Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 3
Investigate Microsoft 365 Activities to Identify Threats SC-200 Practice Questions (Page 6)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
8concepts
35–40%of the exam
Questions 26–30
- 26
Your organization has enabled Microsoft Graph activity logs. You need to analyze the logs to identify which applications are making excessive API calls. You have access to the logs in your SIEM. What is the most effective way to identify the top calling applications?
Select an answer first - 27
In the Microsoft Purview portal, where would you go to access the audit log search tool?
Select an answer first - 28
During an investigation, you need to find all emails in a user's mailbox that contain the phrase 'invoice' and were sent to a specific external domain in the last 30 days. You have the required eDiscovery permissions. What should you use?
Select an answer first - 29
What is the primary purpose of Microsoft Purview Audit in the context of threat investigation?
Select an answer first - 30
You are a security analyst and need to investigate a potential data exfiltration incident involving a user downloading a large number of files from SharePoint Online. You have been granted the 'View-Only Audit Logs' role. What is the first step to access the relevant audit records?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.