Courseiva

CCNA Respond Security Incidents Questions

75 of 375 questions · Page 1/5 · Respond Security Incidents topic · Answers revealed

1
MCQeasy

Your organization uses Microsoft Defender XDR. You receive an alert about a potentially unwanted application (PUA) being installed on a device. The PUA is not blocked by your current policy. You need to prevent future installations of this PUA without affecting other software. What should you do?

A.Enable blocking of all potentially unwanted applications in the antivirus policy.
B.Reset the device to its factory settings.
C.Create a custom indicator of compromise (IoC) to block the specific file's hash.
D.Run a full scan on the device to remove the PUA.
AnswerC

Creating a custom indicator of compromise (IoC) for the specific file hash, with the action set to Block and remediate, is the precise and recommended response. This indicator is propagated to all devices through Microsoft Defender XDR, preventing the file from executing and automatically triggering remediation of existing copies on any onboarded endpoint. Because the block is scoped solely to that file hash, legitimate applications are preserved, avoiding false positives, and the defense persists for future attempts to execute or download the file.

Why this answer

Creating a custom indicator of compromise (IoC) with the specific file hash allows you to block only that exact PUA file without affecting other software. This leverages Microsoft Defender for Endpoint's custom IoC capability to override the default PUA detection policy, targeting the specific file hash rather than enabling a broad block on all PUAs.

Exam trap

The trap here is that candidates may choose Option A, thinking that enabling PUA blocking is the simplest solution, but they overlook the requirement to avoid affecting other software, which makes the broad policy change inappropriate.

How to eliminate wrong answers

Option A is wrong because enabling blocking of all potentially unwanted applications would affect other software that may be legitimate or needed, violating the requirement to not affect other software. Option B is wrong because resetting the device to factory settings is an extreme, disruptive action that does not prevent future installations of the PUA and is not a targeted solution. Option D is wrong because running a full scan removes the existing PUA but does not prevent future installations of the same file.

2
MCQeasy

During a security incident response, you need to collect forensic evidence from a Windows 10 device that is suspected to be compromised. The device is not domain-joined and is located in a remote office. You have remote administrative access. Which Microsoft 365 tool should you use to acquire a memory dump of the device?

A.Microsoft Sentinel
B.Microsoft Purview eDiscovery
C.Microsoft Intune
D.Microsoft Defender for Endpoint
AnswerD

Microsoft Defender for Endpoint's live response feature provides a remote shell to the non-domain-joined Windows 10 device, where the memory dump can be captured using its built-in commands. This satisfies the remote acquisition constraint without physical access or domain membership.

Why this answer

Microsoft Defender for Endpoint includes live response and the ability to collect forensic artifacts, including memory dumps, from onboarded devices. It supports remote acquisition from non-domain-joined Windows 10 devices as long as they are onboarded and you have the appropriate permissions. Sentinel, Purview eDiscovery, and Intune do not provide memory dump acquisition.

Exam trap

The trap is confusing forensic acquisition with management or eDiscovery tools—candidates pick Intune or Purview because they sound like they handle devices or data, but only Defender for Endpoint provides live response memory capture.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a SIEM/SOAR platform for detection and investigation, not a forensic acquisition tool for memory dumps. Option B is wrong because Microsoft Purview eDiscovery is for identifying, collecting, and reviewing electronically stored information for legal cases, not for acquiring volatile memory. Option C is wrong because Microsoft Intune is for device management and configuration, not forensic memory capture.

3
MCQmedium

You are responding to a ransomware incident in Microsoft Defender XDR. You have identified that the malware encrypted files on several devices and then deleted the volume shadow copies. Which of the following actions should you take first to contain the incident?

A.Run a remediation action to delete the detected malware
B.Restore encrypted files from backup
C.Run a full antivirus scan on all devices
D.Isolate affected devices using Microsoft Defender for Endpoint
AnswerD

Isolating affected devices using Microsoft Defender for Endpoint is the correct first step because it immediately blocks all incoming and outgoing communication to and from the compromised host, cutting off the ransomware's ability to spread laterally and communicate with command-and-control servers. This action preserves forensic evidence while containing the attack, and it can be initiated remotely from the MDE console without requiring physical access or disrupting the rest of the network. Full isolation still allows the Defender service to communicate, so security teams can continue to investigate and remediate the endpoint.

Why this answer

Isolating affected devices using Microsoft Defender for Endpoint is the correct first action because it immediately cuts off network communication, preventing the ransomware from spreading laterally to other devices and stopping further encryption or deletion of shadow copies. Containment must precede remediation to limit the blast radius, and Defender for Endpoint's device isolation feature achieves this at the network level without requiring physical disconnection.

Exam trap

The trap here is that candidates often confuse containment with remediation, choosing to delete malware or run scans first, but the SC-200 exam emphasizes that immediate isolation is the priority to stop lateral spread before any cleanup or recovery actions.

How to eliminate wrong answers

Option A is wrong because running a remediation action to delete the detected malware does not contain the incident; it attempts to remove the threat after it has already encrypted files and deleted shadow copies, and without isolation the malware could still spread or re-infect. Option B is wrong because restoring encrypted files from backup is a recovery step that should only be performed after containment and eradication are complete; attempting restoration first risks re-encryption if the malware is still active on the network. Option C is wrong because running a full antivirus scan on all devices is a detection and remediation step, not a containment measure; it does not stop the ransomware from continuing to encrypt or spread during the scan.

4
Multi-Selectmedium

Which THREE are valid investigation actions in Microsoft Sentinel? (Select THREE.)

Select 3 answers
A.View related entities such as IP addresses.
B.Run a playbook.
C.View related incidents.
D.Modify an analytics rule.
E.View related alerts.
AnswersA, C, E

Viewing related entities such as IP addresses is a core Sentinel investigation action, letting analysts pivot from an incident to the associated hosts, accounts and addresses on the entity graph. This satisfies the stem's requirement for valid investigation actions, since entity exploration is built into the incident investigation experience.

Why this answer

Viewing related entities such as IP addresses is a fundamental investigation action in Microsoft Sentinel. Option C is correct because viewing related incidents helps in correlating events. Option E is correct because viewing related alerts provides context.

Option B is incorrect because running a playbook is a remediation action, not an investigation action. Option D is incorrect because modifying an analytics rule is a configuration task outside the investigation scope.

5
MCQeasy

An analyst in your SOC receives a Microsoft Defender for Cloud Apps alert indicating a suspicious Power Automate flow that is forwarding emails to an external domain. The analyst needs to disable the flow immediately. Which action should they take?

A.Block the external domain in Exchange Online mail flow rules
B.Remove the flow from the Microsoft 365 admin center
C.Disable the user account in Microsoft Entra ID
D.Use the governance action in Microsoft Defender for Cloud Apps to disable the flow
AnswerD

Microsoft Defender for Cloud Apps governance actions apply remediation directly to connected apps, letting the analyst disable the offending Power Automate flow from within the alert. This stops the exfiltration immediately without leaving the portal, matching the requirement to disable the flow at once.

Why this answer

Microsoft Defender for Cloud Apps (MDCA) provides governance actions directly on discovered app activities, including the ability to disable a Power Automate flow from within the alert. This is the fastest, most targeted remediation because it acts on the specific flow rather than broader controls.

Exam trap

SC-200 often tests whether candidates choose the most targeted remediation action available in the alerting tool rather than broader, slower controls like blocking domains or disabling accounts.

How to eliminate wrong answers

Option A is wrong because blocking the external domain in Exchange mail flow rules only stops delivery to that domain — the malicious flow remains active and could target other domains or exfiltrate via other channels. Option B is wrong because removing the flow from the Microsoft 365 admin center is a manual, slower process and may not be available or practical during an active incident. Option C is wrong because disabling the user account is overly broad, disrupts legitimate user activity, and does not immediately stop the flow if it runs under a service principal or continues executing.

6
MCQeasy

A SOC analyst is triaging an incident in Microsoft Sentinel and needs to assign it to a senior analyst for further investigation. What is the correct action?

A.Create a new incident and manually add the senior analyst as a comment.
B.Open the incident and change the Owner field to the senior analyst.
C.Close the incident and reopen it under the senior analyst's name.
D.Run a playbook that sends an email to the senior analyst.
AnswerB

In Microsoft Sentinel, incident ownership is controlled by the Owner field in the incident details pane; setting it to the senior analyst formally assigns the incident to them, making it appear in their 'My incidents' view and routing any notifications according to the workspace's settings. Updating the owner preserves the incident's original ID, entity links, evidence, and full audit history, which is critical for accurate incident response documentation. This action is the recommended way to escalate an incident for additional review.

Why this answer

In Microsoft Sentinel, the correct way to assign an incident to a specific analyst is to open the incident and change the Owner field to that analyst. This action formally transfers ownership and responsibility for the incident within the SIEM, ensuring proper tracking and accountability. Other methods, such as adding comments or sending emails, do not update the incident's ownership metadata.

Exam trap

The trap here is that candidates might confuse external notification (email) or informal tagging (comments) with the formal ownership change required by Sentinel's incident management model, leading them to choose options that do not actually reassign the incident.

How to eliminate wrong answers

Option A is wrong because adding a comment does not change the incident's owner; it only adds an annotation, leaving the incident unassigned or assigned to the original owner. Option C is wrong because closing an incident marks it as resolved, and reopening it under a different name does not properly reassign ownership—it creates confusion in the incident lifecycle. Option D is wrong because running a playbook to send an email is an external notification, not a Sentinel-native assignment action; it does not update the Owner field or any other incident property.

7
MCQeasy

A security analyst in Microsoft Sentinel receives an incident with a high severity alert from Microsoft Defender for Identity. The incident description mentions a suspected lateral movement pass-the-hash attack. What should the analyst do first?

A.Reset the password of the compromised account.
B.Review the Microsoft Defender for Cloud Apps logs.
C.Isolate the affected device from the network.
D.Create a new analytics rule to detect pass-the-hash attacks.
AnswerC

Isolating the affected device from the network breaks the attacker's ability to use the compromised host to authenticate to other systems via pass-the-hash, effectively containing the lateral movement at the source. This is an immediate containment action that limits the blast radius while preserving process memory and network evidence for forensic analysis. In Microsoft Defender for Endpoint, 'Isolate device' blocks all inbound/outbound traffic except to the Defender service.

Why this answer

The immediate priority in a suspected lateral movement pass-the-hash attack is to contain the threat by isolating the affected device from the network. This prevents the attacker from using the compromised account's NTLM hash to authenticate to other systems, stopping the lateral spread while preserving forensic evidence for further investigation.

Exam trap

The trap here is that candidates often choose password reset (Option A) thinking it immediately revokes access, but they overlook that the cached NTLM hash on the compromised device remains usable for lateral movement until the device is isolated or the hash is cleared.

How to eliminate wrong answers

Option A is wrong because resetting the password of the compromised account does not invalidate the cached NTLM hash already present on the affected device; the attacker can still use that hash for lateral movement until the device is isolated. Option B is wrong because Microsoft Defender for Cloud Apps logs focus on cloud application activity, not on-premises lateral movement techniques like pass-the-hash, which occur at the network authentication level. Option D is wrong because creating a new analytics rule is a proactive detection measure that takes time to deploy and does not address the immediate containment need; the analyst must first stop the active attack.

8
MCQmedium

You are a SOC analyst using Microsoft Defender for Endpoint. A device is flagged as compromised and you need to isolate it from the network while still allowing you to remotely investigate it. Which action should you take?

A.Restrict app execution on the device.
B.Collect an investigation package from the device.
C.Run a full antivirus scan on the device.
D.Isolate the device using the 'Isolate device' action.
AnswerD

The 'Isolate device' action in Microsoft Defender for Endpoint disconnects the device from the network except for the Defender for Endpoint service, allowing you to remotely investigate and remediate. This meets the requirement of isolating the device while maintaining a management channel. It is the correct containment action for a compromised device.

Why this answer

Microsoft Defender for Endpoint's 'Isolate device' action provides network containment by blocking all network traffic except for the Defender for Endpoint cloud service. This allows analysts to remotely connect to the device, run investigations, and remediate threats without the attacker being able to communicate externally or move laterally. It is the standard response for a compromised device.

Exam trap

The trap here is thinking that antivirus scans or app restrictions provide isolation; they do not block network communication.

9
MCQmedium

A Microsoft Defender for Endpoint alert indicates that a device has been communicating with a known command-and-control (C2) server. The device is critical for production. What is the most appropriate response?

A.Disconnect the network cable of the device.
B.Run a full antivirus scan on the device.
C.Block the C2 server URL in the firewall.
D.Isolate the device using Microsoft Defender for Endpoint's device isolation feature.
AnswerD

Isolating the device with Microsoft Defender for Endpoint's device isolation feature is the correct initial response because it severs all inbound and outbound communication except to the Defender service, immediately containing the threat while keeping the device powered on. When forensic preservation mode is enabled, the device remains in a state that preserves volatile evidence and prevents file system changes, allowing security analysts to investigate the compromise, collect artifacts, and remediate without losing critical data—all through a centrally managed, reversible action.

Why this answer

Microsoft Defender for Endpoint's device isolation feature is designed to contain a compromised device while preserving forensic data and minimizing disruption. For a critical production device, full isolation (blocking all network traffic except to the Defender service) stops C2 communication without physically disconnecting the device, allowing the security team to investigate and remediate remotely.

Exam trap

The trap here is that candidates often choose 'Block the C2 server URL in the firewall' (Option C) because it seems like a quick network fix, but they fail to recognize that the device itself is already compromised and must be contained at the endpoint level to prevent lateral movement or data exfiltration.

How to eliminate wrong answers

Option A is wrong because physically disconnecting the network cable is a brute-force containment that may cause abrupt service disruption, loss of remote management, and potential data corruption on a critical production device; it also prevents the security team from performing remote investigation or applying updates. Option B is wrong because running a full antivirus scan is a detection and remediation step, not a containment action; it does not stop active C2 communication and may allow the attacker to exfiltrate data or execute further commands during the scan. Option C is wrong because blocking the C2 server URL in the firewall only prevents future connections to that specific URL, but the device may still be compromised and could communicate with other C2 endpoints or use IP-based fallback; it does not contain the device itself.

10
MCQmedium

An organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident is created when a user is detected as compromised. The incident severity is set to High. The SOC manager wants to ensure that all incidents with severity High or above are automatically assigned to the senior analyst tier. What should the analyst configure?

A.Set a playbook to run when an incident is created.
B.Create an analytics rule with a custom severity.
C.Define an automation rule to assign incidents based on severity.
D.Configure an alert tuning rule.
AnswerC

Automation rules in Microsoft Sentinel trigger on incident creation and can set owner, status or severity. Configuring one with a severity condition of High or above automatically assigns matching incidents to the senior analyst tier, removing manual triage effort.

Why this answer

Microsoft Sentinel automation rules are designed to trigger on incident creation and perform actions such as assigning owners, changing severity, adding tags, or running playbooks. To automatically assign all High-or-above incidents to the senior analyst tier, an automation rule with a severity condition and an 'Assign owner' action is the correct mechanism.

Exam trap

SC-200 often tests the confusion between automation rules (incident-level routing/assignment) and playbooks (action orchestration) — candidates pick playbooks for simple assignment tasks that automation rules handle natively.

How to eliminate wrong answers

Option A is wrong because a playbook (Logic App) can perform many actions but is not the native, lightweight mechanism for owner assignment based on incident severity — automation rules are purpose-built for this and are evaluated before playbooks. Option B is wrong because analytics rules generate incidents and set severity; they do not assign owners or route incidents to tiers. Option D is wrong because alert tuning rules suppress or modify alerts, not route incidents to analysts.

11
MCQhard

Your organization has Microsoft Sentinel and Microsoft Defender for Identity deployed. An incident is created for a user whose account was used to access a sensitive database from an unusual workstation. The user is a member of the 'Database Admins' group. The security team needs to prevent further unauthorized access and preserve evidence. What should you do first?

A.Disable the user's account in Active Directory
B.Reset the user's password
C.Force the user to log off all sessions
D.Remove the user from the Database Admins group
AnswerA

Disabling the account in Active Directory immediately blocks further authentication, stopping the unauthorised access while the account and its activity remain intact for forensic review. Containment first prevents additional damage before broader investigation or remediation.

Why this answer

Disabling the user's account in Active Directory is the fastest and most effective way to immediately prevent further unauthorized access while preserving the account and its associated evidence for forensic investigation. It stops all authentication and access without deleting data or altering group memberships that investigators may need to review. Resetting the password or removing group membership does not immediately terminate existing sessions or prevent access as decisively.

Exam trap

SC-200 often tests the difference between containment actions that immediately stop access (disable account) and those that only partially mitigate (password reset, group removal), so candidates must choose the most decisive first step.

How to eliminate wrong answers

Option B is wrong because resetting the password does not immediately terminate active sessions and the attacker may still have valid tokens or cached credentials; it also changes evidence. Option C is wrong because forcing logoff of all sessions may disrupt business operations and does not prevent the attacker from re-authenticating if the account remains enabled. Option D is wrong because removing the user from the Database Admins group only revokes that specific privilege but leaves the account active and able to access other resources, and it alters group membership evidence.

12
MCQeasy

An organization uses Microsoft Sentinel for security operations. A security engineer needs to automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel. Which feature should the engineer use?

A.Analytics rule
B.Workbook
C.Automation rule with a playbook
D.Hunting query
AnswerC

An automation rule triggers on incident creation and launches a playbook, which executes the Logic Apps workflow calling Microsoft Entra ID to disable the compromised account. This satisfies the requirement for automatic response without manual analyst intervention.

Why this answer

To automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel, the engineer should use an automation rule that triggers a playbook. Automation rules in Microsoft Sentinel allow you to define conditions (e.g., incident severity) and then invoke a playbook, which can contain the logic to call Microsoft Graph or Entra ID to disable the user. This is the standard method for automated response.

Exam trap

SC-200 often tests the confusion between analytics rules (detection) and automation rules (response), leading candidates to select analytics rules for automated remediation tasks.

How to eliminate wrong answers

Option A is wrong because analytics rules are used to detect threats and create incidents, not to perform automated remediation actions. Option B is wrong because workbooks are for visualization and reporting, not automation. Option D is wrong because hunting queries are for proactive threat hunting, not for automated response.

13
MCQmedium

Your organization uses Microsoft Sentinel with Microsoft Defender XDR integrated. A critical incident has been raised involving a user account that was used to access a confidential SharePoint site from an unusual location at 2:00 AM. The incident includes alerts from Microsoft Defender for Cloud Apps, Microsoft Defender for Identity, and Microsoft Defender for Office 365. The analyst needs to contain the incident, investigate the scope, and begin remediation. The environment has the following: Microsoft Entra ID with conditional access policies, Microsoft Intune for device management, and Microsoft Defender for Endpoint on all devices. The analyst has identified the user account and the device used. Which course of action should the analyst take first?

A.Create a conditional access policy to block the user.
B.Isolate the user's device using Microsoft Defender for Endpoint.
C.Run a KQL query to find all resources accessed by the user.
D.Disable the user account in Microsoft Entra ID and revoke all sessions.
AnswerD

Disabling the account in Microsoft Entra ID and revoking all sessions immediately cuts off the attacker's access, containing the incident before scope investigation. This neutralises the compromised identity across SharePoint, Defender XDR workloads and conditional access, which is the priority containment step.

Why this answer

Disabling the user account in Microsoft Entra ID and revoking all sessions is the immediate containment step because it stops the compromised account from being used for any further access, including the suspicious SharePoint access and any lateral movement. This action directly addresses the core of the incident—the user account—and is the fastest way to cut off the attacker's current authentication tokens and sessions, preventing further damage while the investigation proceeds.

Exam trap

The trap here is that candidates often prioritize device isolation (Option B) because they think of endpoint compromise first, but the incident is about a user account used from an unusual location, meaning the account itself is the primary vector—disabling the account is the fastest and most effective containment step before any device or investigation actions.

How to eliminate wrong answers

Option A is wrong because creating a conditional access policy to block the user is a slower, more complex approach that requires policy propagation time and may not immediately revoke existing sessions or tokens, leaving the attacker with active access. Option B is wrong because isolating the user's device using Microsoft Defender for Endpoint contains the device but does not prevent the attacker from using the same compromised user account from another device or via web-based access (e.g., SharePoint Online). Option C is wrong because running a KQL query to find all resources accessed by the user is a forensic investigation step that should occur after containment; performing it first delays the critical containment action and allows the attacker more time to exfiltrate data or move laterally.

14
Multi-Selecteasy

Which TWO Microsoft Defender XDR entities can be managed during incident response?

Select 2 answers
A.Network interfaces
B.Azure subscriptions
C.Devices
D.Microsoft 365 tenants
E.User accounts
AnswersC, E

Devices are a primary managed entity in Microsoft Defender XDR. In Defender for Endpoint, every onboarded workstation, server, and mobile device is represented in the Device inventory and can be isolated, scanned, excluded from automated investigation, or added to a device group. Because device context drives alert correlation across identity, email, and data protection, the device is a core entity for XDR incident management.

Why this answer

During incident response in Microsoft Defender XDR, you can manage devices (endpoints) and user accounts directly from the incident page. Devices can be isolated, have antivirus scans run, or be added to a blocklist, while user accounts can be disabled, forced to sign out, or have their password reset. These actions are executed via Microsoft Defender for Endpoint and Microsoft Defender for Identity integrations within the unified incident response workflow.

Exam trap

The trap here is that candidates often confuse 'entities that can be managed' with 'entities that provide telemetry'—for example, thinking network interfaces or Azure subscriptions are actionable, when in fact only user accounts and devices have direct remediation actions available in the incident response pane.

15
MCQeasy

A SOC analyst is using Microsoft Sentinel to respond to an incident involving multiple compromised user accounts. The analyst needs to quickly see the timeline of all related events. Which feature should the analyst use?

A.Entity behavior page.
B.Analytics rule page.
C.Workbook.
D.Incident timeline.
AnswerD

The Incident timeline is the correct feature because it provides a chronological, visual view of all alerts, bookmarks, and related activities associated with a specific incident. This timeline lets analysts quickly reconstruct the attack sequence, correlate events, and understand the full scope of the incident in one place. It is the primary view used during incident triage and investigation in Microsoft Sentinel.

Why this answer

The Incident timeline (option D) is the correct feature because it provides a chronological view of all events, alerts, and actions associated with a specific incident in Microsoft Sentinel. This allows the SOC analyst to quickly see the sequence of events related to the compromised user accounts without navigating away from the incident investigation page.

Exam trap

The trap here is that candidates may confuse the Incident timeline with the Entity behavior page, thinking they both show event history, but the Entity behavior page is entity-centric and not designed to show the full incident-scoped chronology across multiple compromised accounts.

How to eliminate wrong answers

Option A is wrong because the Entity behavior page focuses on the historical behavior and anomalies of a single entity (e.g., a user or device), not the aggregated timeline of events for a multi-account incident. Option B is wrong because the Analytics rule page is used to create, edit, and manage detection rules, not to view the timeline of events for an active incident. Option C is wrong because a Workbook is a customizable dashboard for visualizing data from multiple queries, but it does not provide the incident-specific, chronological event timeline that the Incident timeline feature offers.

16
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. You receive an alert indicating that a user from the finance department accessed a sensitive SharePoint file from an IP address associated with a known malicious Tor exit node. The file contains payment information. The user's account has not been disabled. What should you do first to contain the incident?

A.Delete the SharePoint file from the site
B.Notify the user of the suspicious activity
C.Block the IP address in Microsoft Defender for Cloud Apps
D.Suspend the user's account in Microsoft Entra ID
AnswerD

Suspending the account prevents further access immediately.

Why this answer

The first step to contain the incident is to suspend the user's account in Microsoft Entra ID (Option D). This immediately revokes access to all resources, preventing further data exfiltration while preserving the current state for investigation. Option A is incorrect because deleting the SharePoint file may destroy evidence.

Option B is incorrect because blocking the IP address in Defender for Cloud Apps is less effective; the attacker can easily switch to a different IP address. Option C is incorrect because notifying the user could alert a potential attacker who might have compromised the account, leading to further malicious actions.

17
Multi-Selecthard

Which THREE actions are part of the containment phase in the Microsoft Incident Response process?

Select 3 answers
A.Notify senior management of the incident.
B.Block known malicious IP addresses at the firewall.
C.Disable compromised user accounts.
D.Isolate affected systems from the network.
E.Collect forensic data from affected systems.
AnswersB, C, D

Blocking known malicious IP addresses at the firewall is a direct and immediate containment action that severs the network communication path between the compromised environment and the attacker's command-and-control (C2) infrastructure. By applying egress and ingress rules to deny traffic to these IPs, you cut off remote commands, data exfiltration, and potential malware downloads, thereby limiting the adversary's operational control without disrupting normal business traffic.

Why this answer

Blocking known malicious IP addresses at the firewall is a containment action because it immediately stops inbound or outbound communication with threat actors, preventing further data exfiltration or command-and-control traffic. In the Microsoft Incident Response (IR) process, containment focuses on limiting the blast radius and stopping the spread of an attack, and firewall rules are a primary technical control for achieving this at the network perimeter.

Exam trap

The SC-200 exam often tests the distinction between containment and investigation phases, where candidates mistakenly choose forensic data collection (Option E) as containment, but in the IR process, containment must happen first to stop the bleeding before any evidence gathering that could alter system state.

18
MCQmedium

Your organization uses Microsoft Sentinel with a workspace in the East US region. You need to respond to an incident involving data exfiltration from a virtual machine in West Europe. The incident was created from a custom analytics rule that queries the AzureActivity table. What should you do to ensure the incident contains all relevant evidence from the West Europe region?

A.Create the analytics rule in a separate workspace in West Europe
B.Ensure that Azure activity logs from West Europe are streamed to the same Sentinel workspace in East US
C.Configure the analytics rule to query the West Europe workspace
D.Use the incident merge feature to combine incidents from multiple workspaces
AnswerB

AzureActivity data is regional; the West Europe VM's activity logs are only written to a workspace in that region unless explicitly streamed. Routing them into the East US workspace ensures the analytics rule can correlate all evidence for the incident.

Why this answer

To have the analytics rule in the East US workspace evaluate AzureActivity logs from West Europe, those logs must be collected into the same workspace. Streaming activity logs from West Europe to the East US workspace ensures all relevant data is available for the rule to query. Option A is incorrect because creating a separate workspace in West Europe would isolate the data, and the incident is in the East US workspace; cross-workspace queries would be required.

Option C is incorrect because the analytics rule runs only in the workspace where it is defined; to query data from another workspace, you would need a cross-workspace query, but the rule is already defined in East US and cannot directly query the West Europe workspace without additional configuration. Option D is incorrect because incident merge is used to combine duplicate incidents within the same workspace, not across different workspaces.

19
MCQhard

Your company uses Microsoft Sentinel and Microsoft Defender for Cloud Apps (MCAS). A security analyst detects that a user is accessing a sanctioned cloud app from an unusual location. The analyst creates an incident in Sentinel. You need to automatically apply a session policy in MCAS to block downloads from that user for the next hour. You have an existing playbook that can apply session policies. What is the most efficient way to automate this response?

A.Create an automation rule in Sentinel that triggers when an incident is created with the relevant conditions and runs the playbook.
B.Instruct the analyst to run the playbook manually from the incident page each time.
C.Configure the incident creation rule in MCAS to automatically run the playbook.
D.Modify the analytics rule that detected the anomaly to run the playbook as an automated response.
AnswerA

An automation rule in Microsoft Sentinel is the correct mechanism for incident-driven response: it evaluates incidents the moment they are created, matches configured conditions (e.g., severity, entity, tactic), and immediately executes a playbook. This is event-driven, consistent, and removes the need for analyst intervention, aligning with the scenario's requirement to automate incident-created actions.

Why this answer

An automation rule in Microsoft Sentinel is triggered by incident creation and can run a playbook automatically when specified conditions are met. This is the most efficient way to automate the response because it eliminates manual intervention and ensures the session policy is applied immediately upon incident creation. The automation rule can be scoped to incidents with specific analytics rules, severities, or entities, matching the requirement.

Exam trap

SC-200 often tests the distinction between analytics rules (detection), automation rules (orchestration), and playbooks (action); candidates may incorrectly think analytics rules can directly run playbooks or that MCAS rules can trigger Sentinel playbooks.

How to eliminate wrong answers

Option B is wrong because instructing the analyst to run the playbook manually each time does not automate the response and is inefficient, contrary to the requirement for automation. Option C is wrong because MCAS incident creation rules create incidents in MCAS but do not natively trigger Sentinel playbooks; integration is done via Sentinel automation rules. Option D is wrong because analytics rules detect and create incidents but do not directly run playbooks as automated responses; automation rules are the correct mechanism for triggering playbooks based on incident creation.

20
Multi-Selecthard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. During a security incident involving a compromised Azure VM, which THREE actions are appropriate to contain and investigate the incident?

Select 3 answers
A.Use Microsoft Defender for Cloud's Just-in-Time VM access to isolate the VM.
B.Create a Microsoft Sentinel automation rule to trigger a playbook that runs investigation actions.
C.Enable network security group flow logs to capture network traffic.
D.Delete the compromised VM to prevent further damage.
E.Update the VM's operating system to the latest patch.
AnswersA, B, C

Just-in-Time VM access in Microsoft Defender for Cloud allows you to control inbound traffic to management ports (RDP/SSH) by enforcing approved source IPs and time windows. When an incident occurs, you can configure JIT to deny all inbound traffic to the VM, effectively isolating it from the network while the VM remains powered on for forensic collection. This non-destructive containment preserves the VM's memory, disk, and logs for investigation, unlike deletion or shutdown.

Why this answer

Microsoft Defender for Cloud's Just-in-Time VM access can be used to lock down inbound traffic to the VM, effectively isolating it from the network while preserving the VM for forensic analysis. This action reduces the attack surface and prevents lateral movement without destroying evidence, which is critical during incident response.

Exam trap

The trap here is that candidates may confuse containment with remediation, choosing to delete or patch the VM immediately, but Microsoft tests the principle of preserving forensic evidence during the containment phase of incident response.

21
MCQmedium

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You receive an alert in MDE about a suspicious PowerShell command executed on a device. You create an incident in Sentinel from this alert. You need to automatically collect a memory dump from the affected device for further analysis. You have a playbook that can initiate a memory dump collection via the MDE API. What is the best way to automate this?

A.Configure the alert details enrichment in Sentinel to automatically add the memory dump to the incident.
B.Create an automation rule that triggers when an incident is created from a MDE alert and runs the playbook to collect the memory dump.
C.Use entity behavior analytics in Sentinel to trigger the playbook when suspicious behavior is detected.
D.Have the analyst manually run the playbook from the incident page.
AnswerB

Automation rules in Microsoft Sentinel respond to incident creation events, and can filter on the alert's product source being Microsoft Defender for Endpoint. Triggering the playbook this way runs the MDE API memory dump collection automatically, satisfying the requirement without manual intervention.

Why this answer

Automation rules in Microsoft Sentinel can trigger playbooks when an incident is created. Option B is correct because it creates an automation rule that triggers on incident creation from a Microsoft Defender for Endpoint alert and runs the playbook to collect the memory dump automatically. Option A is incorrect because alert details enrichment only adds enrichment details, it does not run playbooks.

Option C is incorrect because entity behavior analytics does not directly trigger playbooks on incident creation. Option D is incorrect because the requirement is automation, not manual action.

22
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. During an incident investigation, you find that a device is exfiltrating data to an external IP. You need to isolate the device from the network using automated response. Which action should you configure in an automation rule?

A.Trigger a Microsoft Purview data loss prevention policy.
B.Run a Microsoft Entra ID playbook to disable the device.
C.Run a playbook that triggers a Microsoft Defender for Endpoint 'Isolate device' action.
D.Create an automation rule in Microsoft Intune to wipe the device.
AnswerC

Running a playbook that invokes the Microsoft Defender for Endpoint 'Isolate device' action is the correct containment response because it actively disconnects the endpoint from the corporate network while preserving a connection to the MDE cloud service for management and forensics. This action terminates all network traffic to and from the device (except low-level MDE communication), immediately stopping data exfiltration and command-and-control traffic. In Sentinel, this playbook can be triggered automatically or manually and is the only listed option that provides a network-level isolation layer.

Why this answer

The scenario requires network isolation of a device that is actively exfiltrating data. Microsoft Defender for Endpoint provides a built-in 'Isolate device' action that can be triggered via a playbook from a Microsoft Sentinel automation rule. This action immediately blocks all inbound and outbound network traffic to and from the device, except for communication with the Defender for Endpoint service, effectively containing the threat.

Exam trap

The trap here is that candidates may confuse 'disabling a device' in Entra ID (which only revokes authentication) with true network isolation, or they may think a DLP policy can stop active network-level exfiltration, when in fact only a Defender for Endpoint isolation action blocks all network traffic at the host level.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview data loss prevention (DLP) policies are designed to inspect and prevent data exfiltration at the application or content level (e.g., email, SharePoint), not to perform network-level isolation of a device. Option B is wrong because Microsoft Entra ID (formerly Azure AD) playbooks can disable a device's identity or access tokens, but they do not isolate the device from the network; the device remains connected and can still communicate with external IPs. Option D is wrong because Microsoft Intune's wipe action is a device management operation that resets or removes corporate data, but it does not provide immediate network isolation and is not designed for automated incident response to an active exfiltration event.

23
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. During an incident, you discover that a user is downloading large amounts of data from SharePoint to an unmanaged device. You need to automatically block further downloads from that device. What should you configure?

A.Create a session policy in Microsoft Defender for Cloud Apps to block download.
B.Create a Conditional Access policy to require a compliant device.
C.Configure Microsoft Intune device compliance policy.
D.Create a DLP policy in Microsoft Purview.
AnswerA

A session policy in Microsoft Defender for Cloud Apps operates via reverse-proxy conditional access app control, giving you real-time, action-level visibility and enforcement. By setting the 'block download' action alongside other file-related controls, the policy inspects every HTTP transaction and can block a download request while still allowing viewing or other cloud-app activities. This is the only option here that directly targets downloads as a discrete action rather than toggling all-or-nothing access to the application.

Why this answer

A session policy in Microsoft Defender for Cloud Apps uses reverse proxy capabilities to monitor and control user activities in real time. By configuring a session policy with the 'block download' action, you can immediately stop further downloads from SharePoint to the unmanaged device during the incident, without affecting managed devices.

Exam trap

The trap here is that candidates often confuse session policies with Conditional Access or DLP policies, not realizing that only session policies provide real-time, granular control over specific actions like downloads within a cloud app session.

How to eliminate wrong answers

Option B is wrong because a Conditional Access policy to require a compliant device would block access entirely for non-compliant devices, but it does not provide granular, real-time control to block only downloads while allowing other activities like viewing. Option C is wrong because Intune device compliance policy is used to define compliance requirements for managed devices, but it cannot enforce real-time blocking of downloads from an unmanaged device that is not enrolled in Intune. Option D is wrong because a DLP policy in Microsoft Purview is designed to detect and prevent data loss by inspecting content at rest or in transit, but it does not provide session-level, real-time blocking of downloads based on device trust or risk.

24
MCQmedium

A company uses Microsoft Defender XDR and has enabled automatic attack disruption for human-operated ransomware. During an incident, the system automatically contains a compromised account. However, the SOC team wants to ensure that the containment action is reversible and that the account can be restored after investigation. What should the team do before restoring the account?

A.Change the account's password and enable multi-factor authentication.
B.Verify that no other accounts were compromised.
C.Remove the account from all administrative roles.
D.Run a full antivirus scan on the account's devices.
AnswerA

Resetting the account's password invalidates the compromised credentials that an attacker may be using, and enabling MFA adds a second authentication layer that blocks unauthorized re-entry. This is the required remediation step before restoring the account because it directly addresses the known compromise of the identity itself. Without this step, any restoration action would leave the account vulnerable to immediate re-compromise, as existing tokens or cached credentials could still be leveraged.

Why this answer

After automatic containment disables a compromised account, the SOC team must change its password and enable multi-factor authentication before restoring it. This ensures the attacker cannot regain access with stolen credentials. Option B is a good practice but not a prerequisite for restoring this specific account.

Option C is unnecessary if the account was not an administrator. Option D is irrelevant because containment applies to the account, not devices.

25
MCQeasy

Your organization uses Microsoft Sentinel. A security incident is created, and the assigned analyst needs to perform initial triage. What is the first step the analyst should take according to Microsoft best practices for incident response?

A.Contain the affected resources immediately to prevent further damage.
B.Run a full investigation using Microsoft 365 Defender hunting queries.
C.Review the incident details and verify the alert is a true positive.
D.Escalate the incident to the senior security team.
AnswerC

The correct first step is to open the incident in Microsoft Sentinel and review its details to verify the alert is a true positive. This means checking the incident's severity, status, entities, MITRE ATT&CK tactics, and the raw data or logs that triggered the analytics rule, then correlating it with other alerts on the same resource to confirm the activity is genuinely malicious. Only after this validation should you decide whether to contain, investigate, or escalate, because taking response actions on an unverified false positive can cause unnecessary damage.

Why this answer

The first step in the Microsoft incident response process is to verify the alert and determine its validity. Option A is wrong because containment should follow after verification. Option B is wrong because escalating before verification bypasses triage.

Option D is wrong because detailed investigation comes after initial triage.

26
MCQhard

Your organization uses Microsoft Sentinel. You need to implement a custom incident response process that requires approval before taking action on an incident. What should you use?

A.Automation rules with conditions
B.Watchlist for approval status
C.Playbook with Microsoft Teams connector for approval
D.Analytics rule with custom details
AnswerC

A playbook is an Azure Logic Apps workflow and can include the Microsoft Teams connector, which enables sending an adaptive card to a designated Teams channel and using the approval action to wait for a Yes/No response from a user. This directly delivers a human-in-the-loop checkpoint that blocks subsequent steps until the approver decides, satisfying the need for approval in the incident response process. Once the response is collected, the playbook can branch to different actions based on the outcome, making it the correct mechanism for this requirement.

Why this answer

A playbook with a Microsoft Teams connector is the correct choice because it enables an interactive approval workflow directly within Teams. When an incident is triggered, the playbook can send an adaptive card to a Teams channel or user, pause execution until an approval decision is made, and then continue with the next steps based on that decision. This satisfies the requirement for a custom approval process before taking action on an incident.

Exam trap

The trap here is that candidates often confuse automation rules (which can run playbooks automatically) with the playbook itself, failing to recognize that only a playbook with an interactive connector like Teams can implement a human-in-the-loop approval step.

How to eliminate wrong answers

Option A is wrong because automation rules with conditions can trigger actions based on incident properties but cannot pause for human approval; they execute actions automatically without any interactive approval step. Option B is wrong because a watchlist for approval status is a static reference table used for correlation or enrichment, not a mechanism to request, track, or enforce an approval workflow. Option D is wrong because an analytics rule with custom details is used to generate alerts and incidents from log data, not to implement an approval process after an incident is created.

27
Multi-Selecteasy

Your organization uses Microsoft Sentinel. You are investigating an incident and need to gather additional context about a suspicious IP address. Which TWO Microsoft Sentinel features can you use to enrich the investigation?

Select 2 answers
A.Threat intelligence
B.Watchlist
C.Hunting
D.Entity behavior analytics
E.User and Entity Behavior Analytics (UEBA)
AnswersA, D

Threat intelligence can indicate if the IP is known malicious.

Why this answer

Threat intelligence is correct because it allows you to cross-reference the suspicious IP address against known threat intelligence feeds (e.g., Tor exit nodes, known C2 servers) directly within Microsoft Sentinel. This enriches the investigation by providing context such as reputation scores, associated malware families, and geographic origin, helping you assess the IP's maliciousness.

Exam trap

The trap here is that candidates often confuse UEBA (Option E) with entity behavior analytics (Option D), but UEBA is a broader analytics framework that does not directly enrich a specific IP address with external threat context, whereas entity behavior analytics is the correct feature for enriching investigation by providing entity-specific behavioral insights.

28
MCQeasy

A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request. What is the first step the analyst should take?

A.Disable the user account
B.Reset the user's password
C.Run a full antivirus scan on the user's device
D.Validate the alert by checking the user's recent activity
AnswerD

Validating the alert by checking the user's recent activity is the correct first step because it confirms whether the alert corresponds to a genuine security event, such as anomalous sign-ins, impossible travel, or suspicious mailbox activity in Microsoft Defender. By reviewing the user's sign-in logs and other evidence, you can determine the alert's true positive or false positive status, which guides all subsequent containment and remediation decisions. This triage approach aligns with incident response best practices, ensuring you act based on evidence rather than assumptions and avoiding unnecessary disruption to the user.

Why this answer

When Microsoft Defender for Identity alerts on a suspicious Kerberos ticket request, the first step is to validate the alert by checking the user's recent activity. This ensures the alert is not a false positive caused by legitimate behavior (e.g., scheduled tasks or application service tickets) before taking any disruptive action. Defender for Identity uses network traffic and event logs to detect anomalies like overpass-the-hash or Kerberoasting, but initial validation prevents unnecessary account lockouts or password resets.

Exam trap

The trap here is that candidates often jump to containment (disable account) or remediation (reset password) without first validating the alert, confusing the 'respond' phase with the initial 'validate' step required by incident response best practices.

How to eliminate wrong answers

Option A is wrong because disabling the user account is a containment step that should only occur after the alert is validated as a true positive, as premature disabling can disrupt legitimate access and generate false incident response overhead. Option B is wrong because resetting the user's password is a remediation step that assumes the account is compromised, but without validation, it may be unnecessary and could alert an actual attacker prematurely. Option C is wrong because running a full antivirus scan on the user's device addresses endpoint malware, but the alert originates from network-level Kerberos authentication anomalies, not from a local infection; the scan would not validate the specific ticket request.

29
MCQeasy

You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different workloads. You need to view all related alerts in a single timeline. What should you use?

A.Incident page
B.Advanced hunting
C.Action center
D.Device timeline
AnswerA

The incident page is the central investigation surface in Microsoft Defender XDR. It automatically aggregates all alerts related to a single attack campaign from across the Microsoft 365 security stack—Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps—into a unified view. Along with alerts, it surfaces the full attack story, affected assets, and evidence, making it the correct place to investigate the full scope of an incident. This page directly answers the need to see all related alerts in one place.

Why this answer

The Incident page in Microsoft Defender XDR aggregates all alerts from different workloads (e.g., Microsoft Defender for Endpoint, Office 365, Identity) into a single, unified timeline view. This allows you to see the sequence of events and alerts related to the incident in chronological order, which is essential for understanding the attack chain and coordinating response actions.

Exam trap

The trap here is that candidates confuse the Incident page's unified alert timeline with Advanced hunting, thinking they need to write a KQL query to see related alerts, when in fact the Incident page automatically provides that consolidated view without any querying.

How to eliminate wrong answers

Option B (Advanced hunting) is wrong because it is a query-based tool for proactively searching raw data across workloads, not a pre-built timeline view for a specific incident. Option C (Action center) is wrong because it lists pending and completed remediation actions (e.g., isolate device, block file) across incidents, not the alerts or their timeline for a single incident. Option D (Device timeline) is wrong because it shows events and alerts for a single device only, not the cross-workload alerts aggregated for an incident.

30
MCQmedium

You are a security analyst investigating a detected phishing campaign targeting users in your organization. The Microsoft Defender for Office 365 alert indicates that several users clicked on a malicious link. Which action should you take first to prevent further compromise?

A.Add the malicious URL to the Microsoft Defender for Endpoint custom threat indicator list.
B.Isolate all affected users' devices from the network.
C.Report the email to Microsoft for analysis.
D.Block the sender email address in the tenant.
AnswerA

Creating a custom threat intelligence indicator for the malicious URL in Microsoft Defender for Endpoint triggers an immediate Alert/Block enforcement action on all onboarded endpoints via the built-in Network Protection component. When any user clicks the link, the endpoint blocks outbound connectivity to that URL before the content loads, regardless of the fact that the phishing email is already sitting in their mailbox. This is the fastest operational control because it addresses the actual click vector across all affected devices, not just the email envelope, and can also generate an alert for incident investigation.

Why this answer

Adding the malicious URL to the Microsoft Defender for Endpoint custom threat indicator list is the correct first action because it immediately blocks future access to that URL across all endpoints protected by Defender for Endpoint, preventing further compromise from users clicking the same link. This leverages the threat intelligence feed to enforce a block action at the network level, stopping the attack vector proactively without disrupting user productivity or requiring device isolation.

Exam trap

The trap here is that candidates often confuse incident response containment steps (like device isolation) with the most immediate preventive action, failing to recognize that blocking the malicious URL at the endpoint level stops the attack vector for all users without the operational impact of isolating devices.

How to eliminate wrong answers

Option B is wrong because isolating all affected users' devices from the network is an extreme containment step that disrupts operations and should only be taken after confirming active compromise or lateral movement, not as the first action when the primary threat is the URL itself. Option C is wrong because reporting the email to Microsoft for analysis is a reactive, long-term feedback action that does not immediately prevent further users from clicking the malicious link. Option D is wrong because blocking the sender email address is ineffective against phishing campaigns that often use spoofed or disposable addresses, and it does not block the malicious URL which could be delivered via other senders or methods.

31
MCQeasy

Your organization uses Microsoft Defender for Office 365. You detect a phishing email that was delivered to a user's inbox. You want to remove the email from all recipients. What should you do?

A.Submit the email to Microsoft for analysis.
B.Create a mail flow rule to delete similar emails in the future.
C.Block the sender using the Tenant Allow/Block List.
D.Use Threat Explorer to find the email and take action to delete it.
AnswerD

Threat Explorer (part of Microsoft Defender for Office 365) provides a deep, filterable view of email activity, including sender, recipient, subject, and threat signals. You can locate the specific email(s) that match the attack, select them, and use the 'Take action' drop-down to choose 'Delete' (or 'Soft delete/Delete'), which performs a bulk removal of the message from all affected mailboxes and can optionally trigger a remediation action. This is the appropriate tool because it combines search, investigation, and remediation for already-delivered threats.

Why this answer

Threat Explorer in Microsoft Defender for Office 365 allows security analysts to search for specific emails based on attributes like sender, subject, or recipient, and then take bulk remediation actions such as soft-delete (move to Deleted Items) or hard-delete (purge from mailbox). This is the correct tool to remove a phishing email that has already been delivered to users' inboxes, as it provides granular search and remediation capabilities for existing messages.

Exam trap

The trap here is that candidates often confuse proactive blocking (e.g., blocking the sender or creating a rule) with reactive remediation, failing to recognize that Threat Explorer is the only option that can remove already-delivered emails from user mailboxes.

How to eliminate wrong answers

Option A is wrong because submitting the email to Microsoft for analysis (e.g., via the Submissions portal) is used to improve detection algorithms or verify classification, not to remove already-delivered emails from recipients' mailboxes. Option B is wrong because creating a mail flow rule (transport rule) applies to future emails only; it cannot retroactively delete messages already delivered to inboxes. Option C is wrong because blocking the sender via the Tenant Allow/Block List prevents future delivery from that sender but does not remove emails already delivered to users' inboxes.

32
MCQhard

Your organization uses Microsoft Defender for Identity and Microsoft Defender XDR. You receive an alert about a suspicious LDAP query originating from a domain controller. The alert indicates potential use of the DCSync attack technique. What is the most effective immediate action to contain the attack?

A.Block all LDAP traffic at the firewall.
B.Restart the domain controller to clear any malicious processes.
C.Disable the account that initiated the suspicious replication request.
D.Reset the krbtgt account password twice.
AnswerC

Disabling the account is the correct immediate containment action because DCSync attacks (like Golden Ticket or DCshadow pre-staging) rely on the compromised identity having directory replication permissions, and disabling it blocks that account from authenticating or invoking DRS replication any further. This directly severs the attacker's current access path and halts the unauthorized replication request without requiring a full DC restart or broad network disruption. After disabling, the SID of the account can be added to a honeytoken or monitored for any further attempts during incident response. It is the fastest, least-destructive way to stop the bleeding.

Why this answer

The DCSync attack abuses the Directory Replication Service Remote Protocol (MS-DRSR) to impersonate a domain controller and request replication of credentials. Disabling the compromised account that initiated the suspicious LDAP replication request immediately stops the attacker's ability to request further replication, effectively containing the attack at the source without disrupting the entire domain.

Exam trap

The trap here is that candidates often confuse DCSync with a standard LDAP query and choose to block LDAP traffic, not realizing DCSync uses the DRSR protocol over RPC, and that disabling the offending account is the precise immediate containment step.

How to eliminate wrong answers

Option A is wrong because blocking all LDAP traffic at the firewall would break legitimate domain controller replication and authentication traffic, causing a domain-wide outage, and DCSync uses the DRSR protocol over RPC, not standard LDAP, so it would not even block the attack. Option B is wrong because restarting the domain controller would only clear volatile processes temporarily; the attacker's account or session would still be active, and the malicious replication request could be re-initiated immediately after reboot. Option D is wrong because resetting the krbtgt account password twice is a recovery step to invalidate existing Kerberos tickets after the attack has been contained, not an immediate containment action, and it does not stop the ongoing DCSync replication.

33
MCQhard

During a ransomware incident, security team needs to prevent encryption while preserving forensic data. Which action best achieves this balance?

A.Shut down all affected servers immediately.
B.Run a full antivirus scan on all endpoints.
C.Enable network micro-segmentation to isolate affected systems from file servers and take memory snapshots.
D.Disconnect the network but leave systems running.
AnswerC

Network micro-segmentation enforces granular access control at the workload level, so even if a host is compromised, it cannot reach file servers or other critical systems, halting lateral movement and additional encryption. Taking memory snapshots contemporaneously preserves volatile forensic evidence such as encryption keys and process artifacts, which are vital for identifying the ransomware variant and potentially recovering data without paying the ransom. This approach provides both containment and evidence preservation.

Why this answer

Network micro-segmentation (e.g., using Azure Network Security Groups or software-defined networking) isolates affected systems from file servers, halting lateral movement and preventing encryption of shared data, while memory snapshots (e.g., via Azure VM snapshots or live memory acquisition tools like WinPmem) preserve volatile forensic evidence such as encryption keys or process artifacts. This balances containment with forensic preservation, unlike destructive actions like shutdown or disconnection that lose memory data.

Exam trap

The trap here is that candidates confuse 'preserving forensic data' with keeping systems powered on (Option D), failing to realize that memory snapshots require a controlled capture before isolation, and that micro-segmentation specifically targets file server access to stop encryption at the network layer.

How to eliminate wrong answers

Option A is wrong because shutting down servers immediately destroys volatile memory (e.g., encryption keys, running processes) and may trigger anti-forensic mechanisms that delete logs. Option B is wrong because running a full antivirus scan on all endpoints can modify file timestamps, trigger ransomware to encrypt remaining data, and consume I/O that overwrites forensic evidence. Option D is wrong because disconnecting the network but leaving systems running does not prevent ransomware from continuing to encrypt local files and may allow persistence mechanisms to execute, while also failing to isolate from file servers that could be encrypted via cached credentials.

34
MCQhard

Refer to the exhibit. A security analyst creates a scheduled analytics rule in Microsoft Sentinel based on the JSON shown. After enabling the rule, the analyst notices that the rule generates alerts every hour for the same user accounts even after the incidents are resolved. What is the most likely cause?

A.The severity is set to High, causing multiple alerts
B.The query period is too short, causing the rule to refetch old data
C.Suppression is disabled, so the rule fires every hour with overlapping results
D.The trigger threshold is too low, causing the rule to fire too often
AnswerC

When suppression is disabled, the scheduled rule has no mechanism to pause or stop additional runs after an alert is created, so it executes every hour exactly as scheduled. Because each hourly run uses a 1-day query period, the same events fall into multiple overlapping lookback windows, causing the rule to generate a new alert each time the query returns results that meet the threshold. Enabling suppression would suspend the rule for a defined period after an alert is generated, preventing overlapping and duplicate alerts from the same activity.

Why this answer

In Microsoft Sentinel, an analytics rule with suppression disabled will fire every time its query period elapses and the query returns results, even if those results overlap with previously generated incidents. Since the rule runs hourly and the query period likely covers a window that includes the same user accounts, it repeatedly generates alerts for the same entities. Enabling suppression (or configuring the rule to group and suppress duplicate alerts) prevents this repetitive firing.

Exam trap

SC-200 often tests the difference between rule scheduling parameters (query period, frequency, threshold) and suppression settings, catching candidates who blame alert frequency on severity or thresholds instead of the missing suppression configuration.

How to eliminate wrong answers

Option A is wrong because severity level (High) affects the incident's priority and labeling, not the frequency of alert generation; a High severity rule does not inherently fire more often. Option B is wrong because a short query period would actually reduce overlap by looking at a smaller time window, not cause repeated alerts for the same data; the issue is the lack of suppression, not the query period length. Option D is wrong because the trigger threshold controls how many results must be returned before an alert is generated, not how often the rule fires; a low threshold might make the rule more sensitive but does not cause hourly repetition of the same alerts.

35
MCQmedium

Your organization uses Microsoft Sentinel. A security incident is generated by a scheduled analytics rule. You need to automatically assign the incident to the SOC team and set its severity. What should you create?

A.An analytics rule
B.An automation rule
C.A workbook
D.A playbook
AnswerB

An automation rule is the correct choice because it executes natively and immediately when an incident is created, and it directly supports simple actions such as 'Assign owner' and 'Set severity' through conditions that evaluate incident properties at that moment. Unlike a playbook, it requires no Logic App or separate trigger, so it provides the fastest, most reliable method to impose mandatory ownership and severity settings during initial incident generation, exactly matching the requirement.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to a specific team (e.g., SOC team) and set their severity based on conditions like analytics rule name or incident properties. Unlike playbooks, automation rules are lightweight, run immediately without a Logic Apps connector, and are designed for simple, no-code incident management tasks such as assignment and severity changes.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, thinking that any automated response requires a playbook, but Microsoft Sentinel specifically uses automation rules for lightweight, built-in incident management actions like assignment and severity changes, reserving playbooks for more complex or multi-step workflows.

How to eliminate wrong answers

Option A is wrong because an analytics rule generates alerts and incidents based on queries, but it cannot automatically assign incidents or change severity after creation; it only defines the initial severity in the rule configuration. Option C is wrong because a workbook provides visualizations and dashboards of Sentinel data, but it cannot perform automated actions like incident assignment or severity modification. Option D is wrong because a playbook is a workflow built on Azure Logic Apps that can automate complex responses, but it is not the simplest or most direct method for simple assignment and severity changes; automation rules are preferred for these straightforward actions and run without the overhead of a playbook.

36
MCQhard

Your organization uses Microsoft Sentinel and has enabled the Microsoft 365 Defender connector. You want to automatically assign incidents to a specific analyst team based on the incident severity and type. Which component should you configure?

A.Analytics rule in Microsoft Sentinel
B.Workbook in Microsoft Sentinel
C.Automation rule in Microsoft Sentinel
D.Custom playbook in Microsoft Sentinel
AnswerC

Automation rules in Microsoft Sentinel are the native, lightweight mechanism for automating incident management tasks, including assigning an owner, changing status, or applying tags, without requiring a Logic Apps connector or additional code. You can create a rule with a condition like 'When incident is created' and an action 'Assign owner' to set the incident owner to a specific user or group. This is simpler, more performant, and directly integrated into the incident pipeline compared to custom code or playbooks.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific teams based on conditions like severity and type. This is the correct component because it provides a no-code, rule-based engine for incident management tasks, including assignment, without requiring custom logic or external automation.

Exam trap

The SC-200 exam often tests the distinction between automation rules (for incident management) and playbooks (for response actions), leading candidates to choose playbooks when a simpler, built-in rule suffices.

How to eliminate wrong answers

Option A is wrong because analytics rules are used to generate alerts and incidents from data sources, not to manage or assign incidents after creation. Option B is wrong because workbooks are visualization tools for querying and displaying data, not for automating incident assignment. Option D is wrong because custom playbooks (based on Azure Logic Apps) can automate responses but are overkill for simple assignment; automation rules are the native, simpler solution for this task.

37
MCQhard

You are investigating a Microsoft Defender XDR incident where a user's device is showing signs of compromise. The incident includes alerts from Microsoft Defender for Endpoint and Microsoft Defender for Identity. You need to isolate the device from the network while preserving forensic evidence. Which action should you take?

A.Initiate a full antivirus scan on the device and then reboot it to remove the threat.
B.Use Microsoft Defender for Identity to disable the user account and then isolate the device from the Defender for Identity portal.
C.Run the 'Live response' session and execute the 'isolate' command.
D.Run the 'Isolate device' action in Microsoft Defender for Endpoint, selecting the 'Full isolation' option.
AnswerD

Full isolation in Microsoft Defender for Endpoint disconnects the device from all network traffic except for the Defender for Endpoint cloud service, allowing you to contain the threat while maintaining communication for investigation. It preserves forensic evidence on the device because it does not wipe or modify files. This action is appropriate for a compromised device requiring containment and evidence preservation.

Why this answer

Full isolation in Microsoft Defender for Endpoint is the correct action to contain a compromised device while preserving forensic evidence. It restricts network communication to only the Defender for Endpoint service, preventing lateral movement and C2 traffic, and allows investigators to perform live response and collect evidence. Other options either misstate capabilities or do not achieve isolation.

Disabling a user account does not isolate the device, and antivirus scans do not contain the threat.

Exam trap

The trap here is confusing device isolation capabilities across Microsoft Defender services; only Defender for Endpoint provides device isolation, not Defender for Identity or live response commands.

38
MCQeasy

A Microsoft Defender XDR incident shows a malicious email delivered to a user, and the analyst confirms the message contains a credential-harvesting link. Before the user clicks, you need to remove the message from all mailboxes in the tenant and block the sender and URL for the future. Which Microsoft Defender for Office 365 capability should you use from the incident?

A.Threat Explorer with a message trace filter to identify and delete matching messages.
B.The email entity page action to soft delete, hard delete, or move to junk, plus submitting the sender and URL for blocking.
C.Automated investigation and response with the soft delete action on the email entity.
D.A mail flow transport rule in the Exchange admin center that rejects messages from the sender domain.
AnswerB

Microsoft Defender for Office 365 exposes email entity actions in the incident that include soft delete, hard delete, and move to junk, letting you purge the message across all mailboxes. Submitting the sender and URL through the same workflow lets the service add them to tenant-level block entries. This directly removes the active threat and prevents recurrence, matching both requirements in the scenario.

Why this answer

When a malicious email is confirmed, Microsoft Defender for Office 365 provides email entity remediation actions that purge the message tenant-wide and let you block the associated sender and URL. This combines cleanup of the delivered threat with prevention of recurrence. Tools that only investigate, or controls that only affect future mail, leave the delivered message reachable and do not satisfy both halves of the requirement.

Exam trap

The trap here is confusing investigation tooling, such as Threat Explorer, with remediation actions that actually remove and block content.

39
MCQmedium

A security analyst is investigating a Microsoft Defender for Cloud Apps alert about a suspicious OAuth app that has high permissions. The analyst needs to disable the app immediately. What is the correct action?

A.Revoke all tokens for the app in Microsoft Entra ID.
B.Generate a new client secret for the app.
C.From the Microsoft Defender for Cloud Apps alert, select 'Disable app'.
D.Go to Microsoft Entra ID admin center and delete the app registration.
AnswerC

This is the recommended remediation because Defender for Cloud Apps provides a built-in governance action that disables the OAuth app directly from the alert. Disabling the app denies the app's service principal from acquiring new tokens and revokes existing grants, effectively cutting off access to Microsoft 365 resources. This action is integrated with the investigation workflow, ensuring immediate and consistent enforcement across the organization.

Why this answer

Microsoft Defender for Cloud Apps provides a built-in 'Disable app' action directly from the alert, which immediately revokes the OAuth app's permissions and prevents further access without deleting the app registration. This is the fastest way to mitigate the threat while preserving the app for potential forensic analysis.

Exam trap

The trap here is that candidates often assume revoking tokens (Option A) or deleting the app registration (Option D) is the correct immediate response, but the exam tests the specific 'Disable app' action available within the Defender for Cloud Apps alert workflow, which is the designed incident response step for OAuth app compromise.

How to eliminate wrong answers

Option A is wrong because revoking all tokens for the app in Microsoft Entra ID would invalidate current sessions but does not disable the app itself; the app could still request new tokens and regain access. Option B is wrong because generating a new client secret only rotates credentials; the app retains its high permissions and can continue to use the old secret until it is updated, which does not stop the immediate threat. Option D is wrong because deleting the app registration in Microsoft Entra ID is a permanent action that removes the app entirely, which may be too destructive and could disrupt legitimate use; it also bypasses the Defender for Cloud Apps alert's purpose-built disablement workflow.

40
MCQmedium

An analyst is investigating a potential data exfiltration incident involving a user who accessed sensitive files from a personal device. The analyst wants to gather evidence about the device's compliance status and recent activity. Which Microsoft Intune feature should the analyst use?

A.Exchange Online message trace
B.Microsoft Intune device inventory and compliance reports
C.Azure Activity Log
D.Microsoft 365 Defender's service health dashboard
AnswerB

Microsoft Intune device inventory and compliance reports give a centralized view of every enrolled device, including its operation system, ownership type, enrollment date, and compliance status against assigned policies. These reports also surface recent device activity, such as check-ins and policy evaluation results, which allows an analyst to pinpoint non-compliant or unmanaged devices that might be involved in data exfiltration. This is the correct tool because it directly supports identifying which devices lack the required security controls.

Why this answer

Microsoft Intune device inventory and compliance reports provide detailed information about a device's compliance status, including whether it meets security policies, has required updates, and is managed correctly. This is essential for investigating potential data exfiltration from a personal device, as it allows the analyst to verify if the device was compliant and review recent activity logs within Intune.

Exam trap

The trap here is that candidates may confuse Azure Activity Log (which covers Azure resource operations) with Intune's device management logs, or mistakenly think Exchange message trace can reveal device compliance status.

How to eliminate wrong answers

Option A is wrong because Exchange Online message trace is used for tracking email delivery and routing, not for device compliance or activity monitoring. Option C is wrong because Azure Activity Log records subscription-level events (e.g., resource creation, RBAC changes) and does not include device compliance or user activity on a personal device. Option D is wrong because Microsoft 365 Defender's service health dashboard shows the operational status of Microsoft services, not device-specific compliance or activity data.

41
MCQeasy

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel during an investigation. The analyst expects to see alerts related to malware from IP 10.0.0.5 but receives no results. The SecurityAlert table contains data from the last 24 hours. What is the most likely reason for no results?

A.The ExtendedProperties column does not contain a key named 'IPAddress' for these alerts.
B.The 'contains' operator is case-sensitive.
C.The time filter 'ago(1d)' is too restrictive; should use 'ago(7d)'.
D.The 'project' statement drops the necessary columns.
AnswerA

The query filters on ExtendedProperties parsing a key named IPAddress. If the alerts store the address under a different key or format, the dynamic field access returns null and every row is filtered out, so no results appear despite matching data existing in the table.

Why this answer

The most likely reason for no results is that the ExtendedProperties column does not contain a key named 'IPAddress' for these alerts. In Microsoft Sentinel, the SecurityAlert table stores additional alert details in the ExtendedProperties column as a dynamic (JSON) field, and the specific key name varies by alert provider — if the key is not 'IPAddress', the query filter returns nothing.

Exam trap

SC-200 often tests the assumption that column names and JSON keys are consistent across all alert providers — candidates assume 'IPAddress' is a standard key in ExtendedProperties, when in reality the schema is provider-dependent and must be verified.

How to eliminate wrong answers

Option B is wrong because the 'contains' operator in KQL is case-insensitive by default (unlike 'has_cs' or 'contains_cs'), so case sensitivity would not cause zero results. Option C is wrong because the SecurityAlert table only contains data from the last 24 hours per the scenario, so extending the time filter to 7 days would not help — the data simply is not there. Option D is wrong because the 'project' statement only selects columns for output; it does not filter rows, so it cannot be the cause of zero results.

42
MCQmedium

You are a SOC analyst using Microsoft Defender XDR. An incident named "Multi-stage intrusion on FIN-PC01" contains alerts for a malicious PowerShell script, a suspicious outbound connection to a known C2 IP, and credential dumping activity. You need to perform an investigation that automatically shows the full attack story, including related entities, alerts, and timeline, without manually correlating each alert. What should you use?

A.The Microsoft Sentinel incident investigation graph
B.The incident's attack story timeline in the Microsoft Defender XDR portal
C.Automated investigation and response (AIR) investigation details page
D.Advanced hunting with a custom KQL query across DeviceProcessEvents and DeviceNetworkEvents
AnswerB

The attack story timeline automatically aggregates all alerts, entities, and events related to the incident into a single visual timeline. It shows the full chain of events, including process execution, network connections, and user actions, enabling rapid correlation without manual effort. This is the primary investigation view for incidents in Microsoft Defender XDR.

Why this answer

The attack story timeline in Microsoft Defender XDR is designed to automatically correlate all alerts, entities, and events from an incident into a single, interactive timeline. It eliminates manual correlation and provides a comprehensive view of the attack, which is exactly what the analyst needs to understand the full scope quickly.

Exam trap

The trap here is assuming that advanced hunting or Sentinel's investigation graph provides the same automated incident correlation as the Defender XDR attack story timeline.

43
Multi-Selectmedium

Which TWO actions are appropriate when handling a confirmed ransomware incident in Microsoft 365?

Select 2 answers
A.Run a full antivirus scan on all devices.
B.Restore encrypted files from backup immediately without investigation.
C.Pay the ransom to regain access.
D.Isolate affected devices from the network.
E.Change passwords for all potentially compromised accounts.
AnswersD, E

Isolating affected devices from the network is the correct containment measure because it immediately severs the ransomware's ability to propagate laterally via SMB, RDP, or other network protocols. This should be performed at the endpoint level (disconnecting the NIC or blocking in the switch/firewall) and ideally include domain controllers and backup servers to prevent mass encryption and credential theft. The goal is to preserve evidence and stop the incident from becoming a full-domain compromise while allowing responders to analyze the threat safely.

Why this answer

Option D is correct because isolating affected devices from the network is a standard containment step that prevents the ransomware from spreading laterally to other endpoints and limits further encryption or exfiltration within the Microsoft 365 environment. Option E is correct because changing passwords for all potentially compromised accounts revokes the attackers' access, invalidates stolen credentials, and is essential when identity compromise (e.g., via phishing or token theft) is a common ransomware entry vector in Microsoft 365. Option A is not appropriate as a primary incident response action because a full antivirus scan is a remediation/detection step that does not contain an active ransomware incident and may be ineffective against fileless or cloud-based attacks.

Option B is wrong because restoring from backup immediately without investigation can reintroduce the threat or restore already-compromised data, and the root cause must be identified first. Option C is wrong because paying the ransom is discouraged by Microsoft and law enforcement, does not guarantee data recovery, and may fund further criminal activity.

Exam trap

SC-200 often tests the misconception that immediate restoration or antivirus scanning is the first response to ransomware, when in fact containment and identity remediation are the priority.

44
Multi-Selectmedium

Which TWO actions should you take when responding to a confirmed ransomware incident in Microsoft Defender XDR?

Select 2 answers
A.Run a full antivirus scan
B.Reset the user's password
C.Restore files from backup
D.Disable the user account
E.Isolate the affected devices
AnswersA, E

Running a full antivirus scan is a critical eradication step that identifies and removes malware from the affected system, including worms, trojans, and ransomware. The scan should be performed after the device is isolated to prevent the infection from spreading while the scan is in progress. It also provides valuable indicators of compromise (IOCs) that can be used for further threat hunting and to ensure the system is clean before recovery.

Why this answer

Running a full antivirus scan (Option A) is a critical containment and remediation step in a confirmed ransomware incident because it detects and removes malicious files, including ransomware binaries and associated artifacts, from affected devices. In Microsoft Defender XDR, a full scan leverages the Microsoft Defender Antivirus engine to inspect all files and running processes, ensuring that the ransomware payload is eliminated from the system. This action helps prevent further encryption or lateral movement by the malware.

Exam trap

The trap here is that candidates often confuse recovery actions (like restoring from backup) with immediate containment actions, leading them to select Option C instead of recognizing that isolation and scanning are the correct first steps in the incident response playbook.

45
Multi-Selectmedium

Your Microsoft Sentinel workspace ingests logs from Microsoft Defender for Cloud and Microsoft 365 Defender. You need to create an incident response playbook that automatically responds to high-severity incidents. Which THREE components are required? (Choose three.)

Select 3 answers
A.A workbook to visualize the incident data
B.An analytics rule that generates the incident
C.An automation rule in Microsoft Sentinel
D.A hunting query to search for similar activity
E.A Logic Apps workflow with Microsoft Sentinel trigger
AnswersB, C, E

An analytics rule is the foundational component that uses a KQL query to detect a specific security pattern and, when matched, creates an incident in Microsoft Sentinel. Because automated responses (such as playbooks or automation rules) only operate on incidents, an analytics rule is strictly required to generate the incident in the first place. Without this rule, there is no incident object to act upon, regardless of any downstream automation.

Why this answer

Option B is required because an analytics rule is what detects the activity and generates the incident in Microsoft Sentinel; without an incident, there is nothing for the playbook to respond to. Option C is required because an automation rule in Microsoft Sentinel is the mechanism that triggers a playbook automatically when an incident is created, matching conditions such as high severity. Option E is required because the playbook itself is implemented as an Azure Logic Apps workflow that uses the Microsoft Sentinel incident trigger to run the response actions.

Option A is not required because a workbook is only a visualization/reporting tool and plays no role in automated incident response. Option D is not required because a hunting query is used for proactive threat hunting, not for automatically triggering a playbook.

Exam trap

SC-200 often tests whether candidates confuse visualization (workbooks) and hunting (queries) with the actual automation chain — analytics rule, automation rule, and Logic Apps playbook — that is required for automated response.

46
MCQmedium

A security analyst receives a high-severity alert for a suspicious login from an unusual location. The alert was generated by Microsoft Sentinel from Microsoft Entra ID sign-in logs. The analyst needs to determine if the login was successful and if any data exfiltration occurred. What is the MOST efficient first step?

A.Run a KQL query in Microsoft Sentinel to review the SigninLogs table for the user within the alert time range.
B.Use Microsoft Defender XDR to check the user's device timeline for suspicious activity.
C.Run a KQL query in Microsoft Sentinel to check Microsoft Defender for Cloud Apps alerts for the user.
D.Check the firewall logs in Azure Firewall for outbound connections from the user's IP.
AnswerA

The SigninLogs table in Microsoft Sentinel stores authentication events from Microsoft Entra ID, including interactive and non-interactive sign-ins. Querying this table within the alert time range for the affected user reveals the login success/failure status, source IP, location, MFA result, and conditional access policies applied. This is the authoritative source for validating whether the suspicious sign-in succeeded and assessing the blast radius.

Why this answer

The most efficient first step is to run a KQL query in Microsoft Sentinel against the SigninLogs table for the specific user within the alert time range. This directly confirms whether the suspicious login was successful by checking the 'ResultType' and 'ResultDescription' fields, which is the fastest way to validate the alert's core claim before investigating data exfiltration.

Exam trap

The trap here is that candidates often jump to investigating data exfiltration (e.g., checking firewall logs or Defender for Cloud Apps) without first confirming the login was successful, which wastes time and resources if the login actually failed.

How to eliminate wrong answers

Option B is wrong because checking the user's device timeline in Microsoft Defender XDR is a secondary step that assumes the login was successful and the device was involved, but it does not first confirm the login status. Option C is wrong because querying Microsoft Defender for Cloud Apps alerts for the user is premature; those alerts would only be generated after the login is successful and suspicious activity is detected, so it is not the most efficient first step. Option D is wrong because checking Azure Firewall logs for outbound connections from the user's IP is a deep investigation step for data exfiltration that should only be performed after confirming the login was successful, making it inefficient as a first step.

47
MCQhard

During a security incident, you need to isolate a compromised Windows device from the network while allowing communication with Microsoft Defender for Endpoint services. Which Microsoft Defender for Endpoint action should you use?

A.Run antivirus scan
B.Isolate device
C.Collect investigation package
D.Restrict app execution
AnswerB

Device isolation in Defender for Endpoint places the machine in a state where all inbound and outbound network traffic is blocked, except for traffic to the Defender for Endpoint cloud service. This preserves the management channel, allowing security operations to issue further commands, receive telemetry, and complete remediation while the host is quarantined from the network. It directly prevents the attacker from continuing their C2 and lateral movement, making it the correct containment action.

Why this answer

The correct action is 'Isolate device' because it disconnects the compromised Windows device from the network while maintaining a dedicated communication channel to Microsoft Defender for Endpoint (MDE) services. This ensures the device cannot be used to spread laterally or exfiltrate data, yet MDE can still receive telemetry and apply remediation commands. The isolation is enforced via a Windows Filtering Platform (WFP) firewall rule that blocks all inbound and outbound traffic except for MDE-related endpoints (e.g., *.events.data.microsoft.com).

Exam trap

The trap here is that candidates confuse 'Restrict app execution' with network isolation, not realizing that restricting apps only controls what software can run locally, not the device's ability to communicate over the network.

How to eliminate wrong answers

Option A is wrong because 'Run antivirus scan' only performs a local malware scan and does not alter network connectivity, leaving the device able to communicate with other network hosts and potentially spread the threat. Option C is wrong because 'Collect investigation package' gathers forensic data (e.g., registry, memory, event logs) for analysis but does not isolate the device from the network, so lateral movement remains possible. Option D is wrong because 'Restrict app execution' uses Windows Defender Application Control (WDAC) to block untrusted software from running, but it does not block network traffic, so the device can still communicate with other systems and MDE services are not specifically preserved.

48
Multi-Selectmedium

Your organization uses Microsoft Sentinel. You have been asked to configure automated responses to security incidents. Which TWO of the following can be used to automate responses in Microsoft Sentinel?

Select 2 answers
A.Workbooks
B.Power Automate flows
C.Playbooks (Azure Logic Apps)
D.Custom connectors
E.Automation rules
AnswersC, E

Playbooks are cloud workflows built on Azure Logic Apps that you can invoke from Microsoft Sentinel to automate a security response. They can be triggered by an analytics rule (automatically on alert creation) or by an automation rule on an incident, and they support actions such as isolating a compromised host, resetting credentials, opening a ticket, or sending a Teams notification. Because they run with the Sentinel connector's context, playbooks are the native mechanism for incident-triggered orchestration and satisfy the requirement for automated responses.

Why this answer

Playbooks in Microsoft Sentinel are built on Azure Logic Apps, allowing you to automate complex, multi-step response workflows triggered by security incidents. They can execute actions like blocking IPs, resetting passwords, or enriching alerts with threat intelligence, making them a core automation tool for incident response.

Exam trap

The trap here is that candidates confuse 'automation' with 'visualization' or 'integration', incorrectly selecting Workbooks (which only display data) or Custom connectors (which are infrastructure for APIs, not response actions) instead of recognizing that only Playbooks and Automation rules directly execute automated responses.

49
MCQmedium

You have a Microsoft Sentinel analytical rule with the above configuration. During a security incident, multiple high-severity alerts are generated within a 5-minute window. How does the rule handle these alerts?

A.Only the first alert creates an incident; subsequent alerts are ignored.
B.Each alert creates a separate incident.
C.Alerts with the same entities are grouped into a single incident.
D.Alerts are suppressed for 5 minutes after the first alert.
AnswerC

This is the correct behavior for the rule's grouping settings. Microsoft Sentinel uses the entity matching method of 'All' to require that alerts share the exact same set of entities for grouping into one incident. When the rule fires, the incident creation engine evaluates each alert against the defined entities and groups those with matching values, providing a unified incident for triage and investigation.

Why this answer

The analytical rule is configured with 'Group alerts into incidents by: Grouping alerts into a single incident based on matching entities.' This means that when multiple high-severity alerts are generated within a 5-minute window, the rule evaluates the entities (e.g., IP addresses, user accounts) in each alert. If the alerts share the same entities, they are grouped into a single incident, preventing alert flooding and consolidating related security events.

Exam trap

The trap here is that candidates often confuse 'alert grouping' with 'alert suppression' or assume that multiple alerts always create multiple incidents, failing to notice the specific entity-based grouping configuration in the rule settings.

How to eliminate wrong answers

Option A is wrong because the rule does not ignore subsequent alerts; instead, it groups them based on entity matching, not a first-alert-only behavior. Option B is wrong because the rule is explicitly configured to group alerts into a single incident when entities match, not to create separate incidents for each alert. Option D is wrong because alert suppression is a separate configuration (e.g., 'Suppression query' or 'Suppression duration') not shown in the provided configuration; the rule groups alerts but does not suppress them for a fixed 5-minute window.

50
MCQmedium

Your organization uses Microsoft Sentinel. A security analyst reports that an incident was automatically created for a sign-in from an unfamiliar location, but after investigation, it was determined to be a false positive. You need to reduce similar false positives in the future without affecting legitimate detections. What should you do?

A.Disable the analytics rule that created the incident.
B.Add the location to a watchlist and reference it in the analytics rule.
C.Create an automation rule to close similar incidents automatically.
D.Modify the analytics rule query to exclude sign-ins from the specific location.
AnswerD

Modifying the analytics rule query to exclude sign-ins from the specific location is the precise fix because it filters out false positives at the source while preserving detection for all other events. In KQL, you would add a clause such as `| where Location != 'Country'` or filter by IP address, ensuring the rule's logic specifically ignores the unwanted sign-in origin. This keeps the rule active and focused on real anomalies, reducing alert noise without losing coverage for other suspicious activities.

Why this answer

Modifying the analytics rule query to exclude sign-ins from the specific location directly addresses the false positive at the detection logic level. This ensures that only sign-ins from that location are ignored, while all other unfamiliar location detections remain active, preserving legitimate detections.

Exam trap

The trap here is that candidates may confuse automation rules (which handle post-detection actions) with analytics rule modifications (which prevent detection at the source), leading them to choose option C instead of D.

How to eliminate wrong answers

Option A is wrong because disabling the analytics rule would stop all detections from that rule, not just the false positive, which would miss legitimate threats. Option B is wrong because adding the location to a watchlist and referencing it in the analytics rule would require complex query modifications and does not inherently exclude the location; watchlists are typically used for inclusion or enrichment, not exclusion, and would still trigger the incident if not properly referenced. Option C is wrong because creating an automation rule to close similar incidents automatically would only suppress the incident after creation, not prevent it, and could inadvertently close legitimate incidents if the criteria are too broad.

51
MCQeasy

A SOC analyst is investigating an incident where a user's credentials were compromised. The analyst uses Microsoft Sentinel to find all activities performed by the user in the last 24 hours. Which data source should the analyst query FIRST to get the most comprehensive view of the user's actions across Microsoft 365?

A.DeviceEvents
B.OfficeActivity
C.AzureActivity
D.SigninLogs
AnswerB

OfficeActivity represents the unified audit log for Microsoft 365, pulling records from Exchange, SharePoint, OneDrive, Teams, and other workloads. It captures user-level events such as email actions, file accesses, and messages sent after authentication, making it the appropriate table to investigate a user's activities in M365. This table is the primary source for reconstructing user behavior in the M365 environment.

Why this answer

OfficeActivity (Option B) is the correct first query because it captures user actions across Exchange Online, SharePoint Online, OneDrive for Business, Teams, and other Microsoft 365 workloads via the unified audit log. This provides the most comprehensive view of a user's activities—including email sends, file accesses, and Teams messages—within the last 24 hours, which is essential for investigating compromised credentials.

Exam trap

The trap here is that candidates often choose SigninLogs (Option D) thinking it covers all user actions, but it only shows authentication events, not the actual activities performed after sign-in, which is a common misconception tested in SC-200.

How to eliminate wrong answers

Option A is wrong because DeviceEvents (from Microsoft Defender for Endpoint) focuses on endpoint-level events (process creation, file modifications) and does not cover cloud-based Microsoft 365 activities like email or SharePoint access. Option C is wrong because AzureActivity logs only Azure resource management operations (e.g., VM creation, RBAC changes) and excludes user-level productivity actions in Microsoft 365. Option D is wrong because SigninLogs captures only authentication events (successful/failed logins) and not the subsequent actions the user performed after signing in.

52
MCQmedium

Your organization uses Microsoft Sentinel. You receive an incident that involves a potential lateral movement detected by Microsoft Defender for Identity. You need to investigate the timeline of the attack. Which Microsoft Sentinel feature should you use?

A.Workbooks
B.Automation rules
C.Investigation graph
D.Analytics rules
AnswerC

The investigation graph visualises related entities, alerts and activities on a timeline, letting you trace the lateral movement path across accounts and hosts. It surfaces the attack chronology that a raw incident list or hunting query alone would not present as clearly.

Why this answer

The Investigation graph in Microsoft Sentinel is specifically designed to explore the scope and timeline of an attack by visually mapping entities (e.g., users, devices, IPs) and their connections. For a lateral movement incident detected by Defender for Identity, the graph automatically surfaces related alerts, entities, and activities in a chronological view, enabling you to trace the attacker's path across resources. This makes it the correct tool for investigating the attack timeline.

Exam trap

The trap here is that candidates confuse the Investigation graph with Workbooks, assuming any visual tool for analysis is a Workbook, but Workbooks are for aggregated reporting, not for per-incident entity timeline exploration.

How to eliminate wrong answers

Option A is wrong because Workbooks are used for creating custom dashboards and reports from pre-defined queries, not for interactive, entity-based timeline investigation of a specific incident. Option B is wrong because Automation rules are designed to trigger automated responses (e.g., closing incidents, assigning tasks) based on conditions, not to explore the historical sequence of an attack. Option D is wrong because Analytics rules define detection logic to generate alerts from data sources, but they do not provide a visual, entity-centric timeline for investigating an already-triggered incident.

53
MCQeasy

An incident response playbook in Microsoft Sentinel has a step: 'Investigate the user's recent activities using Microsoft 365 Defender.' Which data source would provide the most relevant information for this step?

A.Azure Activity Log
B.Microsoft Purview Data Loss Prevention reports
C.Microsoft 365 Defender's user investigation page
D.Azure Resource Graph
AnswerC

The Microsoft 365 Defender user investigation page (now within the unified Microsoft Defender XDR) provides a single, entity-centric view of a user's alerts, incidents, sign-ins, and related activities across identities, endpoints, email, and cloud apps. It automatically correlates evidence and provides a timeline that allows an incident responder to quickly detect the scope and blast radius of a compromised account. This is the correct investigation surface because it is specifically designed for user entity investigation, and Sentinel can ingest these detections through the Microsoft 365 Defender connector.

Why this answer

The Microsoft 365 Defender user investigation page is the correct data source because it provides a consolidated view of a user's activities across Microsoft 365 services, including email, Teams, and endpoint alerts. This directly supports the incident response step of investigating recent user activities within the Microsoft 365 Defender ecosystem, which is the explicit scope of the playbook step.

Exam trap

The trap here is that candidates may confuse Azure Activity Log (which logs Azure resource operations) with user activity logs in Microsoft 365, or assume that any Microsoft security tool (like Purview DLP) would contain the needed user activity data, when only the Microsoft 365 Defender user investigation page provides the specific, integrated view required by the playbook step.

How to eliminate wrong answers

Option A is wrong because Azure Activity Log records management-plane operations on Azure resources (e.g., creating VMs), not user activities within Microsoft 365 services like email or Teams. Option B is wrong because Microsoft Purview Data Loss Prevention reports focus on policy violations and sensitive data exposure, not a comprehensive timeline of a user's recent activities across Microsoft 365. Option D is wrong because Azure Resource Graph is used for querying and exploring Azure resources at scale, not for investigating user activities in Microsoft 365 Defender.

54
MCQeasy

You are investigating a suspicious sign-in to a privileged account. You need to determine if the sign-in was from a known malicious IP address. Which Microsoft Sentinel data source should you query?

A.ThreatIntelligenceIndicator
B.SecurityEvent
C.SigninLogs
D.AuditLogs
AnswerA

ThreatIntelligenceIndicator tables store ingested threat indicators, including malicious IP addresses, matched against your environment. Querying it lets you confirm whether the sign-in's source IP appears in known threat intelligence, directly satisfying the requirement to identify a known malicious IP address rather than relying on sign-in logs alone.

Why this answer

The ThreatIntelligenceIndicator table in Microsoft Sentinel stores threat intelligence indicators (IPs, domains, URLs, file hashes) imported from TI providers or uploaded via API. To determine if a sign-in originated from a known malicious IP, you query this table for the IP address and check for matches.

Exam trap

SC-200 often tests the confusion between sign-in logs (which show the IP) and threat intelligence indicators (which classify the IP as malicious); candidates pick SigninLogs thinking it contains reputation data.

How to eliminate wrong answers

Option B (SecurityEvent) is wrong because it contains Windows security events from agents (e.g., logon events), not threat intelligence indicators; it would not tell you if an IP is known malicious. Option C (SigninLogs) is wrong because it contains Azure AD sign-in records (user, IP, status), but does not itself classify IPs as malicious — you would need to join it with ThreatIntelligenceIndicator. Option D (AuditLogs) is wrong because it contains Azure AD audit events (e.g., user management, role changes), not threat intelligence or sign-in IP reputation data.

55
MCQhard

During a ransomware incident, the security team needs to prevent the encryption of files while allowing the investigation to continue. Which feature in Microsoft Defender for Endpoint should be used to achieve this?

A.Controlled folder access.
B.Device isolation.
C.Attack surface reduction (ASR) rules.
D.Custom detection rules.
AnswerA

Controlled folder access (CFA) in Microsoft Defender for Endpoint is the correct proactive control because it uses a Windows kernel mini-filter to intercept file-write and delete operations, blocking any process that is not on an approved allowlist from modifying files inside protected directories. This directly stops ransomware from encrypting user data in real time, even if the malware has already executed. CFA can be configured via Intune or group policy and provides a targeted, low-disruption defense that preserves forensic data and remote remediation capabilities.

Why this answer

Controlled folder access (CFA) blocks unauthorized applications from modifying files in protected folders, which is exactly what ransomware does. ASR rules are broader and may not target file encryption specifically. Device isolation disconnects the device from the network but stops the investigation.

Custom detection rules are reactive.

56
MCQeasy

Refer to the exhibit. You are reviewing an alert in Microsoft Defender for Endpoint. The alert details are shown. Which of the following actions should you take first?

A.Investigate the device and the alert details
B.Mark the alert as a false positive
C.Initiate device isolation to contain the threat
D.Run a full antivirus scan on the device
AnswerA

Before containing or remediating, you must establish scope and impact. Reviewing the device timeline and alert details reveals the affected processes, files and network connections, ensuring subsequent response actions target the actual threat rather than disrupting legitimate activity.

Why this answer

The first step in incident response is to investigate the alert details and the affected device to understand the scope and severity of the threat. Without investigation, you cannot determine whether the alert is a true positive, whether isolation is appropriate, or which remediation steps are needed. Microsoft Defender for Endpoint provides a rich investigation experience, including the alert story, device timeline, and related events, which must be reviewed before taking any containment or remediation actions.

Exam trap

The trap here is that candidates often jump to containment (isolation) or remediation (scan) because they think speed is critical, but the SC-200 exam emphasizes that investigation must always come first to avoid disrupting business operations or misclassifying alerts.

How to eliminate wrong answers

Option B is wrong because marking an alert as a false positive without investigation risks ignoring a real threat; you must first analyze the alert to confirm it is indeed benign. Option C is wrong because initiating device isolation should only be done after confirming the alert is a true positive and understanding the threat's behavior, as premature isolation can disrupt legitimate operations and lose forensic data. Option D is wrong because running a full antivirus scan is a remediation step that should follow investigation and containment, not precede them; scanning without context may miss advanced threats or alert on known good files.

57
MCQeasy

A SOC analyst is reviewing an incident in Microsoft Sentinel that involves a user receiving a phishing email with a malicious attachment. The attachment was opened on a device managed by Microsoft Intune. Which Microsoft Defender XDR component would have provided the earliest detection of the malicious file?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Office 365
C.Microsoft Defender for Endpoint
D.Microsoft Purview Data Loss Prevention
AnswerC

Microsoft Defender for Endpoint is the correct source because it is an endpoint detection and response (EDR) solution that installs a sensor on the device, continuously monitoring processes, file executions, registry changes, and behaviors. Its real-time protection and behavioral analytics would detect the malicious file directly on the endpoint, and this detection would surface as an alert in Microsoft Sentinel. As the only option with a local agent capable of seeing file execution, it is the definitive source for this incident.

Why this answer

Microsoft Defender for Endpoint (MDE) provides the earliest detection of malicious files at the endpoint level. When the user opens the malicious attachment on an Intune-managed device, MDE's real-time protection (antivirus and behavior monitoring) scans the file immediately upon execution or write, blocking the threat before it can execute further. This is faster than cloud-based or email-level detections because the file is already on the device.

Exam trap

The trap here is that candidates often choose Microsoft Defender for Office 365 (Option B) because they focus on the phishing email vector, but the question explicitly states the attachment was already opened on the device, shifting the earliest detection point to the endpoint protection layer.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps (formerly MCAS) is a cloud access security broker that detects threats in cloud applications (e.g., anomalous behavior in SaaS apps), not malicious files on endpoints. Option B is wrong because Microsoft Defender for Office 365 protects against phishing emails and attachments at the email gateway level, but the question states the attachment was already opened on the device, meaning the email-level detection was bypassed or occurred later. Option D is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent unauthorized data exfiltration, not to detect malicious files or malware.

58
MCQmedium

A security operations center (SOC) analyst is investigating an incident involving a user who received a phishing email with a malicious macro. The analyst needs to determine if any other users received the same email. Which Microsoft 365 Defender feature should the analyst use?

A.Advanced Hunting
B.Alert queue filtering
C.Threat Explorer (Investigation)
D.Email entity page
AnswerC

Threat Explorer (Investigation) is the correct choice because it is a purpose-built email security search tool that lets the analyst search all mail across the organization using filters like sender, recipient, subject, message ID, and delivery status. It provides a comprehensive, KQL-free view of every instance of the email, including delivery actions and threat detections, and supports direct remediation. This makes it the natural first tool for locating and analyzing a specific reported email.

Why this answer

Threat Explorer in Microsoft 365 Defender allows hunting for email messages by sender, subject, or other attributes. Advanced Hunting is for raw queries; Email entity page shows one email; Alert queue filters by alert not email.

59
MCQhard

A SOC analyst is using Microsoft Sentinel to investigate an incident involving a user who accessed a sensitive database from an unusual location. The analyst wants to find all activities performed by this user within the last 24 hours from multiple data sources. Which KQL operator should the analyst use to combine the results of two queries that return different schemas?

A.summarize
B.join
C.union
D.where
AnswerC

The KQL `union` operator is the correct choice because it appends rows from two or more tables vertically into a single result set. If the tables have different columns, `union` returns all distinct columns and fills missing values with nulls, which is exactly what is needed to consolidate security data from various sources like SigninLogs, SecurityEvent, and AzureActivity. In Sentinel hunting queries, `union` allows an analyst to stack data sources with different schemas without losing any columns and is standard for cross-source investigation.

Why this answer

The union operator in KQL combines the results of two or more queries that may have different schemas, appending rows and filling missing columns with nulls. This is exactly what the analyst needs to pull user activity from multiple data sources (e.g., SigninLogs, AuditLogs, OfficeActivity) into a single result set for the last 24 hours. join, by contrast, requires matching columns and merges rows horizontally.

Exam trap

SC-200 often tests the difference between union (append, different schemas) and join (match, same key columns), causing candidates to pick join when the question explicitly says 'different schemas'.

How to eliminate wrong answers

Option A is wrong because summarize aggregates data (count, sum, avg, etc.) and does not combine result sets from different queries. Option B is wrong because join merges rows from two tables based on matching key columns and requires compatible schemas — it does not append results with different schemas. Option D is wrong because where filters rows in a single query and does not combine multiple queries at all.

60
MCQeasy

Your organization uses Microsoft Sentinel. You have configured a data connector to ingest events from a third-party firewall. However, you notice that the logs are not appearing in Sentinel. What is the first thing you should check?

A.Check the firewall's syslog server configuration.
B.Verify that the workspace is in the correct region.
C.Reinstall the Log Analytics agent on the firewall.
D.Check the connector health page in Microsoft Sentinel.
AnswerD

Checking the connector health page in Microsoft Sentinel is the correct first step because it provides a centralized view of each data connector's status, including whether it's connected, when the last event was received, and any ingestion errors. This page also shows the connector type, relevant log tables, and version information. If the connector is healthy, the issue likely lies in the source device or forwarder; if unhealthy, you can see specific error messages and take targeted corrective action.

Why this answer

The connector health page in Microsoft Sentinel is the first place to check because it shows whether the data connector is connected, when data was last received, and any ingestion errors. If the connector shows a healthy status but no data arrives, the issue is likely upstream (firewall or agent); if it shows disconnected or error, the problem is with the connector itself. This diagnostic step narrows the fault domain before investigating the firewall or agent.

Exam trap

SC-200 often tests troubleshooting order — candidates jump to source-side or remediation actions (firewall config, agent reinstall) instead of first using Sentinel's built-in connector health telemetry to localize the fault.

How to eliminate wrong answers

Option A is wrong as a first step because checking the firewall's syslog configuration assumes the problem is on the source side, but you should first confirm whether Sentinel is even receiving anything via the connector health page — otherwise you may troubleshoot the wrong layer. Option B is wrong because workspace region affects data residency and feature availability, not whether logs from a configured connector appear; region mismatch would not silently drop ingested events. Option C is wrong because reinstalling the Log Analytics agent is a disruptive remediation step, not a diagnostic first step, and for a third-party firewall connector the agent may not even be the ingestion path (many use syslog via a Linux forwarder or CEF).

61
MCQmedium

During an incident, an analyst finds that a user's account was compromised and used to send spam. The analyst needs to revoke all active sessions for that user. What should the analyst do?

A.Reset the user's password.
B.Revoke the user's sessions in Microsoft Entra ID.
C.Create a Conditional Access policy to block the user.
D.Disable the user account in Microsoft Entra ID.
AnswerB

Revoking sessions in Microsoft Entra ID invalidates all refresh tokens and active sessions for the compromised account, immediately cutting off the attacker's access while the password is reset. This directly satisfies the requirement to revoke all active sessions.

Why this answer

Revoking sessions in Microsoft Entra ID immediately invalidates all refresh tokens and active sign-in sessions for the compromised user, cutting off the attacker's access without disrupting the account's ability to be re-secured. This is the targeted response for session hijacking because it terminates existing tokens rather than just changing credentials. Password reset alone does not invalidate already-issued tokens, so the attacker could remain authenticated.

Exam trap

SC-200 often tests the misconception that resetting a password immediately logs out an attacker — candidates must recognize that token revocation is the only action that invalidates existing sessions.

How to eliminate wrong answers

Option A is wrong because resetting a password does not revoke existing refresh tokens or access tokens — the attacker's active session can persist until token expiry. Option C is wrong because creating a Conditional Access policy to block the user is a preventive control applied at future sign-in attempts, not an immediate revocation of already-issued sessions. Option D is wrong because disabling the account blocks future authentication but does not necessarily terminate already-issued refresh tokens, and it is a broader, more disruptive action than session revocation.

62
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. A security investigator discovers that a user's session token was stolen and used to access sensitive data in SharePoint Online from an anomalous IP address. You need to immediately revoke the attacker's access while minimizing impact on the legitimate user. What should you do?

A.Suspend the user account in Microsoft Entra ID until the investigation is complete.
B.From Microsoft Defender for Cloud Apps, use the 'Require re-authentication' action on the anomalous session.
C.Revoke all refresh tokens for the user in Microsoft Entra ID.
D.Reset the user's password immediately.
AnswerB

The 'Require re-authentication' action is a session-level conditional access app control in Microsoft Defender for Cloud Apps that terminates only the specific anomalous session, leaving the user's other active sessions unaffected. It forces both the user and the attacker to re-authenticate, effectively invalidating the stolen access token for that session and any associated refresh token for that session context. Because it is applied solely to the identified risky session, it minimizes user productivity loss while successfully revoking the attacker's unauthorized access, making it the most targeted and proportionate response.

Why this answer

The 'Require re-authentication' action in Microsoft Defender for Cloud Apps immediately terminates the attacker's session by invalidating the stolen session token, forcing the attacker to re-authenticate. This action targets only the anomalous session, leaving the legitimate user's other sessions intact and minimizing disruption. It directly addresses the session token theft without affecting the user's account status or requiring password changes.

Exam trap

The trap here is that candidates confuse session-level remediation (requiring re-authentication for a specific session) with account-level remediation (suspending the user or resetting passwords), failing to recognize that the stolen token is independent of the user's credentials and can be invalidated without affecting other sessions.

How to eliminate wrong answers

Option A is wrong because suspending the user account in Microsoft Entra ID would block all access for the legitimate user, causing unnecessary disruption and potentially locking them out of critical resources while the investigation is ongoing. Option C is wrong because revoking all refresh tokens for the user in Microsoft Entra ID would invalidate all sessions, including the legitimate user's active sessions, forcing them to re-authenticate everywhere and causing significant productivity loss. Option D is wrong because resetting the user's password immediately would not revoke the stolen session token; the attacker could still use the existing token until it expires, and it would also disrupt the legitimate user's access across all services.

63
Multi-Selectmedium

Which THREE resources can be used as data sources for Microsoft Sentinel to detect security incidents? (Choose three.)

Select 3 answers
A.Microsoft 365 Defender
B.Microsoft Defender for Cloud
C.Azure Activity Log
D.Azure Cost Management
E.Azure Advisor
AnswersA, B, C

Microsoft 365 Defender is a valid data source because its built-in connector streams unified alerts and incidents from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps into Microsoft Sentinel. These security signals include attacker activities, malware events, and phishing detections, which are mapped directly to Sentinel's incident schema for correlation and investigation.

Why this answer

Options A, B, and C are correct. Microsoft 365 Defender provides integrated threat signals across endpoints, email, and identities. Microsoft Defender for Cloud delivers security alerts and posture assessments for cloud workloads.

Azure Activity Log captures subscription-level operational events, which can be streamed to Sentinel. Option D is incorrect because Azure Cost Management focuses on cost tracking and budgeting, not security events. Option E is incorrect because Azure Advisor provides optimization recommendations, not security incident data.

64
MCQhard

During an incident response, you need to collect forensic evidence from a compromised Azure virtual machine that is currently offline. What is the most efficient method to acquire a disk snapshot for analysis while preserving the integrity of the evidence?

A.Attach a new data disk and copy the contents manually
B.Create a snapshot of the OS disk from the Azure portal
C.Start the VM and use Azure Backup to take a backup
D.Export the disk to a storage account using AzCopy
AnswerB

Creating a snapshot of the OS disk from the Azure portal is the correct first step because it produces a read-only, point-in-time copy of the entire virtual disk without powering on the VM, ensuring no writes alter the original evidence. The snapshot captures the raw disk structure including deleted data and file slack, and you can later attach it to a secure analysis VM or use it to instantiate a new disk for offline forensic examination, while storing the snapshot in a separate, access-controlled resource group to maintain chain of custody.

Why this answer

Exporting a disk via AzCopy is not the most efficient forensic-sound method here because it requires first generating a SAS URL for the disk (e.g., via Grant-AzDiskAccess), which typically means the disk should not be attached to a running VM — the opposite of what this option implies. Even done correctly, going straight to an AzCopy export skips the read-only, platform-level point-in-time snapshot step, so any error or interruption during export risks touching the original disk. Taking a snapshot first (option B) is safer and is the standard first step; the snapshot can subsequently be exported with AzCopy for offline analysis if needed.

65
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident has been generated from Microsoft Defender for Cloud indicating that a Linux VM in Azure is running a cryptocurrency miner. The VM is part of a production application and cannot be shut down immediately. The incident severity is High. You need to contain the threat while maintaining application availability, investigate the root cause, and prevent recurrence. The environment includes Azure Policy, Microsoft Defender for Endpoint on the VM, and a Log Analytics workspace. You must minimize manual steps. What course of action should you take?

A.Remotely connect to the VM and run a script to kill the miner process, then update antivirus definitions
B.Remove the VM from the load balancer, then use Azure Policy to enforce that all VMs have antivirus enabled
C.Stop the VM immediately, take a snapshot for forensic analysis, and then redeploy a clean VM from a backup
D.Use Microsoft Sentinel automation to apply a block rule on the VM's network security group (NSG) to block outbound traffic to known mining pools, initiate Live Response to collect evidence, and create an Azure Policy to automatically deploy Microsoft Defender for Endpoint on all VMs
AnswerD

Using Sentinel automation to block outbound traffic to mining pools via NSG rules contains the threat without affecting legitimate traffic; Live Response collects evidence for investigation; Azure Policy to enforce Defender for Endpoint deployment prevents future occurrences by ensuring all VMs have EDR coverage.

Why this answer

It uses Microsoft Sentinel automation to apply a network security group (NSG) rule to block outbound traffic to known mining pools, which contains the threat without disrupting the VM's availability for production traffic. Initiating Live Response on the VM allows collection of forensic evidence for investigation. Creating an Azure Policy to enforce Microsoft Defender for Endpoint deployment on all VMs helps prevent recurrence by ensuring all VMs have endpoint detection and response (EDR) capabilities.

Option A is incorrect because remotely connecting and killing the process is a manual step that does not block the miner from restarting or communicating outbound, and it may not be immediately effective. Option B is incorrect because removing the VM from the load balancer alone does not stop the miner from running locally or potentially communicating via other routes, and Azure Policy for antivirus is insufficient for modern threats like miners. Option C is incorrect because stopping the VM immediately would disrupt production, and taking a snapshot then redeploying from backup does not address the immediate containment of the threat on the current VM.

66
MCQhard

During an incident, you need to isolate a compromised device from the network while allowing communication with Microsoft Defender for Endpoint cloud services. Which isolation type should you choose in Microsoft Defender XDR?

A.Controlled folder access
B.Network protection
C.Block file
D.Full isolation
E.Selective isolation
AnswerE

Selective isolation is the preferred containment action in Microsoft Defender for Endpoint because it blocks all network traffic except communication with the Defender for Endpoint cloud service. This preserves the sensor's ability to send telemetry and receive automated or manual remediation commands, so the security team retains visibility and control during the incident. It effectively halts lateral movement and command-and-control while keeping the device within the security management plane, making it the only option that both contains the threat and maintains operational monitoring.

Why this answer

Selective isolation (E) is the correct choice because it restricts network communication to only Microsoft Defender for Endpoint cloud services, blocking all other inbound and outbound traffic. This allows the compromised device to remain manageable and receive security updates while preventing lateral movement and further compromise. Full isolation would block all network traffic, including Defender services, rendering the device unmanageable.

Exam trap

The trap here is that candidates often confuse 'full isolation' with 'selective isolation,' assuming full isolation is always the safest choice, but they overlook that full isolation breaks the device's ability to communicate with Defender cloud services, making it unmanageable.

How to eliminate wrong answers

Option A is wrong because Controlled folder access is a Windows Defender Exploit Guard feature that protects files and folders from unauthorized changes by untrusted applications, not a network isolation mechanism. Option B is wrong because Network protection is a feature that blocks outbound connections to malicious IPs/domains using the Windows Filtering Platform, but it does not isolate a device from the network while selectively allowing Defender cloud services. Option C is wrong because Block file is an action in Microsoft Defender for Endpoint that prevents a specific file from executing or being written, not a device-level network isolation.

Option D is wrong because Full isolation blocks all network traffic, including communication with Microsoft Defender for Endpoint cloud services, which would prevent the device from receiving policy updates or reporting telemetry.

67
Multi-Selecthard

Which THREE are valid methods to collect forensic evidence from a compromised Windows machine during incident response in Microsoft Defender XDR? (Choose three.)

Select 3 answers
A.Reset the device to a clean state
B.Collect a memory dump from the device using Live Response
C.Perform a full disk image using Microsoft Defender for Endpoint
D.Run Live Response commands to collect files and run scripts
E.Export Windows Event Logs using Live Response
AnswersB, D, E

Live Response in Microsoft Defender XDR supports running the `Get-File` and memory-dump collection commands directly on a compromised Windows endpoint, satisfying the requirement to gather volatile forensic evidence without disrupting the device. This preserves RAM contents that would otherwise be lost on shutdown, which is essential for incident response.

Why this answer

Options B, D, and E are correct: Live Response allows script execution and file collection; collecting a memory dump captures volatile evidence necessary for forensic analysis; exporting Windows Event Logs provides a timeline of events. Option A is incorrect because resetting the device destroys evidence instead of preserving it. Option C is incorrect because full disk imaging is not natively supported in Microsoft Defender XDR; it requires external tools.

68
MCQmedium

A security analyst detects a suspicious sign-in from an unfamiliar IP address for a user with high privileges. The analyst wants to immediately contain the threat while preserving the user's ability to work with proper approvals. What is the most effective first step?

A.Block the IP address in the firewall.
B.Disable the user account in Microsoft Entra ID.
C.Reset the user's password without revoking sessions.
D.Initiate a user risk remediation in Microsoft Entra ID Protection by confirming compromise and resetting password with session revocation.
AnswerD

Initiating user risk remediation in Microsoft Entra ID Protection is the correct, containment-focused response because it lets you confirm the sign-in as compromised, immediately revoke all refresh tokens and session cookies, and force the user to reauthenticate with a new password. This directly neutralizes the attacker's token-based access while preserving the legitimate user's ability to regain access after verification. It combines detection with automated, policy-driven response and is the documented best practice for handling confirmed user risk in Entra ID.

Why this answer

It directly addresses the immediate threat by confirming compromise in Microsoft Entra ID Protection, which triggers a password reset and revokes all existing sessions, effectively terminating the attacker's access. This approach preserves the user's ability to work after re-authentication with proper approvals, as the account remains enabled and can be restored once the risk is mitigated. It is the most effective first step because it combines containment (session revocation) with remediation (password reset) while maintaining operational continuity.

Exam trap

The trap here is that candidates may choose to disable the user account (Option B) thinking it is the fastest containment, but they overlook that session revocation is necessary to stop active attacker sessions, and disabling the account also blocks the legitimate user without a clear path for re-enabling with approvals.

How to eliminate wrong answers

Option A is wrong because blocking the IP address in the firewall is a network-level control that does not revoke the attacker's existing authenticated session; the attacker may still have active tokens or cookies that bypass the firewall. Option B is wrong because disabling the user account in Microsoft Entra ID completely prevents the user from working, even with proper approvals, and does not automatically revoke existing sessions or tokens, leaving potential for lateral movement. Option C is wrong because resetting the password without revoking sessions leaves the attacker's active tokens and sessions intact, allowing continued access despite the password change.

69
MCQeasy

Your organization is using Microsoft Defender for Office 365. A user reports receiving a suspicious email that appears to be from the CEO requesting an urgent wire transfer. You need to investigate the email and take immediate action. What should you do first?

A.Use the Exchange admin center to run a message trace.
B.Use Threat Explorer in the Microsoft 365 Defender portal to find and delete the email.
C.Use the Security & Compliance Center to create a mail flow rule.
D.Submit the email to Microsoft for analysis using the Submissions page.
AnswerB

Threat Explorer in the Microsoft 365 Defender portal is the actual investigation-and-remediation surface for email threats; it combines a robust queryable event store with built-in actions. You can filter by threat type, sender, subject, or detection technology, select one or multiple messages, and directly delete (soft or hard) them from user mailboxes. For a suspicious email already delivered, this is the only option that both finds and removes it. Also supports in-place review of the payload and email summary.

Why this answer

Threat Explorer in the Microsoft 365 Defender portal provides the fastest and most direct way to investigate and remediate a specific suspicious email across all mailboxes. It allows you to search for the email by sender, subject, or recipient, and then take immediate action such as soft-delete or hard-delete to remove it from user inboxes. This is the correct first step for an urgent incident response scenario involving a targeted phishing attack.

Exam trap

The trap here is that candidates often confuse the purpose of message traces (delivery tracking) with the immediate remediation capabilities of Threat Explorer, or they mistakenly think that creating a mail flow rule can retroactively remove already delivered emails.

How to eliminate wrong answers

Option A is wrong because a message trace in the Exchange admin center is designed for delivery troubleshooting and tracking, not for immediate remediation or bulk deletion of a malicious email across multiple mailboxes. Option C is wrong because creating a mail flow rule in the Security & Compliance Center is a proactive configuration change that takes time to propagate and does not remove an already delivered email; it is not an immediate investigative or response action. Option D is wrong because submitting the email to Microsoft for analysis is a secondary step used for improving detection, not for urgent containment or removal of the threat from user mailboxes.

70
Multi-Selecthard

You are responding to a ransomware incident where multiple devices are encrypted. The incident is captured in Microsoft Sentinel. Which TWO actions should you take first to contain the incident?

Select 2 answers
A.Disable user accounts associated with the affected devices in Microsoft Entra ID.
B.Isolate affected devices using Microsoft Defender for Endpoint.
C.Reset passwords for all affected users.
D.Run a malware analysis on a sample of the ransomware.
E.Restore encrypted files from backups.
AnswersA, B

Disabling the associated accounts in Microsoft Entra ID revokes authentication tokens and prevents the attacker reusing compromised credentials to re-encrypt or pivot. This satisfies containment by cutting the identity path, since ransomware operators routinely retain valid accounts to re-establish access after device-level cleanup.

Why this answer

Option A is correct because disabling the associated user accounts in Microsoft Entra ID immediately blocks the compromised identities from authenticating and prevents the attacker from using those credentials to move laterally or re-access resources during containment. Option B is correct because isolating affected devices through Microsoft Defender for Endpoint severs network communication while preserving the device state for forensic investigation, which is the standard first containment step for ransomware. Option C is not a first containment action; password resets are remediation steps that come after disabling accounts and can be performed later without stopping active spread.

Option D is incorrect because malware analysis is a post-containment investigative activity, not an immediate containment measure. Option E is incorrect because restoring from backups is a recovery action and should only occur after the threat is fully contained and eradicated, otherwise restored data can be re-encrypted.

Exam trap

The trap is confusing containment with recovery or investigation; candidates pick password resets or backup restoration because they sound urgent, but those are later phases — the first actions must stop the spread by isolating devices and disabling accounts.

71
MCQeasy

You receive an alert in Microsoft Sentinel indicating a potential privilege escalation using the 'AzureHound' tool. You need to determine if the alert is a true positive. What is the first step you should take?

A.Check the user's recent activity and the targeted resource in Microsoft Entra ID audit logs
B.Review the Microsoft Defender for Cloud recommendation for the resource
C.Block the user account immediately
D.Run a full antivirus scan on all devices
AnswerA

Reviewing Microsoft Entra ID audit logs exposes the specific directory operations AzureHound performs, such as role assignments and service principal enumeration, letting you confirm whether the flagged activity is genuine privilege-escalation reconnaissance rather than benign administrative behaviour. This directly satisfies the stem's requirement to validate the alert before escalating.

Why this answer

To determine whether an AzureHound privilege-escalation alert is a true positive, you must validate the underlying identity activity — specifically what the user did and which resource was targeted — using Microsoft Entra ID audit logs. AzureHound enumerates Azure AD/Entra ID objects and permissions, so the audit trail of directory reads, role assignments, or consent grants is the authoritative evidence. This confirms or refutes the alert before taking disruptive action.

Exam trap

SC-200 often tests the ordering of incident response steps, so candidates who jump to containment (blocking the account) instead of first validating the alert with identity audit logs pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because Defender for Cloud recommendations are posture/configuration guidance, not evidence of whether a specific identity performed malicious enumeration. Option C is wrong because immediately blocking the account is a containment action taken after validation — doing it first risks disrupting a legitimate user and destroying forensic context. Option D is wrong because AzureHound is a cloud identity reconnaissance tool, not endpoint malware, so an antivirus scan on devices is irrelevant to confirming the alert.

72
MCQhard

Your organization uses Microsoft Sentinel and has enabled UEBA (User and Entity Behavior Analytics). You notice a series of incidents involving anomalous logon times for a privileged user. You want to automate the response to disable the user's account in Microsoft Entra ID when such incidents are created. What should you configure?

A.Create an automation rule that runs a playbook when an incident from the UEBA analytics rule is created, and configure the playbook to disable the user in Microsoft Entra ID.
B.Create an analytics rule that triggers on UEBA anomalies and directly disables the user.
C.Add the user to a watchlist and create a playbook that runs on a schedule.
D.Configure UEBA to automatically disable the user when anomalous behavior is detected.
AnswerA

In Microsoft Sentinel, an automation rule is the correct mechanism to trigger a playbook when an incident is created. Since the UEBA analytics rule generates incidents for suspicious behavior, you attach an automation rule to that rule that invokes a playbook. The playbook can then call Microsoft Entra ID to disable a user account, providing immediate, coordinated incident response.

Why this answer

Microsoft Sentinel automation rules can trigger a playbook when an incident is created by a specific analytics rule (e.g., a UEBA-based rule). The playbook, built in Azure Logic Apps, can then use the Microsoft Graph API to disable the user's account in Microsoft Entra ID. This provides a fully automated, event-driven response to anomalous logon time incidents without manual intervention.

Exam trap

The trap here is that candidates often assume UEBA or analytics rules can directly perform remediation actions, but in Sentinel, detection and response are separated—analytics rules only detect, while playbooks (via automation rules) execute the response.

How to eliminate wrong answers

Option B is wrong because analytics rules in Sentinel are designed to generate alerts or incidents, not to directly execute actions like disabling a user; direct user disablement must be performed by a playbook or a separate automation mechanism. Option C is wrong because adding a user to a watchlist and running a playbook on a schedule would not react to the specific incident creation event; it would run periodically regardless of whether an incident occurred, leading to delayed or unnecessary actions. Option D is wrong because UEBA itself is a detection engine that identifies anomalies and generates alerts; it does not have built-in remediation capabilities to automatically disable user accounts—that requires an external automation layer like a playbook.

73
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You suspect a compromised on-premises admin account that has been used to modify security groups. You want to quickly contain the threat. What should you do first?

A.Move the user account to an Organizational Unit (OU) with blocked logon hours.
B.Reset the user's password in on-premises Active Directory.
C.Revoke the user's sessions in Microsoft Entra ID and reset the password in both on-premises AD and Entra ID.
D.Disable the user account in Microsoft Entra ID.
AnswerC

Revoking Entra ID sessions invalidates refresh tokens immediately, while resetting the password in both directories removes the attacker's on-premises and cloud credentials. This dual reset contains the compromised admin account before further security group modifications occur.

Why this answer

When a hybrid identity admin account is compromised and has modified security groups, the fastest containment is to revoke the user's sessions in Microsoft Entra ID and reset the password in both on-premises AD and Entra ID. Revoking sessions invalidates refresh tokens and active sessions, while resetting in both directories ensures the attacker cannot re-authenticate via either identity plane. This addresses both cloud and on-premises access paths.

Exam trap

SC-200 often tests whether candidates forget that disabling or resetting in only one identity plane leaves the other plane accessible in hybrid environments.

How to eliminate wrong answers

Option A is wrong because moving an account to an OU with blocked logon hours does not immediately stop an active attacker and does not affect cloud sessions or existing tokens. Option B is wrong because resetting only the on-premises password leaves Entra ID sessions and tokens valid, allowing the attacker to continue cloud access. Option D is wrong because disabling only the Entra ID account does not stop on-premises AD authentication or on-premises resource access, and the attacker could still use the on-premises identity.

74
MCQeasy

Your organization uses Microsoft Sentinel. An incident is created from an Azure Active Directory (now Microsoft Entra ID) sign-in alert. You need to determine if the sign-in was from a compromised token. What data source should you examine?

A.Audit logs in Microsoft Entra ID
B.Azure Activity Log
C.Sign-in logs in Microsoft Entra ID
D.Microsoft Defender for Cloud Apps logs
AnswerC

Sign-in logs record token issuance details, including the token's unique identifier and authentication context, letting you correlate the alert with the specific session and confirm whether a stolen or replayed token was used rather than legitimate credentials.

Why this answer

Sign-in logs in Microsoft Entra ID contain detailed token information such as token issuer, session ID, and device details, which are essential for determining if a token was compromised. Option A is incorrect because audit logs track changes to directory objects, not sign-in details. Option B is incorrect because Azure Activity Log monitors Azure resource operations, not sign-in events.

Option D is incorrect because Microsoft Defender for Cloud Apps logs focus on cloud application sessions and anomalies, but do not provide the granular sign-in token details found in sign-in logs.

75
Multi-Selecteasy

Which TWO are valid incident classification categories in Microsoft Sentinel?

Select 2 answers
A.Benign positive
B.Unknown
C.True positive
D.Informational
E.False positive
AnswersC, E

True positive is one of the two valid incident classification categories in Microsoft Sentinel. You select this classification when investigation confirms the alert correctly identified a real security threat. Applying True positive is important because it enables accurate reporting on detection effectiveness and helps tune analytics rules for future incidents. It must be paired with the incident status 'Closed' (or 'Resolved') in the classification workflow.

Why this answer

Microsoft Sentinel incidents are closed with one of THREE classification categories, not two: True Positive (reason: Suspicious activity), False Positive (reasons: Inaccurate data or Inaccurate alert logic), and Benign Positive (reason: Suspicious but expected — used when the detected activity is real but was expected/authorized, e.g., an approved penetration test or a known admin script). 'Unknown' and 'Informational' are not valid classification values; they are respectively an alert-severity-adjacent concept and a severity level, not part of the incident-closing classification field. Because 3 of the 5 options (A, C, E) are actually valid, the stem must also be changed from 'Select TWO' to 'Select THREE' when this question is corrected.

Exam trap

The trap here is that candidates often confuse incident classification categories (True positive, False positive, Benign positive) with alert severity levels (Informational, Low, Medium, High) or investigation statuses (New, In progress, Resolved), leading them to select 'Informational' or 'Unknown' as valid classifications.

Page 1 of 5 · 375 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Respond Security Incidents questions.