Courseiva

CCNA Respond to security incidents Questions

75 of 375 questions · Page 5/5 · Respond to security incidents · Answers revealed

301
MCQhard

A user reports that they cannot access their Microsoft 365 apps after clicking a link in an email. You suspect token theft. In Microsoft Defender XDR, which incident investigation action should you take first to verify the scope?

A.Review the user's sign-in logs in Microsoft Entra ID for anomalous locations
B.Isolate the user's device from the network
C.Check the user's device for malware using Microsoft Defender for Endpoint
D.Investigate the email in Microsoft Defender for Office 365
AnswerA

Sign-in logs in Microsoft Entra ID reveal the authentication events tied to the suspected token theft, showing anomalous locations, IP addresses and session details. Reviewing them first establishes which accounts and sessions are affected, defining the incident scope before deeper investigation.

Why this answer

When token theft is suspected, the first investigative step is to determine scope by reviewing the user's sign-in logs in Microsoft Entra ID for anomalous locations, IPs, or impossible-travel patterns. This confirms whether the token was used from an unexpected location and helps identify other affected accounts before taking containment actions. Verifying scope precedes remediation.

Exam trap

SC-200 often tests the order of operations in incident response, and candidates who jump to containment (isolate device) before scoping (review sign-in logs) fall into the trap of acting before understanding the incident's breadth.

How to eliminate wrong answers

Option B is wrong because isolating the device is a containment action that should follow scope verification—if the token was stolen and used elsewhere, isolating the user's device may not address the attacker's access. Option C is wrong because checking for malware is a device-focused investigation that may be relevant but does not first establish the scope of the token theft across identities. Option D is wrong because investigating the email in Defender for Office 365 examines the delivery vector, not the scope of the compromised token or affected accounts.

302
MCQeasy

Your security team uses Microsoft Sentinel analytics rules to detect brute-force attacks. A rule triggers when more than 10 failed logins occur within 5 minutes from a single IP. An incident is generated. Which first step should the analyst take?

A.Block the source IP address on the firewall
B.Investigate the incident details
C.Notify the users of the failed login attempts
D.Reset passwords for all affected accounts
AnswerB

Investigating the incident details is the correct first step because it provides the necessary context to determine the scope and severity of the threat. In Microsoft Sentinel, you open the incident to review the full timeline, related alerts, entities (accounts, hosts, IPs), and raw evidence gathered by the analytics rule. This investigation enables triage—confirming whether the failed logins indicate a brute-force attack, a password spray, or a false positive—and guides all subsequent containment and remediation decisions with data rather than assumptions.

Why this answer

The first step in incident response within Microsoft Sentinel is to investigate the incident details to validate the alert and understand the scope. This aligns with the NIST incident response lifecycle (identification and analysis) and Sentinel's built-in investigation graph, which allows analysts to correlate entities, timelines, and related events before taking any containment action.

Exam trap

The trap here is that candidates often jump to a reactive containment action (blocking the IP) without first validating the alert, confusing incident triage with incident response escalation.

How to eliminate wrong answers

Option A is wrong because blocking the source IP on the firewall without investigation could disrupt legitimate users (e.g., shared NAT IPs) and violates the 'verify before act' principle; Sentinel does not automatically validate false positives. Option C is wrong because notifying users of failed login attempts is premature and could cause unnecessary alarm or confusion before confirming the attack is real and identifying affected accounts. Option D is wrong because resetting passwords for all affected accounts is a containment step that should only occur after investigation confirms compromise, and it may lock out legitimate users if the alert is a false positive.

303
MCQhard

You are investigating a security incident in Microsoft Sentinel. You need to identify which user account was used to perform a suspicious Azure Resource Manager operation that deleted a virtual machine. The operation was logged in Azure Activity logs. Which Kusto Query Language (KQL) query should you use to find the user identity associated with the deletion?

A.SecurityEvent | where Activity == 'Delete Virtual Machine' | project Account
B.AzureActivity | where OperationName == 'Delete Virtual Machine' | project Caller
C.AuditLogs | where OperationName == 'Delete Virtual Machine' | project InitiatedBy
D.SigninLogs | where OperationName == 'Delete Virtual Machine' | project UserPrincipalName
AnswerB

The AzureActivity table contains Azure Activity logs, including the Caller field which holds the user identity (UPN or object ID) that initiated the operation. Filtering by OperationName for 'Delete Virtual Machine' and projecting Caller directly returns the user account responsible, making this the correct and efficient query for the scenario.

Why this answer

The AzureActivity table is the correct source for Azure Resource Manager operations, including VM deletions. The Caller field provides the identity of the user or service principal that performed the action. Filtering by OperationName ensures you isolate the deletion event.

Other tables like SecurityEvent, SigninLogs, and AuditLogs do not contain ARM control plane operations, so they would not yield the required user identity.

Exam trap

The trap here is assuming that any log table containing 'Audit' or 'Activity' will have the needed data, without verifying the specific log source for Azure Resource Manager operations.

304
MCQhard

Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. What will happen when a new incident with severity Medium is created?

A.The rule will not trigger because severity is Medium
B.The rule will trigger and create a new incident
C.The rule will trigger and run the playbook
D.The rule will update the incident severity to High
E.The rule will trigger but skip the playbook
AnswerA

The rule will not trigger because the incident has Medium severity, while the rule's condition explicitly requires an incident severity of High. When an incident is created or updated, Microsoft Sentinel evaluates the rule's trigger conditions against that incident's properties, and a failed condition prevents the rule from executing any actions. Because no action runs, neither the playbook nor any severity update occurs.

Why this answer

The automation rule is configured with a condition that triggers only when the incident severity is 'High'. Since the new incident has a severity of 'Medium', the condition is not met, and the rule does not trigger. Automation rules in Microsoft Sentinel evaluate conditions based on the incident's properties at creation time; if the condition fails, no actions (including playbook execution or incident creation) occur.

Exam trap

The trap here is that candidates assume the rule will trigger and then skip the playbook due to a mismatch, but in reality, the condition check happens first—if the severity does not match, the rule does not trigger at all, and no actions are evaluated.

How to eliminate wrong answers

Option B is wrong because the rule does not trigger at all, so it cannot create a new incident; automation rules modify existing incidents or run playbooks, they do not create incidents. Option C is wrong because the rule does not trigger, so no playbook is run. Option D is wrong because the rule does not trigger, so no update to severity occurs; even if it triggered, the rule's action is to run a playbook, not to change severity.

Option E is wrong because the rule does not trigger, so it does not skip the playbook—it never evaluates the playbook step.

305
MCQmedium

Refer to the exhibit. You are reviewing a Microsoft Sentinel automation rule definition. The rule is intended to automatically change the severity to High, assign to tier2, and set status to Active for incidents triggered by alerts containing 'malware'. However, incidents are not being updated. What is the most likely cause?

A.The action configuration is missing the 'incident' property.
B.The condition operator 'Contains' is incorrect; should be 'Equals'.
C.The trigger type should be 'IncidentCreated', not 'AlertRule'.
D.The playbook requires a managed identity to run.
AnswerC

Automation rules act on incidents, so the trigger must be 'IncidentCreated' to fire and apply severity, assignment and status changes. An 'AlertRule' trigger responds to alerts instead, meaning the incident-level actions never execute, which explains why incidents remain unmodified.

Why this answer

Microsoft Sentinel automation rules are triggered by incident-related events, and the correct trigger for acting on newly created incidents is 'Incident created' (IncidentCreated). If the rule is configured with an 'Alert rule' trigger, it fires on alert creation rather than incident creation, so the actions (change severity, assign owner, set status) never execute against the incident object — which is why incidents remain unchanged. Automation rules operate on incidents, not raw alerts, so the trigger must match the incident lifecycle.

Exam trap

SC-200 often tests the confusion between alert-level and incident-level triggers — candidates pick 'Alert rule' thinking it covers incidents, but automation rules that mutate incidents require the 'Incident created' trigger.

How to eliminate wrong answers

Option A is wrong because the 'incident' property is not a required field in the action configuration — automation rules inherently target the incident that triggered them, and the actions (severity, owner, status) are applied to that incident without needing an explicit property reference. Option B is wrong because 'Contains' is a valid and commonly used condition operator for matching substrings like 'malware' in alert names; switching to 'Equals' would actually make matching stricter and less likely to fire, not fix the problem. Option D is wrong because managed identity is required for playbooks that call external services or Azure resources, not for automation rules that perform native Sentinel actions like severity change or assignment.

306
MCQmedium

You are investigating an incident in Microsoft Defender XDR that involves a user who clicked a link in a phishing email. The email was detected and blocked by Microsoft Defender for Office 365, but the user still clicked the link before it was blocked. The incident includes an alert for 'Malicious URL click'. What additional information should you check to determine if the user's credentials were compromised?

A.Check if the link was blocked by the time the user clicked
B.Check for sign-in events from unusual locations or anonymous IP addresses after the click
C.Check if the user has recently changed their password
D.Check if the email had any attachments
AnswerB

Sign-in events from unusual locations or anonymous IP addresses after the click indicate whether stolen credentials were used. This telemetry, available through Microsoft Entra ID sign-in logs, confirms or rules out credential compromise following the malicious URL click.

Why this answer

The 'Malicious URL click' alert confirms the user interacted with the phishing link, but it does not confirm credential theft. The definitive indicator of compromise is a subsequent successful authentication using those credentials from an anomalous source. Checking Microsoft Entra ID sign-in logs (via Defender XDR's Advanced Hunting with AADSignInEventsBeta or the Entra sign-in log) for sign-ins from unusual geolocations, anonymous proxies (e.g., Tor exit nodes), or unfamiliar IPs immediately after the click timestamp reveals whether the attacker actually used the harvested credentials.

Exam trap

SC-200 often tests the distinction between a detection alert (the click) and a confirmed compromise indicator (an anomalous sign-in), tricking candidates into treating the alert itself as proof of credential theft.

How to eliminate wrong answers

Option A is wrong because whether the link was blocked at click time only affects payload delivery, not whether credentials were already submitted on the phishing page — the user's click itself is the exposure event. Option C is wrong because a recent password change is a normal user action and does not indicate compromise; it also does not correlate with the phishing click. Option D is wrong because email attachments are a separate delivery vector from URL-based phishing and are irrelevant to determining credential theft from a clicked link.

307
MCQmedium

During an incident involving a compromised Azure VM, the security team wants to capture a memory dump for forensic analysis. The VM is running Windows Server 2022. What is the recommended approach?

A.Use Azure Backup to create a VM snapshot.
B.Establish a PowerShell remote session and run 'Get-Process | Export-CliXML'.
C.Initiate a live response session on the VM and run the 'dump memory' command.
D.Use Azure Disk Encryption to export the disk.
AnswerC

Initiating a live response session on the VM and running the 'dump memory' command uses Microsoft Defender for Endpoint's built-in forensic capability to gather a complete memory dump from the endpoint. This preserves the volatile state for analysis—including running processes, network connections, and any malware injected into memory—which is exactly what is needed during an active compromise. Live response is the correct documented method for memory acquisition on an MDE-protected Azure VM.

Why this answer

Microsoft Defender for Endpoint's live response capability provides a built-in 'dump memory' command that captures a full memory dump of the compromised Azure VM for forensic analysis. This is the recommended approach as it allows memory acquisition without requiring additional tools or direct RDP/PSRemoting access, preserving the forensic integrity of the volatile data.

Exam trap

The trap here is that candidates may confuse disk-level snapshots (Azure Backup) or process listing (PowerShell) with a full memory dump, not realizing that only a dedicated memory acquisition tool or command (like 'dump memory' in live response) captures the complete volatile memory state needed for deep forensic analysis.

How to eliminate wrong answers

Option A is wrong because Azure Backup creates a crash-consistent or file-consistent snapshot of the VM's disks, not a memory dump; it captures disk state but not volatile memory contents like running processes or kernel data. Option B is wrong because 'Get-Process | Export-CliXML' only exports a list of running processes as XML, not a full memory dump; it misses critical memory artifacts such as loaded drivers, network connections, and unlinked processes. Option D is wrong because Azure Disk Encryption encrypts disks at rest but does not capture or export a memory dump; it is a security control, not a forensic acquisition method.

308
MCQhard

During an incident response, a forensic investigator needs to collect a memory dump from a compromised Windows server that is still running. The server has Microsoft Defender for Endpoint installed but is not connected to the internet. Which method should the investigator use?

A.Collect a system memory snapshot from the Microsoft 365 Defender portal
B.Use Live Response to run a memory dump collector on the device
C.Initiate a memory dump from the Microsoft Defender for Endpoint portal
D.Use Sysinternals Suite to capture a memory dump locally
AnswerD

Sysinternals Suite tools such as procdump execute natively on the local computer, using Windows internals (e.g., MiniDumpWriteDump) to capture process memory without relying on any network connection. This makes them ideal for an offline server because a forensic examiner can copy the tool to the machine via removable media and run it from an elevated command prompt to save a .dmp file to local disk. The resulting dump can then be analyzed on a separate workstation, preserving volatile evidence on the original host.

Why this answer

The correct answer is D because the server is not connected to the internet, which means cloud-based tools like Microsoft 365 Defender portal and Live Response cannot be used. Sysinternals Suite, specifically tools like ProcDump or RAMMap, can be run locally to capture a memory dump without requiring internet connectivity. This is the only option that works in an offline scenario, as it relies on local execution rather than cloud services.

Exam trap

SC-200 often tests the misconception that cloud-based security tools like Microsoft 365 Defender portal or Live Response can be used on devices without internet connectivity, but they require the device to be online and connected to the service.

How to eliminate wrong answers

Option A is wrong because collecting a system memory snapshot from the Microsoft 365 Defender portal requires the device to be connected to the internet and the portal to communicate with the device. Option B is wrong because Live Response is a feature of Microsoft Defender for Endpoint that requires the device to be connected to the cloud service to execute commands remotely. Option C is wrong because initiating a memory dump from the Microsoft Defender for Endpoint portal also requires internet connectivity and the device to be online and managed by the service.

309
MCQeasy

You are an incident responder for a company using Microsoft 365 Defender. A critical incident is assigned to you. What is the first action you should take according to best practices?

A.Triage the incident to determine the scope and severity.
B.Escalate the incident to senior management.
C.Immediately isolate all affected devices.
D.Collect a full memory dump from the affected systems.
AnswerA

Triage establishes scope and severity before containment, eradication or recovery, so responders can prioritise the critical incident correctly. Skipping straight to remediation risks wasted effort and missed affected assets, whereas triage directly satisfies the best-practise first-action requirement in the stem.

Why this answer

The first and most critical step in incident response is to triage the incident. Triage involves assessing the incident's scope, severity, and potential impact to prioritize and guide subsequent actions. Without triage, you risk wasting resources on low-priority issues or taking inappropriate steps.

Option A is correct because it enables informed decision-making. Option B (escalate) should come after triage if necessary. Option C (isolate devices) may be too hasty and could hinder investigation.

Option D (collect memory dump) is premature before understanding the incident.

310
Multi-Selecthard

Your organization uses Microsoft Sentinel. A security incident related to a compromised user account has been fully investigated and remediated. Which THREE steps should you take to close the incident properly? (Choose three.)

Select 3 answers
A.Verify that all related alerts are resolved or closed.
B.Create a new analytics rule to detect similar activity.
C.Change the incident status to Closed and select an appropriate classification.
D.Add comments summarizing the investigation and remediation steps.
E.Delete the incident to clean up the workspace.
AnswersA, C, D

Closing an incident while child alerts remain active leaves orphaned detections that can regenerate the incident or skew metrics. Confirming every linked alert is resolved or closed ensures the remediation is genuinely complete before the incident itself is finalised.

Why this answer

Options A, C, and D are correct. Verifying that all related alerts are resolved or closed (A) ensures no lingering issues. Changing the incident status to Closed with an appropriate classification (C) provides proper closure.

Adding comments summarizing the investigation and remediation steps (D) documents the process. Option B (creating a new analytics rule) is not required for closing an incident. Option E (deleting the incident) is not recommended; incidents should be closed, not deleted.

311
MCQhard

Your Microsoft Sentinel workspace is receiving a high volume of false positive alerts from a specific analytics rule. You need to suppress these alerts without disabling the rule. Which feature should you use?

A.Create an automation rule to close incidents
B.Adjust the alert threshold in the analytics rule
C.Configure alert suppression in the analytics rule
D.Disable incident creation for the rule
AnswerC

The correct approach is to enable Alert suppression in the analytics rule's 'Set rule logic' settings. When the rule fires, you can configure it to stop running the query for a specified duration (e.g., 1, 6, or 12 hours), so the same matching condition does not immediately generate multiple duplicate alerts. This suppresses additional alerts from that rule during the suppression window while preserving the rule for future detections.

Why this answer

Alert suppression in a Microsoft Sentinel analytics rule lets you define conditions (such as matching entity, IP address, or account) under which subsequent matching alerts are suppressed for a configurable time window. This stops the false-positive noise without turning off the rule, so genuine detections from other entities or conditions still fire. It is configured directly on the analytics rule's 'Incident settings' / suppression section, making it the precise tool for this requirement.

Exam trap

SC-200 often tests the distinction between suppressing alerts at the rule level versus closing incidents after the fact with automation rules — candidates pick automation because it sounds like 'handling' the noise, but it does not prevent incident creation.

How to eliminate wrong answers

Option A is wrong because an automation rule that closes incidents still allows the incident to be created and logged, so the false positives continue to consume analyst attention and incident quota. Option B is wrong because changing the alert threshold alters when the rule triggers at all, which can cause true positives to be missed and does not target the specific recurring false positives. Option D is wrong because disabling incident creation for the rule stops the rule from generating incidents entirely, effectively neutering the detection rather than selectively suppressing noise.

312
Multi-Selectmedium

Your organization is responding to a ransomware incident. Which TWO actions should be taken first to contain the incident while preserving forensic evidence?

Select 2 answers
A.Isolate affected devices using Microsoft Defender for Endpoint.
B.Reset passwords for all users in the organization.
C.Disable compromised user accounts in Microsoft Entra ID.
D.Perform a factory reset on all affected devices.
E.Shut down network switches to isolate the network segment.
AnswersA, C

Isolating affected devices through Microsoft Defender for Endpoint halts lateral spread and further encryption while keeping the machine powered on, so volatile memory, running processes and network connections remain intact for forensic capture. This directly satisfies the stem's dual constraint: contain the ransomware outbreak yet preserve evidential artefacts.

Why this answer

Option A is correct because isolating affected devices through Microsoft Defender for Endpoint (using the "Isolate device" action) severs network communication while keeping the device powered on, so volatile memory and forensic artifacts remain intact for investigation. Option C is correct because disabling compromised user accounts in Microsoft Entra ID immediately blocks the attacker's ability to authenticate, move laterally, or access cloud resources, and it is a reversible containment step that preserves sign-in and audit logs as evidence. Option B is not appropriate as a first action because a blanket password reset across all users is disruptive, does not stop an active session or token-based access, and can destroy or complicate evidence of which accounts were actually compromised.

Option D is wrong because a factory reset wipes the device and destroys the forensic evidence needed for the investigation. Option E is wrong because shutting down network switches disrupts the entire segment and business operations, and powering off systems can lose volatile evidence, making it a disproportionate and evidence-destructive containment measure.

Exam trap

SC-200 often tests the balance between containment and evidence preservation, where candidates may choose destructive actions like factory reset or network shutdown, which hinder forensic investigation.

313
MCQeasy

During an incident response, a SOC analyst needs to automatically collect relevant evidence from multiple Microsoft 365 services. Which Microsoft Sentinel playbook trigger should the analyst configure?

A.Microsoft Sentinel Playbook trigger 'When a response action is executed'.
B.Microsoft Sentinel Scheduled Analytics rule trigger.
C.Microsoft Sentinel Alert trigger.
D.Microsoft Sentinel Incident trigger with action 'Collect evidence'.
AnswerD

The Microsoft Sentinel Incident trigger with the action 'Collect evidence' is the correct choice because it fires when an incident is created, providing a single orchestration point for gathering evidence across multiple sources. This trigger can invoke a playbook automatically via an automation rule or manually, and the playbook can connect to various connectors to collect related evidence and append it to the incident. This aligns with best practice for incident-centric automation.

Why this answer

The Microsoft Sentinel Incident trigger with the 'Collect evidence' action is specifically designed to automate evidence collection across Microsoft 365 services during incident response. This trigger fires when an incident is created or updated, allowing the playbook to gather relevant data from sources like Microsoft Defender for Endpoint, Microsoft 365 Defender, and Azure Active Directory without manual intervention.

Exam trap

The trap here is that candidates often confuse the Alert trigger (which fires on individual alerts) with the Incident trigger (which aggregates alerts into incidents), and fail to recognize that only the Incident trigger has the dedicated 'Collect evidence' action for multi-service evidence gathering.

How to eliminate wrong answers

Option A is wrong because 'When a response action is executed' is a trigger for Microsoft 365 Defender playbooks, not Microsoft Sentinel, and it fires after a manual response action is taken, not for automated evidence collection. Option B is wrong because a Scheduled Analytics rule trigger is used for periodic queries on log data, not for real-time incident response or evidence collection from multiple services. Option C is wrong because the Microsoft Sentinel Alert trigger fires on individual alerts, not on incidents, and lacks the built-in 'Collect evidence' action that aggregates data from multiple Microsoft 365 services.

314
Multi-Selectmedium

Which TWO actions should you perform to contain a ransomware incident in Microsoft Defender for Endpoint?

Select 2 answers
A.Reset the local administrator password.
B.Isolate the device from the network.
C.Run a full antivirus scan.
D.Kill the malicious processes.
E.Collect the ransomware sample for analysis.
AnswersB, D

Isolating the device from the network is the immediate containment action because it severs the ransomware's C2 channel, preventing key exchange, additional payload downloads, and SMB-based worm-like propagation to adjacent systems. Physically disconnecting the network cable, disabling the Wi-Fi adapter, or applying a host-based firewall rule to block all inbound and outbound traffic ensures the encryption process cannot phone home or spread. This preserves evidence while stopping the attack in place, making it the first priority in any ransomware containment playbook.

Why this answer

Isolating the device from the network (Option B) is a critical containment step in a ransomware incident because it immediately stops the ransomware from communicating with its command-and-control (C2) server and prevents lateral movement to other devices. In Microsoft Defender for Endpoint, device isolation can be initiated from the Security Center, which applies a network-level block that only allows communication with the Defender for Endpoint service, effectively quarantining the device while preserving forensic data.

Exam trap

The trap here is that candidates confuse containment actions (like isolation and killing processes) with post-incident steps (like password resets, scanning, or sample collection), leading them to select options that are reactive rather than immediately preventive.

315
MCQeasy

A security analyst receives a Microsoft Defender for Identity alert about a suspicious Kerberos attack. The analyst needs to contain the compromised account immediately. What should the analyst do?

A.Disable the user account in Microsoft Entra ID.
B.Remove the user from all privileged groups.
C.Require the user to change their password at next sign-in.
D.Reset the user's password and notify the user.
AnswerA

Disabling the account in Microsoft Entra ID immediately blocks authentication, satisfying the requirement to contain the compromised identity. For a hybrid user, however, this alone may not stop on-premises Kerberos activity, since the domain controller still validates tickets until directory sync propagates the change.

Why this answer

Disabling the user account in Microsoft Entra ID immediately prevents any further authentication and access, containing the compromised account. This is the fastest and most direct containment action for a suspicious Kerberos attack alert in Microsoft Defender for Identity.

Exam trap

The trap is choosing a less immediate action like password reset or group removal, which does not stop an attacker who already has valid Kerberos tickets or credentials.

How to eliminate wrong answers

Option B is wrong because removing the user from privileged groups does not prevent the attacker from using the compromised account for other access; it only reduces privileges but leaves the account active. Option C is wrong because requiring a password change at next sign-in does not stop an attacker who already has valid credentials or Kerberos tickets; they can continue until the password is changed. Option D is wrong because resetting the password and notifying the user is reactive and does not immediately block the attacker; the attacker may still have active sessions or tickets.

316
Multi-Selecteasy

Which TWO of the following are valid data connectors for Microsoft Sentinel? (Select TWO.)

Select 2 answers
A.Docker containers
B.Amazon RDS
C.Azure Firewall
D.Google Cloud Storage
E.Microsoft Entra ID
AnswersC, E

Azure Firewall is a supported Microsoft Sentinel data connector, streaming firewall network and application rule logs into the workspace via Azure Monitor diagnostic settings. This satisfies the question's requirement to identify valid connectors, alongside Microsoft Entra ID.

Why this answer

Azure Firewall and Microsoft Entra ID are both supported data connectors in Microsoft Sentinel. Azure Firewall can be connected via the Azure Firewall connector, and Microsoft Entra ID (formerly Azure Active Directory) has built-in connectors for auditing and sign-in logs. Docker containers (A) are not a native data source for Sentinel; they would require a custom solution.

Amazon RDS (B) is not directly supported; you would need to ingest via AWS CloudTrail or similar. Google Cloud Storage (D) also requires custom ingestion methods.

317
MCQmedium

During an investigation, you need to check if any user has been assigned privileged roles in Microsoft Entra ID outside of normal business hours. Which data source would provide this information?

A.OfficeActivity (Office 365)
B.SecurityEvent (Windows Event Logs)
C.SigninLogs (Microsoft Entra ID)
D.AuditLogs (Microsoft Entra ID)
AnswerD

AuditLogs (Microsoft Entra ID) is the authoritative log for directory administrative changes, capturing activities such as 'Add member to role,' 'Remove member from role,' and 'Activate role' in the RoleManagement category. Each log entry includes the actor, target user, role name, and timestamp, enabling full visibility into who was granted elevated permissions and when. In Log Analytics or Microsoft 365 Defender, this appears as the AuditLogs table in the EntraID sign-in/logs connector. Therefore, it is the correct data source for verifying whether any user has been added to a privileged role.

Why this answer

AuditLogs in Microsoft Entra ID (formerly Azure AD) capture all directory-level changes, including privileged role assignments (e.g., Global Administrator, Privileged Role Administrator) along with the timestamp and user who performed the action. This allows you to filter for role assignments occurring outside normal business hours, making it the correct data source for this investigation.

Exam trap

The trap here is that candidates often confuse SigninLogs (which show when a user logs in) with AuditLogs (which show administrative changes like role assignments), leading them to choose Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because OfficeActivity (Office 365) logs cover user actions in Exchange Online, SharePoint, and Teams, but do not include Entra ID role assignments. Option B is wrong because SecurityEvent logs are Windows Event Logs from on-premises or hybrid-joined devices, not from Microsoft Entra ID, and they do not track cloud directory role changes. Option C is wrong because SigninLogs record authentication events (successful/failed sign-ins) and do not capture administrative role assignment operations.

318
Multi-Selectmedium

Which THREE steps should be included in a Microsoft Sentinel playbook for automatic incident response when a high-severity alert fires?

Select 3 answers
A.Investigate the alert by enriching with threat intelligence
B.Notify the security team via email or Teams
C.Pause the incident for 24 hours before taking action
D.Create a new Azure resource for logging
E.Contain the threat by blocking indicators
AnswersA, B, E

In Microsoft Sentinel, enriching an alert with threat intelligence is a standard investigative step: you pivot on entities such as IPs, domains, or hashes to query TI feeds and identify known malicious context, which helps validate the alert's severity and false-positive risk. This enrichment often leverages the built-in Threat Intelligence workbook or the hunting queries, enabling the analyst to correlate the current alert with historical compromise activity. It directly supports the 'Investigate' phase of the incident response lifecycle, making it a correct step.

Why this answer

Microsoft Sentinel playbooks, built on Azure Logic Apps, can automatically enrich alerts with threat intelligence from sources like the Threat Intelligence API or integrated TI platforms (e.g., VirusTotal, AlienVault OTX). This enrichment provides context (e.g., known malicious IPs, hashes, or domains) directly within the incident, enabling faster triage and informed response decisions without manual investigation.

Exam trap

The trap here is that candidates may confuse 'pausing' an incident with 'suppression' or 'tuning' rules, but in the context of automated response, any delay for high-severity alerts is unacceptable because it contradicts the goal of immediate containment.

319
MCQmedium

You are responding to an incident where a user's credentials were used to access a federated SaaS application from an IP address associated with a known threat actor. The user's account is not disabled. Which action is most effective to prevent further unauthorized access?

A.Reset the user's password and revoke active sessions
B.Create a Conditional Access policy to block the IP
C.Disable the user's account
D.Block the source IP address on the firewall
AnswerA

Resetting the password invalidates the attacker's knowledge of the compromised secret, while explicitly revoking the user's active sessions and refresh tokens terminates the attacker's existing authenticated access to Microsoft 365/Entra ID apps. This should be done before any other investigation step because it limits dwell time and prevents further lateral movement or data exfiltration as long as the attacker is not already using alternate backdoors. The 'Revoke user sessions' action in the Entra ID admin center (or Microsoft Graph `revokeSignInSessions`) closes current bearer/refresh tokens, not just the password-based login path.

Why this answer

Resetting the user's password and revoking active sessions immediately invalidates the compromised credentials and terminates any existing authenticated sessions, including the session used by the threat actor. This directly addresses the root cause—credential compromise—without unnecessarily disrupting the user's account permanently. In a federated SaaS scenario, password reset combined with session revocation ensures the threat actor cannot re-authenticate even if they possess the previous password hash or tokens.

Exam trap

The trap here is that candidates often choose to block the IP (Option B or D) because it seems immediate and technical, but they overlook that the attacker can easily change IPs and that the core issue is credential compromise, not network-level access.

How to eliminate wrong answers

Option B is wrong because creating a Conditional Access policy to block the IP only addresses the specific source IP, which can be easily changed by the threat actor (e.g., via proxy or VPN), and does not remediate the compromised credentials. Option C is wrong because disabling the user's account is overly disruptive and may block legitimate access for the user, while the threat actor could still use other compromised accounts or lateral movement; it also does not revoke existing sessions or tokens. Option D is wrong because blocking the source IP on the firewall is a network-level control that does not affect federated authentication flows (which occur over HTTPS) and does not invalidate the stolen credentials or active sessions.

320
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. A security analyst receives an alert for a suspicious sign-in from an IP address in a sanctioned app. The analyst needs to immediately block the user from accessing the app. Which action should the analyst take?

A.Suspend the user account in Microsoft Entra ID.
B.Add the IP address to the blocked IP list in Defender for Cloud Apps.
C.Create a new access policy in Defender for Cloud Apps to block the user.
D.Revoke the user's session tokens in Microsoft Entra ID.
AnswerA

Suspending the user account in Microsoft Entra ID immediately disables the user object, preventing any fresh authentication and token issuance for all applications, including the sanctioned app protected by Defender for Cloud Apps. This is the most direct and effective containment action because it blocks all sign-in attempts regardless of device, network, or app, and takes effect nearly immediately across Microsoft's identity plane.

Why this answer

Suspending the user account in Microsoft Entra ID immediately revokes all access tokens and prevents the user from authenticating to any app, including the sanctioned app. This is the fastest way to block access because it disables the user's ability to sign in entirely, regardless of the app or IP address. Defender for Cloud Apps alerts often require immediate containment, and account suspension is a direct, irreversible action that stops all ongoing sessions.

Exam trap

The trap here is that candidates confuse a Defender for Cloud Apps policy (which is a conditional access-like rule that applies to future traffic) with the immediate, account-level containment action available in Microsoft Entra ID, which is the fastest way to stop an active threat.

How to eliminate wrong answers

Option B is wrong because adding the IP address to the blocked IP list in Defender for Cloud Apps blocks traffic from that IP, but does not block the specific user—if the user signs in from a different IP, they can still access the app. Option C is wrong because creating a new access policy in Defender for Cloud Apps takes time to propagate and may not apply retroactively to an ongoing session; it is a preventive measure, not an immediate containment action. Option D is wrong because revoking session tokens in Microsoft Entra ID terminates current sessions but does not prevent the user from re-authenticating immediately with valid credentials, whereas suspending the account blocks all future sign-ins.

321
MCQmedium

You are responding to an incident where a malicious PowerShell script was executed on multiple endpoints. You need to collect the script content from the affected devices for analysis. What should you use?

A.Microsoft Defender for Cloud Apps activity logs
B.Microsoft Defender for Endpoint live response
C.Microsoft Purview eDiscovery
D.Azure Automation runbook
AnswerB

Microsoft Defender for Endpoint Live Response is the correct choice because it provides a remote, real-time shell for a compromised device. You can initiate a session from the MDE portal, run PowerShell commands, execute a script from the library, collect forensic artifacts, and retrieve the malicious script file for analysis. This interactive capability allows you to inspect the exact script content, confirm its behavior, and gather evidence directly from the endpoint.

Why this answer

Microsoft Defender for Endpoint live response (Option B) is the correct tool because it provides a remote shell connection to an endpoint, allowing you to collect the malicious PowerShell script content directly from the device's file system or memory. This is essential for forensic analysis when a script has been executed, as you can use commands like `Get-Content` or `Get-File` to retrieve the script file. Other options lack the direct, real-time access needed to extract script content from affected endpoints.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps activity logs with endpoint-level forensic data, assuming cloud logs contain script execution details, when in fact they only track cloud service interactions.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps activity logs capture cloud application usage and sign-in events, not local script execution on endpoints. Option C is wrong because Microsoft Purview eDiscovery is designed for searching and exporting content from Microsoft 365 data sources (e.g., Exchange, SharePoint) for legal or compliance purposes, not for collecting live forensic data from endpoint file systems. Option D is wrong because Azure Automation runbooks are used for automating cloud management tasks (e.g., VM configuration, patching) and cannot directly connect to endpoints to retrieve script content without additional infrastructure like hybrid workers or custom scripts.

322
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. A critical server in Azure was compromised by ransomware. The incident response team needs to ensure that no other resources in the same resource group are affected. What is the most immediate containment action?

A.Delete the virtual machine immediately to stop the ransomware.
B.Disable the public IP address and apply an NSG rule to block all inbound/outbound traffic to the server's subnet.
C.Change the local administrator password on the VM.
D.Move the VM to a different virtual network and subnet.
AnswerB

Disabling the public IP and applying an NSG rule that blocks all inbound and outbound traffic at the server's subnet effectively isolates the VM from both external attackers and internal lateral movement while leaving the machine powered on for evidence preservation. Because NSGs are stateful and evaluated for every flow, this drops current network conversations and prevents new ones, cutting off command-and-control or data exfiltration. This is the proper immediate containment action in an incident response playbook, as it contains the threat without destroying forensic artifacts.

Why this answer

The most immediate containment action is to isolate the compromised server's subnet by disabling its public IP and applying an NSG rule that blocks all inbound and outbound traffic. This prevents lateral movement of ransomware to other resources in the same resource group while preserving the VM for forensic analysis. In Microsoft Defender for Cloud and Sentinel, network isolation at the subnet level is the fastest way to contain a breach without destroying evidence.

Exam trap

The trap here is that candidates often choose to delete or move the VM, not realizing that immediate network isolation is the fastest way to contain lateral movement while preserving evidence for investigation.

How to eliminate wrong answers

Option A is wrong because deleting the VM destroys forensic evidence (memory, disk artifacts) and does not stop ransomware that may have already spread to other resources via network connections. Option C is wrong because changing the local administrator password does not block active network connections or lateral movement; ransomware often uses current sessions or service accounts, not just local credentials. Option D is wrong because moving the VM to a different virtual network and subnet requires the VM to be running and connected, which could propagate the ransomware during the move; it also does not immediately block traffic to other resources in the original resource group.

323
MCQhard

Your SOC uses Microsoft Sentinel. An analytics rule produces an incident, and your runbook requires that when a specific high-severity incident is created, a playbook must automatically post a summary to a Microsoft Teams channel and create a tracking task. You need the playbook to run without a human clicking anything. What should you configure?

A.A scheduled analytics rule that calls the playbook from within its query logic.
B.An automation rule with the trigger When incident is created and an action that runs the playbook.
C.A workbook that refreshes on a schedule and triggers the playbook through a data connector.
D.A playbook with an HTTP trigger that an analyst runs manually from the incident page.
AnswerB

Automation rules in Microsoft Sentinel evaluate incident conditions and can invoke playbooks automatically when their trigger conditions match, such as on incident creation with a specific severity or title. This satisfies the runbook requirement that no analyst clicks anything. The playbook then performs the Teams posting and task creation through its connectors, so the response is fully automated and repeatable for every matching incident.

Why this answer

Automation rules are the Microsoft Sentinel component that watches for incident creation or update events and can launch playbooks automatically when conditions match. Pairing an incident-created trigger with a playbook action delivers the unattended Teams notification and task creation the runbook demands. Analytics rules, workbooks, and manual triggers either detect, display, or require human initiation, so none provides the event-driven response.

Exam trap

The trap here is assuming an analytics rule can call a playbook directly, when playbook execution is wired through automation rules.

324
MCQhard

You are investigating a potential compromise of a service account in Microsoft Sentinel. You need to identify all actions performed by this account across Azure and Microsoft 365. Which Sentinel feature should you use?

A.Entity behavior analytics
B.Logs query with KQL
C.Automation rules
D.Workbooks
AnswerB

Using KQL to query logs in Microsoft Sentinel allows you to search across connected data sources, such as AzureActivity and OfficeActivity, for actions performed by the service account. This provides a detailed and customizable view of all activities, enabling thorough investigation.

Why this answer

Logs query with KQL in Microsoft Sentinel enables analysts to search across multiple data sources for activities related to a specific account. This is essential for identifying all actions performed by a compromised service account. Other features like UEBA, Workbooks, and Automation rules serve different purposes and do not provide the detailed, cross-service activity list needed.

Exam trap

The trap here is confusing UEBA's anomaly detection with a comprehensive activity audit, which is best achieved through direct log queries.

325
Multi-Selecteasy

Which TWO are legitimate sources of threat intelligence that can be ingested into Microsoft Sentinel?

Select 2 answers
A.STIX/TAXII threat intelligence feeds
B.Microsoft Defender Threat Intelligence
C.Exchange Online Protection
D.Microsoft Intune
E.Microsoft Purview Compliance Manager
AnswersA, B

STIX/TAXII threat intelligence feeds are legitimate because STIX (Structured Threat Information eXpression) standardizes how threat indicators and malicious behaviors are described, while TAXII (Trusted Automated eXchange of Indicator Information) provides the standardized transport protocol for sharing those feeds. Microsoft Sentinel natively supports ingestion from TAXII servers via the Threat Intelligence TAXII data connector, allowing organizations to pull in indicators of compromise and campaign context from public or commercial providers. This standards-based interoperability is exactly why these feeds are a recognized, first-class source of threat intelligence in a SIEM.

Why this answer

A is correct because STIX/TAXII is an open-source standard for sharing cyber threat intelligence (CTI). Microsoft Sentinel can ingest threat indicators from any TAXII 2.0 or 2.1 server using the built-in Threat Intelligence - TAXII data connector, allowing organizations to consume structured threat feeds (e.g., from MITRE ATT&CK or third-party providers) directly into Sentinel for correlation and alerting.

Exam trap

The trap here is that candidates confuse security management tools (like EOP, Intune, or Compliance Manager) with actual threat intelligence sources, assuming any Microsoft security product can be a threat feed, whereas only dedicated CTI platforms or feeds (STIX/TAXII, Microsoft Defender Threat Intelligence) provide structured indicator ingestion.

326
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You have a custom analytics rule that triggers on a Defender for Endpoint alert. When the rule triggers, a playbook is executed that creates an incident in Microsoft Sentinel and sends a message to a Teams channel. The playbook fails to execute. Which permission should you verify first?

A.The Teams channel has the appropriate permissions for incoming webhooks
B.The analyst has Microsoft Sentinel Reader role
C.The user has Microsoft Entra ID Global Administrator role
D.The automation rule has the correct managed identity or connection permissions
AnswerD

Automation rules in Microsoft Sentinel invoke playbooks by using either a managed identity or an OAuth connection to authenticate against the Logic App resource. If the managed identity lacks the required RBAC role on the Logic App (for example, Logic App Operator), or if the connection used by the rule has been removed, expired, or lacks the necessary permissions, the automation rule cannot trigger the playbook. This is the most direct and common cause of playbook execution failure, making it the correct answer.

Why this answer

The playbook executes as part of an automation rule triggered by a custom analytics rule. For the playbook to run successfully, the automation rule must have the correct permissions to invoke the playbook. This is typically configured via a managed identity (recommended) or a connection resource.

Without this, the automation rule cannot trigger the playbook, regardless of other permissions.

Exam trap

The trap here is that candidates often focus on the downstream action (Teams webhook) or user roles (Reader, Global Admin) instead of the critical link between the automation rule and the playbook execution permissions.

How to eliminate wrong answers

Option A is wrong because the Teams channel webhook permissions are only relevant after the playbook has been successfully invoked; the failure occurs before the playbook even runs. Option B is wrong because the Microsoft Sentinel Reader role grants read-only access to Sentinel data but does not grant the automation rule the ability to execute playbooks. Option C is wrong because the Global Administrator role is a highly privileged Entra ID role unrelated to the automation rule's ability to invoke a playbook; it is not required for this operation.

327
MCQhard

Your organization has deployed Microsoft Sentinel and uses the Microsoft 365 connector to ingest audit logs. You receive an alert from Microsoft Defender for Office 365 about a phishing email that was delivered to a user's inbox. You need to create an incident in Sentinel and automatically quarantine the email. What is the most efficient way to achieve this?

A.Use Microsoft Defender for Cloud Apps to investigate the alert and manually quarantine the email
B.Create a custom analytics rule that triggers when an alert is generated, and configure the rule to run a playbook that quarantines the email
C.Create an automation rule in Microsoft Sentinel that is triggered when this specific alert is generated, and associate a playbook that uses the Microsoft 365 Defender connector to quarantine the email
D.Manually create an incident in Microsoft Sentinel and then run a playbook to quarantine the email
AnswerC

The correct approach is to create an automation rule in Microsoft Sentinel that triggers when the specific alert from Microsoft 365 Defender is generated. In the automation rule, you associate a playbook that uses the Microsoft 365 Defender connector to quarantine the email. This enables an automated, immediate response without human intervention, leveraging the built-in alert as the trigger and the Logic Apps playbook to execute the quarantine action.

Why this answer

Automation rules in Microsoft Sentinel can be triggered by specific alert generation (e.g., from Microsoft Defender for Office 365) and can execute a playbook. The playbook uses the Microsoft 365 Defender connector, which includes the 'Quarantine email' action, enabling automated quarantine without manual intervention. This is the most efficient method as it combines automatic incident creation with immediate remediation.

Exam trap

The trap here is that candidates confuse 'custom analytics rules' (which generate alerts from raw data) with 'automation rules' (which react to existing alerts), leading them to choose Option B instead of C.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is not designed to handle email quarantine actions; it focuses on cloud app security and would require manual steps, which is inefficient. Option B is wrong because custom analytics rules in Sentinel are used to generate alerts from raw data, not to react to existing alerts from Defender for Office 365; they would duplicate effort and cannot directly trigger a playbook on an external alert. Option D is wrong because manually creating an incident defeats automation and efficiency; the goal is to automate the entire workflow from alert to quarantine.

328
MCQmedium

Your organization uses Microsoft Sentinel with the UEBA (User and Entity Behavior Analytics) feature enabled. A security analyst notices that a user account has been flagged with an anomaly indicating a possible compromised credential. Which entity type in Microsoft Sentinel's UEBA is most relevant for this alert?

A.Device
B.Application
C.IP address
D.User account
AnswerD

In Microsoft Sentinel UEBA, the user account is the primary entity type for detecting credential compromise because authentication and authorization are fundamentally tied to accounts. Attacks such as password spray, brute force, impossible travel, and anomalous sign-in all manifest as unusual activity on a user account, and UEBA builds a behavioral baseline per user to score these deviations. The investigation timeline aggregates sign-in events, machine activity, and assigned alerts around the account, enabling analysts to trace the full scope of a compromise. Therefore, User account is the correct answer.

Why this answer

The UEBA anomaly alert for a possible compromised credential is specifically tied to the User account entity because UEBA profiles user behavior over time and detects deviations from established baselines, such as unusual logon times, locations, or impossible travel. The alert directly reflects a risk to the user's identity, making the User account the most relevant entity type for this scenario.

Exam trap

The SC-200 exam often tests the distinction between entity types in UEBA, and the trap here is that candidates may confuse the IP address entity (which is associated with network-level anomalies) with the user account entity, failing to recognize that credential compromise is fundamentally a user identity anomaly.

How to eliminate wrong answers

Option A is wrong because Device entity in UEBA tracks anomalies related to device behavior (e.g., unusual OS version, rare software installation), not credential compromise. Option B is wrong because Application entity monitors anomalies in application usage patterns (e.g., unusual API calls or access frequency), not user credential risks. Option C is wrong because IP address entity in UEBA is used for network-level anomalies (e.g., unusual geolocation or proxy usage), but the alert specifically flags a compromised credential, which is a user identity issue, not a network endpoint.

329
MCQeasy

An incident in Microsoft Defender XDR shows a device with high severity alert: 'Suspicious PowerShell command line.' The device is currently isolated from the network. What is the best next step to investigate the alert?

A.Review the device timeline for related alerts.
B.Run a live response session on the device.
C.Restore network connectivity to allow the device to communicate with the cloud for analysis.
D.Initiate a full antivirus scan on the device.
AnswerB

Running a live response session on the device establishes an interactive, remote shell through the Microsoft Defender for Endpoint management plane. It enables the incident responder to execute PowerShell scripts, collect forensic artifacts such as memory, registry, and files, and apply remediation actions directly on the endpoint. Crucially, this can be done even while the device remains isolated, because the live response channel uses an outbound HTTPS connection to the cloud service.

Why this answer

Running a live response session on the isolated device lets the analyst execute commands, collect forensic artifacts (process list, network connections, file hashes), and investigate the suspicious PowerShell activity without restoring network connectivity. This is the recommended next step in Microsoft Defender XDR when a device is already isolated, because live response provides direct, interactive access for evidence gathering. It preserves containment while enabling deeper investigation.

Exam trap

SC-200 often tests whether candidates understand that isolation is a containment step and that live response — not restoring connectivity or running a generic AV scan — is the correct investigative action on an isolated device.

How to eliminate wrong answers

Option A is wrong because reviewing the device timeline is useful but passive; it does not provide the interactive forensic depth needed to investigate a high-severity PowerShell alert on an isolated device. Option C is wrong because restoring network connectivity would remove containment and allow potential attacker command-and-control or lateral movement — a dangerous step during active investigation. Option D is wrong because a full antivirus scan is a broad, slow action that may not surface fileless PowerShell activity and does not provide the targeted forensic insight that live response does.

330
Multi-Selecthard

Which TWO actions should you take when responding to a confirmed ransomware incident in Microsoft Defender for Endpoint?

Select 2 answers
A.Run a full antivirus scan on the affected devices.
B.Allow the ransomware executable in the firewall.
C.Collect an investigation package from the affected devices.
D.Isolate the affected devices from the network.
E.Initiate a live response session to delete files.
AnswersA, D

Running a full antivirus scan on affected devices is a primary eradication step because it identifies known ransomware signatures, quarantines the malicious binary, and cleans any dropped files or artifacts. In the context of Microsoft Defender for Endpoint, the scan leverages cloud-delivered protection and tamper protection to remove the threat from all local drives. This action is most effective after isolating the device, because the scan itself does not prevent lateral movement while it is running.

Why this answer

Running a full antivirus scan on affected devices helps identify and remove any remaining ransomware artifacts or secondary payloads that may not have been detected during the initial response. In Microsoft Defender for Endpoint, a full scan leverages the cloud-delivered protection and behavior monitoring to thoroughly examine all files and processes, reducing the risk of reinfection.

Exam trap

The trap here is that candidates often prioritize forensic collection (Option C) or file deletion (Option E) over immediate containment, not realizing that isolation and scanning are the mandated first steps in the Microsoft Defender for Endpoint ransomware response playbook.

331
MCQmedium

Your organization uses Microsoft Sentinel. A security analyst receives an alert indicating that a user account was used to sign in from an unfamiliar location. You need to investigate the incident using Microsoft Defender XDR. Which action should you take first?

A.Create an automated playbook to reset the user's password.
B.Review the alert in the Microsoft Defender XDR portal and classify it as a true or false positive.
C.Turn off the user account in Microsoft Entra ID.
D.Reset the user's password immediately to prevent further access.
AnswerB

The Microsoft Defender XDR portal is the central console for investigating alerts and incidents across the Microsoft 365 Defender suite. The first step in any incident response is to verify the alert's validity by examining the evidence, related entities, and the incident timeline. Classifying the alert as a true or false positive determines whether subsequent containment, eradication, or closure actions are necessary, making this the correct initial action.

Why this answer

The first step in incident response is to validate the alert by reviewing it in the Microsoft Defender XDR portal. This allows the analyst to assess the alert's context, such as sign-in logs, user risk, and related entities, before taking any corrective action. Classifying the alert as a true or false positive ensures that subsequent steps (like password reset or account disablement) are based on accurate threat assessment, preventing unnecessary disruption.

Exam trap

The trap here is that candidates often jump to immediate containment actions like password reset or account disablement, forgetting that the first step in any incident response process is to verify and classify the alert to avoid unnecessary operational impact.

How to eliminate wrong answers

Option A is wrong because creating an automated playbook to reset the password is a remediation step that should only occur after the alert is validated and classified; automating without investigation could lock out legitimate users. Option C is wrong because turning off the user account in Microsoft Entra ID is a drastic containment action that should follow confirmation of a true positive, not be the first step. Option D is wrong because resetting the password immediately bypasses the investigation phase, potentially disrupting the user if the alert is a false positive or a benign anomaly.

332
MCQeasy

During an incident response, you need to collect forensic evidence from a compromised Windows device using Microsoft Defender for Endpoint live response. Which command should you use to gather running processes?

A.dir
B.reg query
C.netstat
D.processes
AnswerD

The 'processes' command enumerates running processes on the target device, returning process names, IDs, and related details. This satisfies the forensic requirement to capture volatile evidence of active processes before the compromised Windows host is remediated or shut down.

Why this answer

The `processes` command in Microsoft Defender for Endpoint live response enumerates all currently running processes on the target device, returning details such as PID, name, and user context. It is one of the built-in live response commands specifically designed for forensic triage and incident investigation without needing to install third-party tooling. This makes it the correct choice for gathering running process evidence during an active incident.

Exam trap

SC-200 often tests whether candidates confuse standard Windows CLI commands (dir, netstat, reg query) with Defender for Endpoint live response's purpose-built command set, so candidates must memorise the live response command inventory rather than assume familiar OS tools are available.

How to eliminate wrong answers

Option A is wrong because `dir` is a file-system listing command that shows directory contents, not running processes. Option B is wrong because `reg query` reads registry keys/values and does not enumerate processes. Option C is wrong because `netstat` displays active network connections and listening ports, not the full process list (though it may show owning PIDs, it is not the process enumeration command).

333
MCQeasy

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. An incident is generated for a user who received a phishing email that bypassed Exchange Online Protection. The user clicked the link and entered credentials on a fake login page. The incident includes alerts from Microsoft Defender for Office 365 and Microsoft Entra ID. You need to respond to the incident. The affected user has administrative privileges. Which of the following should you do FIRST?

A.Reset the user's password and revoke sessions in Microsoft Entra ID.
B.Report the phishing email to Microsoft for analysis.
C.Create a transport rule to block similar phishing emails.
D.Delete the phishing email from the user's mailbox.
AnswerA

Because the user holds administrative privileges, credential reset alone is insufficient — active refresh tokens and sessions must be revoked in Microsoft Entra ID to evict the attacker immediately. This contains the compromised privileged identity before any further investigation, satisfying the stem's requirement to act first.

Why this answer

Resetting the user's password and revoking sessions immediately prevents attacker use of stolen credentials, especially given the user has administrative privileges. Option B is wrong because reporting the email is not the highest priority. Option C is wrong because creating a transport rule is a longer-term action.

Option D is wrong because deleting the email does not address the compromised credentials.

334
MCQmedium

You are a security analyst for a company using Microsoft Defender XDR. An incident is detected involving a device that has been communicating with a known command-and-control (C2) server. The device is currently online and the user is active. What should you do first to contain the threat?

A.Isolate the device from the network using Microsoft Defender for Endpoint
B.Run a full antivirus scan on the device
C.Notify the user to disconnect the device
D.Kill the suspicious processes on the device
AnswerA

Microsoft Defender for Endpoint's device isolation severs all network connectivity except to the MDE cloud service, instantly breaking command and control channels and laterally used protocols such as SMB and RDP. Because isolation is enforced at the operating system's network stack, it does not rely on killing a process that may simply respawn or on user compliance. This action also preserves volatile memory and active connections for subsequent forensic analysis, making it the preferred first response to a compromised, actively communicating endpoint.

Why this answer

Isolating the device from the network using Microsoft Defender for Endpoint immediately cuts off all communication with the C2 server, preventing data exfiltration and further command execution. This is the fastest containment action that does not rely on user compliance or process-level responses, and it preserves the device's state for forensic analysis. In an active incident, stopping network-level communication is the priority over scanning or process termination.

Exam trap

The trap here is that candidates often choose to kill suspicious processes (Option D) thinking it directly stops the threat, but they overlook that network isolation is the only action that guarantees the C2 channel is severed immediately and completely, regardless of process behavior.

How to eliminate wrong answers

Option B is wrong because running a full antivirus scan is a detection and remediation step, not a containment action; the device is already compromised and actively communicating with a C2 server, so scanning does not stop the ongoing threat. Option C is wrong because notifying the user to disconnect the device relies on human action, introduces delay, and may not be reliable; the user could be compromised or unresponsive, and the device remains connected to the network during the notification process. Option D is wrong because killing suspicious processes is a reactive step that does not prevent the device from re-establishing C2 communication or other processes from taking over; network isolation is required to fully sever the connection.

335
Multi-Selecthard

Which TWO actions are valid containment steps for a compromised user account in Microsoft Defender XDR?

Select 2 answers
A.Create a new email rule to forward emails
B.Disable the user account in Microsoft Entra ID
C.Add the user to a privileged role
D.Reset the user's password
E.Run a full antivirus scan on the user's device
AnswersB, D

Disabling the user account in Microsoft Entra ID is a valid containment step because it immediately prevents any further authentication attempts using that identity, cutting off the attacker's current access path to cloud applications, Microsoft 365, and other Entra ID-integrated resources. This reversible, non-destructive action preserves all user data and activity logs for forensic analysis while stopping ongoing malicious activity. It is one of the first actions an incident responder should take when a user identity is known to be compromised.

Why this answer

Disabling the user account in Microsoft Entra ID is a valid containment step because it immediately revokes the user's access to all cloud resources, including Microsoft 365, Azure, and any applications relying on Entra ID authentication. This prevents the compromised account from being used for further malicious activities while preserving the account for investigation. It is a core incident response action in Microsoft Defender XDR for containing identity-based threats.

Exam trap

The trap here is that candidates often confuse remediation steps (like running an antivirus scan) with containment steps, or they mistakenly think that adding a user to a privileged role could help monitor the account, when in fact it escalates the compromise.

336
MCQhard

Your organization uses Microsoft Sentinel. An incident is created from a fusion detection that combines multiple signals. You need to ensure that when the incident is resolved, all related alerts are also resolved automatically. What should you do?

A.Create an automation rule triggered when an incident is closed, with the action 'Close alert'
B.Create a playbook triggered on incident creation that closes alerts
C.Create an automation rule triggered when an alert is created
D.Configure the analytics rule to close alerts when the incident is resolved
AnswerA

In Microsoft Sentinel, an automation rule can be triggered when an incident's status changes to Closed, and its 'Close alert' action explicitly resolves all linked alerts. This ensures that the security operations team does not have to manually close each alert and that the alert-state lifecycle matches the incident-state lifecycle. Conditions such as severity, owner, or tactic can also be applied, making this the correct, supported mechanism to accomplish the goal.

Why this answer

An automation rule triggered when an incident is closed can include the action 'Close alert', which automatically closes all alerts linked to that incident. This ensures that when the incident is resolved, all related alerts are also resolved without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rule triggers (incident creation vs. closure) or assume that closing an incident automatically closes its alerts, which is not the default behavior in Microsoft Sentinel.

How to eliminate wrong answers

Option B is wrong because a playbook triggered on incident creation would close alerts immediately when the incident is created, not when it is resolved, which does not meet the requirement. Option C is wrong because an automation rule triggered when an alert is created would run on alert creation, not on incident closure, and cannot close alerts retroactively. Option D is wrong because analytics rules do not have a setting to close alerts when the incident is resolved; alert closure must be handled via automation rules or playbooks.

337
MCQmedium

During an incident investigation, you discover that an attacker used a legitimate account to access sensitive data in Microsoft Purview Information Protection. You need to identify what data was accessed and by whom. Which log source should you query?

A.Microsoft 365 Defender alerts
B.Microsoft Purview data access logs
C.Microsoft Entra ID sign-in logs
D.Office 365 audit logs (unified audit log)
AnswerB

Microsoft Purview data access logs are the authoritative source for item-level access events in Office 365, recording details such as the specific document downloaded, the user identity, the timestamp, and the device or client IP. These logs are generated by Purview's content discovery and classification pipeline and capture both interactive and background access by apps or users. For an attacker exfiltrating sensitive files, these logs provide the precise chain of access needed to confirm what data was compromised, so this is the correct choice for the investigation.

Why this answer

Microsoft Purview data access logs (option B) are the correct source because they specifically record when users access sensitive data labeled with Microsoft Purview Information Protection, including details about what data was accessed and by whom. Unlike other logs, these capture data-level access events such as viewing, downloading, or modifying protected documents, which is essential for investigating an attacker using a legitimate account to exfiltrate sensitive information.

Exam trap

The trap here is that candidates often confuse the unified audit log (option D) with Purview data access logs, not realizing that while the unified audit log captures many activities, Purview data access logs are the only source that specifically records label-based access events for sensitive data.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Defender alerts provide aggregated threat detection signals and incident summaries, not granular data access logs for Purview-protected content. Option C is wrong because Microsoft Entra ID sign-in logs record authentication events (successful/failed logins) but do not track what specific data was accessed after authentication. Option D is wrong because Office 365 audit logs (unified audit log) capture a broad range of administrative and user activities, but they do not include the detailed data-level access events for Purview Information Protection labels; those are only available in Purview data access logs.

338
Multi-Selecthard

Which THREE steps are part of the containment phase of incident response in a hybrid environment using Microsoft Defender XDR?

Select 3 answers
A.Remove malware from affected systems
B.Restore data from backups
C.Disable compromised user accounts in Microsoft Entra ID
D.Isolate affected devices using Microsoft Defender for Endpoint
E.Block malicious IP addresses at the firewall
AnswersC, D, E

Disabling compromised accounts in Microsoft Entra ID immediately revokes authentication, blocking the attacker from re-entering the environment via cloud or hybrid identity paths. This directly satisfies containment by stopping lateral movement and further compromise while investigation continues, rather than merely detecting or documenting the incident.

Why this answer

Option C is correct because disabling compromised user accounts in Microsoft Entra ID is a classic containment action that stops an attacker from continuing to use stolen credentials for lateral movement or further access. Option D is correct because isolating affected devices via Microsoft Defender for Endpoint cuts off the endpoint's network communication while preserving it for investigation, which is a core containment step in a hybrid environment. Option E is correct because blocking malicious IP addresses at the firewall prevents ongoing command-and-control or exfiltration traffic to known-bad infrastructure, containing the spread of the incident.

Options A and B are not containment: removing malware is part of eradication, and restoring data from backups belongs to the recovery phase, which occurs after the threat has been fully eliminated.

Exam trap

The trap is mixing up incident response phases — candidates often select eradication or recovery actions (like removing malware or restoring backups) thinking they are containment.

339
MCQhard

A SOC analyst is responding to a ransomware incident. The analyst identifies that the ransomware encrypted files on a file share and left a ransom note. The analyst needs to prevent the ransomware from spreading to other shares. Which action should the analyst take first?

A.Revoke the user's access to the file share.
B.Run a full antivirus scan on the server.
C.Restore the encrypted files from backup.
D.Isolate the server from the network using Microsoft Defender for Endpoint's device isolation.
AnswerD

Microsoft Defender for Endpoint's device isolation applies an OS-level network security policy at the client that blocks all inbound and outbound traffic other than the Defender service itself, effectively severing the ransomware's command-and-control channel and preventing further server-side or lateral encryption. This is the immediately effective containment action because it does not rely on terminating the process or cleaning files first. The SOC can then inspect processes, stop the malicious binary, and later restore data from backup in a clean state.

Why this answer

The immediate priority in a ransomware incident is containment to prevent lateral movement and further encryption. Microsoft Defender for Endpoint's device isolation feature disconnects the compromised server from the network while allowing communication with the Defender for Cloud backend, stopping the ransomware from spreading to other shares. This aligns with the NIST incident response framework's containment phase, which must occur before eradication or recovery actions.

Exam trap

The trap here is that candidates confuse containment actions with recovery or eradication steps, mistakenly choosing to restore files or run a scan first, when the correct first action is to isolate the compromised device to stop the spread.

How to eliminate wrong answers

Option A is wrong because revoking the user's access does not stop the ransomware process already running on the server from encrypting additional shares or spreading via other accounts or system-level privileges. Option B is wrong because running a full antivirus scan is a detection and eradication step that should follow containment; the ransomware may continue to spread during the scan, and the scan itself may be disrupted by the active malware. Option C is wrong because restoring encrypted files from backup is a recovery action that should only be performed after the threat is contained and eradicated; attempting restoration first could allow the ransomware to immediately re-encrypt the restored files.

340
Multi-Selectmedium

Which TWO actions should you take when responding to a confirmed data exfiltration incident involving Microsoft 365? (Choose two.)

Select 2 answers
A.Reset passwords for all users
B.Revoke user sessions in Microsoft Entra ID
C.Review audit logs in Microsoft Purview compliance portal
D.Disable all external sharing in SharePoint
E.Block all access to the tenant
AnswersB, C

Revoking sessions in Microsoft Entra ID invalidates refresh and access tokens immediately, cutting off the compromised account's continued access. This satisfies the stem's requirement to contain a confirmed exfiltration, since password resets alone leave existing tokens valid until expiry.

Why this answer

Options B and C are correct. When responding to a confirmed data exfiltration incident involving Microsoft 365, you should contain the threat by revoking user sessions in Microsoft Entra ID (option B) to prevent further unauthorized access, and investigate by reviewing audit logs in the Microsoft Purview compliance portal (option C) to determine the scope and impact of the exfiltration. Option A (resetting passwords for all users) is excessive and disruptive; instead, focus on resetting passwords for compromised accounts only.

Option D (disabling all external sharing in SharePoint) is too broad and may disrupt legitimate business operations. Option E (blocking all access to the tenant) is premature and would cause significant operational disruption.

341
Multi-Selecthard

Which THREE are valid data connectors in Microsoft Sentinel for ingesting security events from Microsoft 365 services? (Choose three.)

Select 3 answers
A.Microsoft 365 Defender
B.Microsoft Purview
C.Microsoft Intune
D.Microsoft Entra ID
E.Office 365
AnswersA, D, E

Microsoft 365 Defender is a native Sentinel data connector that ingests high-fidelity alerts and incidents from the Microsoft Defender XDR suite, including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. This connector enables cross-domain correlation and automates incident response by bringing unified XDR telemetry directly into Sentinel, making it a core component for modern security operations.

Why this answer

Microsoft 365 Defender is a valid data connector in Microsoft Sentinel that ingests alerts and incidents from Microsoft 365 Defender components (Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps). It uses the Microsoft 365 Defender API to pull correlated security events, enabling centralized investigation of advanced threats across the M365 ecosystem.

Exam trap

The trap here is that candidates may confuse Microsoft Purview (a compliance tool) with a security event source, or think Intune's device management logs qualify as 'security events from Microsoft 365 services' when Sentinel's Intune connector is actually for device compliance data, not security events.

342
Multi-Selecthard

Which THREE actions are appropriate when investigating a potential data exfiltration incident in Microsoft Defender for Cloud Apps?

Select 3 answers
A.Check the device inventory for suspicious applications
B.Use the app dashboard to view unusual behavior alerts
C.Suspend the user's account immediately
D.Check the file policy matches for the user
E.Review the user's activity log in Defender for Cloud Apps
AnswersB, D, E

The app dashboard in Defender for Cloud Apps surfaces anomaly detection alerts, such as impossible travel, mass download, or activity from a previously unseen IP. These alerts are produced by user and entity behavior analytics and serve as the initial signal that an exfiltration attempt may be in progress. Reviewing this dashboard is a valid investigative step because it helps you prioritize which users and files warrant deeper log analysis, rather than assuming any single event is malicious.

Why this answer

Options B, D, and E are correct. Option B: Using the app dashboard to view unusual behavior alerts provides context about potential exfiltration. Option D: Checking file policy matches helps identify which files were flagged as suspicious.

Option E: Reviewing the user's activity log in Defender for Cloud Apps helps determine the scope of the exfiltration. Option A is incorrect because checking device inventory is not a cloud app investigation action—it applies to endpoint devices. Option C is incorrect because suspending the user's account is a containment action, not an investigative step.

Exam trap

Candidates may confuse containment actions (e.g., suspending the user) with investigative steps, or mistakenly think device inventory is relevant in cloud app investigations.

343
MCQmedium

Your organization uses Microsoft Sentinel. A new incident is created from a fusion alert that combines multiple low-severity alerts. The analyst needs to determine the entities involved. What should the analyst review?

A.The Sentinel Overview workbook.
B.The incident's entities tab.
C.The analytics rule that generated the incident.
D.The incident's timeline.
AnswerB

In Microsoft Sentinel, the incident's Entities tab displays the normalized entity objects—such as user accounts, hostnames, IP addresses, URLs, and file hashes—that were extracted and mapped during incident creation. These entities are directly linked to the incident and enriched with context for pivoting, allowing analysts to see and investigate all related resources from a single, authoritative view. This is the correct place to find all related entities for the incident.

Why this answer

The incident's entities tab in Microsoft Sentinel provides a consolidated view of all entities (such as users, hosts, IP addresses, and processes) that were identified by the fusion alert. Since fusion alerts combine multiple low-severity alerts, the entities tab is the direct place to see the aggregated entities involved in the incident, enabling the analyst to understand the scope and pivot for investigation.

Exam trap

The trap here is that candidates confuse the incident's timeline (which shows events) with the entities tab (which shows the involved objects), or they mistakenly think the analytics rule's configuration reveals the actual entities, when in fact entities are dynamically extracted from alert data.

How to eliminate wrong answers

Option A is wrong because the Sentinel Overview workbook provides high-level metrics and trends (e.g., incident counts, data ingestion) but does not show the specific entities for a single incident. Option C is wrong because the analytics rule that generated the incident defines the detection logic and configuration, not the dynamic entities extracted from the alert data. Option D is wrong because the incident's timeline shows the chronological sequence of events and activities related to the incident, but it does not present a structured list of entities; entities are explicitly available only in the entities tab.

344
MCQhard

A security team is investigating a ransomware incident that encrypted files on several Windows servers. Microsoft Defender for Endpoint detected the ransomware but the initial infection vector is unknown. Which KQL query in Microsoft Sentinel would BEST identify the initial process that executed the ransomware?

A.DeviceNetworkEvents | where RemoteUrl contains 'malicious' | project DeviceName, RemoteIP, Timestamp
B.DeviceFileEvents | where FileName contains 'ransomware.exe' | project DeviceName, ActionType, Timestamp
C.DeviceProcessEvents | where FileName contains 'ransomware.exe' | project DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, Timestamp
D.DeviceEvents | where ActionType == 'RansomwareDetection' | project DeviceName, Timestamp
AnswerC

The DeviceProcessEvents table records actual process creation events on the endpoint, and this query filters for any process whose file name is 'ransomware.exe' while projecting the initiating process file name and its command line. That parent relationship is the critical forensic evidence: it shows which executable (for example msiexec.exe, rundll32.exe, or a malicious PowerShell) launched the ransomware, enabling the security team to trace back to the initial access vector. Including the timestamp supports chronological reconstruction of the infection, which is the core goal of the incident response investigation.

Why this answer

DeviceProcessEvents captures process creation events, and by filtering for the ransomware executable and projecting the InitiatingProcessFileName and InitiatingProcessCommandLine, you can trace back to the parent process that launched the ransomware. This directly identifies the initial infection vector, which is the core goal of the investigation.

Exam trap

The trap here is that candidates often choose Option D (DeviceEvents with RansomwareDetection) because it directly shows the detection event, but it lacks the parent process information needed to identify the initial infection vector, which is the specific requirement of the question.

How to eliminate wrong answers

Option A is wrong because DeviceNetworkEvents focuses on network connections, not process creation; filtering by a URL containing 'malicious' is speculative and does not identify the initial process that executed the ransomware. Option B is wrong because DeviceFileEvents logs file creation, modification, or deletion events, not process execution; while it shows the ransomware file, it cannot reveal the parent process that launched it. Option D is wrong because DeviceEvents with ActionType 'RansomwareDetection' only indicates that Defender for Endpoint detected ransomware activity, but it does not provide the initiating process details needed to trace the infection vector.

345
MCQmedium

Contoso uses Microsoft Sentinel with Microsoft Defender XDR connector. You receive an incident titled 'Malware detected on endpoint' from Microsoft Defender for Endpoint. The incident includes a detailed timeline showing that the malware was downloaded from a malicious URL. You need to respond to the incident using Microsoft Sentinel and Microsoft Defender XDR capabilities. The affected device is a Windows 10 workstation used by a standard user. You have been asked to contain the threat and prevent recurrence. The organization has a policy to preserve evidence for 90 days. Which action should you take FIRST?

A.Reset the user's password and revoke sessions in Microsoft Entra ID.
B.Create a custom detection rule in Microsoft Sentinel for the malicious URL.
C.Block the malicious URL at the firewall using Microsoft Defender for Cloud Apps.
D.Isolate the device using Microsoft Defender for Endpoint device isolation.
AnswerD

Device isolation via Microsoft Defender for Endpoint immediately cuts the workstation's network connections while preserving the live system and its forensic artefacts, containing lateral movement and further payload downloads. Remediation and evidence collection follow safely afterwards, satisfying the 90-day preservation policy.

Why this answer

Isolating the device using Microsoft Defender for Endpoint immediately contains the threat by disconnecting the device from the network, preventing the malware from spreading or communicating with command-and-control servers. This is the priority first step in incident response. Option A is incorrect because resetting the password does not remove malware from the device.

Option B is incorrect creating a custom detection rule is a proactive step but not an immediate containment action. Option C is incorrect because blocking the URL at the firewall prevents further downloads but does not contain the already infected device.

346
Multi-Selecthard

Which THREE of the following are valid incident management capabilities in Microsoft Sentinel? (Choose three.)

Select 3 answers
A.Assign incidents to analysts or teams
B.Classify incidents as true positive, false positive, or benign positive
C.Merge related incidents into a single incident
D.Create playbooks to automate incident response
E.Create workbooks to visualize incident trends
AnswersA, B, C

Assigning incidents to analysts or teams is a core incident management capability in Microsoft Sentinel. Through the Incident blade, an analyst can set the Owner and assign the incident to a specific person or group, establishing accountability and routing for follow-up actions. Assignment does not change incident state by itself but ensures each case has a clear point of contact.

Why this answer

A is correct because Microsoft Sentinel allows incident owners to be assigned directly to an analyst or a team via the 'Owner' field in the incident details pane. This assignment is used for tracking responsibility, SLA enforcement, and escalation workflows within the Security Operations (SecOps) lifecycle.

Exam trap

The trap here is that candidates confuse automation (playbooks) and reporting (workbooks) with direct incident management actions, but Microsoft Sentinel explicitly separates incident management capabilities (assignment, classification, merging) from automation and visualization features in the exam blueprint.

347
MCQhard

An analyst runs this advanced hunting query to investigate suspicious command-line activity. Which type of activity is this query most likely detecting?

A.Execution of obfuscated scripts via encoded commands
B.Data exfiltration to external IPs
C.Privilege escalation attempts
D.Port scanning activity
AnswerA

Encoded commands, typically Base64 strings passed to PowerShell or command shells, are the signature this hunting query targets. Decoding and inspecting those command lines reveals obfuscated script execution, matching the query's focus on suspicious command-line activity.

Why this answer

The query likely searches for command lines containing encoded or obfuscated script indicators, such as 'powershell -enc' or Base64-encoded commands, which are common in malicious script execution. Advanced hunting in Microsoft 365 Defender uses Kusto Query Language (KQL) to query device process events. Detecting encoded commands is a typical technique to identify obfuscated scripts that evade detection.

Exam trap

SC-200 often tests the ability to interpret KQL queries and map them to attack techniques, so candidates might confuse encoded command execution with other attack types like exfiltration or privilege escalation.

How to eliminate wrong answers

Option B is wrong because data exfiltration queries typically look for network connections to external IPs or large data transfers, not command-line encoding. Option C is wrong because privilege escalation queries focus on processes like 'runas' or token manipulation, not encoded commands. Option D is wrong because port scanning queries involve network events like multiple connection attempts to different ports, not command-line arguments.

348
Multi-Selectmedium

Which TWO actions should an analyst take when a confirmed ransomware incident is detected on multiple endpoints? (Choose TWO.)

Select 2 answers
A.Run a full antivirus scan on all endpoints.
B.Isolate affected endpoints using Microsoft Defender for Endpoint.
C.Block known malicious IP addresses and domains in the firewall.
D.Disconnect network cables but leave endpoints powered on.
E.Shut down all affected endpoints to prevent data loss.
AnswersB, C

Immediately contains the threat by isolating devices.

Why this answer

Microsoft Defender for Endpoint's device isolation feature immediately severs all network communication (both inbound and outbound) from the affected endpoint while keeping the device powered on for forensic analysis. This containment action prevents lateral movement and further encryption of data across the network, which is critical during a ransomware incident.

Exam trap

The trap here is that candidates often confuse 'isolation' with 'shutdown' or 'disconnect', not realizing that isolation preserves forensic data and allows remote management, while shutdown destroys volatile evidence and may accelerate data loss.

349
MCQhard

You are handling an incident where a user's account was used to access sensitive data from an unusual location. Microsoft Entra ID Identity Protection flagged the sign-in as risky. You need to determine if the account is compromised. Which investigation step should you perform first?

A.Block the user from signing in
B.Force a password reset for the user
C.Check if the device used is managed by Intune
D.Review the sign-in details and compare with the user's typical behavior
AnswerD

Reviewing the sign-in details and comparing them with the user's typical behavior is the correct initial triage action because Entra ID sign-in logs contain rich data—client IP, latitude/longitude, user agent, authentication method, device ID, and risk labels (e.g., impossible travel, unfamiliar sign-in properties, anonymized IP)—that can be correlated against the user's historical baseline. This behavioral analytics approach validates whether the sign-in is truly anomalous before any containment steps are taken, which is consistent with the 'identify-scope-contain' incident response lifecycle. Without this evidence-based review, actions like resetting credentials or blocking the account would be premature and potentially misguided, either disrupting a legitimate sign-in or failing to address a real compromise.

Why this answer

Before taking any remediation action, you should first review the sign-in details and compare them with the user's typical behavior to determine if the account is actually compromised. This investigation step provides context and helps avoid unnecessary disruptions. Only after confirming a compromise should you proceed with actions like blocking or password reset.

Exam trap

The trap is jumping to remediation actions (block, reset password) before completing the investigation; candidates may think immediate action is best, but the question asks for the first step in determining if the account is compromised.

How to eliminate wrong answers

Option A is wrong because blocking the user from signing in is a remediation step that should be taken only after confirming a compromise; doing it first could disrupt legitimate user access. Option B is wrong because forcing a password reset is also a remediation action that may be premature without investigation. Option C is wrong because checking if the device is managed by Intune is a useful data point but not the first step; it is part of the broader investigation into sign-in details and behavior.

350
MCQhard

Your organization is using Microsoft Defender for Cloud to protect Azure workloads. A critical vulnerability was discovered in a virtual machine that is part of a production application. The vulnerability has a high severity score and is actively being exploited in the wild. You need to respond quickly to mitigate the risk. What is the most effective immediate action?

A.Apply the vendor patch immediately during business hours.
B.Enable just-in-time (JIT) VM access in Microsoft Defender for Cloud to lock down inbound traffic.
C.Modify the network security group (NSG) to block all inbound traffic to the VM.
D.Use the 'Remediate' option in Defender for Cloud to automatically apply the patch.
AnswerB

Enabling just-in-time (JIT) VM access in Microsoft Defender for Cloud immediately reduces the attack surface by creating temporary NSG rules that only allow specified source IPs and ports during defined schedules. This blocks inbound traffic from the internet or other high-risk sources while preserving legitimate administrative access, unlike a full inbound block. JIT is a fast, reversible, and targeted network-level control that buys time for a safe patch deployment without taking the VM offline.

Why this answer

Enabling just-in-time (JIT) VM access in Microsoft Defender for Cloud immediately reduces the attack surface by locking down inbound traffic to the VM, except for approved connections from specific IP addresses and ports. This is the most effective immediate action when a critical, actively exploited vulnerability exists, as it buys time to apply a patch without exposing the VM to further exploitation. Unlike patching, which may require a reboot or cause downtime, JIT access can be enabled in minutes and does not disrupt production traffic for authorized users.

Exam trap

The trap here is that candidates often choose the 'Remediate' option (D) thinking it automatically patches the vulnerability, but in reality, the patch may not be available or may require a reboot, making JIT access the faster and safer immediate containment action.

How to eliminate wrong answers

Option A is wrong because applying a vendor patch immediately during business hours risks causing unplanned downtime or application instability, and the patch may not be available or tested for the specific vulnerability. Option C is wrong because modifying the NSG to block all inbound traffic would completely deny access to the VM, including legitimate production traffic, effectively taking the application offline. Option D is wrong because the 'Remediate' option in Defender for Cloud applies the vendor patch automatically, which may not be immediately available, could require a reboot, and does not provide the same rapid, non-disruptive containment as JIT access.

351
MCQeasy

Refer to the exhibit. You are deploying this analytics rule in Microsoft Sentinel. Which activity will trigger an alert?

A.cmd.exe launching winword.exe
B.Any process creation event
C.Winword.exe execution
D.Any cmd.exe execution
E.Word launching cmd.exe
AnswerE

The query conditions—ParentImage equals 'winword.exe' and CommandLine contains 'cmd.exe'—precisely describe a Microsoft Word process creating a child command prompt. This is a classic indicator of a document with an embedded macro executing a shell command, a common technique for lateral movement or payload delivery. Therefore, this option correctly interprets the rule's intent and logic.

Why this answer

The analytics rule is configured to trigger an alert when a process creation event (Event ID 4688) has a parent process of 'winword.exe' and a child process of 'cmd.exe'. This specific parent-child relationship indicates that Microsoft Word is launching a command prompt, which is a common technique used in malicious documents to execute commands. The rule's query filters for 'ParentImage' containing 'winword.exe' and 'Image' containing 'cmd.exe', so only when Word launches cmd.exe will the alert fire.

Exam trap

The trap here is that candidates often confuse the parent-child process direction, assuming any execution of cmd.exe or winword.exe will trigger the alert, but the rule explicitly requires winword.exe as the parent and cmd.exe as the child, not the reverse.

How to eliminate wrong answers

Option A is wrong because it describes the reverse relationship (cmd.exe launching winword.exe), which does not match the rule's filter for ParentImage being winword.exe and Image being cmd.exe. Option B is wrong because the rule does not trigger on any process creation event; it specifically requires the parent process to be winword.exe and the child process to be cmd.exe. Option C is wrong because the rule requires both the parent (winword.exe) and child (cmd.exe) to be present; a standalone winword.exe execution without launching cmd.exe will not trigger the alert.

Option D is wrong because the rule requires the parent process to be winword.exe, not any cmd.exe execution; a cmd.exe launched by another process (e.g., explorer.exe) will not match the rule's conditions.

352
MCQhard

During a ransomware incident, a security analyst needs to isolate an affected Windows 10 device managed by Microsoft Intune. The device is currently online and connected to the corporate network. Which remediation action should be taken from Microsoft Defender XDR to achieve this?

A.Block the device in Microsoft Intune
B.Initiate device isolation from the Microsoft Defender for Endpoint console
C.Disable the Windows Firewall via Intune
D.Run a full antivirus scan from Microsoft Defender for Endpoint
AnswerB

Device isolation from the Microsoft Defender for Endpoint console severs network connectivity while preserving the Defender sensor channel, blocking lateral movement and ransomware spread on the online Intune-managed device. This is the supported remediation action within Microsoft Defender XDR.

Why this answer

Device isolation from the Microsoft Defender for Endpoint console (accessible via Microsoft Defender XDR) immediately cuts the device off from the network while preserving the Defender communication channel, allowing the analyst to investigate and remediate without losing contact with the endpoint. This is the purpose-built ransomware containment action.

Exam trap

SC-200 often tests the confusion between Intune device actions (block, wipe, retire) and Defender for Endpoint remediation actions (isolate, restrict app execution, live response) — candidates pick Intune block thinking it isolates the device, when only Defender isolation actually severs network connectivity.

How to eliminate wrong answers

Option A is wrong because blocking a device in Intune marks it as non-compliant and can trigger conditional access restrictions, but it does not sever the device's existing network connections — the ransomware can continue lateral movement. Option C is wrong because disabling Windows Firewall removes a defensive layer and does not isolate the device; it actually increases exposure. Option D is wrong because running a full antivirus scan is a detection/remediation step, not containment — the device remains network-connected and the ransomware continues to spread during the scan.

353
MCQeasy

During an incident response, your team identifies a suspicious PowerShell command executed on multiple devices. Which Microsoft Defender XDR feature should you use to block the command across all endpoints immediately?

A.Potentially Unwanted Application (PUA) protection
B.Indicators of compromise (IoC)
C.Attack Surface Reduction (ASR) rules
D.Device Control policies
AnswerB

Indicators of compromise in Microsoft Defender XDR let you define file hashes, IPs, URLs or commands that block or remediate across onboarded endpoints. Creating a command indicator enforces immediate blocking fleet-wide, satisfying the requirement to stop the PowerShell command on all devices.

Why this answer

Microsoft Defender XDR's Indicators of compromise (IoC) allow creating custom indicators to block file hashes, IPs, URLs, or commands across endpoints. Option A is wrong because Potentially Unwanted Application (PUA) protection targets unwanted software, not specific commands. Option C is wrong because Attack Surface Reduction (ASR) rules are designed to block common attack patterns, not ad-hoc commands.

Option D is wrong because Device Control policies manage peripheral devices like USB drives.

354
MCQmedium

You are investigating a potential malicious PowerShell execution in Microsoft Defender for Endpoint using this KQL query in Advanced Hunting. The query returns no results. What is the most likely cause?

A.The column names are incorrect; 'InitiatingProcessFileName' should be 'ParentProcessFileName'.
B.The table name should be 'DeviceProcessEvents' instead of 'DeviceEvents'.
C.The 'take 100' operator limits results to only 100, but the query may return results if more data exists.
D.The query uses 'ago(7d)' which may be too short for historical data.
AnswerB

The root cause is that the query queries the DeviceEvents table, which does not contain process creation events. Process creation events are stored in the DeviceProcessEvents table, part of the Advanced Hunting schema. Querying DeviceEvents will not return process creation data, even if the rest of the query is correct. Changing the table to DeviceProcessEvents resolves the issue.

Why this answer

The query uses the table 'DeviceEvents', which is incorrect for hunting process execution events. The correct table for process creation events in Microsoft Defender for Endpoint Advanced Hunting is 'DeviceProcessEvents'. 'DeviceEvents' contains other types of events (e.g., registry, file, network) but not process creation data, so the query returns no results.

Exam trap

The trap here is that candidates may focus on column names or time ranges, overlooking the fundamental table mismatch between 'DeviceEvents' and 'DeviceProcessEvents' in Microsoft Defender for Endpoint Advanced Hunting.

How to eliminate wrong answers

Option A is wrong because 'InitiatingProcessFileName' is a valid column in 'DeviceProcessEvents' and correctly refers to the parent process file name; renaming it to 'ParentProcessFileName' would not fix the table issue. Option C is wrong because 'take 100' limits output but does not prevent results from being returned if the query matches data; the issue is that no matching data exists due to the wrong table. Option D is wrong because 'ago(7d)' is a reasonable time range for investigating recent malicious activity; extending it would not help if the table itself is incorrect.

355
MCQmedium

Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). During an incident investigation, you identify that a user account has been exhibiting anomalous behavior, such as logging in from multiple countries within a short time. You need to determine if the account is compromised and take appropriate action. What should you do first?

A.Disable the user account in Microsoft Entra ID.
B.Review the UEBA insights for the user to understand the anomaly.
C.Create a custom automation rule in Sentinel to disable the account on similar alerts.
D.Reset the user's password immediately.
AnswerB

Reviewing the user's UEBA insights is the initial investigative step because Sentinel's UEBA engine has already modeled that user's historical behavior and established a baseline. These insights reveal what made the activity anomalous—for example, unexpected geo-location, new device, unusual hour, or abnormal access frequency—and provide a context-rich timeline for triage. This assessment lets the analyst validate the alert and decide on containment versus false positive before any corrective action is taken.

Why this answer

Before taking any disruptive action like disabling an account or resetting a password, the analyst must review the UEBA insights to validate whether the anomaly is a true compromise or a false positive (e.g., VPN usage, travel, or shared credentials). UEBA in Microsoft Sentinel correlates sign-in logs, Azure Activity, and other sources to surface risk scores and anomalous entities, giving the context needed for an informed decision.

Exam trap

SC-200 often tests the investigate-before-remediate principle, luring candidates into picking immediate containment actions (disable, reset) instead of first validating the anomaly with UEBA context.

How to eliminate wrong answers

Option A is wrong because disabling the account before validating the anomaly could disrupt legitimate business operations and destroy forensic evidence if the account is not actually compromised. Option C is wrong because creating an automation rule is a preventive/detection-engineering task, not the first investigative step during an active incident. Option D is wrong because resetting the password immediately is a remediation action that should follow confirmation of compromise, not precede it, and it may lock out a legitimate user.

356
MCQmedium

Your organization uses Microsoft Sentinel. You are responsible for responding to incidents. A new 'MFA Denied' incident is created from Microsoft Entra ID sign-in logs, indicating that a user in your organization had multiple MFA denials from a suspicious IP address (203.0.113.5). The user is a sales representative who frequently travels. The incident severity is Medium. The incident contains entities: user 'jsmith@contoso.com', IP address 203.0.113.5, and a device running Windows 11. You need to investigate and determine if this is a true positive. The user is currently on a business trip in Europe, but the sign-in attempts originated from an IP address in a different region. What should you do first?

A.Immediately reset the user's password and revoke sessions.
B.Contact the user to confirm if they attempted to sign in at the time of the alerts.
C.Block the suspicious IP address in the Conditional Access policy.
D.Isolate the user's device using Microsoft Defender for Endpoint.
AnswerB

Contacting the user to confirm if they attempted to sign in is the correct initial triage step. In Microsoft Sentinel, sign-in logs and failed attempts are often false positives triggered by user behavior, such as using a personal device or mistyping a password. This direct verification helps the analyst correlate the alert with the user's actual activity, geographic location, and device, enabling a risk-based decision without causing unnecessary disruption. It aligns with standard incident response procedures that emphasize validation before containment.

Why this answer

The first step in investigating a potential true positive is to contact the user to confirm if they attempted to sign in. This helps determine if the MFA denials were legitimate (e.g., user error) or malicious. It is a non-destructive action that gathers critical context.

Exam trap

SC-200 often tests incident response order; candidates may jump to containment actions without first verifying the incident, leading to unnecessary disruption.

How to eliminate wrong answers

Option A is wrong because immediately resetting the password and revoking sessions is a containment action that should be taken only after confirming a compromise; it could disrupt the user unnecessarily. Option C is wrong because blocking the IP in Conditional Access is a mitigation that might affect other users and should be done after investigation. Option D is wrong because isolating the device is a response action that is premature without evidence of compromise on the device.

357
MCQmedium

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. An incident is triggered: 'Lateral movement detected - pass-the-hash attack.' The incident includes alerts from Microsoft Defender for Identity (MDI) showing anomalous NTLM authentication attempts from a compromised workstation to multiple servers. The compromised workstation is a Windows 10 device. You need to contain the incident. Which of the following actions should you take FIRST?

A.Reset the krbtgt account password twice.
B.Isolate the compromised workstation using Microsoft Defender for Endpoint.
C.Disable NTLM authentication across the domain.
D.Reset passwords on all servers that received anomalous authentication attempts.
AnswerB

Isolating the compromised Windows 10 workstation via Microsoft Defender for Endpoint immediately severs the attacker's NTLM authentication path to the target servers, halting lateral movement. Containment precedes investigation, and endpoint isolation is the fastest action that stops pass-the-hash propagation.

Why this answer

The compromised Windows 10 workstation is the source of the pass-the-hash authentication attempts, so isolating it via Microsoft Defender for Endpoint immediately cuts off the attacker's ability to pivot to additional servers. This is the fastest containment action and preserves forensic evidence on the endpoint. Only after containment should the team proceed with credential resets and broader remediation.

Exam trap

SC-200 often tests the order of containment versus eradication — candidates pick disruptive domain-wide actions like krbtgt resets or NTLM disabling instead of the targeted, reversible endpoint isolation that stops the immediate threat.

How to eliminate wrong answers

Option A is wrong because resetting krbtgt twice is a Kerberos Golden Ticket remediation step, not the first response to pass-the-hash NTLM abuse, and it is highly disruptive. Option C is wrong because disabling NTLM domain-wide would break countless legacy applications and is not a proportionate first containment action. Option D is wrong because resetting passwords on all target servers is premature — the attacker's foothold is the workstation, and resetting server passwords without containing the source may not stop ongoing attacks and could cause widespread outages.

358
MCQmedium

Your organization uses Microsoft Sentinel with the Microsoft 365 Defender connector. You receive an incident indicating that a user's account was used to sign in from an unusual location (Russia) while the user is in the United States. The sign-in was successful and no MFA challenge was prompted because the user had a valid session. The incident severity is High. You need to respond immediately. What should you do first?

A.Block the IP address in the Conditional Access policy.
B.Revoke the user's session in Microsoft Entra ID.
C.Investigate the sign-in logs to determine if there are other compromised accounts.
D.Reset the user's password.
AnswerB

Revoking the user's session in Microsoft Entra ID immediately invalidates all refresh tokens for that user and forces re-authentication across all applications, terminating the attacker's active session without waiting for token expiry. This is the correct initial response in a Sentinel incident because it stops ongoing unauthorized access at the session layer, which is faster and more comprehensive than network-level or credential-based actions. It is a precise containment step that precedes password reset and further investigation.

Why this answer

Revoking the user's session in Microsoft Entra ID immediately terminates all active tokens and sessions, preventing the attacker from continuing to use the authenticated session. This is the fastest way to stop the ongoing compromise because the sign-in succeeded without MFA due to a valid session, and the attacker is already inside. Other actions like blocking IP or resetting password are slower or less direct in this scenario.

Exam trap

The trap here is that candidates often choose 'Reset the user's password' thinking it kills all sessions, but in Microsoft Entra ID, password reset does not revoke existing tokens or sessions unless combined with explicit token revocation or a 'Sign out everywhere' action.

How to eliminate wrong answers

Option A is wrong because blocking the IP address in a Conditional Access policy would only affect future sign-in attempts from that IP, not the currently active session that is already authenticated; the attacker could still use the existing session. Option C is wrong because investigating sign-in logs for other compromised accounts is a secondary step that does not immediately stop the current active compromise; it delays containment. Option D is wrong because resetting the user's password does not invalidate existing session tokens or refresh tokens in Microsoft Entra ID unless the user's tokens are explicitly revoked; the attacker could still use the active session until it expires.

359
Multi-Selectmedium

Which TWO are valid sources of evidence in a Microsoft Sentinel incident? (Choose two.)

Select 2 answers
A.Playbooks
B.Watchlists
C.Alerts
D.Bookmarks
E.Hunting queries
AnswersC, D

Alerts are generated by built-in analytics rules, Microsoft Defender services, or custom detections and represent a single security detection with associated entities, timestamps, and severity. When an incident is created, related alerts are automatically linked, and you can explicitly add alerts from the Evidence tab to support the investigation. Each alert carries rich metadata such as rule ID, tactic, technique, and triggered logic, making it a primary evidence source. Alerts are valid evidence because they capture the exact detection that initiated or expanded the incident response.

Why this answer

Alerts are a core evidence type in Microsoft Sentinel incidents because they represent the raw security findings that trigger an incident. When an alert is generated from a detection rule (e.g., analytics rule, fusion, or scheduled query), it is automatically linked to the incident as evidence, providing the initial context and supporting data for investigation.

Exam trap

The trap here is that candidates confuse 'sources of evidence' with 'tools used during investigation'—playbooks and hunting queries are actions or workflows, not static evidence records stored within the incident.

360
MCQeasy

A security analyst needs to contain a compromised device that is spreading malware in the network. The device is enrolled in Microsoft Intune and managed by Microsoft Defender for Endpoint. What is the fastest way to isolate the device from the network?

A.Disable the device in Microsoft Intune.
B.Use Microsoft Defender for Endpoint to initiate device isolation.
C.Perform a remote wipe of the device from Microsoft Intune.
D.Block the user's account in Microsoft Entra ID.
AnswerB

Device isolation in Microsoft Defender for Endpoint is a response action that blocks all inbound and outbound network traffic on the endpoint, except for communication with Defender for Endpoint cloud services. It preserves the sensor's ability to send telemetry and receive additional commands while effectively cutting off lateral movement and data exfiltration. This is the intended containment mechanism for a compromised device during incident response.

Why this answer

Microsoft Defender for Endpoint provides a dedicated 'Device isolation' action that immediately blocks all network traffic to and from the device while maintaining connectivity to the Defender service for management and monitoring. This is the fastest containment method as it can be triggered directly from the Defender portal without requiring additional configuration or user interaction.

Exam trap

The trap here is that candidates often confuse device isolation with account blocking or device wipe, not realizing that isolation is a network-level containment action that preserves the device's ability to communicate with the security management plane.

How to eliminate wrong answers

Option A is wrong because disabling a device in Microsoft Intune only prevents it from receiving new policies or apps; it does not cut existing network connections or stop active malware spread. Option C is wrong because a remote wipe deletes all data from the device, which is a destructive and slower process that does not instantly isolate the device from the network. Option D is wrong because blocking the user's account in Microsoft Entra ID prevents authentication but does not block the device's existing network traffic or stop malware already running on the device.

361
Multi-Selecteasy

Which TWO actions should a SOC analyst take immediately after confirming a ransomware incident in Microsoft Defender XDR?

Select 2 answers
A.Isolate affected devices from the network.
B.Begin restoring data from backups.
C.Disable all mailboxes in the organization.
D.Reset passwords for compromised accounts and enforce MFA.
E.Collect a full memory dump from each affected device.
AnswersA, D

Isolating affected devices at the switch or via VLAN segmentation immediately stops the ransomware's lateral movement over SMB, RDP, or WinRM, while keeping the device powered on so volatile data remains intact for later forensic acquisition. This containment measure is the top priority because a single connected endpoint can encrypt an entire network in minutes, including backups that are mounted as network drives.

Why this answer

Option A is correct because isolating affected devices in Microsoft Defender XDR (via the device isolation action) immediately stops lateral movement, command-and-control communication, and further encryption by cutting the host off from the network while preserving the ability to investigate remotely. Option D is correct because ransomware actors commonly obtain and reuse compromised credentials, so resetting passwords for affected accounts and enforcing MFA revokes the attacker's access and prevents re-entry or persistence through valid accounts. Option B is not an immediate containment action; restoring from backups should occur only after the threat is contained and the environment is verified clean, otherwise restored data can be re-encrypted.

Option C is too broad and destructive — disabling all mailboxes organization-wide is not a proportionate or standard ransomware response and would disrupt business without addressing the root compromise. Option E, collecting a full memory dump, is a forensic step that may be valuable later but is not one of the two immediate containment and credential-remediation actions required upon confirmation.

Exam trap

SC-200 often tests the confusion between containment actions and recovery or forensic actions, tempting candidates to choose backup restoration or memory collection as 'immediate' steps when they are actually later-phase activities.

362
MCQhard

Your organization's Microsoft Sentinel workspace ingests logs from multiple regions. During an incident, you need to search for a specific user's activity across all workspaces in a single query. What is the most efficient way to accomplish this?

A.Use a cross-workspace query with the workspace() expression.
B.Run separate queries in each workspace and combine results manually.
C.Create a new analytics rule that queries all workspaces.
D.Use the Microsoft Sentinel search feature with the workspace filter.
AnswerA

Cross-workspace queries using the workspace() expression allow you to reference multiple Log Analytics workspaces in a single KQL query, typically with the union operator. This is the most efficient way to search for threats across Microsoft Sentinel workspaces because it avoids data duplication and runs in one query request, returning merged results that can be further processed with KQL operators like project, where, or summarize.

Why this answer

The workspace() expression in Kusto Query Language (KQL) allows you to include data from multiple Log Analytics workspaces in a single query. By specifying the workspace ID or name within the expression, you can search across all relevant workspaces without needing to run separate queries or manually combine results. This is the most efficient method because it executes as a single query against the underlying Azure Data Explorer clusters, minimizing latency and administrative overhead.

Exam trap

The trap here is that candidates may confuse the workspace filter in the Sentinel search UI with the KQL workspace() expression, assuming the filter can query multiple workspaces when it actually only filters data within the currently selected workspace.

How to eliminate wrong answers

Option B is wrong because running separate queries in each workspace and manually combining results is inefficient, error-prone, and does not scale; it also prevents using unified KQL operators like union or join across workspaces. Option C is wrong because creating a new analytics rule is designed for ongoing detection and alerting, not for ad-hoc incident investigation; it would also require defining logic and scheduling, which is not suitable for a one-time search. Option D is wrong because the Microsoft Sentinel search feature with the workspace filter only queries the current workspace; it does not support cross-workspace queries natively, and the filter merely narrows results within that single workspace.

363
MCQmedium

You are investigating a Microsoft Sentinel incident involving a user who clicked a phishing link. The incident includes alerts from Microsoft Defender for Office 365. You need to identify if any other users received the same phishing email. What should you do?

A.Check the incident timeline for related alerts
B.Review the incident graph in Microsoft Sentinel
C.Run a KQL query in Advanced Hunting
D.Use the Threat Explorer in Microsoft Defender for Office 365
AnswerD

Threat Explorer (also known as Explorer) in Microsoft Defender for Office 365 is purpose-built for investigating email threats across all mailboxes. It allows searching by message ID, subject, sender, recipient, and delivery status, and can filter by detection technology, threat type, and campaign ID. This enables the analyst to quickly locate every copy of the phishing email, assess the blast radius, and take remediation actions directly.

Why this answer

Threat Explorer in Microsoft Defender for Office 365 is the purpose-built tool for investigating email threats at scale — it lets you pivot on the phishing campaign's sender, URL, or message ID and see every recipient who received the same message. This is exactly the 'who else got this email' question. Sentinel's incident graph and timeline show correlated alerts but do not provide the email-centric recipient enumeration that Threat Explorer does.

Exam trap

SC-200 often tests whether candidates pick the generic Sentinel tool (incident graph, timeline, or Advanced Hunting) when the scenario specifically requires email-centric recipient enumeration, which only Threat Explorer provides.

How to eliminate wrong answers

Option A is wrong because the incident timeline shows chronological alert and entity activity for the incident, not a list of all recipients of a specific phishing email. Option B is wrong because the incident graph visualizes relationships between entities (users, hosts, IPs) in the incident, but it does not enumerate email recipients across the tenant. Option C is wrong because a KQL query in Advanced Hunting could theoretically find related email events, but it is a generic hunting tool, not the purpose-built email investigation interface; Threat Explorer is the direct, intended answer for this scenario.

364
MCQeasy

During an incident response, you need to collect a forensic image of a Windows 10 device managed by Microsoft Intune. Which Microsoft Defender XDR feature should you use?

A.Microsoft Defender for Cloud Apps
B.Microsoft Purview eDiscovery
C.Microsoft Defender for Endpoint Live Response
D.Microsoft Sentinel
AnswerC

Microsoft Defender for Endpoint Live Response provides an interactive, remote shell on an onboarded endpoint, enabling incident responders to run built-in, PowerShell, or Python commands. It supports collecting files (collectfile), viewing processes and network connections, and running forensic scripts to extract memory, registry, or disk artifacts. This is the correct tool for live forensic data collection directly from the machine, using the Defender for Endpoint sensor as the transport.

Why this answer

Microsoft Defender for Endpoint Live Response (Option C) is the correct feature because it provides a remote shell connection to a Windows 10 device, allowing an incident responder to collect a forensic image by running commands such as `getfile` or `putfile` to acquire disk or memory artifacts. This capability is specifically designed for live incident response on Intune-managed endpoints, enabling acquisition of forensic data without requiring physical access or pre-staged imaging tools.

Exam trap

The trap here is that candidates confuse the forensic imaging requirement with a general log collection or eDiscovery tool, overlooking that Live Response is the only option that provides direct, interactive remote access to a managed endpoint for acquiring disk or memory artifacts during an active incident.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) focused on shadow IT discovery and SaaS app governance, not on collecting forensic images from managed Windows 10 endpoints. Option B is wrong because Microsoft Purview eDiscovery is designed for legal discovery of content in Microsoft 365 (e.g., Exchange, SharePoint, Teams), not for live forensic imaging of a device's disk or memory. Option D is wrong because Microsoft Sentinel is a SIEM/SOAR platform that ingests and analyzes security logs from various sources, but it does not have native capabilities to remotely execute forensic image collection commands on a Windows 10 endpoint.

365
MCQeasy

Your team uses Microsoft Sentinel to manage incidents. You want to automatically assign incidents with a severity of 'High' to the Tier 2 security team. Which feature should you configure?

A.Playbook
B.Analytics rule
C.Automation rule
D.Workbook
AnswerC

Automation rules in Microsoft Sentinel trigger on incident creation and can set owner, status and severity automatically. Configuring a rule that matches severity equals High and assigns the Tier 2 team satisfies the automatic assignment requirement without manual triage.

Why this answer

Automation rules in Microsoft Sentinel are designed to perform lightweight incident-level orchestration such as assigning owners, changing severity, adding tags, or closing incidents based on conditions. To auto-assign High-severity incidents to Tier 2, you create an automation rule with a condition on severity and an action to assign the owner. This is exactly the native, no-code mechanism for incident triage routing.

Exam trap

SC-200 often tests the confusion between automation rules (incident orchestration: assign, tag, close) and playbooks (multi-step remediation workflows), so candidates pick Playbook when the task is simple incident assignment.

How to eliminate wrong answers

Option A is wrong because a playbook is a Logic Apps workflow triggered by an automation rule or manually, used for complex multi-step remediation (enrichment, ticketing, containment) — it is not the primary mechanism for simple owner assignment. Option B is wrong because an analytics rule generates alerts and incidents from log queries; it detects threats but does not perform post-creation incident management like assignment. Option D is wrong because a workbook is a visualization/reporting canvas for querying and displaying data, with no incident-handling capability.

366
Multi-Selecthard

A security analyst is investigating a potential data exfiltration incident in Microsoft Sentinel. The analyst needs to identify which users may have been compromised. Which THREE data sources should be queried to gather the most relevant evidence?

Select 3 answers
A.WindowsEvent from Microsoft Defender for Endpoint.
B.AzureActivity from Azure Monitor.
C.SigninLogs and AuditLogs from Microsoft Entra ID.
D.OfficeActivity from Microsoft 365.
E.CloudAppEvents from Microsoft Defender for Cloud Apps.
AnswersC, D, E

SigninLogs records authentication events and AuditLogs captures directory changes such as role assignments, consent grants and credential additions. Together they reveal anomalous sign-ins and privilege escalation tied to compromised accounts, satisfying the need to identify which users were affected.

Why this answer

SigninLogs and AuditLogs from Microsoft Entra ID (C) are essential because SigninLogs reveal authentication anomalies such as impossible-travel or risky sign-ins tied to compromised accounts, while AuditLogs capture directory changes like new credentials or permission grants made by an attacker. OfficeActivity from Microsoft 365 (D) is correct because it records user and admin actions across Exchange, SharePoint, OneDrive, and Teams, exposing mail-forwarding rules, mass downloads, or file-sharing activity typical of exfiltration. CloudAppEvents from Microsoft Defender for Cloud Apps (E) is correct because it provides granular SaaS activity, including file downloads, uploads, and sharing events across connected cloud apps that reveal data movement.

WindowsEvent from Defender for Endpoint (A) is endpoint telemetry focused on device-level process and file events, not user identity or cloud-service activity, so it is less directly relevant to identifying compromised users. AzureActivity from Azure Monitor (B) logs control-plane operations on Azure resources (e.g., role assignments, resource deployments) and does not capture the identity, mail, or SaaS activity needed here.

367
Multi-Selecteasy

Which THREE steps are part of the incident response process when using Microsoft Sentinel?

Select 3 answers
A.Identify the incident by creating an analytics rule.
B.Investigate the incident using hunting queries and entity timelines.
C.Remediate the incident by running playbooks or manual actions.
D.Report the incident to the security team via email.
E.Triage the incident to determine severity.
AnswersB, C, E

Investigation is the phase where the analyst uses threat hunting queries, entity timelines, and the investigation graph to reconstruct the attack chain and determine the full scope of compromise. This step involves correlating alerts, user sign-in data, and network artifacts to identify the root cause, affected assets, and potential data loss. In Microsoft Sentinel, a KQL query might pivot on a compromised entity to reveal lateral movement, while the entity timeline provides a chronological view of activities that contextualizes each alert.

Why this answer

Investigating an incident using hunting queries and entity timelines is a core step in the Microsoft Sentinel incident response process. After an incident is created, analysts use KQL-based hunting queries to proactively search for related threats and leverage entity timelines to visualize the sequence of events and entity interactions, which is essential for understanding the scope and impact of the incident.

Exam trap

The trap here is that candidates confuse the proactive detection step of creating analytics rules (which generates incidents) with the reactive incident response step of triaging and investigating those incidents, leading them to incorrectly select Option A as part of the response process.

368
MCQhard

Wide World Importers uses Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Purview for data loss prevention (DLP). An incident is generated: 'DLP policy violation - sensitive data shared externally.' The incident shows that a user shared a document containing credit card numbers via SharePoint Online with an external guest. The user is a finance department employee. You need to respond to the incident. The organization wants to minimize business disruption while protecting data. Which of the following is the BEST immediate action?

A.Delete the document from SharePoint Online.
B.Modify the DLP policy to block sharing of credit card numbers.
C.Remove the external guest's access to the document in SharePoint Online.
D.Disable the user's account in Microsoft Entra ID and investigate.
AnswerC

Removing the external guest's access to the document in SharePoint Online is the correct containment step because it directly targets the specific sharing permission that caused the incident. This action revokes the guest's ability to view or download the file while preserving the document for investigation and allowing internal users with existing permissions to continue working. It is a granular, least-privilege response that minimizes disruption and aligns with Microsoft incident response guidance for external sharing.

Why this answer

Removing the external guest's access to the document stops data exposure without affecting the user's work. Option A is wrong: disabling the user prevents all work and may be too drastic. Option B is wrong: deleting the document destroys evidence.

Option D is wrong: DLP policy change takes time and does not stop current exposure.

369
MCQhard

You are a SOC analyst at Contoso Ltd. The company uses Microsoft Sentinel and Microsoft Defender XDR. A high-severity incident is generated from a Sentinel analytics rule that detects multiple failed logins followed by a successful login from a geographically unusual location for a user. The incident includes an alert from Microsoft Defender for Identity indicating a possible brute-force attack. The user's account is a privileged administrator. Your organization has strict compliance requirements: any privileged account compromise must be contained within 15 minutes of detection. You have the following tools available: Microsoft Entra ID with Privileged Identity Management (PIM), Microsoft Defender for Cloud Apps, and Microsoft 365 Defender automation rules. The incident is now 5 minutes old. What should you do to meet the compliance requirement?

A.Create an automation rule in Microsoft 365 Defender to alert the security team.
B.Disable the user account in Microsoft Entra ID immediately.
C.Create a conditional access policy to block the user's sign-ins.
D.Activate PIM and remove the user's role assignments.
AnswerB

Disabling the user account in Microsoft Entra ID is the fastest and most direct containment action. Setting the account's AccountEnabled property to false immediately prevents new token issuance and triggers revocation of the user's existing refresh tokens, effectively cutting off access within seconds. This can be done in the Entra admin center or via Microsoft Graph, and it is the recommended first step for a confirmed account compromise because it stops the attacker regardless of which app or resource they are targeting.

Why this answer

Disabling the account in Microsoft Entra ID immediately is the fastest, most direct containment action for a confirmed privileged-account compromise. It revokes the account's ability to authenticate and blocks all new sign-ins and token issuance at the identity provider level, satisfying the 15-minute containment SLA. Since the incident is only 5 minutes old and involves a privileged admin, immediate account disablement is the correct incident-response action rather than a detective or policy-based control.

Exam trap

SC-200 often tests the difference between detective controls (alerts, automation rules) and true containment actions (disable account, revoke sessions), tricking candidates into choosing policy-based or notification-based options that do not meet a strict time-bound SLA.

How to eliminate wrong answers

Option A is wrong because creating an automation rule to alert the security team is a notification action, not a containment action — it does nothing to stop the attacker and wastes the remaining 10 minutes of the SLA. Option C is wrong because a Conditional Access policy is a preventive control that requires policy design, testing, and propagation time; it also may not immediately revoke existing sessions or tokens, so it cannot guarantee containment within 15 minutes. Option D is wrong because activating PIM and removing role assignments addresses privilege scope but does not disable the underlying account — the attacker could still authenticate and the account remains active, and PIM changes may take time to propagate.

370
MCQeasy

During a ransomware incident, you need to prevent the encryption of files in SharePoint Online and OneDrive for Business. You have already identified the compromised user account. What should you do?

A.Disable external sharing for SharePoint Online
B.Lock the compromised user account in Microsoft Entra ID
C.Delete the compromised user's OneDrive files
D.Apply a retention policy to all SharePoint sites
AnswerB

Locking the compromised account in Microsoft Entra ID immediately invalidates its refresh tokens, halting further authenticated access to SharePoint Online and OneDrive for Business. This directly satisfies the stem's requirement to stop ongoing file encryption, since ransomware encrypts through the hijacked session's existing permissions rather than exploiting a separate vulnerability.

Why this answer

Locking the compromised user account in Microsoft Entra ID immediately revokes the attacker's access to SharePoint Online and OneDrive for Business, preventing further file encryption. Option A is incorrect because disabling external sharing does not stop an already authenticated user from encrypting files. Option C is incorrect because deleting the user's OneDrive files does not prevent the attacker from encrypting other files.

Option D is incorrect because a retention policy only protects against deletion or modification, not encryption.

371
MCQhard

You are investigating an incident where a user reported receiving a suspicious email with a malicious attachment. Microsoft Defender for Office 365 did not block it. The email originated from a known malicious sender domain. What configuration should you check first?

A.User-reported message settings
B.SPF record for the sender domain
C.Safe Attachments policy
D.Anti-phishing policy in Microsoft Defender for Office 365
AnswerD

Anti-phishing policy in Microsoft Defender for Office 365 is the correct control because it provides domain impersonation protection and spoof intelligence that can identify and block messages from known malicious domains or those mimicking protected senders. It leverages threat intelligence and real-time reputation to enforce blocking, quarantine, or redirect to Junk before delivery to the user's inbox. This policy is specifically designed to combat phishing and impersonation, which aligns with the reported incident involving a suspicious email.

Why this answer

The anti-phishing policy in Microsoft Defender for Office 365 is the primary configuration that evaluates sender reputation, impersonation attempts, and spoof intelligence. Since the email originated from a known malicious sender domain and was not blocked, the anti-phishing policy's spoof settings or impersonation protection may be misconfigured or not applied to the affected user. This policy directly controls how Defender handles emails from malicious domains, making it the first place to check.

Exam trap

The trap here is that candidates confuse the anti-phishing policy with Safe Attachments or SPF records, but the anti-phishing policy is the correct first check because it directly handles domain-based threats and spoofing, while Safe Attachments focuses on file analysis and SPF is a DNS record not configurable within Defender.

How to eliminate wrong answers

Option A is wrong because user-reported message settings control how users submit emails for analysis (e.g., via the Report Message add-in), not how Defender blocks malicious emails at the transport layer. Option B is wrong because the SPF record for the sender domain is a DNS record that the recipient's mail server checks, but it is not a configuration within Microsoft Defender for Office 365 that you can adjust; you can only configure SPF handling in the anti-phishing policy. Option C is wrong because Safe Attachments policy specifically handles attachments by detonating them in a sandbox, but the question states the email had a malicious attachment that was not blocked, and the primary issue is the sender domain being known malicious, which is addressed by anti-phishing policies, not attachment scanning.

372
MCQeasy

Refer to the exhibit. You are configuring a Microsoft Sentinel scheduled analytics rule with the above incident creation settings. What is the effect of setting 'groupingConfiguration.enabled' to false?

A.Alerts will be suppressed for 5 minutes
B.The rule will run every 5 minutes
C.No incidents will be created
D.Each alert will generate a separate incident
AnswerD

With groupingConfiguration.enabled set to false, Sentinel disables alert grouping, so each individual alert raised by the rule creates its own incident rather than being merged into a single incident. This satisfies the scenario's requirement for one incident per alert.

Why this answer

When groupingConfiguration.enabled is set to false in a Microsoft Sentinel scheduled analytics rule, the alert-grouping logic is disabled entirely. This means Sentinel will not bundle multiple alerts from a single rule run into one incident; instead, every individual alert generated by the query produces its own distinct incident. This is useful when each alert requires separate triage or when alerts represent unrelated events that should not be merged.

Exam trap

SC-200 often tests the distinction between alert grouping, alert suppression, and rule frequency, causing candidates to confuse groupingConfiguration.enabled with suppression or scheduling settings.

How to eliminate wrong answers

Option A is wrong because alert suppression is controlled by the rule's 'suppression' settings (suppressionEnabled, suppressionDuration), not by groupingConfiguration.enabled; setting grouping to false does not suppress alerts. Option B is wrong because the rule's execution frequency is defined by the 'queryPeriod' and 'queryFrequency' fields in the scheduled rule definition, not by groupingConfiguration. Option C is wrong because disabling grouping does not prevent incident creation — it actually increases incident count by creating one incident per alert rather than merging them.

373
MCQeasy

You are investigating a low-severity incident in Microsoft Sentinel where a user reported receiving a phishing email. The email was not blocked by the email security solution. The user did not click any links. What should you do first?

A.Delete the phishing email from the user's inbox
B.Report the email for analysis using the Microsoft 365 Defender portal
C.Reset the user's password as a precaution
D.Isolate the user's device from the network
AnswerB

Reporting the email via the Microsoft 365 Defender portal (using the 'Report a message' or admin submission workflow) submits the original email, including its headers and attachments, to Microsoft's automated detonation and analysis systems. This enables the security team to extract actionable IOCs, update tenant-level block and allow lists, and contribute to global filtering improvements—directly addressing the low-severity phishing incident without destroying evidence. It is the correct initial response because it simultaneously preserves the artifact and enhances email security posture.

Why this answer

The first step is to report the email for analysis using the Microsoft 365 Defender portal. Since the email was not blocked and the user did not click any links, the immediate priority is to submit the message to Microsoft for analysis (via the Submissions page or the Report button) so that detections can be tuned and the sender/URLs can be blocked if malicious. This preserves evidence and improves organizational protection before taking remediation actions.

Exam trap

SC-200 often tests the order of operations in incident response — candidates jump to remediation (delete, reset, isolate) instead of the correct first step of analysis/reporting, especially when the user did not click.

How to eliminate wrong answers

Option A is wrong because deleting the email from the inbox is a remediation step that destroys evidence needed for analysis and does not address the root cause (why it bypassed filtering); it should come after analysis, not first. Option C is wrong because resetting the user's password is unnecessary — the user did not click any links, so there is no indication of credential compromise, and password resets are disruptive. Option D is wrong because isolating the device is a containment action for a confirmed endpoint compromise; with no click and no evidence of execution, it is premature and overly disruptive.

374
Multi-Selecthard

During a security incident, a Microsoft Sentinel analytics rule generated an alert for a suspicious sign-in from an unusual location. The incident involves a user whose account has been compromised. The security team needs to take immediate actions to remediate and prevent further damage. Which THREE actions should the security team prioritize?

Select 3 answers
A.Reset the user's password
B.Revoke the user's session tokens
C.Review audit logs for all users
D.Raise the user's risk level in Identity Protection
E.Disable the user account in Microsoft Entra ID
AnswersA, B, E

Resetting the user's password in Microsoft Entra ID is a direct containment action because it invalidates the previously valid credential. If the attacker gained access via a phished or stolen password, this immediately prevents them from using that secret for interactive sign-in. It is a focused remediation step that should be performed as soon as the user is confirmed as a legitimate account holder, forcing them to create a new password on next sign-in.

Why this answer

Resetting the user's password (A) is a critical immediate step because it invalidates the current compromised credentials, preventing the attacker from using the known password to authenticate again. In Microsoft Entra ID, a password reset forces the user to create a new credential, which the attacker does not possess, effectively cutting off one of the most common attack vectors.

Exam trap

The trap here is that candidates may confuse detection actions (like raising risk level) with containment actions, or mistakenly think reviewing all audit logs is a priority step when the focus should be on immediate remediation of the compromised account.

375
Multi-Selectmedium

Which TWO actions should you take when handling a confirmed ransomware incident in an environment protected by Microsoft Defender for Endpoint?

Select 2 answers
A.Block the ransomware file hash using threat intelligence indicators in Microsoft Defender.
B.Initiate device isolation from the Microsoft Defender for Endpoint console.
C.Disable Windows Defender real-time protection.
D.Submit the ransomware sample to Microsoft for analysis.
E.Reimage all affected servers immediately.
AnswersA, B

Blocking the ransomware executable's SHA-256 hash via Microsoft Defender for Endpoint custom indicators immediately prevents that specific binary from running on any monitored endpoint, independent of signature updates. Because the hash is a known-bad IOC, defining it as a block indicator enforces a deny action at the kernel and network layers, halting execution on already-uninfected devices and stopping the ransomware from propagating through mapped shares.

Why this answer

Blocking the ransomware file hash via threat intelligence indicators in Microsoft Defender for Endpoint (MDE) immediately prevents further execution of that known malicious file across all endpoints in the environment, leveraging the built-in TI indicator feature. Option B is correct because initiating device isolation from the MDE console disconnects the affected device from the network while maintaining connectivity to the MDE service, containing the spread of ransomware without losing visibility or control.

Exam trap

The trap here is that candidates may confuse post-incident actions (like submitting samples or reimaging) with immediate containment actions, or mistakenly think disabling real-time protection is a valid response instead of understanding that isolation and indicator blocking are the primary containment steps in MDE.

← PreviousPage 5 of 5 · 375 questions total

Ready to test yourself?

Try a timed practice session using only Respond to security incidents questions.