Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 4
Configure Detections SC-200 Practice Questions (Page 2)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
8concepts
40–45%of the exam
Questions 6–10
- 6
In Microsoft Defender XDR, where would a security analyst go to edit an existing custom detection rule's query?
Select an answer first - 7
A security architect is reviewing the MITRE ATT&CK coverage in Microsoft Defender XDR. They notice that the organization has no detections for 'Lateral Movement' techniques. They want to create a custom detection rule that covers multiple lateral movement techniques using a single Advanced Hunting query. However, they also need to minimize false positives and ensure the rule does not generate excessive alerts. What is the best approach?
Select an answer first - 8
A SOC team wants to detect data exfiltration by an insider who is downloading large amounts of data from SharePoint. They want to use machine learning to identify unusual download patterns without setting static thresholds. What should they configure in Microsoft Sentinel?
Select an answer first - 9
Which data source is commonly used to provide threat intelligence indicators for analytics rules in Microsoft Sentinel?
Select an answer first - 10
Which Microsoft Sentinel feature provides pre-built machine learning models that can be used to create analytics rules?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.