CertSafari

    Free Microsoft Security Operations Analyst (SC-200) Sample Questions

    35 free sample questions from our bank of 353+, covering every exam domain, with answers and detailed explanations. Updated August 2026.

    Domain 1: Manage a security operations environment

    Subdomain 1.1: Configure automation for Microsoft Defender XDR and Microsoft Sentinel

    1.Two incidents in the Defender portal involve the same compromised device and overlapping timestamps, and Defender's correlation engine determines they should be merged. However, one incident is assigned to Analyst A and the other is assigned to Analyst B. What happens?

    1. A.The incidents remain separate until the assignment conflict is resolved, after which they can be merged manually
    2. B.Defender automatically reassigns both incidents to Analyst A before merging them
    3. C.The incidents merge automatically, and the assignment field is left blank on the resulting incident
    4. D.The lower-severity incident is automatically closed without any of its alerts being transferred
    Show answer & explanation

    Correct answer: AThe incidents remain separate until the assignment conflict is resolved, after which they can be merged manually

    • A. Incidents assigned to two different people are excluded from automatic merging; once the conflicting assignment is removed, an analyst can merge the incidents manually.
    • B. Defender does not reassign incidents on its own to force a merge; the differing assignment is one of the conditions that blocks the automatic merge from happening at all.
    • C. No automatic merge occurs while the assignments differ, so there is no resulting merged incident with a blank assignment field.
    • D. Closing an incident is not how differing assignments are handled, and a real merge always migrates alerts into the target incident rather than discarding them.

    Subdomain 1.1: Configure automation for Microsoft Defender XDR and Microsoft Sentinel

    2.A device matches the device-name matching rule of two different device groups: one ranked 1 and the other ranked 3. Which group does the device get added to?

    1. A.The group ranked 1, since a rank of 1 has the highest priority
    2. B.The group ranked 3, since higher rank numbers take precedence
    3. C.Both groups simultaneously, since matches aren't mutually exclusive
    4. D.The Ungrouped devices group, since the conflict can't be resolved automatically
    Show answer & explanation

    Correct answer: AThe group ranked 1, since a rank of 1 has the highest priority

    • A. A device group ranked 1 is the highest-ranked group, and when a device matches multiple groups, it's added only to the highest-ranked one it matches.
    • B. Rank 1 is the highest priority, not rank 3, so a higher rank number does not take precedence over a lower one.
    • C. A device is added only to the single highest-ranked group it matches, not to every group whose rule it satisfies.
    • D. The Ungrouped devices group only receives devices that match no configured group's rule at all, which isn't the case here since the device matches two groups.

    Subdomain 1.1: Configure automation for Microsoft Defender XDR and Microsoft Sentinel

    3.An attack surface reduction rule set to ___ mode blocks the targeted behavior as if in Block mode, but lets the user select Unblock in a notification pop-up to bypass the block for 24 hours.

    1. A.Audit
    2. B.Warn
    3. C.Not configured
    Show answer & explanation

    Correct answer: BWarn

    • A. This mode logs detections as if the rule were blocking, but it never actually blocks anything and offers no Unblock prompt to the user.
    • B. This mode enforces the block while giving the user a temporary, time-limited Unblock option in a notification pop-up, matching the behavior described.
    • C. This state means the rule isn't explicitly enabled and behaves like it's disabled, so it takes no blocking action and shows no Unblock prompt.

    Subdomain 1.2: Configure the Microsoft Sentinel SIEM and platform

    4.A new hire on the SOC team is given a role that lets them browse existing incidents, workbooks, and Sentinel recommendations for awareness during onboarding, but they must not be able to change anything in the workspace. Which built-in role satisfies this requirement with the fewest permissions?

    1. A.Microsoft Sentinel Reader
    2. B.Microsoft Sentinel Responder
    3. C.Microsoft Sentinel Contributor
    4. D.Logic App Contributor
    Show answer & explanation

    Correct answer: AMicrosoft Sentinel Reader

    • A. Reader grants view-only access to data, incidents, workbooks, and recommendations without permission to modify incidents or resources.
    • B. Responder adds incident management capabilities such as assigning and closing incidents, which exceeds a strictly read-only requirement.
    • C. Contributor adds the ability to create and edit workbooks, analytics rules, and other resources, well beyond view-only access.
    • D. Logic App Contributor manages Logic Apps used for playbooks and has nothing to do with viewing Sentinel incidents or workbooks.

    Subdomain 1.2: Configure the Microsoft Sentinel SIEM and platform

    5.Which of the following are Azure built-in roles specific to Microsoft Sentinel?(Select 3)

    1. A.Microsoft Sentinel Reader
    2. B.Microsoft Sentinel Investigator
    3. C.Microsoft Sentinel Contributor
    4. D.Microsoft Sentinel Analyst
    5. E.Microsoft Sentinel Automation Contributor
    6. F.Microsoft Sentinel Data Exporter
    Show answer & explanation

    Correct answers: A, C, EMicrosoft Sentinel Reader; Microsoft Sentinel Contributor; Microsoft Sentinel Automation Contributor

    • A. Microsoft Sentinel Reader is a genuine built-in Azure role that grants view-only access to Sentinel data, incidents, and workbooks.
    • B. Microsoft Sentinel Investigator is not one of the documented built-in Azure roles for Microsoft Sentinel.
    • C. Microsoft Sentinel Contributor is a genuine built-in Azure role that adds resource creation and editing on top of incident management.
    • D. Microsoft Sentinel Analyst is not one of the documented built-in Azure roles; the closest real roles are Reader, Responder, and Contributor.
    • E. Microsoft Sentinel Automation Contributor is a genuine built-in Azure role used by the service account so automation rules can attach playbooks.
    • F. Microsoft Sentinel Data Exporter is not one of the documented built-in Azure roles for Microsoft Sentinel.

    Subdomain 1.2: Configure the Microsoft Sentinel SIEM and platform

    6.A SOC analyst is setting up a pre-built dashboard for a newly deployed firewall solution using the Content Hub instead of building visualizations from scratch. Which of the following are true about this process?(Select 3)

    1. A.Installing the solution from the Content Hub makes its workbook templates available for use
    2. B.Cloned workbooks created using Save as also appear under the My workbooks tab
    3. C.The workbook automatically ingests the required log data the first time it's opened
    4. D.The Content Hub requires the analyst to manually write each visualization's KQL query first
    5. E.Selecting View saved workbook after saving opens that workbook in the editor for customization
    Show answer & explanation

    Correct answers: A, B, EInstalling the solution from the Content Hub makes its workbook templates available for use; Cloned workbooks created using Save as also appear under the My workbooks tab; Selecting View saved workbook after saving opens that workbook in the editor for customization

    • A. Installing a solution, or the workbook itself, from the Content Hub makes that solution's workbook templates available to save and use.
    • B. Cloned workbooks made using Save as are displayed alongside other customized workbooks under the My workbooks tab.
    • C. The workbook doesn't automatically ingest any log data; it only queries data a connector has already sent to the workspace, so ingestion must be configured separately.
    • D. Content Hub workbook templates come with their visualizations and KQL queries already built in; the analyst doesn't need to write them before saving the template.
    • E. After saving, selecting View saved workbook opens the workbook so it can be customized in edit mode.

    Subdomain 1.2: Configure the Microsoft Sentinel SIEM and platform

    7.When a workbook is saved from a template in the Content Hub, only the workbook's ___ file is saved to the selected location; no underlying log data is copied along with it.

    1. A.JSON
    2. B.CSV
    3. C.PDF
    Show answer & explanation

    Correct answer: AJSON

    • A. Saving a workbook template creates an Azure resource containing only the workbook's JSON definition; the log data it queries stays in the workspace and is never copied.
    • B. CSV is a common export format for query results, but it isn't what's saved when you save a workbook template; the workbook itself is stored as JSON.
    • C. PDF is an output option available later from the print and save menu in the Azure portal, not the file format the workbook is saved as when first created from a template.

    Subdomain 1.3: Ingest data into the Microsoft Sentinel SIEM and platform

    8.A threat intelligence platform wants to push curated indicators directly into Microsoft Sentinel using REST calls, without configuring a data connector in the portal. Which ingestion method supports this scenario?

    1. A.The Threat Intelligence upload API, which accepts indicators over REST without requiring a portal-configured connector.
    2. B.The Threat Intelligence - TAXII connector, which requires selecting a Collection ID in the connector page before any data flows.
    3. C.The Common Event Format via AMA connector, which parses REST payloads as CEF-formatted security events.
    4. D.The Windows Security Events via AMA connector, which exposes a REST endpoint for third-party indicator submission.
    Show answer & explanation

    Correct answer: AThe Threat Intelligence upload API, which accepts indicators over REST without requiring a portal-configured connector.

    • A. The Threat Intelligence upload API is designed for integrated and curated feeds to push indicators via a REST API directly, without needing a connector configured in the Sentinel portal.
    • B. The TAXII connector requires configuring connection details, including a Collection ID, in the portal, which contradicts the requirement of not configuring a connector.
    • C. CEF via AMA parses Syslog-transported security appliance logs and has no mechanism for accepting arbitrary REST-pushed threat indicator payloads.
    • D. The Windows Security Events via AMA connector collects Windows event log data through the Azure Monitor Agent and does not expose a REST endpoint for third-party indicators.

    Subdomain 1.3: Ingest data into the Microsoft Sentinel SIEM and platform

    9.On a Linux log forwarder, the local Syslog daemon collects messages on UDP port 514 and then forwards them internally to the Azure Monitor Agent. On Azure Monitor Agent version 1.28.11 and later, which mechanism is used for this internal handoff?

    1. A.TCP port 28330, which replaced the Unix domain socket used by earlier AMA versions.
    2. B.UDP port 6514, which is reserved specifically for encrypted Syslog-over-TLS handoff to the agent.
    3. C.A shared memory segment, which avoids network sockets entirely for local process-to-process transfer.
    4. D.HTTPS port 443, the same port the agent uses to send parsed data to the Log Analytics workspace.
    Show answer & explanation

    Correct answer: ATCP port 28330, which replaced the Unix domain socket used by earlier AMA versions.

    • A. AMA versions 1.28.11 and above receive logs from the Syslog daemon on TCP port 28330, replacing the Unix domain socket mechanism used by earlier agent versions.
    • B. Port 6514 is commonly associated with Syslog-over-TLS between external sources, not the internal daemon-to-agent handoff described for AMA 1.28.11 and later.
    • C. The daemon-to-agent handoff on newer AMA versions uses a TCP port rather than a shared memory segment.
    • D. Port 443 is used for the agent's outbound communication to the Log Analytics workspace, not for the local handoff from the Syslog daemon to the agent.

    Subdomain 1.3: Ingest data into the Microsoft Sentinel SIEM and platform

    10.For the Windows Security Events via AMA connector, which event set options reduce ingestion volume compared with collecting All Events? (Select all that apply)(Select 2)

    1. A.Common
    2. B.Minimal
    3. C.All Events
    4. D.Verbose
    5. E.Extended
    Show answer & explanation

    Correct answers: A, BCommon; Minimal

    • A. Common collects a curated subset of frequently investigated events, which is smaller in volume than collecting every Security event.
    • B. Minimal collects the smallest baseline set of events, resulting in lower ingestion volume than All Events.
    • C. All Events is the full, uncurated collection option and represents the highest ingestion volume, not a reduction from itself.
    • D. Verbose is not one of the defined event set options for this connector, so it does not apply as a volume-reducing choice.
    • E. Extended is not one of the defined event set options for this connector, so it does not apply as a volume-reducing choice.

    Subdomain 1.3: Ingest data into the Microsoft Sentinel SIEM and platform

    11.An organization cannot install the Azure Monitor Agent directly on its domain controllers, so it deploys a ___ server to centralize forwarded Windows Security events before those events reach Microsoft Sentinel.

    1. A.Windows Event Collector (WEC)
    2. B.Codeless Connector Framework
    3. C.Log Analytics gateway
    Show answer & explanation

    Correct answer: AWindows Event Collector (WEC)

    • A. A Windows Event Collector server is the role designed to centralize events forwarded from other Windows machines, letting AMA be installed only on the collector instead of every source machine.
    • B. The Codeless Connector Framework is used to build REST API-based custom connectors and has no role in centralizing native Windows event forwarding.
    • C. A Log Analytics gateway is used to relay agent traffic through a proxy in restricted network environments, not to centralize forwarded Windows events.

    Subdomain 1.4: Configure detections

    12.An analyst wants to convert an existing custom detection rule to Continuous (NRT) frequency. The query currently joins DeviceProcessEvents with DeviceNetworkEvents to correlate process and network activity. What must change before the rule qualifies for Continuous (NRT) frequency?

    1. A.Rewrite the query to reference only one table, since NRT-eligible queries cannot use joins or unions
    2. B.Increase the lookback window to 30 days so the join has enough historical data to complete
    3. C.Add a summarize operator to the join so results are pre-aggregated before the join runs
    4. D.Convert the rule to target Microsoft Sentinel data instead, since only Sentinel tables support joins in NRT
    Show answer & explanation

    Correct answer: ARewrite the query to reference only one table, since NRT-eligible queries cannot use joins or unions

    • A. NRT-eligible queries must reference a single table and cannot use joins, unions, or the externaldata operator, so the two-table join has to be eliminated.
    • B. Lookback period is unrelated to join eligibility, and NRT rules use minute-level evaluation rather than a 30-day window.
    • C. Adding a summarize operator does not remove the join itself, and joins remain disallowed for Continuous (NRT) frequency regardless of aggregation.
    • D. Sentinel tables are also restricted to single-table, join-free queries for Continuous (NRT) eligibility, so switching data sources does not resolve the restriction.

    Subdomain 1.4: Configure detections

    13.Which role, at minimum, must an analyst be assigned to manage custom detection rules that target Microsoft Sentinel data?

    1. A.Microsoft Sentinel Contributor
    2. B.Microsoft Sentinel Reader
    3. C.Security Reader
    4. D.Global Reader
    Show answer & explanation

    Correct answer: AMicrosoft Sentinel Contributor

    • A. Microsoft Sentinel Contributor is the minimum role that grants the permissions needed to manage Sentinel data, including custom detection rules targeting Sentinel tables.
    • B. Microsoft Sentinel Reader grants read-only access to Sentinel data and dashboards, which is not sufficient to create or manage custom detection rules.
    • C. Security Reader provides broad read-only visibility across Microsoft security products but does not grant the write access needed to manage detection rules.
    • D. Global Reader grants tenant-wide read-only access across Microsoft 365 admin centers but does not grant the Sentinel-specific permissions needed to manage rules.

    Subdomain 1.4: Configure detections

    14.A SOC lead needs analytics rule types whose detection logic cannot be viewed or customized in the rule editor. Which of the following are non-customizable rule types with hidden or fixed logic?(Select 3)

    1. A.Fusion
    2. B.ML Behavior Analytics
    3. C.Threat Intelligence Analytics
    4. D.Scheduled rules
    5. E.NRT rules
    6. F.Microsoft security rules
    Show answer & explanation

    Correct answers: A, B, CFusion; ML Behavior Analytics; Threat Intelligence Analytics

    • A. Fusion is the Advanced multistage attack detection engine whose correlation logic is hidden, so only one non-customizable instance can exist in a workspace.
    • B. ML Behavior Analytics uses Microsoft's proprietary algorithms for SSH and RDP anomaly detection and cannot be edited, though it can be enabled or disabled.
    • C. Threat Intelligence Analytics automatically matches CEF, Syslog, and Windows DNS data against threat indicators using fixed logic that can't be customized.
    • D. Scheduled rules are built from a KQL query and scheduling settings that an analyst can write and fully edit, so their logic is customizable.
    • E. NRT rules function like scheduled rules with editable KQL queries and settings, just evaluated on a per-minute cadence, so they remain customizable.
    • F. Microsoft security rules create incidents from alerts generated by other Microsoft products, and their matching logic can be configured through the rule wizard.

    Subdomain 1.4: Configure detections

    15.The ___ correlation engine in Microsoft Sentinel uses scalable machine learning to correlate many low-fidelity alerts and events across products into a single high-fidelity incident.

    1. A.Fusion
    2. B.UEBA
    3. C.Anomaly
    Show answer & explanation

    Correct answer: AFusion

    • A. Fusion is the correlation engine that uses scalable machine learning to combine low-fidelity alerts and events across products into a high-fidelity incident.
    • B. UEBA builds behavioral baselines for entities like users and hosts; it is not the engine used for multiproduct alert correlation.
    • C. Anomaly rules flag deviations from a baseline for a single behavior; they do not perform the cross-product correlation this engine performs.

    Domain 2: Respond to security incidents

    Subdomain 2.1: Respond to alerts and incidents in Microsoft Defender XDR

    16.Which two response actions listed for automatic attack disruption are described as "Predictive shielding" capabilities rather than reactive containment of an already-compromised asset? (Choose 2)(Select 2)

    1. A.Safeboot hardening
    2. B.GPO hardening
    3. C.Isolate device
    4. D.Contain IP
    5. E.Revoke user session
    Show answer & explanation

    Correct answers: A, BSafeboot hardening; GPO hardening

    • A. Safeboot hardening is listed under the Predictive shielding capability, applying preventive hardening before an attacker can abuse Safe Mode reboots.
    • B. GPO hardening is also listed under Predictive shielding, proactively blocking potential Group Policy abuse rather than reacting to confirmed compromise.
    • C. Isolate device is listed under the Attack disruption capability itself, reacting to a device already identified as an active foothold.
    • D. Contain IP is an Attack disruption capability that blocks communication from an IP already tied to malicious activity, not a predictive action.
    • E. Revoke user session is an Attack disruption action executed through Microsoft Entra ID to interrupt access already granted, not a preventive action.

    Subdomain 2.1: Respond to alerts and incidents in Microsoft Defender XDR

    17.An analyst opens a Microsoft Sentinel incident that was generated by an analytics rule with entity mapping configured. The analyst wants to visually explore how the affected user, device, and IP address relate to each other and to other alerts. Which feature should the analyst use?

    1. A.The investigation graph, reached by selecting Investigate on the incident
    2. B.The Cloud Discovery dashboard for the connected workspace
    3. C.The Purview eDiscovery content search tool
    4. D.The Defender for Cloud Apps app catalog risk score page
    Show answer & explanation

    Correct answer: AThe investigation graph, reached by selecting Investigate on the incident

    • A. The investigation graph displays entity relationships extracted from the raw data and offers exploration queries to expand the investigation scope, exactly matching this scenario.
    • B. The Cloud Discovery dashboard reports on cloud app usage patterns and is unrelated to visualizing entity relationships inside a Sentinel incident.
    • C. Purview eDiscovery content search is used to search mailbox and document content for compliance investigations, not to graph Sentinel incident entities.
    • D. The app catalog risk score evaluates discovered cloud applications and does not provide an entity relationship graph for a Sentinel incident.

    Subdomain 2.1: Respond to alerts and incidents in Microsoft Defender XDR

    18.A SOC analyst opens a completed incident investigation and wants an AI-generated recap of the actions taken and the KQL queries run during the investigation, to hand off the case to a teammate. Which capability, embedded in the Defender portal and powered by Microsoft Security Copilot, should the analyst use?

    1. A.Generate analyst notes
    2. B.Export incident as PDF without Copilot data
    3. C.Cloud Discovery dashboard export
    4. D.Search-UnifiedAuditLog cmdlet
    Show answer & explanation

    Correct answer: AGenerate analyst notes

    • A. Generate analyst notes produces an AI summary that includes the high-level narrative and the step-by-step log of actions and KQL queries run, and it explicitly requires a Security Copilot license, matching the handoff scenario.
    • B. Exporting the incident as a PDF without Copilot data omits the AI-generated summary and report content that this scenario specifically requires.
    • C. The Cloud Discovery dashboard export reports on discovered cloud app usage and has no connection to generating an AI investigation recap.
    • D. The Search-UnifiedAuditLog cmdlet retrieves raw audit log records and does not generate an AI-written investigation summary.

    Subdomain 2.1: Respond to alerts and incidents in Microsoft Defender XDR

    19.A threat hunter identifies malicious activity spanning multiple existing incidents and wants to escalate the finding to the incident response team while keeping the context of the original hunt intact. Which case management capability supports this workflow?

    1. A.Creating a case and linking the relevant incidents to it
    2. B.Deleting the original incidents so a single new incident can be created
    3. C.Manually copying alert data into an external spreadsheet
    4. D.Disabling the analytics rules that generated the original incidents
    Show answer & explanation

    Correct answer: ACreating a case and linking the relevant incidents to it

    • A. Case management is designed for responding to security events that span multiple incidents; linking incidents to a case preserves the hunt context while giving the IR team visibility into the escalation.
    • B. Deleting the original incidents destroys evidence and history rather than preserving the context needed for a clean handoff.
    • C. Copying data into an external spreadsheet loses the native linkage, activity log, and RBAC controls that case management provides inside the Defender portal.
    • D. Disabling the source analytics rules stops future detections but does nothing to escalate or preserve the context of the current finding.

    Subdomain 2.2: Respond to alerts and incidents in Microsoft Defender for Endpoint

    20.An analyst opens a device timeline but sees no firewall-blocked-connection events even though the organization suspects blocked traffic occurred. What is the most likely reason these events are missing?

    1. A.The Filtering Platform connection audit policy is not enabled
    2. B.The device has exceeded its live response session limit for the day
    3. C.The analyst's account lacks the Manage Portal Settings permission
    4. D.The device has not yet been tagged as an internet-facing endpoint
    Show answer & explanation

    Correct answer: AThe Filtering Platform connection audit policy is not enabled

    • A. Firewall events such as blocked connections only appear in the timeline when the Filtering Platform connection audit policy is enabled on the device; without it, this event type is never generated.
    • B. Live response session limits control remote-shell access and have no bearing on whether firewall events populate the timeline.
    • C. Manage Portal Settings controls administrative capabilities like enabling live response, not whether firewall audit events are logged on the endpoint.
    • D. The internet-facing tag reflects external exposure detected through scans or inbound connections; it does not gate whether local firewall block events are recorded.

    Subdomain 2.2: Respond to alerts and incidents in Microsoft Defender for Endpoint

    21.An analyst wants a single artifact from a Windows device that captures autorun registry entries, active network connections, prefetch files, and scheduled tasks for offline forensic review, without opening an interactive shell. Which response action should the analyst take?

    1. A.Collect investigation package
    2. B.Initiate live response session
    3. C.Run antivirus scan
    4. D.Restrict app execution
    Show answer & explanation

    Correct answer: ACollect investigation package

    • A. Collect investigation package bundles data such as autoruns, network connection details, prefetch files, and scheduled tasks into a downloadable package so an analyst can review the device's state offline without an interactive session.
    • B. Live response opens an interactive remote shell for real-time investigation and requires the analyst to run individual commands rather than producing one consolidated offline package.
    • C. Running an antivirus scan checks for and remediates malware but does not produce a forensic bundle of autoruns, connections, prefetch data, and scheduled tasks.
    • D. Restrict app execution blocks non-Microsoft-signed binaries from running on the device; it does not collect forensic artifacts for offline review.

    Subdomain 2.2: Respond to alerts and incidents in Microsoft Defender for Endpoint

    22.An analyst is deciding which live response commands they can run based on their assigned role. Which of the following are advanced live response commands rather than basic commands? (Choose 3)(Select 3)

    1. A.remediate
    2. B.isolate
    3. C.run
    4. D.processes
    5. E.dir
    6. F.cd
    Show answer & explanation

    Correct answers: A, B, Cremediate; isolate; run

    • A. Remediate is an advanced command that removes an entity such as a file, process, service, or registry key, and requires the advanced command permission level.
    • B. Isolate is an advanced live response command that disconnects a macOS device from the network while retaining connectivity to the Defender service.
    • C. Run is an advanced command that executes a PowerShell script from the library on the device.
    • D. Processes is a basic command available to any role permitted to run basic live response commands; it lists running processes without taking remediation action.
    • E. Dir is a basic navigation command that lists files and subdirectories and does not require advanced permissions.
    • F. Cd is a basic command used to change the current directory and is available at the basic permission level.

    Subdomain 2.2: Respond to alerts and incidents in Microsoft Defender for Endpoint

    23.True or False: Actions taken automatically by attack disruption, such as isolating a device or disabling a user, can always be undone by the security team.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. All automatic actions taken by attack disruption can be undone by the security team, which is why Defender maintains a high confidence threshold before acting while still leaving analysts in full control of the response.
    • B. This is incorrect; the documentation explicitly states that automatic actions remain reversible by the security team.

    Subdomain 2.3: Investigate Microsoft 365 activities to identify threats

    24.A SOC wants Microsoft Graph activity logs delivered to an external SIEM in near real time for alerting, rather than stored purely for later querying. Which downstream destination should the diagnostic setting target?

    1. A.Azure Event Hubs
    2. B.Azure Blob Storage only
    3. C.A Log Analytics workspace configured for Basic logs
    4. D.A CSV export scheduled through Power Automate
    Show answer & explanation

    Correct answer: AAzure Event Hubs

    • A. Azure Event Hubs is the documented streaming destination for connecting Microsoft Graph activity logs to external SIEM tools for alerting and near-real-time analysis.
    • B. Blob Storage is intended for long-term archival of log data, not for streaming events to an external SIEM as they occur.
    • C. A Basic-logs Log Analytics workspace reduces ingestion cost for querying within Azure Monitor, it is not the mechanism for pushing events to a third-party SIEM in near real time.
    • D. A scheduled CSV export introduces batching delay and is not one of the supported diagnostic setting destinations for Microsoft Graph activity logs.

    Subdomain 2.3: Investigate Microsoft 365 activities to identify threats

    25.A newly onboarded SOC analyst attempts to open the Audit log search tool in the Microsoft Purview portal but receives an access-denied error. Which action must be taken before the analyst can search the audit log?

    1. A.Assign the analyst the audit log search permission, such as the View-Only Audit Logs role
    2. B.Assign the analyst the Global Administrator role, which is required for any audit access
    3. C.Assign the analyst the eDiscovery Manager role, which also grants unified audit log search rights
    4. D.Wait 24 hours, since Compliance Data Administrator permissions activate automatically without assignment
    Show answer & explanation

    Correct answer: AAssign the analyst the audit log search permission, such as the View-Only Audit Logs role

    • A. Access to the Audit log search tool requires the analyst to be explicitly assigned an appropriate audit permission, such as View-Only Audit Logs or an equivalent audit role.
    • B. Global Administrator is far broader than necessary; least-privilege guidance calls for assigning a dedicated audit role rather than full tenant administration.
    • C. eDiscovery Manager grants rights within eDiscovery cases and searches, it does not automatically include permission to use the separate Audit log search tool.
    • D. Permissions are not granted automatically over time; the required audit role must be explicitly assigned before the analyst gains access to the search tool.

    Subdomain 2.3: Investigate Microsoft 365 activities to identify threats

    26.When configuring a diagnostic setting to stream Microsoft Graph activity logs out of a tenant, which destinations are supported? (Select all that apply.)(Select 3)

    1. A.Azure Log Analytics workspace
    2. B.Azure Storage account
    3. C.Azure Event Hubs namespace
    4. D.Microsoft Purview eDiscovery review set
    5. E.SharePoint document library
    Show answer & explanation

    Correct answers: A, B, CAzure Log Analytics workspace; Azure Storage account; Azure Event Hubs namespace

    • A. A Log Analytics workspace is a supported destination, letting analysts query Microsoft Graph activity logs with Kusto Query Language in Azure Monitor.
    • B. An Azure Storage account is a supported destination for long-term, lower-cost archival of Microsoft Graph activity log data.
    • C. An Event Hubs namespace is a supported destination for streaming logs to third-party SIEM or alerting tools in near real time.
    • D. An eDiscovery review set stores collected case content for review, it is not a diagnostic setting destination for streaming Graph activity logs.
    • E. A SharePoint document library is a collaboration content store, it is not one of the supported diagnostic setting destinations for these logs.

    Subdomain 2.3: Investigate Microsoft 365 activities to identify threats

    27.True or False: Microsoft Graph activity logs let a tenant administrator view the Graph API activity that a multitenant application performs inside a different customer's tenant.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. This is not the correct choice; the feature is explicitly scoped to the resource tenant's own activity and does not expose another tenant's data.
    • B. This is accurate: Microsoft Graph activity logs let administrators collect logs only for their own resource tenant, and this feature does not surface a multitenant app's activity inside a different customer's tenant.

    Domain 3: Perform threat hunting

    Subdomain 3.1: Detect threats by using Microsoft Defender XDR

    28.Which advanced hunting table contains Microsoft 365 email events, including whether a message was delivered, quarantined, or blocked?

    1. A.EmailAttachmentInfo
    2. B.EmailEvents
    3. C.UrlClickEvents
    4. D.CloudAppEvents
    Show answer & explanation

    Correct answer: BEmailEvents

    • A. This table stores information about files attached to emails, not the delivery or blocking status of the message itself.
    • B. Microsoft 365 email events, including delivery and blocking outcomes, are recorded in this table.
    • C. This table records Safe Links click events, not the original email delivery status.
    • D. This table records events involving accounts and objects in Office 365 and other cloud apps, not email delivery outcomes.

    Subdomain 3.1: Detect threats by using Microsoft Defender XDR

    29.An analyst wants to review unusual mass-download activity performed by a user account within a connected cloud app such as SharePoint Online. Which table would contain this activity?

    1. A.CloudAppEvents
    2. B.DeviceFileEvents
    3. C.EmailEvents
    4. D.AlertInfo
    Show answer & explanation

    Correct answer: ACloudAppEvents

    • A. Events involving accounts and objects in Office 365 and other cloud apps, including file downloads in SharePoint Online, are stored in this table.
    • B. This table tracks file activity on managed devices, not actions taken through a cloud app interface.
    • C. This table stores email delivery events, unrelated to cloud app download activity.
    • D. This table stores alert metadata such as severity, not raw cloud app activity.

    Subdomain 3.1: Detect threats by using Microsoft Defender XDR

    30.An analyst wants to build a single query that spans data collected from across the Defender XDR ecosystem. Which combination of products' data can advanced hunting queries search across? (Choose 3)(Select 3)

    1. A.Microsoft Defender for Endpoint
    2. B.Microsoft Defender for Cloud Apps
    3. C.Microsoft Sentinel
    4. D.Microsoft Intune
    5. E.Microsoft Purview Information Protection
    6. F.Microsoft Entra Connect Health
    Show answer & explanation

    Correct answers: A, B, CMicrosoft Defender for Endpoint; Microsoft Defender for Cloud Apps; Microsoft Sentinel

    • A. Advanced hunting supports queries against data collected from Microsoft Defender for Endpoint, one of its core connected data sources.
    • B. Advanced hunting supports queries against data collected from Microsoft Defender for Cloud Apps, another of its core connected data sources.
    • C. When a Sentinel workspace is onboarded, advanced hunting can also query its analytics-tier data, making Sentinel one of the supported sources.
    • D. Intune manages device configuration and compliance policy but is not one of the data sources advanced hunting queries span.
    • E. Purview Information Protection governs sensitivity labels and is not one of the connected data sources for advanced hunting queries.
    • F. Entra Connect Health monitors on-premises identity sync infrastructure and is not one of the connected data sources for advanced hunting queries.

    Subdomain 3.1: Detect threats by using Microsoft Defender XDR

    31.An analyst is choosing a predefined scenario in the hunting graph and needs to know which scenarios require the analyst to supply a specific target entity before the graph renders. Which of the following predefined scenarios require an input? (Choose 2)(Select 2)

    1. A.Attack paths to critical asset (requires a target critical asset)
    2. B.Choke points to SQL data stores (runs without any input)
    3. C.Access to key vaults (requires a target key vault)
    4. D.Paths to domain admins (runs without any input)
    5. E.Critical identities with storage access (runs without any input)
    6. F.Least privilege access (runs without any input)
    Show answer & explanation

    Correct answers: A, CAttack paths to critical asset (requires a target critical asset); Access to key vaults (requires a target key vault)

    • A. This scenario requires the analyst to select a target critical asset before it can trace lateral movement routes toward it.
    • B. This scenario automatically identifies the nodes that appear most in paths leading to SQL data stores and does not require any input from the analyst.
    • C. This scenario requires the analyst to select a target key vault before it can show which entities have access to it.
    • D. This scenario automatically maps paths from non-privileged users to the Domain Admins group and does not require any input from the analyst.
    • E. This scenario automatically identifies critical users with access to storage resources and does not require any input from the analyst.
    • F. This scenario automatically surfaces synced accounts with privileged cloud permissions and does not require any input from the analyst.

    Subdomain 3.2: Detect threats by using the Microsoft Sentinel platform

    32.In the Hunting Queries tab, what do the Results delta and Results delta percentage metrics compare?

    1. A.The results from the last 24 hours against the results from the previous 24-48 hours
    2. B.The total lifetime result count against the count from the query's first run
    3. C.The number of bookmarks created against the number of incidents opened
    4. D.The query execution time this run against the query execution time last month
    Show answer & explanation

    Correct answer: AThe results from the last 24 hours against the results from the previous 24-48 hours

    • A. Results delta and results delta percentage compare the last 24 hours of query results against the prior 24-48 hour window, highlighting spikes or relative changes in volume.
    • B. The metric is a rolling 24-hour comparison, not a lifetime total measured against the query's very first execution.
    • C. These metrics track result counts for a query, not bookmark or incident counts.
    • D. The metrics compare result volume over recent time windows, not query execution duration.

    Subdomain 3.2: Detect threats by using the Microsoft Sentinel platform

    33.Which role and resource are required for an analyst to launch and run a Microsoft Sentinel notebook in an Azure Machine Learning workspace?

    1. A.Microsoft Sentinel Contributor role plus a Contributor role on the Azure Machine Learning workspace
    2. B.Microsoft Sentinel Reader role plus Owner role on the subscription hosting the workspace
    3. C.Global Administrator role in Microsoft Entra ID plus any role in Azure Machine Learning
    4. D.Security Reader role in Microsoft Defender XDR plus no Azure Machine Learning access at all
    Show answer & explanation

    Correct answer: AMicrosoft Sentinel Contributor role plus a Contributor role on the Azure Machine Learning workspace

    • A. Launching and running Sentinel notebooks requires the Microsoft Sentinel Contributor role to save and launch notebooks, along with a Contributor role on the Azure Machine Learning workspace where the notebook runs.
    • B. The Sentinel Reader role alone does not grant permission to save and launch notebooks; Contributor-level access is required in Sentinel.
    • C. Global Administrator is far broader than needed and is not the documented permission model for notebook access; specific Sentinel and Azure Machine Learning roles are required instead.
    • D. Notebooks run inside an Azure Machine Learning workspace, so some level of access to that workspace is required, not none at all.

    Subdomain 3.2: Detect threats by using the Microsoft Sentinel platform

    34.A scheduled KQL job's start time in the From field must be at least ___ minutes after the job is created or edited.

    1. A.30
    2. B.10
    3. C.60
    Show answer & explanation

    Correct answer: A30

    • A. The job start time in the From field must be at least 30 minutes after job creation or editing, giving the platform time to schedule the run.
    • B. A 10-minute lead time is shorter than the documented minimum of 30 minutes and would be rejected by the job creation wizard.
    • C. 60 minutes exceeds the documented minimum lead time; the actual required minimum is 30 minutes after creation or editing.

    Subdomain 3.2: Detect threats by using the Microsoft Sentinel platform

    35.Microsoft Sentinel livestreams remain the current recommended way to automate hunting query notifications and persist results going forward.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. Livestreams are no longer available in Microsoft Sentinel; the documented recommendation is to use KQL jobs, analytics rules, or playbooks instead, so this statement is false.
    • B. This is correct: livestreams have been retired, and Microsoft Sentinel now directs analysts toward KQL jobs, analytics rules, and playbooks for persistent query results and notifications.

    Want the full experience?

    These are just samples. Practice the full Microsoft Security Operations Analyst (SC-200) question bank in quiz mode — free, no signup, with domain practice and exam simulation.