Microsoft Certified:Security Operations Analyst Associate
Domain 3Objective 1
Detect Threats by Using Microsoft Defender XDR SC-200 Practice Questions (Page 5)
Part of the Perform threat hunting domain, which accounts for 20–25% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 4–8 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
20–25%of the exam
Questions 21–25
- 21
A threat hunter at Fabrikam is investigating a compromised device that was used to access multiple internal servers. The hunter wants to see which servers were accessed and what actions were performed on them. Which feature should the hunter use to visualize this relationship?
Select an answer first - 22
A security analyst at Contoso is investigating a compromised user account. The analyst wants to visualize all the devices the user signed into and all the files accessed from those devices to understand the blast radius. Which Microsoft Defender XDR feature should the analyst use?
Select an answer first - 23
A security analyst is investigating a complex attack that involved a compromised user account, a malicious email, and a device that accessed a malicious website. The analyst wants to visualize the full attack path and identify all affected entities. The analyst also needs to determine the blast radius of the attack. Which approach should the analyst take?
Select an answer first - 24
A security analyst is investigating a potential malware infection. The analyst suspects that a process on a device is making unusual network connections to a known malicious IP address. Which KQL query would be most effective in identifying this activity?
Select an answer first - 25
A threat hunter at Fabrikam is using Microsoft Sentinel to investigate a series of suspicious sign-ins. The hunter wants to see how the sign-ins relate to other entities such as devices, IP addresses, and mailboxes to uncover a pattern. Which feature should the hunter use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.