

Why this answer

Removing external sharing permissions on SharePoint sites (A) prevents further data leaks via sharing. Blocking the user account in Microsoft Entra ID (B) stops further access immediately. Isolating the user's device using Microsoft Defender for Endpoint (D) contains the threat by preventing lateral movement.

Resetting the user's password and enforcing MFA (C) is a good follow-up but less immediate than blocking the account. Creating a custom detection rule (E) is proactive but not a direct response to the current incident.

267
Multi-Selecteasy

Which THREE are valid incident classification categories in Microsoft Sentinel? (Select THREE.)

Select 3 answers
A.False Positive
B.Malicious
C.Informational
D.True Positive
E.Benign Positive
AnswersA, D, E

Microsoft Sentinel permits analysts to classify incidents as False Positive, meaning the alert was triggered but represents no genuine malicious activity. It is one of the platform's built-in classification values used to close incidents and tune analytics rules.

Why this answer

In Microsoft Sentinel, incident classification captures the analyst's triage verdict on an incident, and the three supported values are True Positive, Benign Positive, and False Positive. Option D (True Positive) is correct because it marks an incident confirmed as a genuine security threat requiring action. Option E (Benign Positive) is correct because it marks an incident that triggered legitimately but represents expected or authorized activity rather than an attack.

Option A (False Positive) is correct because it marks an incident caused by inaccurate or misconfigured detection logic that does not reflect real activity. Option B (Malicious) is not a classification value — maliciousness is conveyed through severity and tactics/entities, not the classification field. Option C (Informational) is not a classification value either; it is not one of the three triage verdicts Sentinel exposes for incident classification.

Exam trap

The trap is that candidates might assume only two categories are valid, but in fact, three are recognized: False Positive, True Positive, and Benign Positive. Many confuse Benign Positive with False Positive or Informational, but all three are distinct and valid.

268
MCQeasy

During an incident response, you need to collect forensic data from a compromised Linux server that is not managed by Microsoft Defender for Endpoint. You plan to use a manual collection script. Which tool should you use to securely upload the collected data to Azure for analysis?

A.Azure CLI to upload the data to an Azure Files share.
B.AzCopy to upload the data to Azure Blob Storage.
C.PowerShell to send the data to Log Analytics workspace.
D.The Log Analytics agent to forward the data.
AnswerB

AzCopy transfers data directly into Azure Blob Storage over HTTPS, satisfying the requirement to securely upload forensic artefacts from an unmanaged Linux host. Because the server lacks Microsoft Defender for Endpoint, the built-in live response collection is unavailable, so a manual script paired with AzCopy provides the supported upload path.

Why this answer

AzCopy, is the correct tool because it is designed for efficient, secure data transfer to Azure Blob Storage, supports Linux, and does not require a managed agent. Option A is incorrect because Azure CLI is a management tool, not optimized for large file uploads. Option C is incorrect because PowerShell is not natively installed on Linux typically, and Log Analytics works with structured log data, not arbitrary forensic files.

Option D is incorrect because the Log Analytics agent forwards structured log data, not raw files.

269
MCQhard

You are investigating a lateral movement incident in Microsoft Defender for Endpoint. The timeline shows that a user's credentials were used from a compromised workstation to access a sensitive server. Which action should you take to contain the incident?

A.Disable the sensitive server's network account.
B.Isolate the compromised workstation only.
C.Block all network traffic from the compromised workstation to the server.
D.Reset the compromised user's password and revoke all active sessions.
AnswerD

Resetting the compromised user's password and revoking all active sessions directly invalidates the stolen credentials—making any cached NTLM hashes, Kerberos TGTs, or delegating artifacts unusable for further authentication. Revoking active sessions (e.g., forcing sign-out or invalidating refresh tokens) ensures that any already-established remote sessions are terminated immediately, rather than waiting for ticket expiry. This stops lateral movement regardless of which workstation the attacker is using or which network path they choose, because the root cause—compromised identity—has been remediated.

Why this answer

The incident involves lateral movement using stolen credentials. Resetting the compromised user's password and revoking all active sessions immediately invalidates the credentials the attacker used, preventing further unauthorized access to any resource, including the sensitive server. This directly addresses the root cause (credential theft) rather than just blocking network paths or isolating a single device.

Exam trap

The trap here is that candidates focus on the network path (blocking traffic or isolating the workstation) instead of recognizing that credential theft is the core issue, and only resetting the password and revoking sessions stops the lateral movement at its source.

How to eliminate wrong answers

Option A is wrong because disabling the sensitive server's network account does not address the compromised user credentials; the attacker could still use those credentials to access other resources. Option B is wrong because isolating only the compromised workstation does not prevent the attacker from using the stolen credentials from another device to access the sensitive server. Option C is wrong because blocking network traffic from the compromised workstation to the server is a temporary network-level fix that does not revoke the attacker's access via the stolen credentials, and the attacker could pivot from a different machine.

270
Multi-Selectmedium

Which TWO actions can you perform in Microsoft Defender XDR as part of incident response?

Select 2 answers
A.Create a Microsoft Sentinel workbook
B.Modify a Microsoft Entra ID conditional access policy
C.Run a KQL query in Azure Data Explorer
D.Collect an investigation package from a device
E.Isolate a device from the network
AnswersD, E

Collecting an investigation package from a device is a legitimate Defender for Endpoint response action that bundles the device's relevant forensic artifacts—such as the registry, running processes, network connections, and memory information—into a zip file for offline analysis. It is initiated through the device's action menu, and the package is stored in secure storage for the analyst to download. This action is complementary to isolation and is used to gather evidence without requiring a live remote-command channel to the device.

Why this answer

Option D is correct because Microsoft Defender XDR's device response actions include collecting an investigation package, which gathers forensic artifacts (such as running processes, network connections, and event logs) from an endpoint for offline analysis. Option E is correct because isolating a device from the network is a core Defender XDR live response action that cuts off an endpoint's network connectivity (while optionally allowing Defender communications) to contain a compromised host during incident response. The other options fall outside Defender XDR's native incident response capabilities: Microsoft Sentinel workbooks (A) are authored in Microsoft Sentinel, modifying an Entra ID conditional access policy (B) is done in the Microsoft Entra admin center, and running a KQL query in Azure Data Explorer (C) is an Azure Data Explorer operation, not a Defender XDR response action.

Exam trap

The trap here is that candidates may confuse actions available in Microsoft Defender XDR with those in other Microsoft security services like Microsoft Sentinel or Azure Data Explorer, leading them to select options that are valid in those separate tools but not within Defender XDR's incident response workflow.

271
MCQeasy

Your organization uses Microsoft Sentinel. You receive an incident for a potential malware outbreak. You need to quickly see which entities are involved (e.g., IPs, hosts, accounts). Where should you look?

A.Incident timeline
B.Comments section
C.Entities tab
D.Alerts tab
AnswerC

The Entities tab on the incident page aggregates and displays every entity that Microsoft Sentinel extracted from the alert data, such as user accounts, hostnames, IP addresses, URLs, and file hashes. Each entity is presented with its type, name, and a link to its full investigation details, allowing you to pivot directly to related incidents and actions. This dedicated, structured view is the appropriate place to identify all entities associated with the incident.

Why this answer

The Entities tab in a Microsoft Sentinel incident provides a consolidated view of all related entities such as IP addresses, hosts, user accounts, and other resources that were identified during the alert investigation. This allows you to quickly assess the scope of a potential malware outbreak by seeing which systems and identities are involved, without needing to navigate through raw alerts or timeline events.

Exam trap

The trap here is that candidates often confuse the Alerts tab (which shows raw alert details) with the Entities tab (which provides a consolidated, entity-focused view), leading them to select the Alerts tab when they need to quickly see all involved IPs, hosts, and accounts.

How to eliminate wrong answers

Option A is wrong because the Incident timeline shows the chronological sequence of events and activities related to the incident, but it does not aggregate or display the distinct entities (IPs, hosts, accounts) in a structured list. Option B is wrong because the Comments section is for manual notes and collaboration between analysts, not for automatically surfaced entity data. Option D is wrong because the Alerts tab lists the individual alerts that triggered the incident, but it does not extract or present the entities (such as IPs or hosts) in a unified, entity-centric view.

272
MCQhard

The KQL query above is used in a Microsoft Sentinel analytics rule. What is the purpose of this rule?

A.Detect when a disabled user account attempts to sign in.
B.Identify users who have been disabled due to inactivity.
C.Detect brute force attempts against disabled user accounts.
D.Monitor sign-in attempts from suspicious IP addresses.
AnswerC

This is correct because the query combines two key conditions: an account-level condition (the account is disabled) and an activity-level condition (a high count of sign-in attempts from the same source IP within a window). Repeated, high-frequency authentication attempts against disabled accounts are a hallmark of a brute-force attack, where an adversary tries many passwords against a known username without realizing the account has been deactivated. The query's aggregation by IP address and its threshold on the number of attempts filters out ordinary, low-volume failures and isolates a sustained, suspicious pattern.

Why this answer

The KQL query filters for sign-in events where the user account is disabled (e.g., StatusCode = 50057 or UserAccountControl flags indicate disabled) and then groups by source IP and user to count failed attempts over a short window. When the count exceeds a threshold, it signals a brute force attack targeting disabled accounts, which is a common post-exploitation or reconnaissance technique. Option C is correct because the rule specifically detects repeated authentication failures against disabled accounts, not just any sign-in attempt or inactivity.

Exam trap

The trap here is that candidates may choose Option A because they see 'disabled user account' and assume any sign-in attempt is detected, but the rule requires multiple attempts (brute force pattern), not a single event.

How to eliminate wrong answers

Option A is wrong because the rule does not detect a single sign-in attempt by a disabled user; it requires multiple failed attempts (brute force pattern) and does not trigger on a single event. Option B is wrong because the rule does not identify users disabled due to inactivity; it focuses on authentication attempts against already-disabled accounts, not the reason for disablement. Option D is wrong because the rule does not filter by suspicious IP addresses; it aggregates by source IP but does not use threat intelligence or reputation lists to classify IPs as suspicious.

273
MCQhard

During an incident, you need to prevent a malicious process from running on all endpoints using Microsoft Defender for Endpoint. The process is not yet detected by antivirus signatures. Which action should you use?

A.Run antivirus scan
B.Add an indicator to block the process
C.Collect investigation package
D.Initiate Live Response
AnswerB

Adding an indicator of compromise (IoC) in Microsoft 365 Defender with the action 'Alert and block' or 'Block' immediately prevents the malicious process from running on any onboarded device. This indicator can be a file hash, signing certificate, or other process attribute, and the block is enforced by the Defender for Endpoint sensor in real time. Unlike scanning, this is a proactive, organization-wide prevention control that stops execution before or during launch.

Why this answer

Microsoft Defender for Endpoint allows you to create custom indicators of compromise (IoCs) to block or allow specific processes, files, or behaviors. Since the malicious process is not yet detected by antivirus signatures, adding an indicator to block the process file hash or certificate is the most direct and immediate action to prevent it from running on all endpoints.

Exam trap

The trap here is that candidates often confuse 'collect investigation package' or 'Live Response' as proactive blocking tools, when in fact they are post-incident forensic or single-endpoint actions, not scalable prevention mechanisms.

How to eliminate wrong answers

Option A is wrong because running an antivirus scan will only detect threats that are already in the antivirus signature database; since the process is not yet detected by signatures, a scan will not prevent it from running. Option C is wrong because collecting an investigation package gathers forensic data for analysis but does not actively block or prevent the malicious process from executing. Option D is wrong because initiating Live Response provides a remote shell for manual investigation and remediation on a single endpoint, but it is not designed to apply a block across all endpoints simultaneously.

274
MCQeasy

A SOC analyst receives a Microsoft Defender for Cloud Apps alert about a mass download of files from a SharePoint site by a single user. The analyst needs to contain the incident. Which action should be taken first?

A.Increase the SharePoint download limit.
B.Notify the user's manager.
C.Suspend the user account in Microsoft Entra ID.
D.Run a malware scan on the downloaded files.
AnswerC

Suspending the user account in Microsoft Entra ID is the correct immediate containment action because it revokes the user's ability to sign in and access SharePoint, stopping all further downloads at once. Defender for Cloud Apps can trigger this governance action natively, integrating with Entra ID to disable the account. This aligns with incident response best practices, prioritizing containment of a likely data exfiltration before investigation.

Why this answer

Suspending the user account in Microsoft Entra ID immediately revokes all access tokens and prevents further authentication, stopping the mass download in progress. This is the fastest containment action because it disables the user's ability to access any Microsoft 365 resource, including SharePoint, without waiting for other processes like scanning or notifications.

Exam trap

The trap here is that candidates confuse containment with investigation or remediation, picking a post-incident step like malware scanning instead of the immediate account disablement action that stops the active threat.

How to eliminate wrong answers

Option A is wrong because increasing the SharePoint download limit would allow more data to be exfiltrated, worsening the incident. Option B is wrong because notifying the user's manager is a communication step that does not stop the ongoing data exfiltration. Option D is wrong because running a malware scan on already-downloaded files does not prevent further downloads and is a post-incident forensic step, not a containment action.

275
MCQmedium

You have detected a suspicious PowerShell command running on several workstations. The command appears to be downloading a payload from a known malicious URL. What is the most effective immediate response using Microsoft Defender for Endpoint?

A.Add the URL to the custom threat indicator list in Microsoft Defender for Endpoint.
B.Quarantine the affected workstations.
C.Enable attack surface reduction rule to block PowerShell scripts.
D.Initiate a Live Response session to investigate each workstation.
AnswerA

Adding the URL as a custom threat indicator with the action 'Alert and block' creates an immediate, environment-wide deny for that address. Defender for Endpoint enforces URL/domain indicators through Windows Defender SmartScreen and network protection, so any onboarded endpoint attempting to reach the URL is blocked before the response, not after. This targeted action stops further downloads without broad disruption to legitimate PowerShell or other workloads.

Why this answer

Adding the URL to the custom threat indicator list in Microsoft Defender for Endpoint is the most effective immediate response because it creates a block indicator that applies to all endpoints in the organization. This action prevents any further downloads from that malicious URL across all workstations, stopping the attack in its tracks without disrupting user productivity or requiring manual intervention on each machine.

Exam trap

The trap here is that candidates often choose a reactive, manual investigation step (like Live Response) or a broad configuration change (like ASR rules) instead of recognizing that a custom indicator provides an immediate, automated, and organization-wide block that stops the attack at the network layer.

How to eliminate wrong answers

Option B is wrong because quarantining the affected workstations is a reactive, disruptive measure that removes devices from the network, potentially halting business operations, and does not prevent the same attack from occurring on other workstations that have not yet executed the command. Option C is wrong because enabling an attack surface reduction rule to block PowerShell scripts is a broad, preventative configuration change that would require testing and could break legitimate scripts; it is not an immediate response to an active threat. Option D is wrong because initiating a Live Response session to investigate each workstation is a time-consuming, manual forensic step that does not provide an immediate, organization-wide block of the malicious URL, leaving other workstations vulnerable during the investigation.

276
MCQmedium

Your organization has Microsoft Defender XDR enabled. An incident is generated for a user who clicked a phishing link in an email. The analyst needs to automatically disable the user's mailbox for suspicious activity. Which automated action should the analyst configure in a Microsoft Sentinel automation rule?

A.Run a playbook that deletes the phishing email from the user's inbox.
B.Configure an automation rule to block the sender IP address in Defender for Cloud Apps.
C.Run a playbook that resets the user's password.
D.Run a playbook that uses the Microsoft 365 Defender connector to disable the mailbox.
AnswerD

Running a playbook that uses the Microsoft 365 Defender connector is the correct approach because this connector exposes a 'Disable mailbox' remediation action designed for incident response scenarios. When triggered from a Microsoft Defender XDR incident, the playbook can execute this action directly against the affected user's mailbox in Exchange Online, immediately preventing further access and exfiltration. This precisely satisfies the requirement to disable the mailbox as a containment step.

Why this answer

The goal is to disable the user's mailbox, which is a Microsoft 365 Exchange Online action. A Microsoft Sentinel automation rule can trigger a playbook that uses the Microsoft 365 Defender connector to execute the 'Disable mailbox' action directly against Exchange Online, effectively suspending the user's ability to send or receive email. This aligns with the requirement to automatically respond to a phishing incident by disabling the compromised mailbox.

Exam trap

The trap here is that candidates confuse 'disabling the mailbox' with other remediation actions like password reset or email deletion, failing to recognize that only a playbook with the Microsoft 365 Defender connector can directly execute the mailbox disablement action in Exchange Online.

How to eliminate wrong answers

Option A is wrong because deleting the phishing email from the user's inbox does not disable the mailbox; the user could still access other emails or be compromised further. Option B is wrong because blocking the sender IP address in Defender for Cloud Apps is a network-level action that does not affect the user's mailbox state; it also does not address the compromised user account. Option C is wrong because resetting the user's password does not disable the mailbox; the user could still access email via cached credentials or other means until the password change propagates, and it does not prevent mailbox access if the session token is still valid.

277
MCQmedium

During a ransomware incident, an analyst needs to identify which files were encrypted on an endpoint. The endpoint is running Windows and is managed by Microsoft Defender for Endpoint. Which data source should the analyst query in Advanced hunting?

A.DeviceRegistryEvents
B.DeviceNetworkEvents
C.DeviceProcessEvents
D.DeviceFileEvents
AnswerD

DeviceFileEvents is correct because this table records file system operations such as creation, modification, renaming, and deletion. Ransomware encrypts files by writing encrypted content, often renaming them with new extensions and creating ransom notes, all of which generate file events. Security analysts can query this table for patterns like mass FileModified events from a single process or unusual file extension changes, making it the primary source for directly identifying encryption activity.

Why this answer

DeviceFileEvents is the correct data source because it captures file creation, modification, and deletion events on endpoints. During a ransomware incident, encrypted files are typically created with a new extension or modified in place, and DeviceFileEvents logs these changes, allowing the analyst to identify which files were affected.

Exam trap

The trap here is that candidates may confuse process-level events (DeviceProcessEvents) with file-level events, assuming that seeing the ransomware process run is sufficient to identify encrypted files, but only DeviceFileEvents provides the actual file paths and timestamps of encryption.

How to eliminate wrong answers

Option A is wrong because DeviceRegistryEvents tracks changes to the Windows registry, not file-level encryption events. Option B is wrong because DeviceNetworkEvents logs network connections and traffic, which may indicate C2 communication but does not directly show which files were encrypted. Option C is wrong because DeviceProcessEvents records process creation and termination, which can show ransomware execution but not the specific files that were encrypted.

278
MCQeasy

A security analyst in your SOC is investigating a Microsoft Defender XDR incident. The analyst wants to see a visual representation of the attack timeline and related entities across emails, devices, and identities. Which feature should the analyst use?

A.Microsoft Sentinel incident investigation graph.
B.Advanced hunting in Microsoft Defender XDR.
C.Incident graph in Microsoft Defender XDR.
D.Microsoft Defender for Cloud Apps activity log.
AnswerC

The incident graph in Microsoft Defender XDR provides a visual representation of the attack timeline and relationships between entities such as users, devices, and emails. It helps analysts understand the scope and progression of an attack across multiple workloads. This is the correct feature for the described requirement.

Why this answer

The incident graph in Microsoft Defender XDR is designed to provide a visual, interactive representation of an incident, showing the relationships between entities like users, devices, mailboxes, and the timeline of events. It aggregates alerts from multiple Defender workloads, enabling analysts to quickly understand the attack's scope. Advanced hunting is query-based, Sentinel's graph is separate, and Defender for Cloud Apps activity log is app-focused.

The incident graph directly fulfills the need for a visual attack timeline and entity mapping.

Exam trap

The trap here is confusing the incident graph with advanced hunting or other investigation tools; the incident graph is specifically for visual incident visualization in Defender XDR.

279
MCQmedium

You are a Security Operations Analyst at a company that uses Microsoft Defender XDR. An incident named 'Phishing campaign targeting finance' is assigned to you. The incident contains multiple alerts across Exchange Online and Microsoft Defender for Office 365. You need to perform a manual investigation and then take remediation actions. Which built-in incident management capability in the Microsoft 365 Defender portal allows you to view the attack story, evidence, and response actions for this incident in a single pane?

A.The Microsoft Defender for Cloud Apps portal
B.The incident investigation page in the Microsoft 365 Defender portal
C.The Incidents queue page in the Microsoft 365 Defender portal
D.The Advanced hunting page in the Microsoft 365 Defender portal
AnswerB

The incident investigation page is the unified surface in Microsoft Defender XDR where you review the attack story, alert timeline, impacted entities, and evidence, and from which you can run response actions such as soft-deleting emails or isolating devices. It aggregates signals from Defender for Office 365, Exchange Online Protection, and other workloads, exactly matching the need to investigate and remediate this phishing incident in one place.

Why this answer

The incident investigation page in Microsoft Defender XDR consolidates alerts, entities, evidence, and the attack story for a single incident. It is purpose-built for analysts to move from triage to investigation and then to response, with actions like email soft delete and device isolation available inline. Other pages either list incidents, provide raw query access, or focus on a different workload, so they do not meet the single-pane investigation and remediation requirement.

Exam trap

The trap here is confusing the Incidents queue, which is for triage and assignment, with the incident investigation page, where the attack story and response actions actually live.

280
MCQeasy

A security analyst receives a Microsoft Defender for Cloud Apps alert about a user performing unusual file downloads from SharePoint. The analyst needs to investigate the user's activity in the last 24 hours. Which log source should the analyst query first?

A.Microsoft Entra ID sign-in logs
B.Microsoft Intune device logs
C.Office 365 audit logs
D.Cloud App Security logs in Microsoft Sentinel
AnswerD

Microsoft Defender for Cloud Apps logs in Sentinel, specifically the CloudAppEvents table, provide a centralized, enriched record of user activities across cloud applications, including SharePoint Online file downloads. Each event includes the actor, target file, action, source IP, timestamp, and risk indicators. Because the analyst is investigating a Defender for Cloud Apps alert, these logs allow direct correlation of the file-download activity to the reported incident without relying on separate audit consoles.

Why this answer

D is correct because Cloud App Security logs in Microsoft Sentinel provide the most granular and immediate visibility into user activities within Microsoft Defender for Cloud Apps, including file downloads from SharePoint. These logs capture detailed metadata such as file names, download counts, and user IP addresses, enabling the analyst to quickly identify anomalous behavior without needing to correlate across multiple data sources.

Exam trap

The trap here is that candidates often default to Office 365 audit logs (Option C) because they know SharePoint activity is logged there, but they miss that the alert is specifically from Defender for Cloud Apps, which has its own dedicated logs in Sentinel that are optimized for this investigation.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID sign-in logs only record authentication events (e.g., successful or failed logins) and do not include details about specific file downloads or SharePoint activity. Option B is wrong because Microsoft Intune device logs focus on device management, compliance, and configuration, not on user file operations within cloud applications. Option C is wrong because Office 365 audit logs do contain SharePoint file operations, but they are not the first source to query when the alert originates from Defender for Cloud Apps; Cloud App Security logs in Sentinel provide the same data with additional context and are directly integrated with the alert.

281
MCQmedium

An incident in Microsoft Sentinel involves a phishing campaign that delivered a malicious macro-enabled document. The document was opened by 15 users. Which playbook action should be triggered automatically to contain the threat?

A.Isolate all affected devices from the network
B.Block the sender's IP address on the email gateway
C.Block the file hash using Microsoft Defender for Endpoint
D.Disable the user accounts of those who opened the document
AnswerC

Blocking the file hash with Microsoft Defender for Endpoint is the correct immediate containment because it targets the exact malicious artifact that triggered the incident. Defenders can add the SHA-256 hash as a custom file indicator in the Microsoft 365 Defender portal, which instructs the endpoint sensor to block execution and sometimes prevent the file from being written to disk, across all enrolled devices. This is non-disruptive to user productivity, reversible once the threat is confirmed eliminated, and aligns with the automatic response capabilities in Microsoft Sentinel when connected to a playbook. Because the file is the vector, a file-level block nullifies the attack regardless of how the file arrives in the future.

Why this answer

The automatic playbook action should block the file hash at the endpoint to prevent further execution. Isolating devices may be too aggressive. Blocking sender IP is not effective against phishing.

Disabling user accounts is not direct.

282
MCQeasy

Your organization uses Microsoft Sentinel. You have a playbook that sends an email notification to the SOC team when a new incident is created. The playbook is currently triggered manually. You want the playbook to run automatically every time an incident of severity High is created. What should you do?

A.Edit the analytics rule that generates the incident to include the playbook as an automated response.
B.Create an automation rule that triggers when an incident is created with severity High and runs the playbook.
C.Modify the playbook to add a trigger of 'When an incident is created' and set the severity condition.
D.Configure the playbook's Logic Apps designer to use an HTTP trigger that polls Sentinel for new incidents.
AnswerB

Creating an automation rule that triggers when an incident is created with severity High and runs the playbook is correct because automation rules are Microsoft Sentinel's native, event-driven mechanism for incident lifecycle automation. The rule evaluates the incident immediately on creation, checks the severity condition, and executes the playbook via the Actions pane, passing the complete incident context. This approach is consistent, auditable, and ensures that every High-severity incident triggers the playbook without relying on alert-level logic or custom polling.

Why this answer

Automation rules in Sentinel can automatically trigger playbooks based on incident conditions. Option A is correct. Option B is wrong because automation rules are created in the Automation blade.

Option C is wrong because the analytics rule does not directly run playbooks. Option D is wrong because the playbook trigger is not configured in Logic Apps designer.

283
MCQeasy

Your organization uses Microsoft Sentinel. A security analyst receives an alert for a suspicious sign-in from an unfamiliar IP address. The analyst wants to quickly check if the same IP address has been associated with any other alerts in the past 30 days. Which action should the analyst take?

A.Create an automation rule to block the IP address.
B.Submit the IP address to Microsoft for threat intelligence.
C.Create a new analytics rule to detect the IP address.
D.Run a KQL query in the Logs blade to search the Alert table for the IP.
AnswerD

In Microsoft Sentinel, running a KQL query in the Logs blade against the Alert table is the correct way to search for all alerts involving a specific IP address. For example, you can execute a query like `Alert | where TimeGenerated > ago(30d) | where Entities contains "10.0.0.5"` to return every alert where that IP appears in the entity list, enabling a thorough historical investigation. The Alert table stores all alerts generated by analytics rules and data connectors, making it the authoritative source for answering whether an IP is associated with prior alerts. This read-only query provides immediate, actionable evidence without altering detection or response configurations.

Why this answer

The Alert table in Microsoft Sentinel logs contains historical alert data, including IP addresses associated with each alert. Running a KQL query against this table allows the analyst to quickly search for the same IP address across all alerts generated in the past 30 days, enabling efficient incident correlation without modifying detection or response configurations.

Exam trap

The trap here is that candidates may confuse proactive threat hunting actions (like creating rules or submitting to threat intelligence) with the simple investigative task of querying existing log data, leading them to select options that modify the environment rather than just query it.

How to eliminate wrong answers

Option A is wrong because creating an automation rule to block the IP address is a reactive response that does not help the analyst check historical associations; it would only apply to future alerts. Option B is wrong because submitting the IP address to Microsoft for threat intelligence is for enrichment or reputation checking, not for querying existing alert history within the Sentinel workspace. Option C is wrong because creating a new analytics rule to detect the IP address would generate future alerts but does not allow the analyst to search past alerts for the same IP.

284
Multi-Selecthard

Which TWO of the following are valid methods to retrieve data from Microsoft Sentinel for external analysis during an incident?

Select 2 answers
A.Use Microsoft Sentinel PowerShell cmdlets.
B.Create a Power BI dashboard.
C.Use the Export to CSV feature in the Logs blade.
D.Connect Log Analytics workspace to external tools via API.
E.Use the Microsoft Sentinel API to query incidents and alerts.
AnswersD, E

Connecting the Log Analytics workspace to external tools via the Log Analytics Query API is a valid data-retrieval method because it allows external applications, such as custom scripts or third-party SIEM/BI solutions, to send KQL queries over HTTPS and receive the query results in JSON format. The API supports large result sets with batching/pagination, making it suitable for pulling data out of Sentinel's underlying workspace for analysis or integration. This is one of the canonical approaches to retrieving Microsoft Sentinel data externally.

Why this answer

The Log Analytics workspace that underpins Microsoft Sentinel exposes a REST API, allowing external tools to query and export data programmatically for analysis. This API supports OAuth 2.0 authentication and can retrieve log data via KQL queries, making it a valid method for external integration during incident response.

Exam trap

The trap here is that candidates confuse the Log Analytics API (Option D) with the Microsoft Sentinel API (Option E) as separate valid methods, while dismissing the Export to CSV feature (Option C) as a valid retrieval method despite it being a manual export rather than an automated external analysis pipeline.

285
Multi-Selecteasy

Your organization uses Microsoft Defender for Cloud. You need to remediate a security recommendation that indicates a virtual machine is missing critical security updates. Which TWO actions should you take to remediate this recommendation?

Select 2 answers
A.Add a network security group to block inbound traffic to the VM.
B.Connect to the VM and install the missing updates.
C.Create an exemption for the recommendation in Defender for Cloud.
D.Configure the VM to automatically install updates from Windows Update.
E.Restart the VM to trigger update installation.
AnswersB, D

Connecting to the VM and installing the missing updates directly resolves the configuration issue identified by Microsoft Defender for Cloud. This action applies the required patches, bringing the system into compliance with the security baseline and eliminating the known vulnerabilities. It is the immediate and definitive remediation for a recommendation that reports missing updates.

Why this answer

Installing the missing updates directly on the VM resolves the underlying vulnerability that Defender for Cloud identified. Option D is correct because configuring automatic updates ensures the VM receives future critical security patches without manual intervention, which proactively remediates the recommendation over time.

Exam trap

The trap here is that candidates often confuse 'remediate' with 'suppress' or 'mitigate'—they may choose to create an exemption (Option C) or block traffic (Option A) thinking it resolves the recommendation, but only installing updates or enabling automatic updates actually addresses the root cause.

286
MCQeasy

You are investigating a phishing incident in Microsoft Defender XDR. The user reported receiving an email with a malicious link. You need to identify all users who received the same email. Which feature should you use?

A.Automation & investigations
B.Incidents view
C.Threat Explorer
D.Advanced Hunting
AnswerC

Threat Explorer is the dedicated email-trace and forensics tool in Microsoft 365 Defender, purpose-built for investigating malicious mail across Exchange Online and Microsoft Defender for Office 365. It supports near real-time searches and filters by sender, recipient, subject, message ID, detection technology, delivery status, and header data, and it can even display email headers for detailed verification. Because it lets analysts immediately pivot from search results to remediation actions such as soft-deleting from mailboxes, it is the correct surfacing feature for phishing email investigation.

Why this answer

Threat Explorer (part of Microsoft Defender for Office 365 / Defender XDR) is purpose-built for email and collaboration threat investigation. It lets you pivot on a malicious URL, sender, or message and see every recipient who received the same email, along with delivery status and remediation actions. This is the correct tool for identifying the blast radius of a phishing campaign.

Exam trap

SC-200 often tests the distinction between investigation tools — candidates confuse Advanced Hunting (raw KQL queries) with Threat Explorer (purpose-built email investigation UI), even though both can technically surface email data.

How to eliminate wrong answers

Option A is wrong because Automation & investigations (AIR) is used to automate response playbooks and remediate incidents, not to enumerate all recipients of a specific email. Option B is wrong because the Incidents view aggregates correlated alerts into incident records but does not provide email-level recipient enumeration. Option D is wrong because Advanced Hunting (KQL) can query EmailEvents, but it is a raw query tool rather than the purpose-built feature for identifying all recipients of a specific email during phishing triage.

287
MCQhard

Your organization uses Microsoft Sentinel. You have a scheduled analytics rule that queries Windows Security Events to detect local admin group modifications. The rule runs every hour and looks back 1 hour. However, you are missing events that occur within the first few minutes of the hour. What is the most likely cause?

A.The event time is in local time, and the query uses UTC, causing events near the boundary to be excluded.
B.The query period is too short; it should be 2 hours.
C.The rule is using 'Last activity' instead of 'TimeGenerated'.
D.There is a 5-minute ingestion delay for Windows events.
AnswerA

Sentinel stores and queries timestamps in UTC, while Windows event logs record event time in the machine's local time zone. When an analytics rule uses a local-time field (such as EventTime or TimeCreated) for the where clause, events occurring in the last few minutes of the lookback window can be shifted outside the UTC-based query boundary, so the rule misses them even though they occurred within the intended hour. The fix is to convert time fields to UTC (e.g., using `datetime_utc()` or comparing against UTC datetime literals) or rely on `TimeGenerated`, which is always UTC.

Why this answer

The scheduled analytics rule uses a lookback period of 1 hour, but if the event time is stored in local time while the query uses UTC, events near the hour boundary can be excluded due to time zone offset. Microsoft Sentinel stores events in UTC by default, and the query's time filter (e.g., 'TimeGenerated > ago(1h)') compares against UTC timestamps. If the Windows Security Events are logged in local time and not converted, events occurring just after the hour in local time may fall outside the UTC lookback window, causing them to be missed.

Exam trap

The trap here is that candidates often assume ingestion delay or query period length is the cause, but the real issue is time zone mismatch between event timestamps and the query's UTC-based lookback window.

How to eliminate wrong answers

Option B is wrong because increasing the query period to 2 hours would not fix the root cause of time zone mismatch; it would only shift the boundary issue, not resolve it. Option C is wrong because 'Last activity' is not a valid time field in Windows Security Events; the correct field is 'TimeGenerated', and using 'Last activity' would cause different filtering behavior, not specifically the boundary issue described. Option D is wrong because a 5-minute ingestion delay would cause events to appear later, but the rule runs every hour with a 1-hour lookback, so a 5-minute delay would still capture events within the lookback window; the issue is specifically about events at the start of the hour being excluded due to time zone differences.

288
MCQeasy

Your organization uses Microsoft Defender for Cloud. You receive a security alert about a suspicious process on a virtual machine. You want to investigate the process further. What should you do?

A.Create a custom detection rule to alert on similar processes.
B.Run a vulnerability assessment scan on the VM.
C.Initiate a live response session on the VM from Microsoft Defender for Cloud.
D.Initiate an automated investigation on the VM.
AnswerC

Initiating a live response session from Microsoft Defender for Cloud provides a remote interactive shell to the VM, allowing you to run commands, inspect running processes, collect forensic artifacts, and terminate suspicious processes in real time. Live response is specifically designed for ad-hoc investigations where you need immediate, hands-on visibility. This is the appropriate action when you have identified a specific process and need to examine it directly.

Why this answer

Microsoft Defender for Cloud's live response capability allows you to remotely connect to a VM and perform real-time forensic actions, such as running commands, examining running processes, and collecting artifacts. This is the most direct way to investigate a suspicious process on a specific VM, as it provides interactive access without needing to install additional agents or reboot the machine.

Exam trap

The trap here is that candidates often confuse automated investigation (which runs a predefined playbook) with live response (which provides manual, interactive access), leading them to select option D because they think automation is the default way to respond to alerts.

How to eliminate wrong answers

Option A is wrong because creating a custom detection rule is a proactive measure to detect future similar processes, not a method to investigate an already triggered alert on a specific VM. Option B is wrong because a vulnerability assessment scan identifies missing patches or misconfigurations, not the behavior or details of a currently running suspicious process. Option D is wrong because initiating an automated investigation triggers a predefined playbook that may automatically remediate or gather data, but it does not provide the interactive, real-time forensic access needed to manually examine the specific process in depth.

289
Multi-Selecthard

Which THREE of the following are key steps when containing a ransomware incident in Microsoft Defender XDR? (Select THREE.)

Select 3 answers
A.Restore encrypted files from backup
B.Block known malicious file hashes via Indicators of compromise
C.Disable compromised user accounts in Microsoft Entra ID
D.Analyze the root cause of the outbreak
E.Isolate compromised devices using Microsoft Defender for Endpoint
AnswersB, C, E

Blocking known malicious file hashes through indicators of compromise directly satisfies the containment requirement by preventing execution of identified ransomware binaries across endpoints. Custom file-hash indicators in Microsoft Defender XDR enforce immediate prevention, halting lateral spread while investigation continues, and this deterministic, signature-based control is a recognised containment step.

Why this answer

Blocking malicious file hashes via indicators of compromise (B), disabling compromised user accounts (C), and isolating compromised devices (E) are key steps in containing a ransomware incident. Restoring from backup (A) is part of recovery, and analyzing root cause (D) is part of investigation, both of which occur after containment.

290
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You receive an alert about an impossible travel activity for a user. What is the best first step to validate if this is a true positive?

A.Block the user immediately
B.Run an advanced hunting query in Microsoft Sentinel
C.Contact the user's manager
D.Review the user's sign-in logs in Microsoft Entra ID
E.Check the user's device compliance in Microsoft Intune
AnswerD

Reviewing the user's sign-in logs in Microsoft Entra ID is the correct first step because these logs contain the authenticated IP address, exact timestamp, and geolocation data needed to corroborate the anomalous travel activity. This source of truth allows you to verify whether the second sign-in actually occurred from the reported location and whether it was a legitimate authentication. It provides the required evidence to decide whether further action is warranted.

Why this answer

Impossible travel alerts in Microsoft Defender for Cloud Apps are generated based on sign-in activity and user location data. The most direct way to validate whether the alert is a true positive is to review the user's sign-in logs in Microsoft Entra ID (formerly Azure AD), which provides detailed information about each sign-in attempt, including IP addresses, locations, timestamps, and authentication details. This allows you to confirm whether the two sign-ins occurred within an unrealistic time frame for the geographic distance, or if there are anomalies such as VPN usage or IP spoofing that indicate a false positive.

Exam trap

The trap here is that candidates often jump to advanced hunting in Sentinel (Option B) as the first step, forgetting that the alert originates from Defender for Cloud Apps and the most immediate and authoritative source for sign-in details is the Entra ID sign-in logs, which are the same data that Defender for Cloud Apps uses to generate the alert.

How to eliminate wrong answers

Option A is wrong because immediately blocking the user without investigation could disrupt legitimate access and does not validate the alert; it is a reactive action, not a validation step. Option B is wrong because running an advanced hunting query in Microsoft Sentinel is a deeper investigation step that may be appropriate after initial validation, but it is not the best first step when the alert originates from Defender for Cloud Apps and the sign-in logs in Entra ID are the primary source for immediate verification. Option C is wrong because contacting the user's manager is a secondary step that relies on human confirmation and does not provide technical evidence; it should be done after reviewing logs to gather context.

Option E is wrong because checking the user's device compliance in Microsoft Intune addresses device health and policy compliance, which is unrelated to verifying the geographic plausibility of sign-in events in an impossible travel scenario.

291
Multi-Selecteasy

Which TWO are valid incident management actions in Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Merge two incidents into one
B.Export the incident to a CSV file
C.Change the incident status to 'Closed'
D.Delete an incident
E.Assign the incident to another analyst
AnswersC, E

Changing an incident's status to 'Closed' is a valid and common incident-management action in Microsoft Sentinel. The status lifecycle includes New, In Progress, and Closed, and closing an incident indicates that it has been resolved and requires no further action. When closing, you must choose a classification (such as True Positive or False Positive) and optionally a reason, which helps preserve metadata for reporting and auditing purposes.

Why this answer

Changing an incident's status to 'Closed' is a standard incident management action in Microsoft Sentinel. This action finalizes the incident after investigation and remediation, and it is a core part of the incident lifecycle within the Sentinel workspace.

Exam trap

The trap here is that candidates may confuse incident management actions in Microsoft Sentinel with those in other SIEMs (like Splunk or QRadar) where merging or deleting incidents is common, leading them to select options A or D incorrectly.

292
Multi-Selecteasy

Your organization uses Microsoft 365 Defender. During an incident, which TWO actions can be taken directly from the Microsoft 365 Defender portal to remediate a compromised email account?

Select 2 answers
A.Remove mailbox delegation permissions.
B.Block the sender's email address in the tenant's allow/block list.
C.Soft delete malicious emails from the user's mailbox.
D.Reset the user's password and revoke sessions.
E.Isolate the user's mailbox from receiving emails.
AnswersC, D

Soft delete moves the malicious messages to the Recoverable Items folder, removing them from the user's inbox while retaining them for investigation or restore. This satisfies remediation directly from the Microsoft 365 Defender portal without permanent data loss.

Why this answer

Option C is correct because the Microsoft 365 Defender portal (via the Email & collaboration > Explorer/Threat Explorer remediation actions) lets responders soft delete malicious emails from a user's mailbox, moving them to the Recoverable Items folder so they can be purged or restored. Option D is correct because the portal's action center and user investigation page provide 'Reset password' and 'Revoke sessions' actions, which force a password change and invalidate existing authentication tokens to cut off an attacker's access. Option A is not a direct remediation action offered in the Defender portal for a compromised account, and mailbox delegation is managed through Exchange admin center/PowerShell.

Option B is a preventive tenant-level allow/block list change, not an account remediation action, and it targets a sender address rather than the compromised mailbox. Option E is not a supported action; mail flow cannot be selectively 'isolated' for a mailbox from the Defender portal.

Exam trap

The trap is selecting plausible-sounding but non-native actions (blocking sender, isolating mailbox) instead of the two remediation actions actually exposed in the M365 Defender portal for a compromised account.

293
MCQmedium

You are a Security Operations Analyst using Microsoft Defender XDR. An incident named 'Phishing campaign targeting finance' has been automatically created from multiple alerts. The incident contains evidence for several users and mailboxes. You need to determine which users were affected by the campaign and the timeline of their interactions with the malicious emails. Which feature should you use?

A.The Microsoft Defender for Office 365 Explorer
B.Advanced hunting with a custom KQL query
C.The incident's Attack story timeline
D.The Microsoft 365 Defender portal's Incidents queue
AnswerC

The Attack story timeline in Microsoft Defender XDR provides a chronological view of alerts, events, and entities associated with an incident, allowing you to see which users interacted with the phishing emails and when. It aggregates evidence across workloads, helping you quickly assess the scope and sequence of the attack without manually correlating alerts.

Why this answer

The Attack story timeline within a Microsoft Defender XDR incident aggregates alerts, events, and entities into a chronological narrative. This directly shows which users were involved in the phishing campaign and the sequence of their actions, such as clicking links or opening attachments, enabling rapid scoping and response.

Exam trap

The trap here is confusing the Incidents queue summary with the detailed attack story timeline that provides the chronological user interaction view.

294
MCQeasy

Refer to the exhibit. The KQL query runs in Microsoft Sentinel and returns no results. The analyst expects to see failed logon attempts. What is the most likely reason?

A.The Application filter is incorrect.
B.The ResultType field does not exist in IdentityLogonEvents.
C.The summarize operator is misused.
D.The TimeRange variable is too short.
AnswerB

The `IdentityLogonEvents` table, which aggregates logon activities primarily from Microsoft Entra ID, does not utilise a field named `ResultType` for indicating logon outcomes. Instead, this table typically uses `LogonResult` (e.g., "Success", "Failed") or `ActionType` to categorise events. Consequently, filtering on a non-existent `ResultType` field will cause the KQL query to return no results, even if numerous failed logon attempts are present within the `IdentityLogonEvents` data.

Why this answer

The query filters on ResultType == 'Failed', but the field is likely named 'Result' or uses different values like 'Failure'. Also, the table 'IdentityLogonEvents' may not exist; it might be 'AADSignInEventsBeta' or similar. But the most common issue is incorrect field name for result type.

295
MCQeasy

The exhibit shows the output of a Microsoft Defender for Endpoint API call to get machine information. What does the isolationStatus value indicate?

A.The device is healthy and has no issues.
B.The device is currently being scanned for malware.
C.The device is not isolated and is fully connected.
D.The device has been isolated from the network.
AnswerD

The device has been isolated from the network. This correctly interprets the 'IsolationStatus' value of 'Isolated'. Isolation is a containment action that severs the device's network connectivity to prevent an active threat from communicating with command-and-control servers or moving laterally to other hosts. The only traffic usually allowed while isolated is limited communication with the Defender for Endpoint service, allowing admins to monitor or reverse the isolation if needed.

Why this answer

The isolationStatus value in Microsoft Defender for Endpoint indicates whether a device has been isolated from the network. When the value is 'Isolated', it means the device is blocked from communicating with other devices or the internet, typically as a response to a security incident. Option D is correct because this status directly reflects that the device is isolated from the network.

Exam trap

The trap here is that candidates confuse isolationStatus with device health or scanning status, assuming 'isolated' means the device is being scanned or is in a healthy state, rather than recognizing it as a specific network containment state.

How to eliminate wrong answers

Option A is wrong because isolationStatus does not indicate device health; it specifically refers to network isolation state, not overall health or malware presence. Option B is wrong because isolationStatus has no relation to scanning activities; scanning is tracked via separate API fields like scanStatus or threatStatus. Option C is wrong because a 'not isolated' status would be represented by a value like 'Pending' or 'Released', not by the isolationStatus indicating isolation; the option describes a fully connected state, which is the opposite of what the isolated value means.

296
MCQhard

During a security incident, you need to block a malicious IP address at the network level for all Azure resources in a subscription. You have Azure Firewall deployed. What is the MOST efficient method to implement the block?

A.Block the IP using Microsoft Defender for Cloud's adaptive network hardening.
B.Use Azure Firewall Manager to create a global deny rule for the IP address across all firewalls.
C.Create a network security group (NSG) rule on each virtual network subnet to deny the IP.
D.Add a rule to the Azure Firewall policy to deny outbound traffic to the IP address.
AnswerB

Azure Firewall Manager centrally orchestrates firewall policies and applies them consistently across multiple Azure Firewall deployments, including hub and spoke architectures. By creating a Network rule (or Application rule) with a Deny action for the malicious IP address and assigning that policy to all firewalls managed under Firewall Manager, you enforce the block at the perimeter immediately and globally. This approach is the most efficient because a single policy change propagates everywhere, eliminating the need to touch each firewall individually.

Why this answer

Azure Firewall Manager provides centralized management of Azure Firewall policies across multiple firewalls, allowing you to create a global deny rule that applies to all firewalls in a subscription. This is the most efficient method because it avoids configuring individual firewalls or NSGs, and it ensures consistent enforcement at the network level for all Azure resources.

Exam trap

The trap here is that candidates often confuse Azure Firewall Manager with individual firewall rule management, assuming that adding a rule directly to a firewall policy (Option D) is sufficient, but they overlook the need for a centralized, global block that applies to all firewalls and both traffic directions.

How to eliminate wrong answers

Option A is wrong because adaptive network hardening in Microsoft Defender for Cloud is a recommendation engine that suggests NSG rules based on traffic patterns, not a mechanism to manually block a specific IP address during an active incident. Option C is wrong because creating NSG rules on each subnet is inefficient and error-prone, especially in large environments with many subnets, and NSGs do not apply to traffic that bypasses subnets (e.g., Azure Firewall itself). Option D is wrong because adding a rule to the Azure Firewall policy to deny outbound traffic only blocks outbound traffic to the IP, but the question requires blocking the IP at the network level for all traffic (both inbound and outbound); a global deny rule in Firewall Manager covers both directions.

297
MCQmedium

Your security team is investigating a suspicious sign-in from an unfamiliar IP address. The user has Microsoft Entra ID P2 licenses and is assigned a Conditional Access policy that requires MFA for all cloud apps. During the incident response, you find that the sign-in succeeded despite the user not completing MFA. Which action should you take first to investigate the discrepancy?

A.Review the user risk detection in Microsoft Entra ID Protection
B.Check the Microsoft Entra audit logs for policy changes
C.Use the Conditional Access What If tool
D.Review the Microsoft Entra sign-in logs for the specific sign-in event
AnswerD

The Microsoft Entra sign-in logs record which Conditional Access policies applied, whether MFA was satisfied, and the authentication method used, directly explaining why MFA was bypassed. Reviewing this event first satisfies the need to investigate the discrepancy before changing policy or revoking sessions.

Why this answer

Reviewing the Microsoft Entra sign-in logs for the specific sign-in event is the first step because it provides detailed information about the sign-in, including whether MFA was required, satisfied, or bypassed. This log will show the conditional access policy evaluation and any anomalies, helping to identify why MFA was not enforced.

Exam trap

SC-200 often tests the misconception that audit logs or risk detections are the first place to look, but the sign-in log provides the most direct evidence of why MFA was not enforced.

How to eliminate wrong answers

Option A is wrong because user risk detection in Entra ID Protection indicates the risk level of the user but does not explain why MFA was not enforced for this specific sign-in. Option B is wrong because audit logs for policy changes would show if the Conditional Access policy was modified, but that is a secondary check after reviewing the sign-in log. Option C is wrong because the What If tool simulates policy evaluation for hypothetical scenarios, not for a past event.

298
MCQmedium

Your organization uses Microsoft Defender XDR. You receive an automated investigation that found a malicious file on a device. The investigation recommends 'Block the file'. What does this action do?

A.Adds the file hash to the block list in Microsoft Defender for Endpoint.
B.Isolates the device where the file was found.
C.Initiates a full antivirus scan on all devices.
D.Deletes the file from all devices in the organization.
AnswerA

The 'Block file' action in Microsoft Defender for Endpoint (MDE) adds the file's SHA-256 hash to the organization's custom threat intelligence indicators, which are enforced by the MDE cloud block list. This preventive control immediately prevents the file from executing on any device onboarded to MDE, including future instances of the same hash. It is a tenant-wide action and does not require the original device to remain connected, as the block is propagated through the cloud.

Why this answer

In Microsoft Defender XDR, when an automated investigation finds a malicious file and recommends 'Block the file', the action adds the file's hash to the block list in Microsoft Defender for Endpoint. This prevents the file from executing on any device in the organization by leveraging the indicator of compromise (IoC) system. It does not isolate devices, initiate scans, or delete files; it simply blocks future execution based on the hash.

Exam trap

SC-200 often tests the distinction between different response actions in Defender XDR, such as blocking a file versus isolating a device or running a scan. Candidates may confuse 'Block the file' with deleting the file or isolating the device, but blocking specifically adds the hash to the block list to prevent execution.

How to eliminate wrong answers

Option B is wrong because isolating a device is a separate response action that restricts network communication, not blocking a file. Option C is wrong because initiating a full antivirus scan is a different remediation step that scans for threats, not blocks a specific file. Option D is wrong because deleting the file from all devices is not what 'Block the file' does; blocking prevents execution but does not remove the file from disk.

299
MCQhard

You are investigating a compromised user account in Microsoft Sentinel. You have identified that the attacker used the account to send phishing emails internally. You need to contain the threat by disabling the account and revoking all active sessions. Which Microsoft Sentinel feature should you use to perform these actions directly from the incident?

A.Automation rule
B.Entity action
C.Workbook
D.Hunting query
AnswerB

In Microsoft Sentinel, when you select a user entity in an incident, you can perform entity actions such as 'Disable user' and 'Revoke sessions' directly from the investigation graph or entity pane. These actions integrate with Microsoft Entra ID to immediately contain the threat. This is the fastest way to respond without leaving Sentinel.

Why this answer

Microsoft Sentinel's entity actions allow analysts to take direct containment steps on entities like users, devices, and IP addresses. For a user entity, actions include disabling the account in Microsoft Entra ID and revoking all active sessions. These actions are available from the incident investigation graph or entity pane, enabling rapid response without switching to the Entra portal.

Exam trap

The trap here is confusing automation rules or playbooks with direct entity actions; automation rules automate responses but do not provide manual containment buttons.

300
MCQmedium

Refer to the exhibit. An automation rule is configured as shown. When will the playbook be triggered?

A.When any incident is created from Microsoft Defender for Endpoint
B.When a new incident with any severity contains 'Malware' in the title
C.When an incident is updated to High severity
D.When a new incident is created with severity High, from Microsoft Defender for Endpoint, and with 'Malware' in the title
AnswerD

The rule's conditions combine incident creation, High severity, Microsoft Defender for Endpoint as the detection source, and 'Malware' in the title. All must match simultaneously, so the playbook fires only when every condition is satisfied on a newly created incident.

Why this answer

In Microsoft Sentinel automation rules, all configured conditions are evaluated with AND logic — every condition must be true for the rule to fire. The exhibit shows three conditions: incident severity = High, the incident must be created (not updated), and the title must contain 'Malware'. Additionally, the rule is scoped to incidents originating from Microsoft Defender for Endpoint.

Therefore, the playbook triggers only when a new incident is created that is High severity, sourced from Defender for Endpoint, and has 'Malware' in the title.

Exam trap

SC-200 often tests the assumption that automation rules use OR logic or that any single condition can trigger the playbook, when in fact all conditions are combined with AND.

How to eliminate wrong answers

Option A is wrong because it ignores the severity and title conditions — the rule requires High severity and 'Malware' in the title, not just any incident from Defender for Endpoint. Option B is wrong because it ignores the severity and source conditions — the rule requires High severity and Defender for Endpoint as the source, not just any severity with 'Malware' in the title. Option C is wrong because it describes an update trigger, but the rule is configured for incident creation, not updates, and it also ignores the source and title conditions.

← PreviousPage 4 of 5 · 375 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Respond to security incidents questions.