SC-200 sample questions with answers

10 free practice questions for the Microsoft Certified: Security Operations Analyst Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Manage a security operations environment

Relecloud connects Microsoft Defender XDR to Microsoft Sentinel. An automation rule whose only condition is that the analytics rule name contains the word phishing tags and assigns incidents correctly for incidents that Microsoft Sentinel creates, but never runs for the phishing incidents that arrive from Microsoft Defender XDR. Why?

  1. A.

    Incidents synchronized from Microsoft Defender XDR are not created by a Microsoft Sentinel analytics rule, so the condition never matches

  2. B.

    The Microsoft Defender XDR connector synchronizes incidents only once every 24 hours, so the automation rule expires before those incidents reach the workspace

  3. C.

    Automation rules cannot act on incidents that were created in Microsoft Defender XDR, so a playbook triggered by the Microsoft Defender XDR connector is required instead

  4. D.

    Automation rules that contain an Assign owner action are skipped for incidents whose owner field was already populated by the originating security product

Show answer

Answer: A

An incident that came from Microsoft Defender XDR has no Microsoft Sentinel analytics rule name, so a condition written on that property can never be satisfied.

  • A. Synchronized Defender XDR incidents have no Sentinel analytics rule name, so that condition can never match.
  • B. Incident synchronization is near real time, not a daily batch.
  • C. Automation rules do apply to synchronized Defender XDR incidents; the limitation is invented.
  • D. No skip behaviour exists for incidents that already have an owner; the action would simply overwrite it.
Question 2Manage a security operations environment

Contoso Pharmaceuticals deploys a web content filtering policy that blocks two categories and assigns it to all device groups. The web protection reports show browsing activity for the blocked categories, but users are never prevented from opening the sites. Which setting explains the behaviour?

  1. A.

    Microsoft Defender Antivirus is running in passive mode because a third-party antivirus product owns real-time protection on the affected devices

  2. B.

    Network protection is enabled in audit mode on the devices

  3. C.

    The web content filtering policy was assigned to device groups that do not contain the affected devices, so the policy is reporting on them but not enforcing on them

  4. D.

    Tamper protection is turned off, which allows a local administrator to disable the web protection component on the device

Show answer

Answer: B

Web content filtering is enforced by network protection, and network protection in audit mode reports what it would have blocked without blocking anything.

  • A. Passive antivirus does not disable network protection, which is a separate enforcement component.
  • B. Audit mode reports what would have been blocked without blocking, matching the reported symptom exactly.
  • C. Devices outside the assignment would report nothing for the policy rather than report without blocking.
  • D. Tamper protection being off does not by itself disable web protection on every device in the estate.
Question 3Manage a security operations environment

During a confirmed business email compromise incident at Blue Yonder Airlines, automatic attack disruption disabled two of the three accounts the attacker was using. The third account was not acted on, although the same incident lists it as compromised. The SOC must explain why. What is the most likely cause?

  1. A.

    Attack disruption acts on at most two entities in a single incident and defers any remaining entities to the analysts who own the case

  2. B.

    The third account signed in from a device that is not onboarded to Microsoft Defender for Endpoint, so no automated identity action can be taken for it in any circumstances

  3. C.

    The third account is in the automated response exclusion list for attack disruption

  4. D.

    The incident severity was lowered to Medium by an automation rule before the disruption engine evaluated the third account and its related sign-in evidence

Show answer

Answer: C

An account on the automated response exclusion list is deliberately skipped by automatic attack disruption, which is exactly the symptom of two accounts acted on and one not.

  • A. No limit of two entities per incident exists; the constraint is invented.
  • B. Disabling a user is an identity operation and does not depend on the user having used an onboarded device.
  • C. Excluded identities are deliberately skipped by automated action while still appearing in the incident.
  • D. Disruption is driven by high-confidence attack signals, not by the incident severity value.
Question 4Manage a security operations environment

A playbook at Woodgrove Bank must disable a user account in Microsoft Entra ID during an incident. Security policy forbids storing any credential or secret in the workflow or in a connection, and the permissions granted must be auditable and limited to what the playbook needs. How should the playbook authenticate?

  1. A.

    Use a system-assigned managed identity on the workflow and grant that identity the directory role it needs

  2. B.

    Create a connection that signs in with a dedicated service account, store the account password in the connection, and exclude the account from multifactor authentication so that unattended runs succeed

  3. C.

    Register an application in Microsoft Entra ID, create a client secret, store the secret in the workflow parameters, and rotate the secret on a quarterly schedule

  4. D.

    Use the connection created by the analyst who builds the playbook, so that the workflow runs with that analyst's own delegated permissions

Show answer

Answer: A

A managed identity gives the workflow an identity in Microsoft Entra ID with no credential to store, and the directory role assigned to it is visible and auditable.

  • A. A managed identity stores no secret and receives an explicit, auditable role assignment.
  • B. It stores a password in the connection and creates a privileged account exempt from multifactor authentication.
  • C. A client secret is still a stored credential requiring rotation, which the policy forbids.
  • D. Running as the builder inherits their full permissions, breaks when they leave, and destroys the audit trail.
Question 5Manage a security operations environment

A regional team at Litware, Inc. must investigate alerts only for the devices in the EMEA device group, and must see nothing about devices in other groups. The team members are already in a Microsoft Entra ID group named SOC-EMEA. Which two actions should you perform? (Choose TWO.)

Choose 2.

  1. A.

    Assign the role to the EMEA device group so that its holders are scoped to those devices

  2. B.

    Add SOC-EMEA to the Security Reader role in Microsoft Entra ID so that the team inherits read access to every workload in the Microsoft Defender portal

  3. C.

    Turn off the Show user details advanced feature so that user information from other regions is hidden from the team

  4. D.

    Create a device tag named EMEA and apply it to the team members' own user accounts so that their visibility follows the tag

  5. E.

    Create a role that grants the alert investigation permissions the team needs and assign SOC-EMEA to it

Show answer

Answer: A, E

Scoped access needs both halves: a role that says what the team may do, and an assignment of that role to the device group that says where.

  • A. Associating the role with the EMEA device group is what limits its holders to those devices.
  • B. Security Reader grants broad tenant-wide read access, defeating the separation requirement.
  • C. Show user details is a display setting for everyone and provides no access boundary.
  • D. Tags apply to devices, not to user accounts, and do not control visibility.
  • E. The role carries the permissions and is assigned to the existing Microsoft Entra ID group.
Question 6Manage a security operations environment

Contoso Ltd. must stop devices that Microsoft Defender for Endpoint rates as high risk from reaching company data until the risk is cleared. Devices are managed by Microsoft Intune, and conditional access already requires a compliant device. Which two actions should you perform? (Choose TWO.)

Choose 2.

  1. A.

    Configure a Microsoft Intune device compliance policy that marks a device non-compliant at the chosen Microsoft Defender for Endpoint machine risk level

  2. B.

    Create a custom network indicator for the corporate application URLs with the response action set to Block and remediate

  3. C.

    Turn on the Microsoft Defender for Cloud Apps integration in Microsoft Defender for Endpoint advanced features

  4. D.

    Turn on the Microsoft Intune connection in Microsoft Defender for Endpoint advanced features

  5. E.

    Set the automation level of the device group that contains the devices to Full - remediate threats automatically

Show answer

Answer: A, D

The Intune connection shares the device risk score with Intune, and a compliance policy that reacts to that score is what turns risk into a conditional access decision.

  • A. A compliance policy keyed to the machine risk level converts risk into non-compliance, which conditional access enforces.
  • B. A network indicator would block the applications on every device, not only on risky ones.
  • C. The Cloud Apps integration feeds shadow IT reporting and carries no compliance signal.
  • D. The Intune connection is the switch that shares the Defender for Endpoint device risk score with Intune.
  • E. A higher automation level speeds remediation but never gates access while a device is risky.
Question 7Manage a security operations environment

A payroll application at Blue Yonder Airlines posts records to the Logs ingestion API. The custom table, the data collection endpoint and the data collection rule all exist, and the application obtains a Microsoft Entra token successfully, but every call is rejected as unauthorized. What should you do?

  1. A.

    Assign the Monitoring Metrics Publisher role on the data collection rule to the application's service principal

  2. B.

    Regenerate the primary key of the Log Analytics workspace and update the application's configuration with the new value

  3. C.

    Assign the Log Analytics Reader role on the workspace to the application's service principal

  4. D.

    Add the data collection endpoint's public IP address to the workspace firewall allow list so that ingestion calls are accepted

Show answer

Answer: A

A valid token proves authentication; the Logs ingestion API additionally requires the caller to hold Monitoring Metrics Publisher on the data collection rule it posts to.

  • A. Publishing to the Logs ingestion API requires Monitoring Metrics Publisher on the data collection rule the caller posts to.
  • B. The Logs ingestion API authenticates with Microsoft Entra tokens, so workspace shared keys are not involved.
  • C. Log Analytics Reader grants query access to the workspace and confers no right to submit data.
  • D. The application calls the endpoint, and a network block would surface as a connection failure, not an authorization error.
Question 8Manage a security operations environment

After an incident at VanArsdel, Ltd. the SOC must be able to answer two questions from Microsoft Sentinel data: which identity read a specific secret from a key vault, and which identity deleted the key vault resource. Which two configurations are required? (Choose TWO.)

Choose 2.

  1. A.

    Collection of the subscription's Azure activity log into the workspace

  2. B.

    A diagnostic setting on the Microsoft Sentinel workspace that exports its own query logs

  3. C.

    Microsoft Defender for Key Vault enabled on the subscription so that its alerts stream to the workspace

  4. D.

    A data collection rule that collects the Security event log from the virtual machines that use the key vault

  5. E.

    A diagnostic setting on the key vault that sends the audit event category to the workspace

Show answer

Answer: A, E

Reading a secret is a data-plane operation captured by the key vault's own audit resource log; deleting the key vault is a control-plane operation captured by the Azure activity log.

  • A. Deleting the key vault is a control-plane operation recorded in the subscription activity log.
  • B. Workspace query logs record analyst query activity, which is unrelated to key vault operations.
  • C. Defender for Key Vault produces alerts about anomalous access, not the full audit trail of secret reads.
  • D. Windows security events describe logons on virtual machines and contain no key vault access records.
  • E. Reading a secret is a data-plane operation recorded only in the key vault's audit resource log, which a diagnostic setting collects.
Question 9Manage a security operations environment

A custom detection rule at Trey Research runs every 24 hours and has produced no alerts in a week. Running the same query manually in advanced hunting returns rows, but all of them are older than 30 days. The rule is enabled and its query is unchanged. What is the cause?

  1. A.

    Advanced hunting retains 30 days of data, so the rule deletes matches that fall outside that period

  2. B.

    A custom detection rule cannot alert on rows that the analyst has already seen in an advanced hunting session

  3. C.

    The rule evaluates only the data within the lookback window tied to its frequency, and every matching row is older than that window

  4. D.

    The rule was created without the Timestamp and ReportId columns, so it silently skips every matching row

Show answer

Answer: C

Each frequency carries a lookback window, and matches that fall outside it are never considered, so a rule can be perfectly valid and still never fire.

  • A. Retention governs what a query can see, and a detection rule never deletes data.
  • B. Hunting sessions and detection rules are independent; viewing a row in hunting has no effect on alerting.
  • C. Each frequency has a bounded lookback, and matches outside it are never evaluated however valid the query is.
  • D. A query without those columns is rejected when the rule is created rather than silently skipping rows.
Question 10Manage a security operations environment

Litware, Inc. uses both Microsoft Defender XDR and Microsoft Sentinel. A new detection reads only Defender device tables and must automatically isolate the device it identifies, with the smallest number of moving parts. Where should the detection be built?

  1. A.

    As a scheduled analytics rule in Microsoft Sentinel, with a playbook that calls the Defender API to isolate the device

  2. B.

    As a custom detection rule in Microsoft Defender XDR, with the isolate device response action selected on the rule

  3. C.

    As a near-real-time analytics rule in Microsoft Sentinel, with an automation rule that assigns the incident to a responder

  4. D.

    As a Microsoft security rule in Microsoft Sentinel, filtered to the device alerts raised by Defender for Endpoint

Show answer

Answer: B

The data and the response action both live in Microsoft Defender XDR, so a custom detection rule detects and isolates in one object with nothing else to build or maintain.

  • A. This works but needs streamed tables, a rule, a playbook and a permissioned identity where one object would do.
  • B. The tables and the isolation action are both native to Defender XDR, so one rule detects and contains.
  • C. Assigning an owner routes the incident to a person and does not isolate the device.
  • D. A Microsoft security rule consumes existing Defender alerts and cannot express a new query or take an action.

Keep going with 530 more SC-200 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

SC-200 sample questions with answers (10 free) · CertifyCloudx