Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 1
Configure Automation for Microsoft Defender XDR and Microsoft Sentinel SC-200 Practice Questions (Page 6)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
11concepts
40–45%of the exam
Questions 26–30
- 26
In Microsoft Defender for Endpoint, which rules setting allows you to define custom indicators of compromise (IOCs) for detection?
Select an answer first - 27
Which setting in Microsoft Defender for Endpoint controls the automatic remediation actions taken on devices?
Select an answer first - 28
A security team uses Microsoft Sentinel and has an automation rule that triggers on incident creation and runs a playbook to assign incidents to the on-call analyst. They now want to add a second playbook that sends a notification to a Teams channel, but only for incidents with a specific tag. They want to minimize the number of automation rules and avoid running the Teams notification playbook for incidents that are already resolved. What should they do?
Select an answer first - 29
A company wants to delegate the management of Microsoft Defender for Endpoint to two different teams: one for the 'Marketing' device group and one for the 'IT' device group. Each team should have full control over their respective group but no access to the other group. What should you configure?
Select an answer first - 30
In Microsoft Sentinel, what is a playbook?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.