SC-200 Exam Questions
266 real SC-200 exam questions with expert-verified answers and explanations. Page 3 of 6.
- Question #151Perform threat hunting
Which of the following choices best defines threat hunting using Microsoft Defender for Endpoint?
Threat HuntingMicrosoft Defender for EndpointAdvanced HuntingProactive Security - Question #152Manage threat mitigation using Microsoft Defender for Endpoint
Which of the following is not a component of Microsoft Defender for Endpoint?
Microsoft Defender for EndpointMDE componentsEndpoint securityThreat mitigation - Question #153Manage threat mitigation using Microsoft Defender for Endpoint
You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line...
Microsoft Defender for EndpointForensic investigationInvestigation packageLive Response - Question #154Manage threat mitigation using Microsoft Defender for Endpoint
You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line...
Microsoft Defender for EndpointDevice actionsIncident responseThreat containment - Question #155Manage threat mitigation using Microsoft Defender XDR
Which of the below artifact types contains an investigation page?
Microsoft Defender XDRInvestigationArtifactsEntity pages - Question #156Manage threat mitigation using Microsoft Defender for Endpoint
What information is shared by a deep file analysis?
Deep file analysisMalware analysisRegistry modificationsBehavioral analysis - Question #157Manage threat mitigation using Microsoft Defender XDR
Which information is shared on the user account page?
User entity pageSecurity alertsMicrosoft Defender XDR - Question #158Manage threat mitigation using Microsoft Defender for Endpoint
Multiple false positive alerts are generating in a company XYZ. A security operations analyst working for XYZ needs to exclude an executable file to reduce alerts - c:\myxyzapp\myx...
ExclusionsFalse positivesEndpoint securityAlert management - Question #159Manage threat mitigation using Microsoft Defender for Endpoint
In advanced features, which setting must be turned on to obstruct files even if a 3rd party AV is used?
EDR block modeMicrosoft Defender for EndpointThird-party AV coexistenceThreat obstruction - Question #160Manage threat mitigation using Microsoft Defender for Endpoint
Microsoft Defender for Endpoint gives configuration selections for alerts and detections. These include notifications, custom indicators, and detection rules. Which filter is a par...
Microsoft Defender for EndpointAlertsNotificationsConfiguration - Question #161Manage threat mitigation using Microsoft Defender for Endpoint
You are in charge of working with the endpoint team to patch weaknesses reported by Threat Vulnerability Management. Which report keeps an inventory of the vulnerabilities of your...
Vulnerability ManagementMicrosoft Defender for EndpointCVE IDsWeaknesses Report - Question #162Manage threat mitigation using Microsoft Defender for Endpoint
Which selection is an ASR (attack surface reduction) rule that can be implemented and blocked?
Attack Surface ReductionASR rulesMicrosoft Defender for EndpointEndpoint security - Question #163Configure protections and detections
From which of the following can a SOC (Security Operation Center) analyst make a customized detection?
Advanced HuntingCustom Detection RulesThreat DetectionSecurity Operations - Question #164Manage threat mitigation using Microsoft Defender for Endpoint
Microsoft Defender for Endpoint gives a purpose based UI to manage and inspect security incidents and alerts. Which option can't be accomplished in the Action Center?
Microsoft Defender for EndpointAction CenterRemediation actionsUI capabilities - Question #165Manage incident response
A SOC analyst found out about an event of interest. What is the next step to take it forward for further review?
SOC workflowIncident response processEvent escalationAlert triage - Question #166Manage threat mitigation using Microsoft Defender for Endpoint
What type of Behavioural blocking can be utilized with 3rd-party AVs?
EDRBehavioral blockingMicrosoft Defender for Endpoint3rd-party AV integration - Question #167Manage threat mitigation using Microsoft Defender for Endpoint
A Windows 10 system is not showing in the device inventory list. What may be the problem?
Device inventoryDefender for EndpointDevice status - Question #168Manage incident response
Microsoft 365 Defender gives a purpose-based UI to manage and examine security incidents and alerts across Microsoft 365 services. You are a SOC Analyst working at a company XYZ th...
Microsoft 365 DefenderIncident investigationSecurity portalIncident page tabs - Question #169Manage incident response
Microsoft 365 Defender gives a purpose-based UI to manage and examine security incidents and alerts across Microsoft 365 services. You are a SOC Analyst working at a company XYZ th...
Microsoft 365 DefenderIncident ManagementSecurity OperationsAlert Classification - Question #170Manage threat mitigation using Microsoft Purview
You have a Microsoft 365 subscription. The subscription uses Microsoft 365 Defender and has data loss prevention (DLP) policies that have aggregated alerts configured. You need to...
DLP alertsMicrosoft 365 Compliance CenterAggregated alertsImpacted entities - Question #171Perform threat hunting
You have a Microsoft 365 subscription that uses Microsoft 365 Defender. You plan to create a hunting query from Microsoft Defender. You need to create a custom tracked query that w...
Advanced HuntingThreat HuntingMicrosoft 365 DefenderCustom Queries - Question #172Manage threat mitigation using Microsoft Defender for Endpoint
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. You need to add threat indicators for all the IP addresses in a range of 171.23.34.32- 171.23.34.63...
Microsoft Defender for EndpointThreat IndicatorsIP AddressBulk Import - Question #175Manage threat mitigation using Microsoft Defender XDR
You have a Microsoft 365 subscription that uses Microsoft 365 Defender. A remediation action for an automated investigation quarantines a file across multiple devices. You need to...
Microsoft 365 DefenderAutomated Investigation and Remediation (AIR)Action centerQuarantine management - Question #176Manage threat mitigation using Microsoft Defender XDR
You have a Microsoft 365 E5 subscription that uses Microsoft 365 Defender. You need to review new attack techniques discovered by Microsoft and identify vulnerable resources in the...
Microsoft 365 DefenderThreat analyticsVulnerability managementEmerging threats - Question #178Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have a virtual machine named Server1 that runs Windows Server 2022 and is hosted in Amazon Web Ser...
Azure ArcDefender for CloudHybrid cloud securityAWS integration - Question #179Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that uses Microsoft Defender for Cloud. You need to filter the security alerts view to show the following alerts: - Unusual user accessed a key vault...
Security AlertsMicrosoft Defender for CloudAlert Severity - Question #180Manage threat mitigation using Microsoft Defender for Cloud
You plan to review Microsoft Defender for Cloud alerts by using a third-party security information and event management (SIEM) solution. You need to locate alerts that indicate the...
Defender for CloudSIEM integrationAlert data modelMITRE ATT&CK - Question #185Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server. You need to configure Defender for Cloud to collect...
Microsoft Defender for CloudData CollectionAzure Virtual MachinesSecurity Event Logs - Question #186Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that uses Microsoft Defender for Cloud and contains a user named User1. You need to ensure that User1 can modify Microsoft Defender for Cloud securit...
Azure RBACMicrosoft Defender for CloudSecurity PoliciesLeast Privilege - Question #187Manage security threats
You have an Azure subscription that contains a user named User1. User1 is assigned an Azure Active Directory Premium Plan 2 license. You need to identify whether the identity of Us...
Identity ProtectionRisk DetectionsCompromised Identities - Question #188Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that uses Microsoft Defender for Cloud. You have an Amazon Web Services (AWS) account that contains an Amazon Elastic Compute Cloud (EC2) instance na...
Defender for CloudAWS integrationEC2 monitoringMicrosoft Monitoring Agent - Question #190Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that contains a virtual machine named VM1 and uses Microsoft Defender for Cloud. Microsoft Defender for Cloud has automatic provisioning configured t...
Microsoft Defender for CloudAlert suppressionFalse positivesSecurity operations - Question #191Detect and remediate threats using Microsoft Sentinel
You have an Azure subscription that uses Microsoft Sentinel. You detect a new threat by using a hunting query. You need to ensure that Microsoft Sentinel automatically detects the...
Microsoft SentinelAutomated DetectionAnalytics RulesThreat Hunting - Question #192Configure your environment in Microsoft Sentinel
You have a Microsoft Sentinel workspace. You have a query named Query1 as shown in the following exhibit. You plan to create a custom parser named Parser1. You need to use Query1 i...
KQLMicrosoft SentinelCustom ParsersQuery Definition - Question #193Detect and remediate threats using Microsoft Sentinel
You have an Azure subscription that uses Microsoft Sentinel. You need to create a custom report that will visualise sign-in information over time. What should you create first?
Microsoft SentinelWorkbooksCustom ReportsData Visualization - Question #200Configure your environment in Microsoft Sentinel
You have a Microsoft Sentinel workspace. You need to prevent a built-in Advanced Security Information Model (ASIM) parser from being updated automatically. What are two ways to ach...
Microsoft SentinelASIMParsersCustomizationVersioning - Question #202Detect and remediate threats using Microsoft Sentinel
You have an Azure subscription that contains a Microsoft Sentinel workspace. You need to create a playbook that will run automatically in response to a Microsoft Sentinel alert. Wh...
Microsoft SentinelPlaybooksAzure Logic AppsAutomation - Question #204Configure protections and detections
You have an Azure subscription that contains a Microsoft Sentinel workspace. The workspace contains a Microsoft Defender for Cloud data connector. You need to customize which detai...
Microsoft SentinelAnalytics RulesAlert CustomizationDetections - Question #205Configure your environment in Microsoft Sentinel
You have a Microsoft Sentinel workspace named Workspace1 and 200 custom Advanced Security Information Model (ASIM) parsers based on the DNS schema. You need to make the 200 parses...
Microsoft SentinelASIM parsersDeploymentAutomation - Question #207Manage threat mitigation using Microsoft Defender XDR
Case Study 3 - Litware Inc Overview Fabrikam, Inc. is a financial services company. The company has branch offices in New York, London, and Singapore. Fabrikam has remote users loc...
Microsoft Defender for IdentityFalse positivesAlert investigationNetwork Name Resolution - Question #210Manage threat mitigation using Microsoft Defender for Cloud
Case Study 3 - Litware Inc Overview Fabrikam, Inc. is a financial services company. The company has branch offices in New York, London, and Singapore. Fabrikam has remote users loc...
Azure Defender for CloudAWS IntegrationCloud ConnectorAWS IAM - Question #212Configure your environment in Microsoft Sentinel
Case Study 3 - Litware Inc Overview Fabrikam, Inc. is a financial services company. The company has branch offices in New York, London, and Singapore. Fabrikam has remote users loc...
Microsoft SentinelUEBALog AnalyticsIdentity data - Question #213Configure your environment in Microsoft Sentinel
Case Study 3 - Litware Inc Overview Fabrikam, Inc. is a financial services company. The company has branch offices in New York, London, and Singapore. Fabrikam has remote users loc...
Microsoft SentinelAutomation RulesPlaybooksAuthorization - Question #214Manage threat hunting in Microsoft Sentinel
Case Study 3 - Litware Inc Overview Fabrikam, Inc. is a financial services company. The company has branch offices in New York, London, and Singapore. Fabrikam has remote users loc...
Microsoft SentinelThreat HuntingJupyter NotebooksAzure Machine Learning - Question #215Manage a security operations environment
Case Study 3 - Litware Inc Overview Fabrikam, Inc. is a financial services company. The company has branch offices in New York, London, and Singapore. Fabrikam has remote users loc...
Microsoft SentinelWorkbooksSOC MetricsIncident Management - Question #220Manage threat mitigation using Microsoft Defender XDR
You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You need to ensure that you can investigate threats by using data in the unified audit log of Microsoft D...
Microsoft Defender for Cloud AppsOffice 365 connectorUnified audit logThreat investigation - Question #222Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that uses Microsoft Defender for Servers Plan 1 and contains a server named Server1. You enable agentless scanning. You need to prevent Server1 from...
Microsoft Defender for ServersAgentless scanningExclusion tagsDefender for Cloud configuration - Question #225Manage threat mitigation using Microsoft Defender for Endpoint
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. You need to identify any devices that triggered a malware alert and collect evidence related to...
Microsoft Defender for EndpointAutomated investigationsDevice isolationThreat response - Question #227Manage threat mitigation using Microsoft Defender for Cloud
You have the resources shown in the following table. You have an Azure subscription that uses Microsoft Defender for Cloud. You need to enable Microsoft Defender for Servers on eac...
Azure ArcMicrosoft Defender for CloudDefender for ServersHybrid Security - Question #228Manage threat mitigation using Microsoft Defender for Cloud
You have an Azure subscription that uses Microsoft Defender for Cloud. You have a GitHub account named Account1 that contains 10 repositories. You need to ensure that Defender for...
Defender for CloudGitHub IntegrationDevOps SecurityEnvironment Onboarding