SC-200 Sample Questions

SC-200 Sample Questions & Answers

Managing incident response carries the most weight, alongside running the broader security operations environment, configuring protections and detections, Defender for Endpoint's advanced features, and managing day-to-day security threats.

Launch the full SC-200 simulator →

Showing 20 of 40 free samples.

  1. Question 1Intermediate

    Manage a security operations environment · Design and configure Microsoft Sentinel data storage, including log

    A hospital uses Microsoft Sentinel for its security operations. To comply with HIPAA, the SOC team must retain all security logs for a minimum of seven years. The first 90 days of logs need to be available for fast, interactive querying, while the remaining data can be stored in a lower-cost tier. How should the security administrator configure data retention in the Log Analytics workspace?

    Show answer & explanation

    Correct answer: C

    This is the most cost-effective and compliant solution. Setting the interactive retention period to 90 days makes the recent, most relevant data available for high-performance queries. Configuring the total retention to 2555 days (approximately 7 years) moves data older than 90 days to the low-cost Azure Archive storage tier, where it is retained for compliance but can still be queried via search jobs if needed.

  2. Question 2Intermediate

    Manage incident response · Investigate and remediate security alerts from Microsoft Defender for

    A security analyst is investigating an alert from Microsoft Defender for Identity that indicates a potential Pass-the-Ticket attack. The alert details show that a user's Kerberos ticket was allegedly used from a workstation they do not typically access. What is the most effective next step for the analyst to take within the Microsoft Defender portal to validate this threat?

    Show answer & explanation

    Correct answer: C

    Microsoft Defender for Identity provides lateral movement path visualizations. Reviewing these paths for the potentially compromised user is the most effective step to understand the potential blast radius. It shows which sensitive accounts and machines the user could access, helping to validate the severity and scope of the Pass-the-Ticket attack before taking disruptive remediation actions like a password reset.

  3. Question 3Advanced

    Manage a security operations environment · Ingest data sources in Microsoft Sentinel

    A SOC team needs to onboard a custom-developed, on-premises application's logs into Microsoft Sentinel. The application writes logs in a proprietary, multi-line text format to a local file. The logs must be parsed and structured into custom fields like 'TransactionID', 'UserID', and 'ErrorMessage' within a custom table named 'LegacyApp_CL'. What is the most appropriate method to achieve this?

    Show answer & explanation

    Correct answer: B

    Data Collection Rules (DCRs) with the Azure Monitor Agent are the modern and correct way to ingest custom text logs. A DCR can be configured to collect the proprietary log file, and a KQL transformation within the DCR can parse the multi-line format and extract the required fields before sending the data to the specified custom table (LegacyApp_CL). This provides a robust and scalable solution.

  4. Question 4Intermediate

    Manage security threats · Use hunting bookmarks for data investigations

    During a threat hunt, a security analyst discovers a suspicious PowerShell command line executed on several machines. The analyst wants to save the KQL query and its results, add contextual notes about the findings, and map the activity to a MITRE ATT&CK technique. Which Microsoft Sentinel feature is designed for this purpose?

    Show answer & explanation

    Correct answer: C

    Hunting bookmarks in Microsoft Sentinel are specifically designed to capture interesting events found during a threat hunt. An analyst can bookmark one or more log entries, which saves the query results, allows for adding tags and notes, mapping to MITRE ATT&CK tactics and techniques, and can be used to initiate an investigation or promote to an incident.

  5. Question 5Intermediate

    Manage incident response · Investigate and remediate compromised entities identified by Microsoft

    A company wants to prevent users from accidentally sharing documents containing credit card numbers via Microsoft Teams. The security team creates a Microsoft Purview Data Loss Prevention (DLP) policy. An employee attempts to share a text file with 20 credit card numbers in a Teams chat. What is the expected outcome?

    Show answer & explanation

    Correct answer: B

    Microsoft Purview DLP policies for Microsoft Teams are designed to work in near real-time. When a user attempts to share sensitive information that violates a policy, the message will be blocked. The user who sent the message will receive a policy tip explaining that the message was blocked because it contains sensitive information, and administrators will see a corresponding alert.

  6. Question 6Intermediate

    Manage incident response · Investigate and remediate threats by using Microsoft Defender for

    An organization has configured Microsoft Defender for Office 365. An analyst is reviewing the Threat protection status report and notices a large spike in emails categorized as 'ZAP'. What does this indicate?

    Show answer & explanation

    Correct answer: C

    ZAP stands for Zero-hour Auto Purge. It is a protection feature in Defender for Office 365 that detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to Exchange Online mailboxes. A spike in 'ZAP' events means the system identified threats post-delivery and automatically moved them to the junk folder or quarantine.

  7. Question 7Beginner

    Manage security threats · Identify threats by using Kusto Query Language (KQL)

    A security analyst needs to create a KQL query that joins email attachment information with device file creation events to trace a malicious attachment from receipt to execution. The tables to be used are EmailAttachmentInfo and DeviceFileEvents. The join must be based on the file's SHA256 hash. Complete the following KQL query by selecting the correct operator.

    EmailAttachmentInfo
    | where isnotempty(SHA256)
    | _____ (DeviceFileEvents) on SHA256

    Show answer & explanation

    Correct answer: D

    The join operator is used in KQL to merge the rows of two tables to form a new table by matching the values of the specified columns from each table. In this case, it correctly joins the two tables on the common SHA256 column.

  8. Question 8Intermediate

    Manage a security operations environment · Configure Microsoft Sentinel roles

    A new SOC analyst is learning about the different roles within Microsoft Sentinel. A senior analyst needs to be able to manage incidents, run playbooks, and dismiss false positives, but should NOT be able to modify analytics rules, data connectors, or workspace settings. Which built-in Azure role is most appropriate to assign to the senior analyst at the resource group level where Sentinel resides?

    Show answer & explanation

    Correct answer: B

    The Microsoft Sentinel Responder role is designed specifically for this purpose. It grants permissions to perform response actions on incidents, such as assigning, closing, and managing them, without allowing the user to change the configuration of Sentinel itself, like editing analytics rules or data connectors. This follows the principle of least privilege.

  9. Question 9Intermediate

    Configure protections and detections · Configure security policies for Microsoft Defender for Endpoints,

    An organization is concerned about credential theft from LSASS memory on their servers. The security team wants to use Microsoft Defender for Endpoint to block this type of attack. Which security feature should they configure?

    Show answer & explanation

    Correct answer: C

    Microsoft Defender for Endpoint includes a specific Attack Surface Reduction (ASR) rule named 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)'. Enabling this rule in block mode directly prevents processes from accessing LSASS memory, which is a common technique used by tools like Mimikatz.

  10. Question 10Intermediate

    Manage security threats · Identify threats by using Kusto Query Language (KQL)

    A security analyst is writing a KQL query in Microsoft Sentinel to summarize the number of alerts generated by each analytics rule in the last 24 hours. The query should display two columns: the rule name and the count of alerts. Which query is correctly written?

    pie title Alert Distribution by Rule "Brute Force Attempt": 45 "Malicious IP Login": 25 "Impossible Travel": 15 "Anomalous Download": 15
    Show answer & explanation

    Correct answer: B

    This query correctly filters the SecurityAlert table for records within the last day (ago(1d)). It then uses the summarize operator with the count() aggregation function to count the number of rows for each unique AlertName. The by AlertName clause groups the results, producing the desired output of rule names and their corresponding alert counts.

Ready for the real thing?

The full SC-200 simulator has every exam-style question, timed mode, and instant scoring.

Go to the SC-200 simulator →