Microsoft Certified:Security Operations Analyst Associate
Domain 2Objective 1
Respond to Alerts and Incidents in Microsoft Defender XDR SC-200 Practice Questions (Page 6)
Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
10concepts
35–40%of the exam
Questions 26–30
- 26
Microsoft Defender for Cloud Apps alerts you that a user is downloading a large number of files from SharePoint and uploading them to a personal cloud storage app. The user's account shows a sign-in from a new device. You need to determine if this is a security risk and take action. What should you do first?
Select an answer first - 27
When investigating a security risk in Microsoft Defender for Cloud Apps, an analyst wants to see all activities performed by a specific user across all connected cloud apps. Which view should the analyst use?
Select an answer first - 28
A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos activity. What type of activity does Microsoft Defender for Identity primarily monitor?
Select an answer first - 29
A security analyst is investigating a complex incident that spans multiple domains: a user's email account was compromised, leading to a malicious link click, which resulted in a device infection, and then lateral movement to other resources. The incident is visible in Microsoft Defender XDR. The analyst needs to contain the incident while preserving evidence for a legal investigation. What should the analyst do?
Select an answer first - 30
Microsoft Sentinel has an incident that combines alerts from multiple sources, including Microsoft Defender for Endpoint and Microsoft Defender for Identity. The incident indicates a multi-stage attack. The security team wants to investigate the incident and manage it effectively. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.