SC-200 Exam Questions
266 real SC-200 exam questions with expert-verified answers and explanations. Page 1 of 6.
- Question #1Manage threat mitigation using Microsoft Defender for Endpoint
Case Study 1 - Contoso Ltd Overview A company named Contoso Ltd. has a main office and five branch offices located throughout North America. The main office is in Seattle. The bran...
Microsoft Defender for EndpointEndpoint SecurityiOS SecurityThreat Mitigation - Question #2Manage threat mitigation using Microsoft Defender XDR
Case Study 1 - Contoso Ltd Overview A company named Contoso Ltd. has a main office and five branch offices located throughout North America. The main office is in Seattle. The bran...
Microsoft Defender for Office 365Malware protectionSharePoint Online securityThreat mitigation - Question #3Manage threat mitigation using Microsoft Defender for Cloud
Case Study 1 - Contoso Ltd Overview A company named Contoso Ltd. has a main office and five branch offices located throughout North America. The main office is in Seattle. The bran...
Azure DefenderVirtual Machine SecurityBrute Force DetectionSecurity Alerts - Question #6Manage threat mitigation using Microsoft Defender for Endpoint
Case Study 2 - Litware Inc Overview Litware Inc. is a renewable company. Litware has offices in Boston and Seattle. Litware also has remote users located across the United States....
Azure Information ProtectionMicrosoft Defender for EndpointData DiscoverySecurity Integration - Question #7Manage threat mitigation using Microsoft Defender XDR
Case Study 2 - Litware Inc Overview Litware Inc. is a renewable company. Litware has offices in Boston and Seattle. Litware also has remote users located across the United States....
Cloud App SecurityAnomaly detectionPolicy tuningIdentity protection - Question #8Configure your environment in Microsoft Sentinel
Case Study 2 - Litware Inc Overview Litware Inc. is a renewable company. Litware has offices in Boston and Seattle. Litware also has remote users located across the United States....
Azure SentinelRBACPlaybooksAnalytics Rules - Question #9Detect and remediate threats using Microsoft Sentinel
Case Study 2 - Litware Inc Overview Litware Inc. is a renewable company. Litware has offices in Boston and Seattle. Litware also has remote users located across the United States....
Azure SentinelAnalytics RulesEntity MappingIncident Grouping - Question #11Configure protections and detections
You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in. Which anomaly detection...
Anomaly DetectionIdentity ProtectionSign-in Risk PoliciesLocation-based Security - Question #12Manage threat mitigation using Microsoft Purview
You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365. You have Microsoft SharePoint Online sites that contain sensitive documents. The documents contai...
Data Loss Prevention (DLP)Sensitive Information TypesMicrosoft PurviewAzure Information Protection - Question #14Manage threat mitigation using Microsoft Defender for Endpoint
Your company uses Microsoft Defender for Endpoint. The company has Microsoft Word documents that contain macros. The documents are used frequently on the devices of the company's a...
Defender for EndpointFalse PositivesAlert ManagementSuppression Rules - Question #15Configure protections and detections
You have the following advanced hunting query in Microsoft 365 Defender. You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defe...
Advanced HuntingCustom Detection RulesMicrosoft 365 DefenderAlerting - Question #16Manage threat mitigation using Microsoft Defender for Endpoint
You are investigating a potential attack that deploys a new ransomware strain. You plan to perform automated actions on a group of highly valuable machines that contain sensitive i...
Device ManagementDevice GroupingDevice TagsAutomated Remediation - Question #17Configure protections and detections
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Microsoft Defender for IdentityHoneytoken accountsThreat detectionEntity tags - Question #18Configure protections and detections
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Microsoft Defender for IdentityAzure Identity ProtectionHoneytoken accountsIdentity security - Question #19Configure protections and detections
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Microsoft Defender for Identity (MDI)Honeytoken accountsSensitive accountsActive Directory integration - Question #20Manage threat mitigation using Microsoft Defender for Cloud
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Microsoft Defender for CloudSecurity alertsRemediation recommendationsIncident response workflow - Question #21Configure protections and detections
You receive an alert from Azure Defender for Key Vault. You discover that the alert is generated from multiple suspicious IP addresses. You need to reduce the potential of Key Vaul...
Azure Key VaultNetwork SecurityFirewallIncident Mitigation - Question #22Manage threat mitigation using Microsoft Defender for Cloud
You have a Microsoft 365 subscription that uses Azure Defender. You have 100 virtual machines in a resource group named RG1. You assign the Security Admin roles to a new user named...
Azure RBACLeast PrivilegeMicrosoft Defender for CloudVirtual Machine Security - Question #23Manage threat mitigation using Microsoft Defender for Cloud
You provision a Linux virtual machine in a new Azure subscription. You enable Azure Defender and onboard the virtual machine to Azure Defender. You need to verify that an attack on...
Microsoft Defender for CloudLinux SecurityThreat Detection TestingEDR Testing - Question #24Manage threat mitigation using Microsoft Defender for Cloud
You create an Azure subscription named sub1. In sub1, you create a Log Analytics workspace named workspace1. You enable Azure Security Center and configure Security Center to use w...
Azure Security CenterMicrosoft Defender for CloudData CollectionLog Analytics Workspace - Question #25Manage threat mitigation using Microsoft Defender for Cloud
Your company uses Azure Security Center and Azure Defender. The security operations team at the company informs you that it does NOT receive email notifications for security alerts...
Microsoft Defender for CloudAzure Security CenterEmail notificationsSecurity alerts configuration - Question #26Manage threat mitigation using Microsoft Defender for Cloud
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Microsoft Defender for CloudSecurity alertsSecurity recommendationsRegulatory compliance - Question #27Manage threat mitigation using Microsoft Defender for Cloud
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Microsoft Defender for CloudSecurity alertsRemediation recommendationsThreat mitigation - Question #28Create KQL queries for Microsoft Sentinel
You plan to create a custom Azure Sentinel query that will track anomalous Azure Active Directory (Azure AD) sign-in activity and present the activity as a time chart aggregated by...
KQLAzure SentinelData aggregationTime series - Question #29Detect and remediate threats using Microsoft Sentinel
You are configuring Azure Sentinel. You need to send a Microsoft Teams message to a channel whenever a sign-in from a suspicious IP address is detected. Which two actions should yo...
Azure SentinelPlaybooksAutomationIncident Response - Question #30Manage threat hunting in Microsoft Sentinel
You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC). What should you use?
Azure SentinelNotebooksData EnrichmentThreat Hunting - Question #31Create KQL queries for Microsoft Sentinel
You plan to create a custom Azure Sentinel query that will provide a visual representation of the security alerts generated by Azure Security Center. You need to create a query tha...
KQLAzure SentinelQueryingAggregation - Question #32Perform threat hunting
You use Azure Sentinel. You need to receive an immediate alert whenever Azure Storage account keys are enumerated. Which two actions should you perform?Each correct answer presents...
Azure SentinelThreat HuntingReal-time MonitoringKQL - Question #33Detect and remediate threats using Microsoft Sentinel
You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually. You deploy Azure Sentinel. You need to use...
Azure Sentinel PlaybooksLogic App TriggersSecurity AutomationIncident Remediation - Question #34Manage threat hunting in Microsoft Sentinel
Your company uses Azure Sentinel to manage alerts from more than 10,000 IoT devices. A security manager at the company reports that tracking security threats is increasingly diffic...
Microsoft SentinelJupyter NotebooksThreat HuntingMachine Learning - Question #35Detect and remediate threats using Microsoft Sentinel
You have a playbook in Azure Sentinel. When you trigger the playbook, it sends an email to a distribution group. You need to modify the playbook to send the email to the owner of t...
Azure Sentinel PlaybooksAutomated ResponseLogic AppsDynamic Parameters - Question #36Configure protections and detections
You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector. While creating a new rule from a template in the connector, you decide...
Azure SentinelAnalytics RulesAlert GroupingIncident Creation - Question #37Manage threat hunting in Microsoft Sentinel
Your company stores the data for every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant. Every project consist...
Azure SentinelThreat HuntingKQLCross-workspace queries - Question #38Manage incident response
You have an Azure Sentinel workspace. You need to test a playbook manually in the Azure portal. From where can you run the test in Azure Sentinel?
Azure SentinelPlaybooksIncident ResponseAutomation - Question #39Configure protections and detections
You have a custom analytics rule to detect threats in Azure Sentinel. You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of...
Azure SentinelAnalytics RulesTroubleshootingPermissions - Question #40Manage incident response
Your company uses Azure Sentinel. A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The...
Azure SentinelRBACIncident ManagementLeast Privilege - Question #41Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that contains the resources shown in the following table. You plan to enable Azure Defender for the subscription. Which resources can be protected by...
Microsoft Defender for CloudAzure Defender capabilitiesResource protectionSupported resources - Question #53Detect and remediate threats using Microsoft Sentinel
Case Study 1 - Contoso Ltd Overview A company named Contoso Ltd. has a main office and five branch offices located throughout North America. The main office is in Seattle. The bran...
Microsoft SentinelSecurity AutomationLogic AppsIncident Remediation - Question #58Configure protections and detections
You implement Safe Attachments policies in Microsoft Defender for Office 365. Users report that email messages containing attachments take longer than expected to be received. You...
Microsoft Defender for Office 365Safe AttachmentsDynamic DeliveryEmail security - Question #59Manage threat mitigation using Microsoft Defender for Endpoint
You receive a security bulletin about a potential attack that uses an image file. You need to create an indicator of compromise (IoC) in Microsoft Defender for Endpoint to prevent...
Indicator of CompromiseMicrosoft Defender for EndpointFile hashThreat prevention - Question #60Manage threat mitigation using Microsoft Defender for Endpoint
Your company deploys the following services: - Microsoft Defender for Identity - Microsoft Defender for Endpoint - Microsoft Defender for Office 365 You need to provide a security...
Microsoft Defender for EndpointRole-Based Access Control (RBAC)Least PrivilegeMicrosoft 365 Security Center - Question #61Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that has Azure Defender enabled for all supported resource types. You need to configure the continuous export of high-severity alerts to enable their...
Microsoft Defender for CloudSecurity AlertsContinuous ExportAzure Event Hubs - Question #62Manage threat mitigation using Microsoft Defender for Cloud
You are responsible for responding to Azure Defender for Key Vault alerts. During an investigation of an alert, you discover unauthorized attempts to access a key vault from a Tor...
Azure Key Vault securityNetwork access controlFirewallThreat mitigation - Question #63Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that contains a Log Analytics workspace. You need to enable just-in-time (JIT) VM access and network detections for Azure resources. Where should you...
Microsoft Defender for CloudAzure DefenderJust-in-Time (JIT) VM accessSubscription level - Question #64Manage threat mitigation using Microsoft Defender for Cloud
You use Azure Defender. You have an Azure Storage account that contains sensitive information. You need to run a PowerShell script if someone accesses the storage account from a su...
Microsoft Defender for CloudWorkflow AutomationAzure Logic AppsAutomated Response - Question #65Manage log connection to Microsoft Sentinel
You recently deployed Microsoft Sentinel. You discover that the default Fusion rule does not generate any alerts. You verify that the rule is enabled. You need to ensure that the F...
Microsoft SentinelFusion ruleData connectorsAlert generation - Question #66Detect and remediate threats using Microsoft Sentinel
A company uses Azure Sentinel. You need to create an automated threat response. What should you use?
Azure SentinelPlaybooksAutomated ResponseSecurity Automation - Question #67Configure your environment in Microsoft Sentinel
You have an Azure Sentinel deployment in the East US Azure region. You create a Log Analytics workspace named LogsWest in the West US Azure region. You need to ensure that you can...
Azure SentinelLog Analytics WorkspaceCross-workspace queriesOnboarding - Question #68Detect and remediate threats using Microsoft Sentinel
You create a custom analytics rule to detect threats in Azure Sentinel. You discover that the rule fails intermittently. What are two possible causes of the failures? Each correct...
Azure SentinelAnalytics rulesTroubleshootingKQL query performance - Question #69Configure protections and detections
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure SentinelAnalytics RulesThreat IntelligenceIncident creation