Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 1Objective 2

Configure the Microsoft Sentinel SIEM and Platform SC-200 Practice Questions (Page 4)

Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 17 practice questions to prepare you well beyond it. (estimate)

17questions here
4free pages
5concepts
40–45%of the exam

Questions 16–17

  1. 16expert · medium

    Your SOC has a team of analysts who need to create and edit workbooks, but they should not be able to modify analytics rules or manage incidents. You need to assign the least-privilege role that meets these requirements. Which role should you assign?

    Select an answer first
  2. 17application · medium

    Your Microsoft Sentinel workspace is ingesting large volumes of verbose logs that are rarely used for security investigations. You want to reduce costs without losing the ability to query these logs when needed. What should you do?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to SC-200

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.