Microsoft Security Operations Analyst Free Sample Questions

Description

Covers configuring protections, detections and alert rules, managing incident response, Microsoft Defender for Endpoint advanced features, and security threats and endpoint rule settings.

40 free sample questions297 in the full practice test

Try simulator

SC-200 Sample Questions

  1. Question 1

    Intermediate

    Manage incident response · Investigate and remediate incidents in Microsoft Sentinel

    A security analyst at a retail company is investigating a Microsoft Sentinel incident that contains multiple alerts related to a single user account. The analyst needs to understand the full sequence of events, from a suspicious sign-in to potential data exfiltration, in a chronological order. Which Microsoft Sentinel feature provides a graphical timeline and allows the analyst to explore related entities for this purpose?

    Answer and explanation

    Correct answer: B

    The Investigation Graph in Microsoft Sentinel is specifically designed to help analysts visualize and traverse the relationships between entities within an incident. It provides a timeline and an interactive map to understand the scope and sequence of an attack, making it the correct tool for this scenario. Workbooks are for visualization and reporting, Hunting is for proactive threat discovery, and Automation Rules are for automating responses.

  2. Question 2

    Advanced

    Manage a security operations environment · Manage automated investigation and response capabilities in Microsoft

    A security operations team is configuring Microsoft Defender for Endpoint. They want to ensure that if a high-confidence phishing URL is detected on a device, the device is automatically isolated from the network, but only if the device belongs to the 'Standard User Workstations' device group. Devices in the 'Executive Laptops' group should not be automatically isolated. Which feature should be configured to achieve this specific, conditional automation?

    Answer and explanation

    Correct answer: C

    In Microsoft Defender for Endpoint, automation levels can be configured per device group. To meet the requirement, you would set the automation level for the 'Standard User Workstations' group to 'Full - remediate threats automatically' and the 'Executive Laptops' group to a lower level, such as 'Semi - require approval for all folders'. This provides the granular control needed for conditional automated responses.

  3. Question 3

    Advanced

    Manage a security operations environment · Plan a Microsoft Sentinel workspace

    A consultant is designing a Microsoft Sentinel deployment for a multinational corporation with data centers in North America, Europe, and Asia. To comply with regional data sovereignty laws like GDPR, logs generated within a specific region must be stored in a Log Analytics workspace within that same region. However, the global SOC team, based in North America, needs to hunt for threats and manage incidents across all regions from a single interface. Which Microsoft Sentinel architecture should the consultant recommend?

    Answer and explanation

    Correct answer: B

    This architecture correctly addresses both requirements. Creating a separate Microsoft Sentinel workspace in each region ensures data is stored locally, satisfying data sovereignty laws. The global SOC team can then use cross-workspace querying capabilities from their primary North American workspace to run KQL queries, hunt for threats, and manage incidents across all regional workspaces, providing a single pane of glass for operations.

  4. Question 4

    IntermediateMultiple answers

    Manage security threats · Identify threats by using Kusto Query Language (KQL)

    A security engineer needs to write a KQL query to identify user accounts that have experienced a successful logon from a new country within the last 7 days. The query must compare the logon location to a baseline of countries the user has logged on from in the previous 30 days. Which KQL functions and operators are essential for building this query? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    The make_set() function is crucial for creating an array (or set) of unique countries a user has logged in from during the 30-day baseline period.

    The set_difference() function is used to compare the set of countries from the last 7 days against the baseline set from the previous 30 days, identifying any new countries.

  5. Question 5

    Intermediate

    Configure protections and detections · Configure and manage analytics rules

    A manufacturing company's SOC team is concerned about attackers disabling security controls on endpoints. They want to create a Microsoft Sentinel analytics rule that detects when the vssadmin.exe command is used to delete shadow copies, a common ransomware tactic. The data source is the SecurityEvent table from Windows endpoints. Which KQL query fragment correctly identifies this specific activity?

    Answer and explanation

    Correct answer: B

    This option is the most precise. Event ID 4688 logs process creation. Filtering for NewProcessName ending in 'vssadmin.exe' correctly identifies the process. Critically, it also checks the CommandLine for the specific arguments 'delete shadows', which is the malicious action. This combination minimizes false positives.

  6. Question 6

    Beginner

    Manage incident response · Create and configure automation rules

    True or False: In Microsoft Sentinel, a single automation rule can be configured to trigger multiple playbooks simultaneously based on the incident's properties.

    Answer and explanation

    Correct answer: A

    True. An automation rule in Microsoft Sentinel can be configured with multiple actions. If the conditions of the rule are met, it can execute all configured actions, including running several different playbooks in a specified order.

  7. Question 7

    Intermediate

    Manage incident response · Perform actions on the device, including live response and collecting

    A SOC analyst is using Microsoft Defender for Endpoint's live response feature to investigate a potentially compromised device. The analyst needs to upload a forensic analysis script to the device, execute it, and then download the resulting output file for offline analysis. Which sequence of live response commands should the analyst use?

    Answer and explanation

    Correct answer: C

    The correct sequence is: 1. put to upload the script file from the analyst's machine to the compromised device. 2. run to execute the uploaded script on the device. 3. get to download the output file generated by the script from the device back to the analyst's machine.

  8. Question 8

    Beginner

    Configure protections and detections · Configure cloud workload protections in Microsoft Defender for Cloud

    A security team has deployed Microsoft Defender for Cloud and enabled enhanced security features. They receive a high-severity alert indicating that Just-In-Time (JIT) VM access is not enabled for an internet-facing virtual machine. What is the primary risk mitigated by enabling JIT VM access?

    Answer and explanation

    Correct answer: D

    JIT VM access mitigates the risk of brute-force attacks by keeping management ports (like RDP port 3389 and SSH port 22) closed by default. Access is only granted for a limited time to specific IP addresses upon an approved request. This significantly reduces the attack surface of the virtual machine.

  9. Question 9

    Beginner

    Manage security threats · Create and configure Microsoft Sentinel workbooks

    A SOC manager wants to create a visual dashboard in Microsoft Sentinel to track the number of incidents by severity and assignee over the past 30 days. The dashboard must be interactive, allowing analysts to filter the data dynamically. Which Sentinel feature is best suited for this requirement?

    Answer and explanation

    Correct answer: A

    Microsoft Sentinel Workbooks, which are based on Azure Monitor Workbooks, are the ideal feature for creating interactive reports and dashboards. They allow for rich visualizations, dynamic filtering, and combining data from multiple sources, which perfectly matches the manager's requirements.

  10. Question 10

    Advanced

    Configure protections and detections · Configure policies for Microsoft Defender for Cloud Apps

    A company is using Microsoft 365 and has a policy that prohibits employees from using unapproved cloud storage services. A security analyst needs to create a policy in Microsoft Defender for Cloud Apps that will block file uploads to any discovered cloud storage application that has a risk score below 6, while still allowing downloads. What type of policy should the analyst create?

    Answer and explanation

    Correct answer: C

    A Session policy is required for this scenario because it can control user activities within a browser session in real-time. The analyst can configure a session policy to filter for 'File Upload' activities to apps with a risk score less than 6 and then apply the 'Block' action. This allows for granular control over in-session activities like uploads, which an Activity policy (for post-activity alerting) or an App discovery policy (for tagging/sanctioning apps) cannot do.