Courseiva

SC-200 · topic practice

Manage a security operations environment practice questions

This domain covers operating Microsoft Sentinel and Microsoft Defender XDR after deployment: tuning analytics and data connectors, configuring automation rules and playbooks, managing incidents and entities, and applying UEBA and watchlists to reduce noise while preserving detection coverage. Questions present operational scenarios and ask you to select the correct Sentinel or Defender feature, setting, or classification value.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage a security operations environment

What the exam tests

What to know about Manage a security operations environment

Be able to configure Microsoft Sentinel automation rules and playbooks to triage, assign, and close incidents by severity and status, and tune analytics, connectors, and UEBA to cut noise. The key skill is choosing the right feature for the stated operational goal without dropping detection coverage.

Configuring Microsoft Sentinel automation rules to close, assign, or tag incidents by severity and status

Using Microsoft Sentinel incident classification values: True positive, Benign positive, False positive

Reducing alert noise with analytics rule tuning, entity mapping, and UEBA settings

Managing Microsoft Defender XDR incidents, alerts, and advanced hunting queries across workloads

Watch out for

Common Manage a security operations environment exam traps

  • ▸Confusing automation rules (incident-level, built in Sentinel) with playbooks (Logic Apps triggered by rules) when the task is simple auto-closing.
  • ▸Selecting 'Informational' as an incident severity or classification value; Sentinel severities are High, Medium, Low, Informational, and classifications differ.
  • ▸Disabling or deleting noisy analytics rules or connectors instead of tuning them, which removes detection coverage the scenario requires.

Practice set

Manage a security operations environment questions

20 questions · select your answer, then reveal the explanation

Your SOC team uses Microsoft Sentinel to manage incidents. You want to improve the efficiency of incident triage by automatically enriching incidents with threat intelligence data from Microsoft Threat Intelligence. What should you configure?

You are reviewing an automation rule in Microsoft Sentinel with the configuration shown in the exhibit. The rule is intended to delete a custom analytics rule when an incident is created. What is the most likely issue with this configuration?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Safely delete custom analytics rule",
    "description": "Deletes a custom analytics rule after verification",
    "trigger": {
      "type": "IncidentCreation",
      "entityType": "Incident",
      "incidentType": "Alert"
    },
    "actions": [
      {
        "actionType": "RunPlaybook",
        "playbookName": "Delete-AnalyticsRule",
        "logicAppResourceId": "/subscriptions/.../providers/Microsoft.Logic/workflows/Delete-AnalyticsRule"
      }
    ]
  }
}
```

You run the PowerShell command shown in the exhibit to enable diagnostics on an Azure VM. The VM is running Windows Server 2022. You want to collect security events and send them to a Log Analytics workspace. What should you include in the diagnostics.json configuration file?

Exhibit

Refer to the exhibit.

```powershell
Set-AzVMDiagnosticsExtension -ResourceGroupName "RG1" -VMName "VM1" -DiagnosticsConfigurationPath "C:\Diagnostics\diagnostics.json"
```

Your SOC team uses Microsoft Sentinel analytics rules. You need to ensure that a scheduled rule runs every hour, but only during business hours (8 AM to 6 PM). What configuration should you use?

Which TWO of the following are valid methods to reduce the cost of Microsoft Sentinel data ingestion?

Refer to the exhibit. You are reviewing a Microsoft Sentinel scheduled analytics rule defined in ARM template format. The rule is enabled but no incidents are being created even though matching sign-in events exist. What is the most likely reason?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Malicious IP Login Detection",
    "description": "Detects logins from known malicious IPs",
    "severity": "Medium",
    "enabled": true,
    "query": "SigninLogs | where IPAddress in (dynamic(['10.0.0.1', '192.168.1.1'])) | project TimeGenerated, UserPrincipalName, IPAddress",
    "queryFrequency": "PT5H",
    "queryPeriod": "PT5H",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 0,
    "suppressionDuration": "PT5H",
    "suppressionEnabled": false,
    "tactics": ["InitialAccess"],
    "techniques": ["T1078"],
    "alertRuleTemplateName": null,
    "incidentConfiguration": {
      "createIncident": true,
      "groupingConfiguration": {
        "enabled": false,
        "reopenClosedIncident": false,
        "lookbackDuration": "PT5H",
        "matchingMethod": "AllEntities",
        "groupByEntities": [],
        "groupByAlertDetails": [],
        "groupByCustomDetails": null
      }
    },
    "eventGroupingSettings": {
      "aggregationKind": "SingleAlert"
    }
  }
}
```

Refer to the exhibit. You are analyzing a KQL query for a Microsoft Sentinel scheduled rule. The query is intended to detect devices that have both a high number of process executions and network connections to a single IP within an hour. However, the query returns no results even though there are devices meeting the criteria. What is the most likely cause?

Exhibit

Refer to the exhibit.

```kusto
// KQL query in Microsoft Sentinel
let threshold = 10;
DeviceProcessEvents
| where Timestamp > ago(1h)
| summarize ProcessCount = count() by DeviceName, InitiatingProcessFileName
| where ProcessCount > threshold
| join kind=inner (DeviceNetworkEvents
| where Timestamp > ago(1h)
| summarize NetworkCount = count() by DeviceName, RemoteIP
| where NetworkCount > threshold
) on DeviceName
| project DeviceName, InitiatingProcessFileName, RemoteIP, ProcessCount, NetworkCount
```

Refer to the exhibit. You have a Microsoft Sentinel analytic rule configured to detect brute force attacks. The rule runs every 30 minutes and groups alerts into incidents based on Account and IP. You notice that multiple incidents are created for the same user and IP within a short time. What should you do to reduce the number of incidents?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Brute Force Detection",
    "enabled": true,
    "query": "SigninLogs | where ResultType == '50057' | summarize FailedAttempts = count() by UserPrincipalName, IPAddress, bin(TimeGenerated, 5m) | where FailedAttempts > 5",
    "queryFrequency": "PT30M",
    "queryPeriod": "PT30M",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 0,
    "incidentConfiguration": {
      "createIncident": true,
      "groupingConfiguration": {
        "enabled": true,
        "lookbackDuration": "PT30M",
        "matchingMethod": "AllEntities",
        "groupByEntities": ["Account", "IP"]
      }
    }
  }
}
```

Your security team uses Microsoft Defender XDR to investigate incidents. You have a custom detection rule that runs a KQL query every hour. Recently, the rule stopped generating alerts. You verify that the query syntax is correct and that data is being ingested. What is the most likely cause?

Question 10hardmulti select
Read the full Ansible explanation →

Which THREE components are required to automate incident response in Microsoft Sentinel using playbooks? (Choose three.)

Refer to the exhibit. Your SOC manager runs this KQL query in Microsoft Sentinel to see which analysts have the most active high-severity incidents in the past 7 days. The query returns no results. What is the most likely reason?

Exhibit

Refer to the exhibit.
```kusto
SecurityIncident
| where Status == "Active" and Severity == "High"
| where CreatedTime > ago(7d)
| summarize Count = count() by Owner
| top 5 by Count desc
```

Your Microsoft Sentinel environment uses multiple workspaces. You need to centrally manage incidents from all workspaces in a single interface. What should you use?

Which TWO actions are valid methods to ingest non-Microsoft security logs into Microsoft Sentinel?

Your organization uses Microsoft Sentinel and you have configured a fusion analytics rule for advanced multistage attack detection. You notice that the rule is generating a high number of false positives. What should you do to reduce the false positives without disabling the rule?

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel that returns accounts with more than 10 failed logins within 5 minutes. The query is not returning any results even though you know there have been multiple failed logins. What is the most likely reason?

Exhibit

Refer to the exhibit.

```kusto
SecurityEvent
| where EventID == 4625
| where Account !startswith "ANONYMOUS LOGON"
| summarize FailedLogins = count() by Account, IPAddress, bin(TimeGenerated, 5m)
| where FailedLogins > 10
```

Your security team uses Microsoft Defender XDR (formerly Microsoft 365 Defender) to investigate incidents. You notice that some alerts from Microsoft Defender for Endpoint are not being automatically correlated into incidents as expected. You have confirmed that the relevant alert sources are enabled in the Microsoft Defender XDR portal. What is the most likely cause?

Which TWO Azure services can be used to automate response actions in Microsoft Sentinel when an incident is created?

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. The query returns no results even though you know there are alerts with the name 'Malware detected'. What is the most likely issue?

Exhibit

SecurityAlert
| where AlertName == "Malware detected"
| extend entities = parse_json(Entities)
| mv-expand entities
| where entities.Type == "file"
| project FileHash = entities.FileHash, AlertTime = TimeGenerated
Question 19hardmultiple choice
Read the full Ansible explanation →

Your organization has Microsoft Defender for Cloud Apps and Microsoft Sentinel integrated. You need to create an automated playbook that, when a Microsoft Sentinel incident is created from a Defender for Cloud Apps alert, automatically suspends the user in Microsoft Entra ID and sends a notification to the security team. Which two connectors should you use in the playbook?

Your security team uses Microsoft Defender XDR to investigate a potential malware outbreak. You need to collect a full memory dump from an affected Windows 10 device for forensic analysis. Which action should you take from the Microsoft Defender XDR portal?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage a security operations environment sessions

Start a Manage a security operations environment only practice session

Every question in these sessions is drawn from the Manage a security operations environment domain — nothing else.

Related practice questions

Related SC-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-200 exam test about Manage a security operations environment?
Be able to configure Microsoft Sentinel automation rules and playbooks to triage, assign, and close incidents by severity and status, and tune analytics, connectors, and UEBA to cut noise. The key skill is choosing the right feature for the stated operational goal without dropping detection coverage.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage a security operations environment questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage a security operations environment domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-200 topics?
Use the topic links above to move to related areas, or go back to the SC-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-200 exam covers. They are not copied from any real exam or dump site.