Microsoft Certified:Security Operations Analyst Associate
Domain 3Objective 1
Detect Threats by Using Microsoft Defender XDR SC-200 Practice Questions (Page 4)
Part of the Perform threat hunting domain, which accounts for 20–25% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 4–8 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
20–25%of the exam
Questions 16–20
- 16
A security analyst is reviewing a threat analytics report about a new vulnerability in a widely used software. The report includes a list of recommended actions and hunting queries. What should the analyst do first?
Select an answer first - 17
A security analyst is proactively hunting for signs of a new ransomware campaign that uses a specific file extension. The analyst wants to find all devices that have files with this extension. Which advanced hunting query would be most appropriate?
Select an answer first - 18
A security analyst is reviewing threat analytics in Microsoft Defender XDR for a newly discovered ransomware campaign. What is the primary purpose of the threat analytics report?
Select an answer first - 19
A security analyst is using the hunting graph feature in Microsoft Defender XDR to investigate a suspicious email that was opened by a user. What type of entities would the analyst expect to see in the graph?
Select an answer first - 20
A security analyst is reading a threat analytics report about a specific malware family. Which section of the report would the analyst use to understand the specific actions the malware performs on a system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.