Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 2Objective 3

Investigate Microsoft 365 Activities to Identify Threats SC-200 Practice Questions (Page 2)

Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
8concepts
35–40%of the exam

Questions 6–10

  1. 6application · medium

    You are investigating a potential insider threat. You need to find all instances where a user deleted files from OneDrive and SharePoint. You have been granted the necessary permissions. What should you do?

    Select an answer first
  2. 7foundation · easy

    In a Content search query, which keyword would you use to find emails that contain the word 'malware'?

    Select an answer first
  3. 8application · medium

    You need to find all documents in SharePoint Online that contain the word 'budget' and were modified by a specific user in the last quarter. You are using eDiscovery Content search. Which query should you use?

    Select an answer first
  4. 9foundation · easy

    In the Microsoft Purview audit log search, which field allows you to narrow results to a specific user's activities?

    Select an answer first
  5. 10foundation · easy

    Which of the following is a useful technique for analyzing Microsoft Graph activity logs to detect threats?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.