Courseiva
← Back to Microsoft Security Operations Analyst SC-200 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Microsoft Security Operations Analyst SC-200 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
SC-200
exam code
Microsoft
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related SC-200 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymultiple choice
Full question →

You are reviewing the automation rule configuration shown in the exhibit. What is the purpose of this rule?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Malware Alert Auto-Isolate",
    "triggers": [
      {
        "type": "Incident",
        "conditions": [
          {
            "condition": "AlertTitle",
            "operator": "Contains",
            "value": "Malware"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "RunPlaybook",
        "playbookName": "IsolateDevice"
      }
    ]
  }
}
```
Question 2mediummultiple choice
Full question →

Refer to the exhibit. You are reviewing a KQL query used in a Microsoft Sentinel scheduled analytics rule. What is the primary purpose of this query?

Exhibit

Refer to the exhibit.
```kusto
SecurityAlert
| where TimeGenerated > ago(7d)
| where AlertName == "Suspicious process execution"
| extend Entities = parse_json(Entities)
| mv-expand Entities
| where Entities.Type == "account"
| project AccountUpn = Entities.Upn, AlertName, TimeGenerated
| summarize Count = count() by AccountUpn
| where Count > 5
```
Question 3easymultiple choice
Full question →

Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. What is the effect of this rule?

Exhibit

Refer to the exhibit.
{
  "properties": {
    "displayName": "SOC Automation Rule",
    "order": 1,
    "triggeringLogic": {
      "triggersOn": "Incidents",
      "triggersWhen": "Created",
      "conditions": [
        {
          "property": "Status",
          "operator": "Equals",
          "value": "New"
        }
      ]
    },
    "actions": [
      {
        "actionType": "ChangeStatus",
        "status": "Active"
      }
    ]
  }
}
Question 4easymultiple choice
Full question →

The exhibit shows the output of a Microsoft Defender for Endpoint API call to get machine information. What does the isolationStatus value indicate?

Exhibit

Refer to the exhibit.

```json
{
  "value": [
    {
      "id": "12345",
      "machineName": "PC-001",
      "isolationStatus": "Isolated",
      "isolationState": "Isolated",
      "healthStatus": "Healthy"
    }
  ]
}
```
Question 5mediummultiple choice
Read the full Ansible explanation →

The exhibit shows a partial playbook trigger configuration in Microsoft Sentinel. When will this playbook be triggered?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Block Malicious IP",
    "description": "Playbook to block IP in firewall",
    "triggers": [
      {
        "type": "Microsoft.SecurityInsights/incidents",
        "conditions": [
          {
            "property": "Severity",
            "operator": "Equals",
            "value": "High"
          }
        ]
      }
    ],
    "actions": [...]
  }
}
```
Question 6hardmultiple choice
Full question →

Refer to the exhibit. You are deploying an Azure Resource Manager (ARM) template to create a saved search in Microsoft Sentinel. However, the template does not create an analytics rule. What is missing to turn this saved search into a scheduled analytics rule?

Exhibit

Refer to the exhibit.
```json
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.OperationalInsights/workspaces/savedSearches",
      "apiVersion": "2020-08-01",
      "name": "[concat(parameters('workspaceName'), '/', parameters('ruleName'))]",
      "properties": {
        "category": "Security",
        "displayName": "[parameters('ruleName')]",
        "query": "SecurityEvent | where EventID == 4688 | where ProcessName endswith '\\powershell.exe'",
        "tags": [
          { "name": "AlertSeverity", "value": "Medium" }
        ]
      }
    }
  ]
}
```
Question 7mediummultiple choice
Full question →

Refer to the exhibit. You are reviewing a Microsoft Sentinel scheduled analytics rule configured as above. An incident was created for multiple alerts triggering within a 5-hour window. The SOC team needs to investigate each alert separately because they involve different user accounts. What should the analyst do to ensure each alert generates a separate incident?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "incidentConfiguration": {
      "createIncident": true,
      "groupingConfiguration": {
        "enabled": true,
        "reopenClosedIncident": false,
        "lookbackDuration": "PT5H",
        "matchingMethod": "AllEntities",
        "groupByEntities": [],
        "groupByAlertDetails": [],
        "groupByCustomDetails": null
      }
    },
    "alertRuleTemplateName": null,
    "description": "Detects suspicious sign-ins.",
    "displayName": "Suspicious Sign-In",
    "enabled": true,
    "query": "SigninLogs | where ResultType == 50057"
  }
}
```
Question 8hardmultiple choice
Full question →

Refer to the exhibit. An automation rule in Microsoft Sentinel is configured as shown. When a high-severity incident is created, what is the expected behavior?

Exhibit

{
  "properties": {
    "displayName": "SOC Automation Rules",
    "rules": [
      {
        "name": "High Severity Incidents",
        "description": "Assign incidents with severity High to tier1 group and run a playbook.",
        "actions": [
          { "order": 1, "actionType": "AddIncidentTask", "taskName": "Notify SOC Lead" },
          { "order": 2, "actionType": "RunPlaybook", "logicAppResourceId": "/subscriptions/.../resourceGroups/.../providers/Microsoft.Logic/workflows/NotifySOC" },
          { "order": 3, "actionType": "ModifyIncident", "status": "Active", "owner": "SOC-Tier1@contoso.com" }
        ]
      }
    ]
  }
}
Question 9mediummultiple choice
Full question →

Refer to the exhibit. You are investigating a user entity in Microsoft Sentinel. The entity details show a riskLevel of 'high' and riskState 'atRisk'. What does this indicate?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "entityType": "Account",
    "displayName": "testuser@contoso.com",
    "aadUserId": "00000000-0000-0000-0000-000000000001",
    "riskLevel": "high",
    "riskDetail": "User performed anomalous sign-in from unfamiliar location",
    "riskState": "atRisk",
    "riskLastUpdatedDateTime": "2026-03-15T10:30:00Z"
  }
}
```
Question 10hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing a Microsoft Sentinel analytics rule created via ARM template. What is the effect of the grouping configuration?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Ransomware Detection",
    "description": "Detects ransomware patterns",
    "severity": "High",
    "enabled": true,
    "query": "SecurityAlert | where AlertName contains \"Ransomware\"",
    "queryFrequency": "PT1H",
    "queryPeriod": "PT1H",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 0,
    "suppressionDuration": "PT5H",
    "suppressionEnabled": false,
    "incidentConfiguration": {
      "createIncident": true,
      "groupingConfiguration": {
        "enabled": true,
        "reopenClosedIncident": false,
        "lookbackDuration": "PT5H",
        "entitiesMatchingMethod": "All"
      }
    }
  }
}
```
Question 11mediummultiple choice
Full question →

Refer to the exhibit. A Microsoft Sentinel scheduled rule is configured as shown. The rule generates an alert, but the incident created contains only the first alert, and subsequent alerts do not update the incident. What is the most likely cause?

Exhibit

Refer to the exhibit.

```json
{
  "id": "/subscriptions/.../resourceGroups/rg-sentinel/providers/Microsoft.OperationalInsights/workspaces/workspace-sentinel/providers/Microsoft.SecurityInsights/alertRules/5b7c8d9e-...",
  "kind": "Scheduled",
  "properties": {
    "displayName": "RDP brute force success",
    "query": "SecurityEvent | where EventID == 4625 | summarize count() by Account, IpAddress, bin(TimeGenerated, 5m) | where count_ > 10",
    "queryFrequency": "PT5M",
    "queryPeriod": "PT10M",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 0,
    "severity": "High",
    "enabled": true
  }
}
```
Question 12hardmultiple choice
Full question →

Refer to the exhibit. You have an automation rule defined as shown. The rule is enabled but never triggers. What is the most likely reason?

Exhibit

{
  "properties": {
    "displayName": "Test Automation Rule",
    "order": 1,
    "triggers": [
      {
        "type": "IncidentCreated",
        "conditions": [
          {
            "property": "IncidentStatus",
            "operator": "Equals",
            "value": "Active"
          },
          {
            "property": "Severity",
            "operator": "Equals",
            "value": "High"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "RunPlaybook",
        "order": 1,
        "playbookId": "/subscriptions/.../providers/Microsoft.Logic/workflows/MyPlaybook"
      }
    ]
  }
}
Question 13hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing an automation rule configuration in Microsoft Sentinel. Based on the JSON snippet, what will happen when a high-severity incident is created?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "High severity incidents to Teams",
    "order": 1,
    "triggers": [
      {
        "type": "IncidentsTrigger",
        "conditions": [
          {
            "property": "Severity",
            "operator": "Equals",
            "value": "High"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "RunPlaybook",
        "order": 1,
        "playbookId": "/subscriptions/.../providers/Microsoft.Logic/workflows/PostTeamsMessage"
      }
    ]
  }
}
```
Question 14mediummultiple choice
Full question →

Refer to the exhibit. The KQL query is used in a Microsoft Sentinel scheduled alert rule. What scenario does this query detect?

Exhibit

Refer to the exhibit.
```kql
let TimeRange = 7d;
let Threshold = 100;
SigninLogs
| where TimeGenerated > ago(TimeRange)
| where ResultType == "50057"
| summarize Attempts = count() by UserPrincipalName, IPAddress
| where Attempts > Threshold
```
Question 15hardmultiple choice
Full question →

You are reviewing the ARM template snippet shown in the exhibit. What is the purpose of this template?

Exhibit

Refer to the exhibit.
```json
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.OperationalInsights/workspaces/savedSearches",
      "apiVersion": "2020-08-01",
      "name": "[concat(parameters('workspaceName'), '/SampleSavedSearch')]",
      "properties": {
        "displayName": "Sample Saved Search",
        "category": "Security",
        "query": "SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(1h)",
        "tags": []
      }
    }
  ]
}
```

These SC-200 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style SC-200 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.