Sample questions
Microsoft Security Operations Analyst SC-200 practice questions
Match each Microsoft Sentinel data connector on the left with the table name it populates on the right.
A security analyst is investigating a suspicious process on an endpoint and needs to see all network connections initiated by that process. The analyst knows the ProcessId and Devi…
A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect a possible password spray attack. The rule must trigger when a single source IP address has mor…
Which THREE are valid incident classification options in Microsoft Sentinel?
A SOC team wants to use Microsoft Sentinel to detect when a user logs in from a new country not previously seen for that user. They have the SigninLogs table. Which KQL function is…
Wide World Importers uses Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Purview for data loss prevention (DLP). An incident is generated: 'DLP policy violation - sensit…
Your security team uses Microsoft Defender XDR (formerly Microsoft 365 Defender) to investigate incidents. You notice that some alerts from Microsoft Defender for Endpoint are not…
During a ransomware incident, Microsoft Defender for Cloud Apps alerts indicate that a user is uploading large volumes of data to an external cloud storage provider not approved by…
You are investigating an incident where a user reported receiving a suspicious email with a malicious attachment. Microsoft Defender for Office 365 did not block it. The email orig…
Your organization uses Microsoft Sentinel with UEBA (User and Entity Behavior Analytics) enabled. The SOC team notices that UEBA is not generating any anomalies for a specific user…
A security analyst in Microsoft Defender for Cloud receives an alert that an Azure VM has a vulnerability with a high severity. The analyst wants to see the detailed finding, inclu…
Which TWO conditions must be met to enable Microsoft Sentinel UEBA? (Choose two.)
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →You are reviewing a hunting query. What is the primary purpose of this query?
Your organization uses Microsoft Defender XDR. The incident queue shows multiple alerts related to a single endpoint: malware detected, suspicious PowerShell execution, and data ex…
A security analyst is investigating a phishing campaign using Microsoft 365 Defender advanced hunting. The analyst needs to find all emails sent from a specific sender address in t…
Your organization uses Microsoft Defender XDR. You need to configure automatic attack disruption for identity-related threats. The solution should automatically contain a compromis…
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →You are configuring Microsoft Sentinel to ingest logs from Azure Active Directory (now Microsoft Entra ID). Which of the following connectors should you use to collect sign-in logs…
Your organization uses Microsoft Purview Data Loss Prevention (DLP) policies. You need to investigate an incident where sensitive data was shared externally. You want to view the d…
Your SOC uses Microsoft Sentinel and Microsoft Defender for Cloud Apps. You need to configure a policy that triggers when a user downloads a large number of files from SharePoint O…
Your organization uses Microsoft Sentinel. An incident is created for a possible data exfiltration via an unapproved external IP address. Which type of Microsoft Sentinel automatio…
Which TWO actions should you take when configuring Microsoft Sentinel to minimize false positives from an analytics rule?
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →Which THREE components are required to automate incident response in Microsoft Sentinel using playbooks? (Choose three.)
You are threat hunting in Microsoft Defender XDR for signs of Kerberoasting. Which hunting query would be most effective in identifying Kerberoasting activity?
Your organization uses Microsoft Defender XDR and has a custom detection rule that queries DeviceProcessEvents for suspicious PowerShell commands. You notice that the rule is gener…