Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 4
Configure Detections SC-200 Practice Questions (Page 3)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
8concepts
40–45%of the exam
Questions 11–15
- 11
A security team at Fabrikam wants to detect when a user accesses a known malicious domain. They have a threat intelligence feed that provides indicators of compromise (IOCs) for malicious domains. The team wants to use these IOCs in Microsoft Sentinel analytics rules. What should they do?
Select an answer first - 12
In Microsoft Sentinel, what is the main purpose of a machine learning analytics rule?
Select an answer first - 13
A security analyst at Contoso wants to detect a complex attack pattern that involves multiple stages: initial access, privilege escalation, and exfiltration. The pattern is not easily defined by a single KQL query. The analyst wants to use a Microsoft Sentinel rule that can learn from historical data and identify similar multi-stage attacks. Which rule type should they use?
Select an answer first - 14
In Microsoft Sentinel, what is the primary benefit of integrating threat intelligence into analytics rules?
Select an answer first - 15
A SOC team wants to detect a new type of phishing attack that uses legitimate cloud services. They have a large volume of Office 365 logs. They want to use machine learning to detect anomalies, but they are concerned about the cost of running ML models. What is the most cost-effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.