Courseiva
← Back to Microsoft Security Operations Analyst SC-200 questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Microsoft Security Operations Analyst SC-200 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
SC-200
exam code
Microsoft
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SC-200 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

Which THREE are valid incident classification options in Microsoft Sentinel?

Question 2hardmulti select
Full question →

During a ransomware incident, Microsoft Defender for Cloud Apps alerts indicate that a user is uploading large volumes of data to an external cloud storage provider not approved by your organization. Which two actions should you take first? (Choose two.)

Question 3easymulti select
Full question →

Which THREE components are part of Microsoft Defender XDR? (Select three.)

Question 4hardmulti select
Full question →

Which THREE of the following are recommended practices for creating effective threat hunting queries in Microsoft Sentinel? (Select three.)

Question 5mediummulti select
Full question →

Which TWO conditions must be met to enable Microsoft Sentinel UEBA? (Choose two.)

Question 6hardmulti select
Full question →

Which THREE data sources can be used in Microsoft Sentinel for threat hunting to detect unusual authentication patterns? (Choose three.)

Question 7mediummulti select
Full question →

Which THREE techniques are commonly used in Microsoft Sentinel threat hunting to identify command and control (C2) communication? (Select THREE.)

Question 8mediummulti select
Full question →

Which THREE of the following are key components of a successful threat hunting program in a Microsoft Defender XDR environment?

Question 9mediummulti select
Full question →

Which TWO actions should you take when handling a confirmed ransomware incident in an environment protected by Microsoft Defender for Endpoint?

Question 10easymulti select
Full question →

Which TWO are supported data sources for Microsoft Sentinel?

Question 11easymulti select
Full question →

Which TWO data sources are natively supported by Microsoft Sentinel for ingesting security events? (Choose two.)

Question 12hardmulti select
Full question →

Which THREE actions should be taken when a phishing attack is detected in Microsoft Defender XDR?

Question 13hardmulti select
Full question →

Which THREE components are required to use Microsoft Sentinel's automation rules to automatically respond to incidents?

Question 14mediummulti select
Read the full Ansible explanation →

A SOC analyst is configuring a Microsoft Sentinel automation rule to trigger a playbook when an incident is created. The playbook should only run if the incident severity is 'High' and the incident title contains 'Phishing'. Which two conditions should the analyst add to the automation rule? (Select all that apply.) (Choose 2.)

Question 15mediummulti select
Full question →

Your organization uses Microsoft Sentinel. You have been asked to configure automated responses to security incidents. Which TWO of the following can be used to automate responses in Microsoft Sentinel?

Question 16hardmulti select
Full question →

A Microsoft Sentinel scheduled analytics rule detects impossible travel but creates too many duplicate incidents for the same user within a short period. Which two rule settings should you tune? (Choose 2.)

Question 17hardmulti select
Full question →

Your Microsoft Defender XDR environment has an advanced hunting query that returns devices potentially affected by a known vulnerability. You want to create a custom detection rule that triggers an alert when more than 10 devices are affected. Which THREE steps are required?

Question 18mediummulti select
Full question →

A SOC analyst is building a scheduled analytics rule in Microsoft Sentinel to detect when a user is added to a privileged Microsoft Entra ID role (e.g., Global Administrator). Which two tables must be included in the KQL query to capture the role assignment event and to retrieve user details? (Choose 2.)

Question 19hardmulti select
Full question →

Which THREE data sources in Microsoft Sentinel can be used to detect lateral movement in a network? (Choose three.)

Question 20mediummulti select
Full question →

Which TWO actions require the Global Administrator role in Microsoft 365?

These SC-200 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style SC-200 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.