Courseiva
← Back to Microsoft Security Operations Analyst SC-200 questions

Scenario-based practice

Hard Difficulty Questions

Practise Microsoft Security Operations Analyst SC-200 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
SC-200
exam code
Microsoft
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SC-200 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Your organization uses Microsoft 365 Defender. An incident is created for a user who received a phishing email that contained a link to a malicious website. The user clicked the link but did not enter any credentials. The incident includes the alert 'Phishing delivered' from Microsoft Defender for Office 365. You need to remediate the incident and prevent future occurrences. The user is in the Finance department and frequently receives emails from external vendors. What is the best course of action?

Question 2hardmultiple choice
Full question →

A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect a possible password spray attack. The rule must trigger when a single source IP address has more than 10 failed logon attempts on different user accounts within a 30-minute window. The analyst writes a KQL query starting with 'SigninLogs | where ResultType == 50057' (failed logon). Which operator should the analyst use to group events by source IP and count distinct user accounts, then filter for counts above 10?

Question 3hardmultiple choice
Full question →

A SOC team wants to use Microsoft Sentinel to detect when a user logs in from a new country not previously seen for that user. They have the SigninLogs table. Which KQL function is most appropriate to build this anomaly detection?

Question 4hardmultiple choice
Full question →

Wide World Importers uses Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Purview for data loss prevention (DLP). An incident is generated: 'DLP policy violation - sensitive data shared externally.' The incident shows that a user shared a document containing credit card numbers via SharePoint Online with an external guest. The user is a finance department employee. You need to respond to the incident. The organization wants to minimize business disruption while protecting data. Which of the following is the BEST immediate action?

Question 5hardmultiple choice
Full question →

Your organization uses Microsoft Defender XDR for threat detection and response. The security team wants to automatically isolate a compromised device when a specific malware alert is triggered, but only if the device is not a critical server. What is the most efficient way to achieve this?

Question 6hardmultiple choice
Read the full Ansible explanation →

A security analyst receives a high-severity incident in Microsoft Sentinel for a user who is suspected of lateral movement. The analyst wants to automatically run a playbook that isolates the user's machine and disables their account when such an incident is created. What is the most efficient way to achieve this?

Question 7hardmultiple choice
Full question →

Your security team uses Microsoft Defender XDR (formerly Microsoft 365 Defender) to investigate incidents. You notice that some alerts from Microsoft Defender for Endpoint are not being automatically correlated into incidents as expected. You have confirmed that the relevant alert sources are enabled in the Microsoft Defender XDR portal. What is the most likely cause?

Question 8hardmulti select
Full question →

During a ransomware incident, Microsoft Defender for Cloud Apps alerts indicate that a user is uploading large volumes of data to an external cloud storage provider not approved by your organization. Which two actions should you take first? (Choose two.)

Question 9hardmultiple choice
Full question →

You are investigating an incident where a user reported receiving a suspicious email with a malicious attachment. Microsoft Defender for Office 365 did not block it. The email originated from a known malicious sender domain. What configuration should you check first?

Question 10hardmultiple choice
Full question →

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You suspect a compromised on-premises admin account that has been used to modify security groups. You want to quickly contain the threat. What should you do first?

Question 11hardmultiple choice
Full question →

As a threat hunter at Contoso, you are investigating a potential advanced persistent threat (APT) that may have compromised multiple Azure subscriptions. You have Microsoft Defender for Cloud enabled and Microsoft Sentinel collecting data from all subscriptions. You suspect the attacker is using Azure Resource Manager operations to create malicious resources. You need to create a hunting query that identifies anomalous Azure management operations, specifically focusing on operations that create new resources (e.g., virtual machines, storage accounts) from unusual IP addresses or at unusual times. Which approach should you take?

Question 12hardmulti select
Full question →

A security analyst is investigating a sophisticated attack where an attacker used a compromised account to send a phishing email. The analyst wants to correlate the email event with the subsequent sign-in activity from the same sender's mailbox using Advanced Hunting. Which two tables should the analyst join to link the email sender to the sign-in IP address?

Question 13hardmulti select
Full question →

Which THREE of the following are recommended practices for creating effective threat hunting queries in Microsoft Sentinel? (Select three.)

Question 14hardmultiple choice
Full question →

You are reviewing a hunting query. What is the primary purpose of this query?

Exhibit

Refer to the exhibit.
```kusto
// KQL query in Microsoft Sentinel hunting
let TargetUsers = dynamic(["admin@contoso.com", "user1@contoso.com"]);
SigninLogs
| where TimeGenerated > ago(7d)
| where UserPrincipalName in (TargetUsers)
| where RiskLevelDuringSignIn == "medium"
| project TimeGenerated, UserPrincipalName, IPAddress, RiskLevelDuringSignIn
| join kind=leftouter (
    AADServicePrincipalSignInLogs
    | where TimeGenerated > ago(7d)
    | project ServicePrincipalName, IPAddress
) on IPAddress
| summarize Count = count() by UserPrincipalName
| where Count > 5
```
Question 15hardmultiple choice
Read the full Ansible explanation →

You are configuring Microsoft Sentinel to use automation rules for incident response. You need to ensure that when an incident is created with a severity of High, a playbook is triggered to isolate the affected device. However, the playbook should not run if the incident is created by a specific analytics rule (RuleID: '12345'). What is the best way to implement this?

Question 16hardmulti select
Full question →

Which THREE data sources can be used in Microsoft Sentinel for threat hunting to detect unusual authentication patterns? (Choose three.)

Question 17hardmultiple choice
Full question →

A threat hunter is analyzing a potential advanced persistent threat (APT) that uses living-off-the-land binaries (LOLBins) like certutil.exe to download payloads. The hunter wants to find instances where certutil.exe was used to download files from the internet in the last week. Which KQL query in Microsoft Sentinel would be most effective?

Question 18hardmultiple choice
Full question →

A threat hunter is investigating a potential data exfiltration incident. The hunter suspects that a user is using an unauthorized cloud storage service. Which Microsoft Defender for Cloud Apps signal would be most useful to detect this activity?

Question 19hardmultiple choice
Full question →

Refer to the exhibit. You are hunting for PowerShell used to launch cmd.exe. The query is intended to find cmd.exe processes that occurred after the first PowerShell execution on the same device. However, it returns no results. What is the most likely issue?

Exhibit

Refer to the exhibit.

```kql
let FirstSeen = (DeviceProcessEvents
| where FileName == "powershell.exe"
| summarize min(Timestamp));
DeviceProcessEvents
| where Timestamp between (FirstSeen .. ago(0d))
| where FileName == "cmd.exe"
| join kind=leftsemi (
    DeviceProcessEvents
    | where FileName == "powershell.exe"
    | project DeviceId, ParentProcessFileName
) on DeviceId
| project Timestamp, DeviceName, FileName, ParentProcessFileName
```
Question 20hardmultiple choice
Full question →

Your organization uses Microsoft Sentinel and has several analytics rules that generate incidents from various data sources. The SOC team is overwhelmed by the number of incidents. You need to implement a triage system that automatically assigns incidents to different analysts based on the incident's tactics and severity. You also want to send a notification to the assigned analyst via Teams. What should you do?

These SC-200 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style SC-200 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.