Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 4
Configure Detections SC-200 Practice Questions (Page 5)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
8concepts
40–45%of the exam
Questions 21–25
- 21
A security analyst has an existing custom detection rule in Microsoft Defender XDR that was created from an Advanced Hunting query. The rule currently alerts on a specific process name, but the analyst wants to expand it to also alert on a related process and update the MITRE technique mapping. What is the most efficient way to make these changes?
Select an answer first - 22
A SOC team in Microsoft Sentinel wants to detect unusual sign-in behavior, such as a user signing in from a new country or at an unusual time, without creating a custom KQL query. They want the detection to adapt over time to the user's normal behavior. What should they configure?
Select an answer first - 23
A SOC team in Microsoft Sentinel wants to detect anomalous behavior in Azure AD sign-ins. They have configured an anomaly rule, but it is generating too many false positives. They want to reduce false positives without losing detection of true anomalies. What should they do?
Select an answer first - 24
A security team at Fabrikam wants to enhance their Microsoft Sentinel detections by incorporating threat intelligence feeds. They have a custom threat intelligence solution that publishes indicators to a TAXII server. The team wants to use these indicators in analytics rules to detect network connections to known malicious IP addresses. What should they configure?
Select an answer first - 25
What is the key characteristic of a near-real-time (NRT) analytics rule in Microsoft Sentinel?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.