Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 2
Respond to Alerts and Incidents in Microsoft Defender for Endpoint SC-200 Practice Questions (Page 1)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
35–40%of the exam
Questions 1–5
- 1
When analyzing a device timeline in Microsoft Defender for Endpoint, which type of information would an analyst primarily use to identify patterns of suspicious activity?
Select an answer first - 2
You have collected an investigation package from a compromised device. The package includes a memory dump and event logs. You need to identify the malware's persistence mechanism. What should you do?
Select an answer first - 3
After remediating a malware infection on a device, you need to ensure that the device is clean and that no remnants of the malware remain. What should you do?
Select an answer first - 4
Which of the following is a primary goal of evidence investigation in Microsoft Defender for Endpoint?
Select an answer first - 5
You are investigating a device that is part of a larger incident. The device timeline shows a series of events: a file downloaded, then executed, then made network connections. You need to determine if the file is malicious and if it is related to the larger incident. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.