Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 1
Configure Automation for Microsoft Defender XDR and Microsoft Sentinel SC-200 Practice Questions (Page 7)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
11concepts
40–45%of the exam
Questions 31–35
- 31
In Microsoft Defender XDR, what is the purpose of automated investigation and response (AIR)?
Select an answer first - 32
In Microsoft Defender XDR, which setting determines the email addresses that receive notifications when a new incident is created?
Select an answer first - 33
A company wants to block malicious Office applications from creating child processes on all devices. They are using Microsoft Defender for Endpoint. What should they configure?
Select an answer first - 34
A security team wants to collect custom data from Windows devices in Microsoft Defender for Endpoint, specifically the creation of scheduled tasks. They have created a custom data collection rule using the appropriate schema. What is the next step to ensure the data is collected from the target devices?
Select an answer first - 35
A security operations team wants to automatically contain a compromised user account as soon as a high-confidence attack is detected, even before the investigation completes. They are using Microsoft Defender XDR. What should they enable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SC-200
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.