Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 1Objective 1

Configure Automation for Microsoft Defender XDR and Microsoft Sentinel SC-200 Practice Questions (Page 2)

Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
11concepts
40–45%of the exam

Questions 6–10

  1. 6application · medium

    A security team wants to automatically block an IP address in Azure Firewall when a specific Sentinel incident is created. They have a playbook that does this. What is the required configuration to trigger the playbook automatically?

    Select an answer first
  2. 7application · medium

    A company wants to collect specific Windows event logs from their servers to detect suspicious PowerShell activity. They are using Microsoft Defender for Endpoint. What should they configure?

    Select an answer first
  3. 8foundation · easy

    In Microsoft Sentinel, what is the primary purpose of an automation rule?

    Select an answer first
  4. 9foundation · easy

    Which of the following can be an action in a Microsoft Sentinel automation rule?

    Select an answer first
  5. 10foundation · easy

    Which of the following is a capability of automatic attack disruption in Microsoft Defender XDR?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.