Courseiva
Free · No account needed · No credit card

Microsoft Security Operations Analyst SC-200 Practice Test

1,303 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 120 min
Pass mark: 700/1000

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

Q1Respond to security incidentsmedium
Full explanation →

Your organization uses Microsoft Sentinel with Microsoft Defender XDR integrated. A critical incident has been raised involving a user account that was used to access a confidential SharePoint site from an unusual location at 2:00 AM. The incident includes alerts from Microsoft Defender for Cloud Apps, Microsoft Defender for Identity, and Microsoft Defender for Office 365. The analyst needs to contain the incident, investigate the scope, and begin remediation. The environment has the following: Microsoft Entra ID with conditional access policies, Microsoft Intune for device management, and Microsoft Defender for Endpoint on all devices. The analyst has identified the user account and the device used. Which course of action should the analyst take first?

ACreate a conditional access policy to block the user.
BIsolate the user's device using Microsoft Defender for Endpoint.
CRun a KQL query to find all resources accessed by the user.
Disable the user account in Microsoft Entra ID and revoke all sessions.Correct

Disabling the user account in Microsoft Entra ID and revoking all sessions is the immediate containment step because it stops the compromised account from being used for any further access, including the suspicious SharePoint access and any lateral movement. This action directly …Read full explanation

Q2Manage a security operations environmentmedium
Full explanation →

Refer to the exhibit. You are creating a scheduled analytics rule in Microsoft Sentinel using the ARM template snippet. The rule runs every 5 minutes and queries the last 5 minutes of data. The rule is not generating alerts even though malware detections are occurring. What is the most likely issue?

AThe queryPeriod and queryFrequency are the same, causing overlapping windows.
BThe triggerThreshold is set to 0, which should always trigger.
CThe ARM template is missing the required 'kind' property.
The table DeviceEvents is not ingested into the Log Analytics workspace.Correct

DeviceEvents is a table from Microsoft Defender for Endpoint, but it is not automatically available in Microsoft Sentinel's Log Analytics workspace. The data connector for Microsoft Defender for Endpoint must be configured and the table must be mapped to Sentinel's workspace. Wit…Read full explanation

Q3Manage a security operations environmenthard
Full explanation →

Refer to the exhibit. You are analyzing a KQL query used in a custom detection rule in Microsoft Defender XDR. The rule is supposed to detect devices where a parent process launched more than 10 instances of PowerShell or cmd.exe in the last 7 days. However, the query returns no results even though you know such activity exists. What is the most likely reason?

AThe 'extend' line creates a new column that is not used in the subsequent summarize, causing the query to not group by parent process as intended.
BThe 'summarize' operator cannot be used with 'count()' in this context.
CThe 'where' clause filters out all events because the FileName list is incorrect.
The 'extend' line uses a column that does not exist in the DeviceProcessEvents schema.Correct

The 'extend' line references a column named 'ParentProcessFileName' that does not exist in the DeviceProcessEvents schema. The actual column is 'InitiatingProcessFileName' (or 'ParentProcessName' in some schemas). Since the column doesn't exist, the 'extend' operation fails silen…Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All SC-200 questionsSC-200 exam guideStudy guidePractice by domain