Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 3Objective 2

Detect Threats by Using the Microsoft Sentinel Platform SC-200 Practice Questions (Page 6)

Part of the Perform threat hunting domain, which accounts for 20–25% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 4–8 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts
20–25%of the exam

Questions 26–30

  1. 26foundation · easy

    What is the primary purpose of creating a KQL job in Microsoft Sentinel?

    Select an answer first
  2. 27expert · hard

    A security team has a summary rule table that aggregates failed login attempts by user and IP address. They need to use this table for a hunting query that identifies users with more than 10 failed attempts from different IP addresses. However, the summary table only stores the count of failed attempts, not the distinct IP addresses. What should they do?

    Select an answer first
  3. 28application · medium

    A security analyst is hunting for signs of PowerShell abuse. They have written a KQL query that returns all PowerShell events, but the results are too broad. The analyst wants to refine the query to focus on suspicious command-line arguments and also wants to visualize the results by time. What should the analyst do?

    Select an answer first
  4. 29application · medium

    A security operations team wants to create a summary rule table that aggregates network traffic by source IP and destination port. The table will be used by multiple hunting queries. What should the team configure to ensure the table is kept up-to-date?

    Select an answer first
  5. 30expert · hard

    A security analyst is monitoring the results of a hunting query that uses a summary rule table. The analyst notices that the results are inconsistent: some days show data, and other days do not. The summary rule is scheduled to run daily. What should the analyst do to diagnose the issue?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.