Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 4
Configure Detections SC-200 Practice Questions (Page 4)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
8concepts
40–45%of the exam
Questions 16–20
- 16
A security analyst at Contoso wants to detect unusual behavior in their Azure AD sign-in logs, such as sign-ins from unusual locations or at unusual times. The analyst wants to use a Microsoft Sentinel rule that can automatically learn the baseline of normal behavior and alert on deviations. Which rule type should they configure?
Select an answer first - 17
In Microsoft Sentinel, which rule type is best suited for detecting a security event that requires immediate attention, such as a single failed login from a critical account?
Select an answer first - 18
When configuring an anomaly detection rule in Microsoft Sentinel, what is typically required?
Select an answer first - 19
A security team at Fabrikam wants to assess their current detection coverage against the MITRE ATT&CK framework. They have several analytics rules in Microsoft Sentinel and want to identify which attack techniques are not covered by any rule. What should they do?
Select an answer first - 20
When analyzing attack vector coverage using the MITRE ATT&CK matrix in Microsoft Sentinel, what does an uncovered technique indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.