Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 3
Investigate Microsoft 365 Activities to Identify Threats SC-200 Practice Questions (Page 4)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
8concepts
35–40%of the exam
Questions 16–20
- 16
What is the primary purpose of Content search in Microsoft Purview eDiscovery?
Select an answer first - 17
What is the primary role of Microsoft Graph activity logs in threat investigation?
Select an answer first - 18
You are investigating a possible account compromise. You need to find all audit log entries where a user performed 'MailboxLogin' or 'SendMail' activities in the last 24 hours. You are using the Microsoft Purview audit log search. What is the most efficient way to filter the results?
Select an answer first - 19
You are analyzing Microsoft Graph activity logs and notice that a service principal is making 'Group.Read.All' calls at a much higher rate than usual. The service principal is used by a legitimate application. You need to determine if the activity is malicious. What should you do?
Select an answer first - 20
Which of the following activities would be recorded in the Microsoft Purview Audit log?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.