Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Microsoft Security Operations Analyst Question and Answers

Microsoft Security Operations Analyst

Last Update May 25, 2026
Total Questions : 388

We are offering FREE SC-200 Microsoft exam questions. All you do is to just go and sign up. Give your details, prepare SC-200 free exam questions and then go for complete pool of Microsoft Security Operations Analyst test questions that will help you more.

SC-200 pdf

SC-200 PDF

$40.25  $114.99
SC-200 Engine

SC-200 Testing Engine

$47.25  $134.99
SC-200 PDF + Engine

SC-200 PDF + Testing Engine

$61.25  $174.99
Questions 1

You need to complete the query for failed sign-ins to meet the technical requirements.

Where can you find the column name to complete the where clause?

Options:

A.  

Security alerts in Azure Security Center

B.  

Activity log in Azure

C.  

Azure Advisor

D.  

the query windows of the Log Analytics workspace

Discussion 0
Questions 2

You have an Azure subscription that contains the users shown in the following table.

You need to delegate the following tasks:

• Enable Microsoft Defender for Servers on virtual machines.

• Review security recommendations and enable server vulnerability scans.

The solution must use the principle of least privilege.

Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 3

You have a Microsoft Sentinel workspace.

You receive multiple alerts for failed sign in attempts to an account.

You identify that the alerts are false positives.

You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements.

• Ensure that failed sign-in alerts are generated for other accounts.

• Minimize administrative effort

What should do?

Options:

A.  

Create an automation rule.

B.  

Create a watchlist.

C.  

Modify the analytics rule.

D.  

Add an activity template to the entity behavior.

Discussion 0
Questions 4

You need to build a KQL query in a Microsoft Sentinel workspace. The query must return the SecurityEvent record for accounts that have the last record with an EventID value of 4624. How should you complete the query ' To answer, select the appropriate options in the answer area.

NOTE: Each coned selection is worth one point

Options:

Discussion 0
Questions 5

You have a Microsoft Sentinel workspace named Workspaces

You configure Workspace1 to c

ollect DNS events and deploy the Advanced Security information Model (ASIM) unifying parser for the DNS schema.

You need to query the ASIM DNS schema to list all the DNS events from the last 24 hours that have a response code of ' NXDOMAIN ' and were aggregated by the source IP address in 15-minute intervals. The solution must maximize query performance.

How should you complete the query? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 6

You have an Azure subscription that contains a resource group named RG1. RG1 contains a Microsoft Sentinel workspace. The subscription is linked to a Microsoft Entra tenant that contains a user named User1.

You need to ensure that User1 can deploy and customize Microsoft Sentine1 workbook templates. The solution must follow the principle of least privilege.

Which role should you assign to User1 for RG1?

Options:

A.  

Workbook Contributor

B.  

Microsoft Sentinel Contributor

C.  

Contributor

D.  

Microsoft Sentinel Automation Contributor

Discussion 0
Questions 7

You have a Microsoft 365 tenant that uses Microsoft Exchange Online and Microsoft Defender for Office 365.

What should you use to identify whether zero-hour auto purge (ZAP) moved an email message from the mailbox of a us er?

Options:

A.  

the Threat Protection Status report in Microsoft Defender for Office 365

B.  

the mailbox audit log in Exchange

C.  

the Safe Attachments file types report in Microsoft Defender for Office 365

D.  

the mail flow report in Exchange

Discussion 0
Questions 8

You have an Azure subscription that uses Microsoft Sentinel and contains a user named User1.

You need to ensure that User1 can enable User and Entity Behavior Analytics (UEBA) for entity behavior in Azure AD The solution must use The principle of least privilege.

Which roles should you assign to Used? To answer select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 9

You receive an alert from Azure Defender for Key Vault.

You discover that the alert is generated from multiple suspicious IP addresses.

You need to reduce the potential of Key Vault secrets being leaked while you investigate the issue. The solution must be implemented as soon as possible and must minimize the impact on legitimate users.

What should you do first?

Options:

A.  

Modify the access control settings for the key vault.

B.  

Enable the Key Vault firewall.

C.  

Create an application security group.

D.  

Modify the access policy for the key vault.

Discussion 0
Questions 10

You have a Microsoft Sentinel workspace that contains a custom workbook named Workbook1.

You need to create a visual based on the SecuntyEvent table. The solution must meet the following requirements:

• Identify the number of security events ingested during the past week.

• Display the count of events by day in a timechart

What should you add to Workbook1?

Options:

A.  

a query

B.  

a metric

C.  

a group

D.  

links or tabs

Discussion 0
Questions 11

You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud.

You need to assign the PCI DSS 4.0 initiative to Sub1 and have the initiative displayed in the Defender for Cloud Regulatory compliance dashboard.

From Security policies in the Environment settings, you discover that the option to add more industry and regulatory standards is unavailable.

What should you do first?

Options:

A.  

Enable the Cloud Security Posture Management (CSPM) plan for the subscription.

B.  

Disable the Microsoft Cloud Security Benchmark (MCSB) assignment.

C.  

Configure the Continuous export settings for Azure Event Hubs.

D.  

Configure the Continuous export settings for Log Analytics.

Discussion 0
Questions 12

You have the Azure subscriptions shown in the following table.

You have a Microsoft Entra tenant that contains the users shown in the following table.

The users have the Azure roles shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 13

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant.

You need to identify LDAP requests by AD DS users to enumerate AD DS objects.

How should you complete the KQL query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 14

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You use Azure Security Center.

You receive a security alert in Security Center.

You need to view recommendations to resolve the alert in Security Center.

Solution: From Security alerts, you select the alert, select Take Action, and then expand the Prevent future attacks section.

Does this meet the goal?

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 15

You have a Microsoft Sentinel workspace that has User and Entity Behavior Analytics (UEBA) enabled.

You need to identify all the log entries that relate to security-sensitive user actions performed on a server named Server1. The solution must meet the following requirements:

• Only include security-sensitive actions by users that are NOT members of the IT department.

• Minimize the number of false positives.

How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 16

You have a Microsoft 365 E5 subscription.

You need to configure Microsoft Sentinel to collect logs from Microsoft Entra.

Which two nodes should you use in the Microsoft Defender portal? To answer, select the appropriate nodes in the answer area.

NOTE: Each correct answer is worth one point.

Options:

Discussion 0
Questions 17

You have a Microsoft 365 subscription that uses Microsoft 365 Defender.

You plan to create a hunting query from Microsoft Defender.

You need to create a custom tracked query that will be used to assess the threat status of the subscription.

From the Microsoft 365 Defender portal, which page should you use to create the query?

Options:

A.  

Policies & rules

B.  

Explorer

C.  

Threat analytics

D.  

Advanced Hunting

Discussion 0
Questions 18

You have a suppression rule in Azure Security Center for 10 virtual machines that are used for testing. The virtual machines run Windows Server.

You are troubleshooting an issue on the virtual machines.

In Security Center, you need to view the alerts generated by the virtual machines during the last five days.

What should you do?

Options:

A.  

Change the rule expiration date of the suppression r ule.

B.  

Change the state of the suppression rule to Disabled.

C.  

Modify the filter for the Security alerts page.

D.  

View the Windows event logs on the virtual machines.

Discussion 0
Questions 19

You are configuring Azure Sentinel.

You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.

Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.  

Enable Entity behavior analytics.

B.  

Associate a playbook to the analytics rule that triggered the incident.

C.  

Enable the Fusion rule.

D.  

Add a playbook.

E.  

Create a workbook.

Discussion 0
Questions 20

You have the following advanced hunting query in Microsoft 365 Defender.

You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.  

Create a detection rule.

B.  

Create a suppression rule.

C.  

Add | order by Timestamp to the query.

D.  

Block DeviceProcessEvents with DeviceNetworkEvents.

E.  

Add DeviceId and ReportId to the output of the query.

Discussion 0
Questions 21

You need to create an advanced hunting query to i nvestigate the executive team issue.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 22

You have a Microsoft 365 E5 subscription that contains a database server named DB1. DB1 is onboarded to Microsoft Defender XDR.

You need to ensure that DB1 appears on the attack surface map.

What should you configure?

Options:

A.  

a critical asset rule

B.  

an asset rule

C.  

a honeytoken entity tag

D.  

a sensitive entity tag

Discussion 0
Questions 23

The issue for which team can be resolved by using Microsoft Defender for Endpoint?

Options:

A.  

executive

B.  

sales

C.  

marketing

Discussion 0
Questions 24

You need to implement the Azure Information Protection requirements. What should you configure first?

Options:

A.  

Device health and compliance reports settings in Microsoft Defender Security Center

B.  

scanner clusters in Azure Information Protection from the Azure portal

C.  

content scan jobs in Azure Information Protection from the Azure portal

D.  

Advanced features from Settings in Microsoft Defender Security Center

Discussion 0
Questions 25

You need to recommend remediation actions for the Azure Defender alerts for Fabrikam.

What should you recommend for each threat? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 26

Which rule setting should you configure to meet the Microsoft Sentinel requirements?

Options:

A.  

From Set rule logic, turn off suppression.

B.  

From Analytic rule details, configure the tactics.

C.  

From Set rule logic, map the entities.

D.  

From Analytic rule details, configure the severity.

Discussion 0
Questions 27

You need to modify the anomaly detection policy settings to meet the Cloud App Security requirements. Which policy should you modify?

Options:

A.  

Activity from suspicious IP addresses

B.  

Activity from anonymous IP addresses

C.  

Impossible travel

D.  

Risky sign-in

Discussion 0
Questions 28

You need to configure the Azure Sentinel integration to meet the Azure Senti nel requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 29

You need to modify the anomaly detection policy settings to meet the Microsoft Defender for Cloud Apps requirements and resolve the reported problem.

Which policy should you modify?

Options:

A.  

Activity from suspicious IP addresses

B.  

Risky sign-in

C.  

Activity from anonymous IP addresses

D.  

Impossible travel

Discussion 0
Questions 30

You need to create the test rule to meet the Azure Sentinel requirements. What should you do when you create the rule?

Options:

A.  

From Set rule logic, turn off suppression.

B.  

From Analytics rule details, configure the tactics.

C.  

From Set rule logic, map the entities.

D.  

From Analytics rule details, configure the severity.

Discussion 0
Questions 31

You need to restrict cloud apps running on CUENT1 to meet the Microsoft Defender for Endpoint requirements. Which two configurations should you modify? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options:

A.  

the Cloud Discovery settings in Microsoft Defender for Cloud Apps

B.  

the Onboarding settings from Device management in Settings in Microsoft 365 Defender portal

C.  

Microsoft Defender for Cloud Apps anomaly detection policies

D.  

Advanced features from the Endpoints Settings in the Microsoft 365 Defender portal

Discussion 0
Questions 32

You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 33

You need to configure DC1 to meet the business requirements.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Discussion 0
Questions 34

You need to restrict cloud apps running on CLIENT1 to meet the Microsoft Defender for Endpoint requirements.

Which two configurations should you modify? Each correct answ er present part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.  

the Onboarding settings from Device management in Microsoft Defender Security Center

B.  

Cloud App Security anomaly detection policies

C.  

Advanced features from Set tings in Microsoft Defender Security Center

D.  

the Cloud Discovery settings in Cloud App Security

Discussion 0
Questions 35

You need to assign a role-based access control (RBAC) role to admin1 to meet the Azure Sentinel requirements and the business requirements.

Which role should you assign?

Options:

A.  

Automation Operator

B.  

Automation Runbook Operator

C.  

Azure Sentinel Contributor

D.  

Logic App Contributor

Discussion 0
Questions 36

You need to add notes to the events to meet the Azure Sentinel requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of action to the answer area and arrange them in the correct order.

Options:

Discussion 0
Questions 37

You need to configure the Microsoft Sentinel integration to meet the Microsoft Sentinel requirements. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 38

You need to implement Microsoft Defender for Cloud to meet the Microsoft Defender for Cloud requirements and the business requirements. What should you include in the solution? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 39

You need to ensure that the configuration of HuntingQuery1 meets the Microsoft Sentinel requirements.

What should you do?

Options:

A.  

Add HuntingQuery1 to a livestream.

B.  

Create a watch list.

C.  

Create an Azure Automation rule.

D.  

Add HuntingQuery1 to favorites.

Discussion 0
Questions 40

You need to ensure that the processing of incidents generated by rulequery1 meets the Microsoft Sentinel requirements.

What should you create first?

Options:

A.  

a playbook with an incident trigger

B.  

a playbook with an entity trigger

C.  

an Azure Automation rule

D.  

a playbook with an alert trigger

Discussion 0
Questions 41

You need to implement the query for Workbook1 and Webapp1. The solution must meet the Microsoft Sentinel requirements. How should you configure the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 42

You need to configure event monitoring for Server1. The solution must meet the Microsoft Sentinel requirements. What should you create first?

Options:

A.  

a Microsoft Sentinel automation rule

B.  

a Microsoft Sentinel scheduled query rule

C.  

a Data Collection Rule (DCR)

D.  

an Azure Event Grid topic

Discussion 0
Questions 43

You need to implement the scheduled rule for incident generation based on rulequery1.

What should you configure first?

Options:

A.  

entity mapping

B.  

custom details

C.  

event grouping

D.  

alert details

Discussion 0
Questions 44

You need to implement the Microsoft Sentinel NRT rule for monitoring the designated break glass account. The solution must meet the Microsoft Sentinel requirements.

How should you complete the query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 45

You need to ensure that the Group1 members can meet the Microsoft Sentinel requirements.

Which role should you assign to Group1?

Options:

A.  

Microsoft Sentinel Automation Contributor

B.  

Logic App Contributor

C.  

Automation Operator

D.  

Microsoft Sentinel Playbook Operator

Discussion 0
Questions 46

You need to implement the ASIM query for DNS requests. The solution must meet the Microsoft Sentinel requirements. How should you configure the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 47

You need to implement the Defender for Cloud requirements.

What should you configure for Server2?

Options:

A.  

the Microsoft Antimalware extension

B.  

an Azure resource lock

C.  

an Azure resource tag

D.  

the Azure Automanage machine configuration extension for Windows

Discussion 0
Questions 48

You need to implement the Defender for Cloud requirements.

Which subscription-level role should you assign to Group1?

Options:

A.  

Security Admin

B.  

Owner

C.  

Security Assessment Contributor

D.  

Contributor

Discussion 0
Questions 49

You need to monitor the password resets. The solution must meet the Microsoft Sentinel requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 50

You have an Azure subscription that uses Microsoft Defender for Cloud and contains a storage account named storage1. You receive an alert that there was an unusually high volume of delete operations on the blobs in storage1. You need to identify which blobs were deleted. What should you review?

Options:

A.  

the activity logs of storage1

B.  

the Azure Storage Analytics logs

C.  

the alert details

D.  

the related entities of the alert

Discussion 0
Questions 51

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan Z and contains 1,000 Windows devices.

You have a PowerShell script named Script Vps1 that is signed digitally.

You need to ensure that you can run Script1.psl in a live response session on one of the devices.

What should you do first from the live response session?

Options:

A.  

Run the library command.

B.  

Run the putfile command

C.  

Modify the PowerShell execution policy of the device.

D.  

Upload Script1.ps 1 to the library.

Discussion 0
Questions 52

You have the resources shown in the following table.

You need to prevent duplicate events from occurring in SW1.

What should you use for each action? To answer, drag the appropriate resources to the correct actions. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 53

Your company stores the data for every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant.

Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine’s respective subscription.

You deploy Azure Sentinel to a new Azure subscription.

You need to perform hunting queries in Azure Sentinel to search across all the Log Analytics workspaces of all the subscriptions.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.  

Add the Security Events connector to the Azure Sentinel workspace.

B.  

Create a query that uses the workspace expression and the union operator.

C.  

Use the alias statement.

D.  

Create a query that uses the resource expression and the alias operator.

E.  

Add the Azure Sentinel solution to each workspace.

Discussion 0
Questions 54

You need to update the threat intelligence list to include the entities.

Which entities can you add on the Incident page?

Options:

A.  

175.45.176.99 only

B.  

Host1 only

C.  

Used only

D.  

175.45.176.99 and Host1 only

E.  

Host1 and User1 only

F.  

175.45.176.99, Host1, and User1

Discussion 0
Questions 55

Your company uses Azure Sentinel to manage alerts from more than 10,000 IoT devices.

A security manager at the company reports that tracking security threats is increasingly difficult due to the large number of incidents.

You need to recommend a solution to provide a custom visualization to simplify the investigation of threats and to infer threats by using machine learning.

What should you include in the recommendation?

Options:

A.  

built-in queries

B.  

livestream

C.  

notebooks

D.  

bookmarks

Discussion 0
Questions 56

You need to create a query to investigate DNS-related activity. The solution must meet the Microsoft Sentinel requirements. How should you complete the Query? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 57

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains a Windows device named Device1.

Twenty files on Device1 are quarantined by custom indicators as part of an investigation.

You need to release the 20 files from quarantine.

How should you complete the command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 58

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. You need to create a detection rule that meets the following requirements:

• Is triggered when a device that has critical software vulnerabilities was active during the last hour

• Limits the number of duplicate results

How should you complete the KQL query? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0