Microsoft Certified:Security, Compliance, and Identity Fundamentals
Domain 3Objective 3
Describe Capabilities of Microsoft Sentinel SC-900 Practice Questions (Page 2)
Part of the Describe the capabilities of Microsoft security solutions domain, which accounts for 35–40% of the SC-900 exam. Microsoft does not publish an official question count, but from its 45-minute exam (~20–30 total, ~7–12 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
35–40%of the exam
Questions 6–10
- 6
Which built-in capability of Microsoft Sentinel helps identify unusual user behavior?
Select an answer first - 7
A multinational company has security data in Azure, AWS, and on-premises. They need to correlate sign-in logs from all sources to detect a coordinated attack. They also have a limited budget and want to minimize the number of tools to manage. What should they do?
Select an answer first - 8
During a security incident, an analyst needs to isolate an infected virtual machine and collect forensic evidence. The response must be repeatable and require minimal manual steps. What should the analyst use in Microsoft Sentinel?
Select an answer first - 9
What is an example of a manual response action that can be performed in Microsoft Sentinel?
Select an answer first - 10
Which method does Microsoft Sentinel use to mitigate threats?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-900” is a trademark of its owner, used for identification only.