Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 2
Respond to Alerts and Incidents in Microsoft Defender for Endpoint SC-200 Practice Questions (Page 3)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
35–40%of the exam
Questions 11–15
- 11
A device is suspected of being used as a pivot point for lateral movement. You need to gather real-time information about the device's current state, including running processes and open network connections, and then preserve that information for later analysis. What should you do?
Select an answer first - 12
A user reports that their workstation has been running slowly and showing pop-ups. In Microsoft Defender for Endpoint, you open the device timeline and see a process that launched from a temp folder, then made an outbound connection to an IP known for C2 activity. You also notice the same process attempted to access multiple files on the device. Which action should you take first to contain the threat while preserving evidence?
Select an answer first - 13
Microsoft Defender for Endpoint generates an incident labeled 'Automatic attack disruption' for a device. The incident indicates that a ransomware attack was automatically contained. You need to understand what happened and ensure the threat is fully remediated. What should you do?
Select an answer first - 14
An incident involves a user account that was used to log into multiple devices. You need to assess the impact of the compromised account across the environment. What should you do?
Select an answer first - 15
You need to collect evidence from a device that is suspected of being compromised, but the device is in a remote office with limited bandwidth. You need to minimize the amount of data transferred while still collecting relevant evidence. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.