Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 3
Investigate Microsoft 365 Activities to Identify Threats SC-200 Practice Questions (Page 2)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
8concepts
35–40%of the exam
Questions 6–10
- 6
You are investigating a potential insider threat. You need to find all instances where a user deleted files from OneDrive and SharePoint. You have been granted the necessary permissions. What should you do?
Select an answer first - 7
In a Content search query, which keyword would you use to find emails that contain the word 'malware'?
Select an answer first - 8
You need to find all documents in SharePoint Online that contain the word 'budget' and were modified by a specific user in the last quarter. You are using eDiscovery Content search. Which query should you use?
Select an answer first - 9
In the Microsoft Purview audit log search, which field allows you to narrow results to a specific user's activities?
Select an answer first - 10
Which of the following is a useful technique for analyzing Microsoft Graph activity logs to detect threats?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.