Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 4
Configure Detections SC-200 Practice Questions (Page 7)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
8concepts
40–45%of the exam
Questions 31–35
- 31
A security manager wants to assess which attack techniques are covered by the current custom detection rules in Microsoft Defender XDR. They need a visual representation of coverage against the MITRE ATT&CK framework and want to identify gaps. What should they use?
Select an answer first - 32
Which setting is essential to configure when creating a scheduled analytics rule in Microsoft Sentinel?
Select an answer first - 33
A security operations team has a custom detection rule in Microsoft Defender XDR that generates a high volume of false positives. The rule was created from an Advanced Hunting query that detects suspicious logon activity. The team wants to reduce false positives without losing detection of genuine threats. They also want to track the effectiveness of the change. What should they do?
Select an answer first - 34
A security architect is using the MITRE ATT&CK coverage view in Microsoft Defender XDR and notices that the organization has no detections for 'Persistence' techniques. They want to create a custom detection rule that covers multiple persistence techniques, but they are concerned about performance impact on the Advanced Hunting queries. What is the best approach?
Select an answer first - 35
A large enterprise uses Microsoft Sentinel. They want to detect a new, unknown malware variant that does not match any known signature. They have a large volume of endpoint telemetry. Which analytics rule type should they use to identify this novel threat without writing custom detection logic?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.