Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 3Objective 1

Detect Threats by Using Microsoft Defender XDR SC-200 Practice Questions (Page 2)

Part of the Perform threat hunting domain, which accounts for 20–25% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 4–8 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts
20–25%of the exam

Questions 6–10

  1. 6application · medium

    A threat intelligence report describes a new campaign that uses a specific PowerShell script to download a payload from a known malicious domain. The SOC team wants to proactively hunt for this activity in their environment. Which approach would be most effective?

    Select an answer first
  2. 7application · medium

    A security analyst is investigating a potential data breach. The analyst suspects that a user exfiltrated data by sending it via email. Which KQL query would be most effective in identifying this activity?

    Select an answer first
  3. 8expert · hard

    A security analyst is proactively hunting for signs of a new malware campaign that uses a specific PowerShell script to download a payload from a known malicious domain. The analyst wants to find all instances of this activity in the environment. The analyst also wants to identify any devices that may be affected. Which approach would be most effective?

    Select an answer first
  4. 9foundation · easy

    A security analyst wants to use KQL to find all devices that have a specific file named 'malware.exe' on them. Which KQL query correctly searches the DeviceFileEvents table for this file?

    Select an answer first
  5. 10foundation · easy

    A security analyst wants to create an advanced hunting query to find all devices that have both a suspicious process and a network connection to a known malicious IP address. Which KQL approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.