SC-200 Practice Questions
Prepare for SC-200 with more than an answer.
- Exam fee
- $165 USD
- Level
- Associate
- Valid for
- 1 year
Domains covered on the exam 4
- Manage a security operations environment22%
- Configure protections and detections17%
- Manage incident response27%
- Manage security threats17%
- 1
While investigating a threat in Microsoft Sentinel using the Logs blade, you identify a suspicious row in the query results. You want to preserve this specific result for later reference and add notes to it.
What feature should you use, and which table is the data stored in?
Show answer details
Correct answer: B
Hunting bookmarks allow analysts to preserve query results, add tags/notes, and these are stored in the
HuntingBookmarktable in the Log Analytics workspace. - 2
You are investigating a report that a user permanently deleted a critical file from a SharePoint Online site. You need to identify who performed the deletion and when.
Which tool in the Microsoft Defender portal or Microsoft Purview compliance portal should you use to search for the 'FileDeleted' operation?
Show answer details
Correct answer: A
The Unified Audit Log (Audit) in the Microsoft Purview compliance portal contains records of user and admin activities across Microsoft 365 services, including SharePoint file deletions.
- 3
When configuring multiple automation rules in Microsoft Sentinel that trigger on the same incident, the 'Order' value determines the sequence of execution.
If you have three rules with Order values 1, 5, and 10, and the rule with Order 5 has an action to 'Close' the incident, what happens to the rule with Order 10?
Show answer details
Correct answer: D
Automation rules run sequentially. Even if an incident is closed by a prior rule, subsequent automation rules will still run unless they have a specific condition that checks the incident status (e.g., 'Status equals Open').
flowchart TD A[Trigger] --> B{Rule Order 1} B --> C{Rule Order 5} C -->|Closes Incident| D{Rule Order 10} D -->|Executes unless condition prevents| E[End] - 4
An organization requires that certain high-volume, low-security value logs (like verbose firewall allow logs) be retained for 7 years for compliance but queried very rarely. To minimize costs in Microsoft Sentinel, which data plan should be configured for the custom table receiving these logs?
Show answer details
Correct answer: B
Basic Logs are a low-cost plan for retaining high-volume logs that are queried infrequently. They support a limited KQL subset and are significantly cheaper than Analytics Logs. For 7-year retention, these can be moved to the Archive tier.
- 5
You are investigating a complex incident in Microsoft Sentinel. You want to visualize the relationships between the alerted entities (users, IPs, hosts) and identify if they are part of other alerts.
Which tool provides a visual interface to expand entities and explore connections?
Show answer details
Correct answer: A
The Investigation Graph in Microsoft Sentinel allows analysts to visualize alerts and entities, explore relationships, and expand the scope of the investigation by finding related alerts.
- 6
A security team receives threat intelligence feeds in STIX format via a TAXII server. They want to import these indicators into Microsoft Sentinel to correlate with their logs.
Which Data Connector should they configure?
Show answer details
Correct answer: A
The 'Threat Intelligence - TAXII' data connector in Microsoft Sentinel is specifically designed to ingest STIX-formatted threat indicators from TAXII 2.0 and 2.1 servers.
- 7
You receive complaints that a built-in detection rule in Microsoft Defender for Endpoint is generating too many false positives for a specific internal application 'AppX'. You want to stop alerts for this specific application without disabling the rule entirely for other processes.
What should you create?
Show answer details
Correct answer: B
Creating a suppression rule (or tuning the alert) allows you to define specific criteria (like file path or hash) to hide alerts or resolve them automatically, preventing false positives while keeping the rule active for other threats.
- 8
A SOC analyst needs to run a custom PowerShell script on a compromised device to collect specific forensic artifacts. The device is isolated but connected to Microsoft Defender for Endpoint. The script is not currently available in the Live Response library.
Which permission is required to upload this script to the Live Response library?
Show answer details
Correct answer: C
To upload scripts to the Live Response library, the user must have the 'Manage Security Settings' permission in Microsoft Defender for Endpoint roles.
- 9
You manage three separate Microsoft Sentinel workspaces: 'US-Ops', 'EU-Ops', and 'Asia-Ops'. You need to write a hunting query that searches for a specific malicious file hash across ALL three workspaces simultaneously.
Which KQL syntax allows you to query multiple workspaces?
Show answer details
Correct answer: A
The
workspace('workspace-name').tablesyntax allows you to reference tables in different Log Analytics workspaces. Usingunioncombines the results from all of them.graph TD Query[Analyst Query] --> Union[Union Operator] Union --> US[US-Ops Workspace] Union --> EU[EU-Ops Workspace] Union --> Asia[Asia-Ops Workspace] - 10
You are querying a custom log table
AppLogs_CLin Microsoft Sentinel. The logs contain a column namedProperties_swhich holds a JSON string with dynamic fields likeUser,Action, andResource. You need to extract theUserfield into a separate column for filtering.Which KQL function should you use?
Show answer details
Correct answer: B
The
parse_json()function interprets a string as a JSON value, allowing access to nested fields using dot notation (e.g.,parse_json(Properties_s).User). - 11
A user reports an email in their junk folder was automatically moved there, but they believe it is legitimate. Upon investigation in Microsoft Defender for Office 365, you see the email was moved by ZAP (Zero-hour Auto Purge).
What does this indicate about the email?
Show answer details
Correct answer: A
ZAP (Zero-hour Auto Purge) retroactively detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to Exchange Online mailboxes.
- 12
You want to connect a new SaaS application to Microsoft Sentinel using the Codeless Connector Platform (CCP). You have the API documentation for the SaaS app.
Which file format must you use to define the data connector's polling configuration and data parsing logic?
Show answer details
Correct answer: B
The Codeless Connector Platform (CCP) uses a JSON configuration file to define how to connect to the data source (API), how to authenticate, and how to parse the data.
