SC-200 Sample Questions & Answers
Managing incident response carries the most weight, alongside running the broader security operations environment, configuring protections and detections, Defender for Endpoint's advanced features, and managing day-to-day security threats.
Launch the full SC-200 simulator →Showing 20 of 40 free samples.
- Question 1Intermediate
Manage a security operations environment · Design and configure Microsoft Sentinel data storage, including log
A hospital uses Microsoft Sentinel for its security operations. To comply with HIPAA, the SOC team must retain all security logs for a minimum of seven years. The first 90 days of logs need to be available for fast, interactive querying, while the remaining data can be stored in a lower-cost tier. How should the security administrator configure data retention in the Log Analytics workspace?
Show answer & explanation
Correct answer: C
This is the most cost-effective and compliant solution. Setting the interactive retention period to 90 days makes the recent, most relevant data available for high-performance queries. Configuring the total retention to 2555 days (approximately 7 years) moves data older than 90 days to the low-cost Azure Archive storage tier, where it is retained for compliance but can still be queried via search jobs if needed.
- Question 2Intermediate
Manage incident response · Investigate and remediate security alerts from Microsoft Defender for
A security analyst is investigating an alert from Microsoft Defender for Identity that indicates a potential Pass-the-Ticket attack. The alert details show that a user's Kerberos ticket was allegedly used from a workstation they do not typically access. What is the most effective next step for the analyst to take within the Microsoft Defender portal to validate this threat?
Show answer & explanation
Correct answer: C
Microsoft Defender for Identity provides lateral movement path visualizations. Reviewing these paths for the potentially compromised user is the most effective step to understand the potential blast radius. It shows which sensitive accounts and machines the user could access, helping to validate the severity and scope of the Pass-the-Ticket attack before taking disruptive remediation actions like a password reset.
- Question 3Advanced
Manage a security operations environment · Ingest data sources in Microsoft Sentinel
A SOC team needs to onboard a custom-developed, on-premises application's logs into Microsoft Sentinel. The application writes logs in a proprietary, multi-line text format to a local file. The logs must be parsed and structured into custom fields like 'TransactionID', 'UserID', and 'ErrorMessage' within a custom table named 'LegacyApp_CL'. What is the most appropriate method to achieve this?
Show answer & explanation
Correct answer: B
Data Collection Rules (DCRs) with the Azure Monitor Agent are the modern and correct way to ingest custom text logs. A DCR can be configured to collect the proprietary log file, and a KQL transformation within the DCR can parse the multi-line format and extract the required fields before sending the data to the specified custom table (
LegacyApp_CL). This provides a robust and scalable solution. - Question 4Intermediate
Manage security threats · Use hunting bookmarks for data investigations
During a threat hunt, a security analyst discovers a suspicious PowerShell command line executed on several machines. The analyst wants to save the KQL query and its results, add contextual notes about the findings, and map the activity to a MITRE ATT&CK technique. Which Microsoft Sentinel feature is designed for this purpose?
Show answer & explanation
Correct answer: C
Hunting bookmarks in Microsoft Sentinel are specifically designed to capture interesting events found during a threat hunt. An analyst can bookmark one or more log entries, which saves the query results, allows for adding tags and notes, mapping to MITRE ATT&CK tactics and techniques, and can be used to initiate an investigation or promote to an incident.
- Question 5Intermediate
Manage incident response · Investigate and remediate compromised entities identified by Microsoft
A company wants to prevent users from accidentally sharing documents containing credit card numbers via Microsoft Teams. The security team creates a Microsoft Purview Data Loss Prevention (DLP) policy. An employee attempts to share a text file with 20 credit card numbers in a Teams chat. What is the expected outcome?
Show answer & explanation
Correct answer: B
Microsoft Purview DLP policies for Microsoft Teams are designed to work in near real-time. When a user attempts to share sensitive information that violates a policy, the message will be blocked. The user who sent the message will receive a policy tip explaining that the message was blocked because it contains sensitive information, and administrators will see a corresponding alert.
- Question 6Intermediate
Manage incident response · Investigate and remediate threats by using Microsoft Defender for
An organization has configured Microsoft Defender for Office 365. An analyst is reviewing the Threat protection status report and notices a large spike in emails categorized as 'ZAP'. What does this indicate?
Show answer & explanation
Correct answer: C
ZAP stands for Zero-hour Auto Purge. It is a protection feature in Defender for Office 365 that detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to Exchange Online mailboxes. A spike in 'ZAP' events means the system identified threats post-delivery and automatically moved them to the junk folder or quarantine.
- Question 7Beginner
Manage security threats · Identify threats by using Kusto Query Language (KQL)
A security analyst needs to create a KQL query that joins email attachment information with device file creation events to trace a malicious attachment from receipt to execution. The tables to be used are
EmailAttachmentInfoandDeviceFileEvents. The join must be based on the file's SHA256 hash. Complete the following KQL query by selecting the correct operator.EmailAttachmentInfo| where isnotempty(SHA256)| _____ (DeviceFileEvents) on SHA256Show answer & explanation
Correct answer: D
The
joinoperator is used in KQL to merge the rows of two tables to form a new table by matching the values of the specified columns from each table. In this case, it correctly joins the two tables on the commonSHA256column. - Question 8Intermediate
Manage a security operations environment · Configure Microsoft Sentinel roles
A new SOC analyst is learning about the different roles within Microsoft Sentinel. A senior analyst needs to be able to manage incidents, run playbooks, and dismiss false positives, but should NOT be able to modify analytics rules, data connectors, or workspace settings. Which built-in Azure role is most appropriate to assign to the senior analyst at the resource group level where Sentinel resides?
Show answer & explanation
Correct answer: B
The Microsoft Sentinel Responder role is designed specifically for this purpose. It grants permissions to perform response actions on incidents, such as assigning, closing, and managing them, without allowing the user to change the configuration of Sentinel itself, like editing analytics rules or data connectors. This follows the principle of least privilege.
- Question 9Intermediate
Configure protections and detections · Configure security policies for Microsoft Defender for Endpoints,
An organization is concerned about credential theft from LSASS memory on their servers. The security team wants to use Microsoft Defender for Endpoint to block this type of attack. Which security feature should they configure?
Show answer & explanation
Correct answer: C
Microsoft Defender for Endpoint includes a specific Attack Surface Reduction (ASR) rule named 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)'. Enabling this rule in block mode directly prevents processes from accessing LSASS memory, which is a common technique used by tools like Mimikatz.
- Question 10Intermediate
Manage security threats · Identify threats by using Kusto Query Language (KQL)
A security analyst is writing a KQL query in Microsoft Sentinel to summarize the number of alerts generated by each analytics rule in the last 24 hours. The query should display two columns: the rule name and the count of alerts. Which query is correctly written?
pie title Alert Distribution by Rule "Brute Force Attempt": 45 "Malicious IP Login": 25 "Impossible Travel": 15 "Anomalous Download": 15Show answer & explanation
Correct answer: B
This query correctly filters the
SecurityAlerttable for records within the last day (ago(1d)). It then uses thesummarizeoperator with thecount()aggregation function to count the number of rows for each uniqueAlertName. Theby AlertNameclause groups the results, producing the desired output of rule names and their corresponding alert counts. - Question 11Intermediate
Manage a security operations environment · Plan and configure collection of Windows Security events by using data
A security engineer is configuring data collection for a fleet of Windows Servers using the Azure Monitor Agent (AMA). To optimize costs, the organization requires that only specific Security Event IDs (4624 and 4625) be ingested into Microsoft Sentinel. The engineer creates a Data Collection Rule (DCR).
Which configuration step is required within the DCR to achieve this granular filtering at the source?
Show answer & explanation
Correct answer: B
When using the Azure Monitor Agent (AMA) with Data Collection Rules (DCR), you can use XPath queries to filter Windows events at the source before they are sent to the workspace. This reduces ingestion costs compared to collecting all events and filtering later.
- Question 12Intermediate
Manage incident response · Run playbooks on on-premises resources
A SOC team wants to implement an automated response that blocks a malicious IP address on an on-premises Cisco firewall whenever a specific high-severity incident is triggered in Microsoft Sentinel. The automation will use a Logic App.
Which component is ESSENTIAL to allow the cloud-based Logic App to communicate securely with the on-premises firewall?
Show answer & explanation
Correct answer: B
The On-premises Data Gateway acts as a bridge to provide quick and secure data transfer between on-premises data (data that isn't in the cloud) and several Microsoft cloud services, including Logic Apps. It is required for a Logic App to execute actions on on-premises network devices.
- Question 13Advanced
Manage security threats · Create custom hunting queries by using KQL
A threat hunter is investigating a potential compromise involving a list of suspicious IP addresses provided by a third-party threat intelligence vendor. The list is stored in a CSV file hosted on an Azure Blob Storage container that is publicly accessible via a SAS token. The hunter needs to cross-reference this list with the
SigninLogstable in Microsoft Sentinel.Which KQL operator should the hunter use to ingest this external CSV data directly into the query context?
Show answer & explanation
Correct answer: B
The
externaldataoperator returns a table whose schema is defined in the query, and whose data is read from an external storage artifact, such as a blob in Azure Blob Storage. This allows dynamic referencing of external files in KQL queries. - Question 14Intermediate
Configure protections and detections · Configure and manage analytics rules
A security analyst is creating a new analytics rule in Microsoft Sentinel. The goal is to detect a high volume of failed sign-in attempts within a short timeframe. The analyst decides to use a Near-Real-Time (NRT) analytics rule instead of a standard Scheduled rule.
What is a key limitation of NRT rules that the analyst must consider?
Show answer & explanation
Correct answer: B
Near-Real-Time (NRT) rules run once every minute and are designed for speed. Unlike scheduled rules, they do not support alert grouping (grouping events into a single alert). They generate a separate alert for each event that matches the query.
- Question 15Beginner
Manage incident response · Perform actions on the device, including live response and collecting
You are a security administrator using Microsoft Defender for Endpoint. You have identified a device (DeviceA) that is currently communicating with a known Command and Control (C2) server. You need to immediately prevent this device from accessing the network while allowing connectivity to the Defender for Endpoint service for further investigation.
Which action should you perform?
Show answer & explanation
Correct answer: B
Isolating the device disconnects it from the network, retaining connectivity only to the Defender for Endpoint service. This contains the threat while allowing the security team to continue the investigation and remediation.
- Question 16Beginner
Manage a security operations environment · Configure Microsoft Sentinel roles
A new member of the SOC team needs the ability to create, edit, and delete custom analytics rules in Microsoft Sentinel. However, they should not have permissions to create or modify playbooks (Logic Apps).
Which Azure RBAC role should be assigned to this user?
Show answer & explanation
Correct answer: B
Microsoft Sentinel Contributor allows creating and editing analytics rules, workbooks, and other Sentinel resources. It does not grant Logic App Contributor permissions required to create/edit playbooks.
- Question 17Intermediate
Manage security threats · Use hunting bookmarks for data investigations
While investigating a threat in Microsoft Sentinel using the Logs blade, you identify a suspicious row in the query results. You want to preserve this specific result for later reference and add notes to it.
What feature should you use, and which table is the data stored in?
Show answer & explanation
Correct answer: B
Hunting bookmarks allow analysts to preserve query results, add tags/notes, and these are stored in the
HuntingBookmarktable in the Log Analytics workspace. - Question 18Intermediate
Manage incident response · Investigate threats by using the unified audit log
You are investigating a report that a user permanently deleted a critical file from a SharePoint Online site. You need to identify who performed the deletion and when.
Which tool in the Microsoft Defender portal or Microsoft Purview compliance portal should you use to search for the 'FileDeleted' operation?
Show answer & explanation
Correct answer: A
The Unified Audit Log (Audit) in the Microsoft Purview compliance portal contains records of user and admin activities across Microsoft 365 services, including SharePoint file deletions.
- Question 19Advanced
Configure protections and detections · Create and configure automation rules
When configuring multiple automation rules in Microsoft Sentinel that trigger on the same incident, the 'Order' value determines the sequence of execution.
If you have three rules with Order values 1, 5, and 10, and the rule with Order 5 has an action to 'Close' the incident, what happens to the rule with Order 10?
Show answer & explanation
Correct answer: D
Automation rules run sequentially. Even if an incident is closed by a prior rule, subsequent automation rules will still run unless they have a specific condition that checks the incident status (e.g., 'Status equals Open').
flowchart TD A[Trigger] --> B{Rule Order 1} B --> C{Rule Order 5} C -->|Closes Incident| D{Rule Order 10} D -->|Executes unless condition prevents| E[End] - Question 20Intermediate
Manage a security operations environment · Design and configure Microsoft Sentinel data storage, including log
An organization requires that certain high-volume, low-security value logs (like verbose firewall allow logs) be retained for 7 years for compliance but queried very rarely. To minimize costs in Microsoft Sentinel, which data plan should be configured for the custom table receiving these logs?
Show answer & explanation
Correct answer: B
Basic Logs are a low-cost plan for retaining high-volume logs that are queried infrequently. They support a limited KQL subset and are significantly cheaper than Analytics Logs. For 7-year retention, these can be moved to the Archive tier.
Ready for the real thing?
The full SC-200 simulator has every exam-style question, timed mode, and instant scoring.