Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 2Objective 1

Respond to Alerts and Incidents in Microsoft Defender XDR SC-200 Practice Questions (Page 3)

Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
10concepts
35–40%of the exam

Questions 11–15

  1. 11foundation · easy

    A security analyst is reviewing a phishing email that was delivered to a user's mailbox. The analyst needs to identify all messages that share the same sender and subject line as the reported email. Which Microsoft Defender for Office 365 capability should the analyst use to find these related messages?

    Select an answer first
  2. 12application · medium

    Microsoft Defender for Identity raises an alert for a user account that has attempted to perform an unusual Kerberos delegation activity. The account is a domain administrator. The security team needs to investigate and remediate the alert. What should the analyst do?

    Select an answer first
  3. 13foundation · easy

    A security analyst uses Microsoft Sentinel to investigate a security incident. Which Microsoft Sentinel feature provides a visual representation of the attack path and related entities?

    Select an answer first
  4. 14application · medium

    Your security team is managing multiple incidents in Microsoft Defender XDR. You need to ensure that each incident is properly tracked and that the team knows who is responsible for each one. What should you do?

    Select an answer first
  5. 15foundation · easy

    A security analyst needs to investigate a data spillage incident involving sensitive documents shared externally. Which Microsoft Purview solution provides investigation and remediation capabilities for such data security threats?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.