Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 1
Respond to Alerts and Incidents in Microsoft Defender XDR SC-200 Practice Questions (Page 5)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
10concepts
35–40%of the exam
Questions 21–25
- 21
A security operations center (SOC) is managing multiple incidents in Microsoft Sentinel. One incident is a high-severity ransomware alert, and another is a low-severity phishing alert. The SOC has limited staff and needs to prioritize its response. What should the analyst do?
Select an answer first - 22
A security analyst wants to use natural language to ask questions about a security incident and receive AI-generated guidance. Which Microsoft security tool provides this capability?
Select an answer first - 23
When investigating a compromised user account in Microsoft Purview, which activity log should an analyst review to see what actions the user performed on sensitive items?
Select an answer first - 24
Microsoft Defender for Cloud raises a security alert about a virtual machine that is communicating with a known malicious IP address. Your investigation in Defender XDR shows that the VM is part of a multi-tier application and the alert is part of a larger attack campaign. You need to isolate the VM while preserving forensic evidence. What should you do?
Select an answer first - 25
After investigating a Microsoft Sentinel incident, an analyst wants to document the findings and actions taken. Which Microsoft Sentinel feature should the analyst use to record this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.