2026 SC-200 Question Bank: Free PDF Download Recently Updated Questions
SC-200 Certification Exam Dumps with 390 Practice Test Questions
Microsoft SC-200 certification is a valuable asset for professionals who want to advance their career in the field of security operations. It is a globally recognized certification that demonstrates the candidate's competence and expertise in security operations. Microsoft Security Operations Analyst certification helps professionals stand out in the job market and opens up new career opportunities. It also helps organizations identify and hire the right candidates for their security operations team.
NEW QUESTION # 180
You have an Azure subscription that contains a user named User1 and a Microsoft Sentinel workspace named WS1.
You need to ensure that User1 can enable User and Entity Behavior Analytics (UEBA) for WS1. The solution must follow the principle of least privilege.
Which roles should you assign to User1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 181
You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC).
What should you use?
- A. Microsoft Cloud App Security
- B. Azure Monitor
- C. hunting queries in Azure Sentinel
- D. notebooks in Azure Sentinel
Answer: D
Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/sentinel/notebooks
NEW QUESTION # 182
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You have a custom detection rule named Rule1 that generates an alert if more than five antivirus detections are identified on a device. Rule1 has a loopback period of 12 hours.
You need to change the loopback period to 48 hours.
What should you modify for Rule1?
- A. the frequency
- B. the summarize operator of the KQL query
- C. the where operator of the KQL query
- D. the scope
Answer: A
Explanation:
XDR Custom Detection Rules Documentation):
In Microsoft Defender XDR, custom detection rules are scheduled KQL queries that evaluate telemetry on a recurring schedule, using a lookback (loopback) period to determine how much historical data to analyze during each run.
The loopback period determines the time window over which data is evaluated (e.g., 12 hours, 48 hours). To change this period, administrators modify the rule's schedule configuration - specifically the frequency or recurrence settings in the custom detection rule editor. The KQL query (including summarize or where operators) defines the logic but not the temporal scope of data evaluation.
Therefore, extending the loopback from 12 hours to 48 hours requires adjusting the frequency (schedule) configuration of the rule, not the query itself.
NEW QUESTION # 183
Hotspot Question
You have a Microsoft Sentinel workspace named SW1.
You plan to create a custom workbook that will include a time chart.
You need to create a query that will identify the number of security alerts per day for each provider.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/azure-sentinel-workbooks-101- with-sample-workbook/ba-p/1409216
NEW QUESTION # 184
You have an Azure subscription named Sub1 and a Microsoft 365 subscription. Sub1 is linked to an Azure Active Directory (Azure AD) tenant named contoso.com.
You create an Azure Sentinel workspace named workspace1. In workspace1, you activate an Azure AD connector for contoso.com and an Office 365 connector for the Microsoft 365 subscription.
You need to use the Fusion rule to detect multi-staged attacks that include suspicious sign-ins to contoso.com followed by anomalous Microsoft Office 365 activity.
Which two actions should you perform? Each correct answer present part of the solution NOTE: Each correct selection is worth one point.
- A. Create an Azure AD Identity Protection connector.
- B. Create custom rule based on the Office 365 connector templates.
- C. Create a Microsoft incident creation rule based on Microsoft Defender for Cloud.
- D. Create a Microsoft Cloud App Security connector.
Answer: A,D
Explanation:
To use the Fusion rule to detect multi-staged attacks that include suspicious sign-ins to contoso.com followed by anomalous Microsoft Office 365 activity, you should perform the following two actions:
* Create an Azure AD Identity Protection connector. This will allow you to monitor suspicious activities in your Azure AD tenant and detect malicious sign-ins.
* Create a custom rule based on the Office 365 connector templates. This will allow you to monitor and detect anomalous activities in the Microsoft 365 subscription. Reference: https://docs.microsoft.com/en- us/azure/sentinel/fusion-rules
NEW QUESTION # 185
You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1. WS1 has the Azure Activity connector and the Microsoft Entra ID connector configured.
You need to investigate which accounts have the most alerts and any corresponding incident information for each alert. The solution must minimize administrative effort What should you do first in WS1?
- A. Enable User and Entity Behavior Analytics (UEBA).
- B. Use User and Entity Behavior Analytics (UEBA) to detect anomalies.
- C. From Content hub, install the Microsoft Purview insider risk management solution.
- D. From Content hub, install Cloud Identity Threat Protection Essentials.
Answer: A
NEW QUESTION # 186
You have an Azure subscription that has Azure Defender enabled for all supported resource types.
You create an Azure logic app named LA1.
You plan to use LA1 to automatically remediate security risks detected in Azure Security Center.
View the window
You need to test LA1 in Security Center.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/security-center/workflow-automation#create-a-logic-app-and-define- when-it-should-automatically-run
NEW QUESTION # 187
You have an Azure subscription that uses Microsoft Defender for Cloud.
You need to create a workflow that will send a Microsoft Teams message to the IT department of your company when a new Microsoft Secure Score action is generated.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
NEW QUESTION # 188
Hotspot Question
You have an Azure subscription that contains a guest user named User1 and a Microsoft Sentinel workspace named workspace1.
You need to ensure that User1 can triage Microsoft Sentinel incidents in workspace1. The solution must use the principle of least privilege.
Which roles should you assign to User1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 189
You need to ensure that the Group1 members can meet the Microsoft Sentinel requirements.
Which role should you assign to Group1?
- A. Logic App Contributor
- B. Automation Operator
- C. Microsoft Sentinel Playbook Operator
- D. Microsoft Sentinel Automation Contributor
Answer: D
Explanation:
The case study requires:
"Ensure that the Group1 members can create and edit playbooks."
In Microsoft Sentinel, the ability to create, edit, and assign playbooks is granted by the Microsoft Sentinel Automation Contributor role.
This role allows users to:
* Create and manage automation rules,
* Create and edit playbooks (Logic Apps) in the connected subscription,
* Associate playbooks with Sentinel incidents or alerts.
By contrast:
* Logic App Contributor allows Logic App creation but doesn't include Sentinel-level integration permissions.
* Automation Operator can run playbooks but not edit or create them.
* Sentinel Playbook Operator can execute playbooks but cannot modify or assign them.
# Answer for Question 11: A. Microsoft Sentinel Automation Contributor
NEW QUESTION # 190
You have 500 on-premises devices.
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You onboard 100 devices to Microsoft Defender XDR.
You need to identify any unmanaged on-premises devices. The solution must ensure that only specific onboarded devices perform the discovery.
What should you do first?
- A. Create a tag.
- B. Create a device group.
- C. Create an exclusion.
- D. Set Discovery mode to Basic
Answer: B
Explanation:
Microsoft Defender XDR includes device discovery, which can identify unmanaged devices on the same network. When performing on-premises device discovery, only selected onboarded devices act as discovery sensors. To limit which devices perform discovery, you use device groups to scope the discovery sensors.
From Microsoft's Defender for Endpoint documentation:
"You can limit network discovery to specific onboarded devices by assigning those devices to a device group and enabling discovery only for that group." The other options are incorrect because:
* A. Set Discovery mode to Basic - Defines how discovery works, not which devices perform it.
* C. Create a tag - Useful for classification, not for discovery scoping.
* D. Create an exclusion - Excludes IP ranges or devices from scanning, not the discovery role itself.
# Final answer: B. Create a device group
NEW QUESTION # 191
Your company uses line-of-business apps that contain Microsoft Office VBA macros.
You plan to enable protection against downloading and running additional payloads from the Office VBA macros as additional child processes.
You need to identify which Office VBA macros might be affected.
Which two commands can you run to achieve the goal?Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
- A.

- B.

- C.

- D.

Answer: A,B
Explanation:
Must use Set-MpPreference with Enabled and then Add-MpPreference with Enabled. Audit does not block.
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-attack-surface- reduction?view=o365-worldwide#powershell
NEW QUESTION # 192
You need to identify which mean time metrics to use to meet the Microsoft Sentinel requirements. Which workbook should you use?
- A. Analytics Efficiency
- B. Security Operations Efficiency
- C. Investigation insights
- D. Event Analyzer
Answer: B
Explanation:
Microsoft Sentinel provides built-in workbooks for operational insights. To analyze mean time metrics (Mean Time to Acknowledge, Mean Time to Resolve, Mean Time to Mitigate), the correct workbook is Security Operations Efficiency.
According to Microsoft's Sentinel documentation:
"The Security Operations Efficiency workbook helps SOC teams monitor and improve operational performance by showing incident trends and key performance indicators such as mean time to acknowledge (MTTA), mean time to resolve (MTTR), and incident closure rates." Other options:
* Analytics Efficiency - tracks analytic rule performance.
* Event Analyzer - provides event data analysis, not MTTA/MTTR.
* Investigation Insights - focuses on incident investigation details, not SOC metrics.
# Correct workbook: Security Operations Efficiency
NEW QUESTION # 193
You are informed of an increase in malicious email being received by users.
You need to create an advanced hunting query in Microsoft 365 Defender to identify whether the accounts of the email recipients were compromised. The query must return the most recent 20 sign-ins performed by the recipients within an hour of receiving the known malicious email.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-emails-devices?view=
NEW QUESTION # 194
You have a Microsoft subscription that has Microsoft Defender for Cloud enabled You configure the Azure logic apps shown in the following table.
You need to configure an automatic action that will run if a Suspicious process executed alert is triggered. The solution must minimize administrative effort.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - Configure teh Trigger automated respnse settings.
2 - Filter by alert title.
3 - Select Take Action
NEW QUESTION # 195
You have a Microsoft 365 E5 subscription that contains 200 Windows 10 devices enrolled in Microsoft Defender for Endpoint.
You need to ensure that users can access the devices by using a remote shell connection directly from the Microsoft 365 Defender portal. The solution must use the principle of least privilege.
What should you do in the Microsoft 365 Defender portal? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: Turn on Live Response
Live response is a capability that gives you instantaneous access to a device by using a remote shell connection. This gives you the power to do in-depth investigative work and take immediate response actions.
Box: 2 : Add a network assessment job
Network assessment jobs allow you to choose network devices to be scanned regularly and added to the device inventory.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-machine-alerts?
view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-devices?view=o365- worldwide
NEW QUESTION # 196
You have a Microsoft Sentinel workspace named Workspace1 and 200 custom Advanced Security Information Model (ASIM) parsers based on the DNS schema. You need to make the 200 parsers available in Workspace1. The solution must minimize administrative effort. What should you do first?
- A. Create a YAML file based on the DNS template.
- B. Create a JSON file based on the DNS template.
- C. Create an XML file based on the DNS template.
- D. Copy the parsers to the Azure Monitor Logs page.
Answer: A
Explanation:
ASIM parsers in Microsoft Sentinel are stored and deployed as YAML-based content files following ASIM schema templates (e.g., DNS, NetworkSession, etc.).
When you have multiple custom parsers (200 in this case), the most efficient way to manage and deploy them is to create a YAML file that defines all parser configurations and then import it into the Sentinel workspace.
YAML is the supported format for ASIM parser templates in Sentinel's content hub and GitHub deployment model.
Hence, the correct first step is to create a YAML file based on the DNS schema template.
NEW QUESTION # 197
You have a Microsoft Sentinel workspace
You develop a custom Advanced Security information Model (ASIM) parser named Parser1 that produces a schema named Schema1.
You need to validate Schema1.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 198
You have a Microsoft 365 E5 subscription that contains a device named Device 1. Device 1 is enrolled in Microsoft Defender for End point.
Device1 reports an incident that includes a file named File1 exe as evidence.
You initiate the Collect Investigation Package action and download the ZIP file.
You need to identify the first and last time File1.exe was executed.
What should you review in the investigation package?
- A. Scheduled tasks
- B. Autoruns
- C. Prefetch files
- D. Processes
- E. Security event log
Answer: C
Explanation:
When you initiate the Collect Investigation Package action on a device in Microsoft Defender for Endpoint, the package includes many forensic artifacts that help you trace file usage, process execution, and system behavior. Among those artifacts are prefetch files. Prefetch files record metadata about which executables were run and when, and can provide first/last execution timestamps. Whizlabs+2InfoSec Write-ups+2 Specifically, Microsoft documents (e.g. Respond-machine alerts) describe that the investigation package contains folders such as Autoruns, Processes, Scheduled tasks, Security event log, Users and Groups, Prefetch files, among others. InfoSec Write-ups+2Whizlabs+2 Among those, the Prefetch files are the best source to determine the first and last run time of a given executable (like File1.exe). Other artifacts (process history, event logs) might also show execution events, but prefetch is the artifact designed for showing executable run metadata and is most commonly used for that purpose in forensic investigations. InfoSec Write-ups+2ExamTopics+2 Because the question specifically asks "first and last time File1.exe was executed," reviewing Prefetch files in the investigation package is the correct approach.
NEW QUESTION # 199
You have a Microsoft 365 E5 subscription.
Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for Endpoint.
You have an incident involving a user that received maIware-infected email messages on a managed device.
Which action requires manual remediation of the incident?
- A. isolating the device
- B. hard deleting the email message
- C. soft deleting the email message
- D. containing the device
Answer: A
NEW QUESTION # 200
......
New SC-200 Exam Dumps with High Passing Rate: https://pass4sure.dumpstests.com/SC-200-latest-test-dumps.html