Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 2Objective 1

Respond to Alerts and Incidents in Microsoft Defender XDR SC-200 Practice Questions (Page 6)

Part of the Respond to security incidents domain, which accounts for 35–40% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~14–26 in this domain), expect 5–9 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
10concepts
35–40%of the exam

Questions 26–30

  1. 26application · medium

    Microsoft Defender for Cloud Apps alerts you that a user is downloading a large number of files from SharePoint and uploading them to a personal cloud storage app. The user's account shows a sign-in from a new device. You need to determine if this is a security risk and take action. What should you do first?

    Select an answer first
  2. 27foundation · easy

    When investigating a security risk in Microsoft Defender for Cloud Apps, an analyst wants to see all activities performed by a specific user across all connected cloud apps. Which view should the analyst use?

    Select an answer first
  3. 28foundation · easy

    A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos activity. What type of activity does Microsoft Defender for Identity primarily monitor?

    Select an answer first
  4. 29expert · hard

    A security analyst is investigating a complex incident that spans multiple domains: a user's email account was compromised, leading to a malicious link click, which resulted in a device infection, and then lateral movement to other resources. The incident is visible in Microsoft Defender XDR. The analyst needs to contain the incident while preserving evidence for a legal investigation. What should the analyst do?

    Select an answer first
  5. 30application · medium

    Microsoft Sentinel has an incident that combines alerts from multiple sources, including Microsoft Defender for Endpoint and Microsoft Defender for Identity. The incident indicates a multi-stage attack. The security team wants to investigate the incident and manage it effectively. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.