Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 3Objective 1

Detect Threats by Using Microsoft Defender XDR SC-200 Practice Questions (Page 1)

Part of the Perform threat hunting domain, which accounts for 20–25% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 4–8 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts
20–25%of the exam

Questions 1–5

  1. 1foundation · easy

    A security analyst wants to create a hunting graph in Microsoft Defender XDR to visualize the impact of a compromised account. What is the primary purpose of a blast radius graph?

    Select an answer first
  2. 2foundation · easy

    A security analyst is using Microsoft Sentinel to investigate a security incident and wants to see how a specific user account is connected to other entities, such as devices and IP addresses. Which feature would the analyst use?

    Select an answer first
  3. 3application · medium

    A security analyst is reviewing a threat analytics report about a new phishing campaign. The report includes indicators of compromise (IOCs) and recommended hunting queries. What should the analyst do with this information?

    Select an answer first
  4. 4foundation · easy

    A security analyst is investigating a potential data exfiltration incident and wants to query network connections made from a compromised device. Which advanced hunting table should the analyst use?

    Select an answer first
  5. 5expert · hard

    A security analyst is investigating a potential data exfiltration incident. The analyst suspects that a user downloaded a large file from a SharePoint site and then uploaded it to a personal cloud storage service. The analyst wants to use advanced hunting to find evidence of both activities. The analyst also needs to determine if the user accessed the SharePoint site from an unusual location. Which KQL query would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.