Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 2
Respond to Alerts and Incidents in Microsoft Defender for Endpoint SC-200 Practice Questions (Page 4)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
35–40%of the exam
Questions 16–20
- 16
Which action in Microsoft Defender for Endpoint initiates the collection of an investigation package from a device?
Select an answer first - 17
An incident involves a file that was detected as malware on multiple devices. You need to determine if the file is part of a larger campaign and if any users were affected. What should you do?
Select an answer first - 18
A phishing attack compromised several user accounts. You have identified the phishing email and the malicious link. You need to remediate the incident and prevent users from clicking the link again. What should you do?
Select an answer first - 19
In Microsoft Defender for Endpoint, which step involves reviewing collected data such as files, processes, and network connections to determine the nature and scope of an incident?
Select an answer first - 20
A device was compromised by malware that uses a legitimate remote administration tool for persistence. The malware is not detected by antivirus, and you need to remediate the device without breaking the legitimate use of the remote administration tool. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.