Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 1Objective 4

Configure Detections SC-200 Practice Questions (Page 8)

Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
8concepts
40–45%of the exam

Questions 36–37

  1. 36application · medium

    A security operations center at Contoso needs to detect a specific suspicious command executed on a Windows endpoint as soon as it happens. The detection must trigger within seconds of the event, not minutes. The team wants to use Microsoft Sentinel. Which rule type should they configure?

    Select an answer first
  2. 37foundation · easy

    When creating a custom detection rule in Microsoft Defender XDR, which query language is used to write the Advanced Hunting query?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to SC-200

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.