Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 2
Respond to Alerts and Incidents in Microsoft Defender for Endpoint SC-200 Practice Questions (Page 6)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
35–40%of the exam
Questions 26–30
- 26
After collecting an investigation package from a compromised device, you need to determine whether the attacker accessed sensitive files and whether any data was exfiltrated. What should you do with the collected evidence?
Select an answer first - 27
In Microsoft Defender for Endpoint, which feature provides a chronological view of events and activities that occurred on a specific device, allowing an analyst to trace the sequence of actions leading up to and following a security alert?
Select an answer first - 28
In Microsoft Defender for Endpoint, which type of entity would an analyst investigate to assess the impact of a security incident on a specific user account?
Select an answer first - 29
An incident is automatically flagged by automatic attack disruption. The incident shows that a compromised account was used to deploy ransomware to several devices. You need to understand the attack and prevent further spread. What should you do first?
Select an answer first - 30
After automatic attack disruption has contained a threat, what should an analyst do to understand and remediate the threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.