Microsoft Certified:Security Operations Analyst Associate
Domain 3Objective 2
Detect Threats by Using the Microsoft Sentinel Platform SC-200 Practice Questions (Page 9)
Part of the Perform threat hunting domain, which accounts for 20–25% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 4–8 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
20–25%of the exam
Questions 41–43
- 41
A security team frequently runs a complex query that joins multiple tables to identify brute-force attacks. The query takes over a minute to run each time, slowing down their investigations. They want to improve performance without changing the query logic. What should they do?
Select an answer first - 42
What is the primary purpose of a summary rule table in Microsoft Sentinel?
Select an answer first - 43
Contoso's security team wants to proactively hunt for signs of credential dumping by looking for processes that access the LSASS process. They plan to run a KQL query in Microsoft Sentinel that returns the relevant events, and then they want to save the results in a way that allows them to quickly re-run the query later without re-typing it. Which two actions should they take?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SC-200
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.