Free SC-200 sample questions
Real questions from the Security Operations Analyst practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 20 of 40 free sample questions.
During a threat hunt, a security analyst discovers a suspicious PowerShell command line executed on several machines. The analyst wants to save the KQL query and its results, add contextual notes about the findings, and map the activity to a MITRE ATT&CK technique. Which Microsoft Sentinel feature is designed for this purpose?
A company wants to prevent users from accidentally sharing documents containing credit card numbers via Microsoft Teams. The security team creates a Microsoft Purview Data Loss Prevention (DLP) policy. An employee attempts to share a text file with 20 credit card numbers in a Teams chat. What is the expected outcome?
An organization has configured Microsoft Defender for Office 365. An analyst is reviewing the Threat protection status report and notices a large spike in emails categorized as 'ZAP'. What does this indicate?
A security analyst needs to create a KQL query that joins email attachment information with device file creation events to trace a malicious attachment from receipt to execution. The tables to be used are `EmailAttachmentInfo` and `DeviceFileEvents`. The join must be based on the file's SHA256 hash. Complete the following KQL query by selecting the correct operator. `EmailAttachmentInfo` `| where isnotempty(SHA256)` `| _____ (DeviceFileEvents) on SHA256`
A new SOC analyst is learning about the different roles within Microsoft Sentinel. A senior analyst needs to be able to manage incidents, run playbooks, and dismiss false positives, but should NOT be able to modify analytics rules, data connectors, or workspace settings. Which built-in Azure role is most appropriate to assign to the senior analyst at the resource group level where Sentinel resides?
An organization is concerned about credential theft from LSASS memory on their servers. The security team wants to use Microsoft Defender for Endpoint to block this type of attack. Which security feature should they configure?
A security analyst is writing a KQL query in Microsoft Sentinel to summarize the number of alerts generated by each analytics rule in the last 24 hours. The query should display two columns: the rule name and the count of alerts. Which query is correctly written? pie title Alert Distribution by Rule "Brute Force Attempt": 45 "Malicious IP Login": 25 "Impossible Travel": 15 "Anomalous Download": 15
20 more free samples are waiting
Create a free account to unlock the whole SC-200 sample bank, or get full access to all 297 practice questions in the simulator.