Skip to content

SC-200 Practice Questions

Prepare for SC-200 with more than an answer.

297 questions in the full set40 sample questionsUpdated Jan 25, 2026
Exam fee
$165 USD
Level
Associate
Valid for
1 year
Domains covered on the exam 4
  1. Manage a security operations environment22%
  2. Configure protections and detections17%
  3. Manage incident response27%
  4. Manage security threats17%
  1. 1

    You are investigating a complex incident in Microsoft Sentinel. You want to visualize the relationships between the alerted entities (users, IPs, hosts) and identify if they are part of other alerts.

    Which tool provides a visual interface to expand entities and explore connections?

    Show answer details

    Correct answer: A

    The Investigation Graph in Microsoft Sentinel allows analysts to visualize alerts and entities, explore relationships, and expand the scope of the investigation by finding related alerts.

  2. 2

    A security team receives threat intelligence feeds in STIX format via a TAXII server. They want to import these indicators into Microsoft Sentinel to correlate with their logs.

    Which Data Connector should they configure?

    Show answer details

    Correct answer: A

    The 'Threat Intelligence - TAXII' data connector in Microsoft Sentinel is specifically designed to ingest STIX-formatted threat indicators from TAXII 2.0 and 2.1 servers.

  3. 3

    You receive complaints that a built-in detection rule in Microsoft Defender for Endpoint is generating too many false positives for a specific internal application 'AppX'. You want to stop alerts for this specific application without disabling the rule entirely for other processes.

    What should you create?

    Show answer details

    Correct answer: B

    Creating a suppression rule (or tuning the alert) allows you to define specific criteria (like file path or hash) to hide alerts or resolve them automatically, preventing false positives while keeping the rule active for other threats.

  4. 4

    A SOC analyst needs to run a custom PowerShell script on a compromised device to collect specific forensic artifacts. The device is isolated but connected to Microsoft Defender for Endpoint. The script is not currently available in the Live Response library.

    Which permission is required to upload this script to the Live Response library?

    Show answer details

    Correct answer: C

    To upload scripts to the Live Response library, the user must have the 'Manage Security Settings' permission in Microsoft Defender for Endpoint roles.

  5. 5

    You manage three separate Microsoft Sentinel workspaces: 'US-Ops', 'EU-Ops', and 'Asia-Ops'. You need to write a hunting query that searches for a specific malicious file hash across ALL three workspaces simultaneously.

    Which KQL syntax allows you to query multiple workspaces?

    Show answer details

    Correct answer: A

    The workspace('workspace-name').table syntax allows you to reference tables in different Log Analytics workspaces. Using union combines the results from all of them.

    graph TD Query[Analyst Query] --> Union[Union Operator] Union --> US[US-Ops Workspace] Union --> EU[EU-Ops Workspace] Union --> Asia[Asia-Ops Workspace]
  6. 6

    You are querying a custom log table AppLogs_CL in Microsoft Sentinel. The logs contain a column named Properties_s which holds a JSON string with dynamic fields like User, Action, and Resource. You need to extract the User field into a separate column for filtering.

    Which KQL function should you use?

    Show answer details

    Correct answer: B

    The parse_json() function interprets a string as a JSON value, allowing access to nested fields using dot notation (e.g., parse_json(Properties_s).User).

  7. 7

    A user reports an email in their junk folder was automatically moved there, but they believe it is legitimate. Upon investigation in Microsoft Defender for Office 365, you see the email was moved by ZAP (Zero-hour Auto Purge).

    What does this indicate about the email?

    Show answer details

    Correct answer: A

    ZAP (Zero-hour Auto Purge) retroactively detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to Exchange Online mailboxes.

  8. 8

    You want to connect a new SaaS application to Microsoft Sentinel using the Codeless Connector Platform (CCP). You have the API documentation for the SaaS app.

    Which file format must you use to define the data connector's polling configuration and data parsing logic?

    Show answer details

    Correct answer: B

    The Codeless Connector Platform (CCP) uses a JSON configuration file to define how to connect to the data source (API), how to authenticate, and how to parse the data.

  9. 9

    Before enabling User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel, which two specific data sources MUST be connected and syncing data to the workspace? (Select TWO)

    Show answer details

    Correct answer: A, B

    UEBA requires Azure AD logs to build user profiles and baselines.

    UEBA needs endpoint/server logs to correlate user activity on devices.

  10. 10

    In Microsoft Defender for Identity, you receive a 'Suspected DCSync attack' alert. This attack mimics the replication process of a Domain Controller to steal password hashes.

    Which of the following investigation steps is most critical to determine if this is a True Positive or a False Positive?

    Show answer details

    Correct answer: A

    DCSync is a valid operation between Domain Controllers and by Azure AD Connect. If the source IP/Computer is a known DC or AADC server, it is likely a False Positive. If it is a workstation or unauthorized server, it is a True Positive.

  11. 11

    A security analyst at a retail company is investigating a Microsoft Sentinel incident that contains multiple alerts related to a single user account. The analyst needs to understand the full sequence of events, from a suspicious sign-in to potential data exfiltration, in a chronological order. Which Microsoft Sentinel feature provides a graphical timeline and allows the analyst to explore related entities for this purpose?

    Show answer details

    Correct answer: B

    The Investigation Graph in Microsoft Sentinel is specifically designed to help analysts visualize and traverse the relationships between entities within an incident. It provides a timeline and an interactive map to understand the scope and sequence of an attack, making it the correct tool for this scenario. Workbooks are for visualization and reporting, Hunting is for proactive threat discovery, and Automation Rules are for automating responses.

  12. 12

    A security operations team is configuring Microsoft Defender for Endpoint. They want to ensure that if a high-confidence phishing URL is detected on a device, the device is automatically isolated from the network, but only if the device belongs to the 'Standard User Workstations' device group. Devices in the 'Executive Laptops' group should not be automatically isolated. Which feature should be configured to achieve this specific, conditional automation?

    Show answer details

    Correct answer: C

    In Microsoft Defender for Endpoint, automation levels can be configured per device group. To meet the requirement, you would set the automation level for the 'Standard User Workstations' group to 'Full - remediate threats automatically' and the 'Executive Laptops' group to a lower level, such as 'Semi - require approval for all folders'. This provides the granular control needed for conditional automated responses.

Create an account to continue.