Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 2Objective 1

Respond to Alerts and Incidents in Microsoft Defender XDR SC-200 Practice Questions (Page 1)

Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
10concepts
35–40%of the exam

Questions 1–5

  1. 1application · medium

    A user receives a phishing email that contains a malicious link. Microsoft Defender for Office 365 detects the email and blocks the link at the time of delivery, but the user has already clicked the link before the block was applied. The security team wants to investigate the impact and remediate the threat. What should the analyst do?

    Select an answer first
  2. 2application · medium

    Microsoft Purview alerts the security team that a user has sent an email containing sensitive data to an external recipient. The data is classified as 'Confidential'. The security team needs to investigate the incident and prevent future occurrences. What should the analyst do?

    Select an answer first
  3. 3application · medium

    A security analyst is investigating a complex incident in Microsoft Defender XDR that involves multiple alerts across email, endpoint, and identity. The analyst wants to use Microsoft Security Copilot to accelerate the investigation. What should the analyst do?

    Select an answer first
  4. 4foundation · easy

    A security team uses case management to track security incidents from detection to resolution. Which activity is a core part of case management?

    Select an answer first
  5. 5foundation · easy

    During an active email attack, Microsoft Defender for Office 365 automatically pauses the delivery of newly detected malicious messages to protect users. What is this capability called?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.