DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft SC-200 Practice Questions & Answers 2026 Part1 | Microsoft Security Operations Analyst

Are you preparing for the Microsoft SC-200 certification exam? SPOTO offers the Microsoft SC-200 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have a Microsoft 365 E5 subscription that uses Microsoft SharePoint Online.You delete users from the subscription.You need to be notified if the deleted users downloaded numerous documents from SharePoint Online sites during the month before their accounts were deleted.What should you use?
A. file policy in Microsoft Defender for Cloud Apps
B. n access review policy
C. n alert policy in Microsoft Defender for Office 365
D. n insider risk policy
View answer
Correct Answer: C

View The Updated SC-200 Exam Questions

SPOTO Provides 100% Real SC-200 Exam Questions for You to Pass Your SC-200 Exam!

Question #2
Your company uses Microsoft Defender XDR. You need to use Microsoft Defender XDR deception rules to detect attacks as early as possible. What Microsoft Defender XDR service should you use to create the deception rules?
A. Microsoft Defender for Cloud Apps
B. Microsoft Defender for Endpoint
C. Microsoft Defender for Identity
D. Microsoft Defender for Office 365
View answer
Correct Answer: B
Question #3
Note: This section contains one or more sets of questions with the same scenario and problem. Eachquestion presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You enable automated investigation and response (AIR). Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #4
You have a Microsoft 365 E5 subscription that contains 100 Windows 10 devices. You onboard the devices to Microsoft Defender 365.You need to ensure that you can initiate remote shell connections to the onboarded devices from the Microsoft 365 Defender portal.What should you do first?
A. Modify the permissions for Microsoft 365 Defender
B. Create a device group
C. From Advanced features in the Endpoints settings of the Microsoft 365 Defender portal, enable automated investigation
D. Configure role-based access control (RBAC)
View answer
Correct Answer: D
Question #5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are configuring Microsoft Defender for Identity integration with Active Directory.From the Microsoft Defender portal, you need to configure several accounts for attackers to exploit. Solution: You add each account as a Sensitive account.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #6
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are configuring Microsoft Defender for Identity integration with Active Directory.From the Microsoft Defender portal, you need to configure several accounts for attackers to exploit. Solution: From Microsoft Entra ID Protection, you configure the sign-in risk policy.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #7
You have a Microsoft 365 subscription that uses Microsoft 365 Defender.A remediation action for an automated investigation quarantines a file across multiple devices. You need to mark the file as safe and remove the file from quarantine on the devices.What should you use in the Microsoft 365 Defender portal?
A. From the History tab in the Action center, revert the actions
B. From the investigation page, review the AIR processes
C. From Quarantine from the Review page, modify the rules
D. From Threat tracker, review the queries
View answer
Correct Answer: A
Question #8
You need to configure Microsoft Defender for Cloud Apps to generate alerts and trigger remediation actions in response to external sharing of confidential files.Which two actions should you perform in the Microsoft Defender portal? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. From Settings, select Cloud Apps, select Microsoft Information Protection, and then select Only scan files for Microsoft Information Protection sensitivity labels and content inspection warnings from this tenant
B. From Cloud apps, select Files, and then filter File Type to Document
C. From Settings, select Cloud Apps, select Microsoft Information Protection, select Files, and then enable file monitoring
D. From Cloud apps, select Files, and then filter App to Microsoft 365
E. From Cloud apps, select Files, and then select New policy from search
F. From Settings, select Cloud Apps, select Microsoft Information Protection, and then select Automatically scan new files for Microsoft Information Protection sensitivity labels and content inspection warnings
View answer
Correct Answer: CF
Question #9
What are two 1 Gb iSCSI best practices to set up and-to-end connectivity (servers, switch,and storage)? (Choose two.)
A. Flow Control
B. Jumbo Frame
C. Spanning Tree
D. Unicast Storm Control
View answer
Correct Answer: BC
Question #10
You have a Microsoft 365 E5 subscription that contains a database server named DB1. DB1 is onboarded to Microsoft Defender XDR.You need to ensure that DB1 appears on the attack surface map.What should you configure?
A. sensitive entity tag
B. critical asset rule
C. n asset rule
D. honeytoken entity tag
View answer
Correct Answer: B
Question #11
You need to configure event monitoring for Server1. The solution must meet the Microsoft Sentinel requirements. What should you create first?
A. a Microsoft Sentinel automation rule
B. a Microsoft Sentinel scheduled query rule
C. a Data Collection Rule (DCR)
D. an Azure Event Grid topic
View answer
Correct Answer: C
Question #12
Which rule setting should you configure to meet the Microsoft Sentinel requirements?
A. AFrom Set rule logic, turn off suppression
B. BFrom Analytic rule details, configure the tactics
C. CFrom Set rule logic, map the entities
D. DFrom Analytic rule details, configure the severity
View answer
Correct Answer: C
Question #13
You need to modify the anomaly detection policy settings to meet the Microsoft Defender for Cloud Apps requirements and resolve the reported problem.Which policy should you modify?
A. Activity from suspicious IP addresses
B. Activity from anonymous IP addresses
C. Impossible travel
D. Risky sign-in
View answer
Correct Answer: C
Question #14
You have an Azure subscription that uses Microsoft Defender for Endpoint. You need to ensure that you can allow or block a user-specified range of IP addresses and URLs. What should you enable first in the advanced features from the Endpoints Settings in the Microsoft 365 Defender portal?
A. Aendpoint detection and response (EDR) in block mode
B. Bcustom network indicators
C. Cweb content filtering
D. DLive response for servers
View answer
Correct Answer: B
Question #15
You have a hybrid environment that includes an on-premises Active Directory Domain Services (AD DS) domain, a Microsoft Entra tenant, and a Microsoft 365 E5 subscription. All Windows 11 devices are onboarded to Microsoft Defender for Endpoint. You deploy Microsoft Defender for Identity sensors to domain controllers. You need to enable automatic attack disruption in Microsoft Defender XDR. The solution must meet the following requirements: - During an active attack, affected devices must be contained automatically, and compromised user accounts must be disabled. - User disruptions must be minimized. What should you configure?
A. attack surface reduction (ASR) rules in Microsoft Defender for Endpoint
B. Advanced features in Microsoft Defender for Identity
C. device isolation in Microsoft Defender for Endpoint
D. indicators in Microsoft Defender for Endpoint
View answer
Correct Answer: B
Question #16
An engineer has installed an SC4020 with four FC ports in each controller. This is a dual-fabric installation with four FC connections in each server. The servers use the OS built-inmulti-pathing capabilities.Which two configurations will cause the controller failover to fail? (Choose two.)
A. Too many volumes are mapped to the server from one controller
B. The switch zoning is incorrectly configured
C. The server HBA timeouts are set incorrectly
D. The multi-pathing software is incorrectly configured
View answer
Correct Answer: BD
Question #17
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You need to implement deception rules. The solution must ensure that you can limit the scope of the rules. What should you create first?
A. device groups
B. device tags
C. honeytoken entity tags
D. sensitive entity tags
View answer
Correct Answer: B
Question #18
Case studyThis is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.To start the case study To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.OverviewAdatum Corporation is a United States-based financial services company that has regional offices in New York, Chicago, and San Francisco.Existing EnvironmentIdentity EnvironmentThe on-premises network contains an Active Directory Domain Services (AD DS) forest named corp.adatum.com that syncs with an Azure AD tenant named adatum.com. All user and group management tasks are performed in corp.adatum.com. The corp.adatum.com domain contains a group named Group1 that syncs with adatum.com.Licensing StatusAll the users at Adatum are assigned a Microsoft 365 ES license and an Azure Active Directory Premium P2 license.Cloud EnvironmentThe cloud environment contains a Microsoft 365 subscription, an Azure subscription linked to the adatum.com tenant, and the resources shown in the following table.On-premises EnvironmentThe on-premises network contains the resources shown in the following table.RequirementsPlanned changesAdatum plans to perform the following changes:Implement a query named rulequery1 that will include the following KQL query.Implement a Microsoft Sentinel scheduled rule that generates incidents based on rulequery1.Microsoft Defender for Cloud RequirementsAdatum identifies the following Microsoft Defender for Cloud requirements:The members of Group1 must be able to enable Defender for Cloud plans and apply regulatory compliance initiatives.Microsoft Defender for Servers Plan 2 must be enabled on all the Azure virtual machines.Server2 must be excluded from agentless scanning.Microsoft Sentinel RequirementsAdatum identifies the following Microsoft Sentinel requirements:Implement an Advanced Security Information Model (ASIM) query that will return a count of DNS requests that results in an NXDOMAIN response from Infoblox1.Ensure that multiple alerts generated by rulequery1 in response to a single user launching Azure Cloud Shell multiple times are consolidated as a single incident.Implement the Windows Security Events via AMA connector for Microsoft Sentinel and configure it to monitor the Security event log of Server1.Ensure that incidents generated by rulequery1 are closed automatically if Azure Cloud Shell is launched by the companys SecOps team.Implement a custom Microsoft Sentinel workbook named Workbook1 that will include a query to dynamically retrieve data from Webapp1.Implement a Microsoft Sentinel near-real-time (NRT) analytics rule that detects sign-ins to a designated break glass account.Ensure that HuntingQuery1 runs automatically when the Hunting page of Microsoft Sentinel in the Azure portal is accessed.Ensure that higher than normal volumes of password resets for corp.adatum.com user accounts are detected.Minimize the overhead associated with queries that use ASIM parsers.Ensure that the Group1 members can create and edit playbooks.Use built-in ASIM parsers whenever possible.Business RequirementsAdatum identifies the following business requirements:Follow the principle of least privilege whenever possible.Minimize administrative effort whenever possible.You need to ensure that the processing of incidents generated by rulequery1 meets the Microsoft Sentinel requirements.What should you create first?
A. playbook with an incident trigger
B. playbook with an alert trigger
C. n Azure Automation rule
D. playbook with an entity trigger
View answer
Correct Answer: B
Question #19
You have a Microsoft 365 E5 subscription that contains 100 Linux devices. The devices are onboarded to Microsoft Defender XDR.You need to initiate the collection of investigation packages from the devices by using the Microsoft Defenderportal.Which response action should you use?
A. Run antivirus scan
B. Initiate Automated Investigation
C. Collect investigation package
D. Initiate Live Response Session
View answer
Correct Answer: C
Question #20
According to the best practices, what are the correct values for the following parameters on a QLogic HBA?
A. onnection options:1 - point-to-point onlyLogin retry count:60 attemptsPort down retry count:60 attemptsLink down timeout:30 seconds
B. onnection options:1 - point-to-point onlyLogin retry count:30 attemptsPort down retry count:5attemptsLink down timeout:60 seconds
C. onnection options:0 - Loop onlyLoginretry count:60 attemptsPort down retry count:60 attemptsLink down timeout:30 seconds
D. onnection options:0 loop onlyLogin retry count:30 attemptsPort down retry count:30 attemptsLink down timeout:30 seconds
View answer
Correct Answer: B
Question #21
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. You need to add threat indicators for all the IP addresses in a range of 171.23.3432-171.2334.63. The solution must minimize administrative effort. What should you do in the Microsoft 365 Defender portal? This will add all the IP addresses in the range of 171.23.34.32/27 as threat indicators. This is the simplest and most efficient way to add all the IP addresses in the range.
A. Create an import file that contains the IP address of 171
B. Select Add indicator and set the IP address to 171
C. Select Add indicator and set the IP address to 171
D. Create an import file that contains the individual IP addresses in the range
View answer
Correct Answer: D
Question #22
An engineer needs to configure a VMware host. According to best practice, the engineer needs to enable a feature by changing the variables QFullSampleSize and QFullThreshold. The engineer sets those two parameters to the value of 0 in VMware ESXi 5.1 Patch 1 and later versions.Which feature is enabled?
A. daptive queue depth
B. nhanced Transmission Selection (ETS)
C. symmetric logical unit access (ALUA)
D. riority Flow Control (PFC)
View answer
Correct Answer: A
Question #23
An engineer receives an alert that the Storage Center has entered Conservation mode.How should the engineer respond to the alert?
A. gnore die alert - Conservation Mode can occur m normal conditions
B. heck the system m the morning - Conservation \lode is a slightly degraded condition with little risk
C. egin recovery operations - Conservation Mode means storage has gone offline
D. ix it immediately - Conservation Mode is a seriously degraded and risky condition but the system is still up
View answer
Correct Answer: D
Question #24
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You configure Controlled folder access. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #25
Your company has an on-premises network that uses Microsoft Defender for Identity.The Microsoft Secure Score for the company includes a security assessment associated with unsecure Kerberos delegation.You need remediate the security risk. What should you do?
A. Disable legacy protocols on the computers listed as exposed entities
B. Enforce LDAP signing on the computers listed as exposed entities
C. Modify the properties of the computer objects listed as exposed entities
D. Install the Windows Local Administrator Password Solution (Windows LAPS) extension on the computers listed as exposed entities
View answer
Correct Answer: C
Question #26
Your organization has a Microsoft 365 subscription and uses Microsoft Defender XDR and Microsoft Purview. You need to identify all the changes made to sensitivity labels during the past seven days.What should you use?
A. the Incidents blade of the Microsoft Defender portal
B. the Alerts settings on the Data Loss Prevention blade of the Microsoft Purview compliance portal
C. Activity explorer in the Microsoft Purview compliance portal
D. the Explorer settings on the Email & collaboration blade of the Microsoft Defender portal
View answer
Correct Answer: C
Question #27
You have a Microsoft 365 subscription that uses Microsoft 365 Defender. You plan to create a hunting query from Microsoft Defender.You need to create a custom tracked query that will be used to assess the threat status of the subscription. From the Microsoft 365 Defender portal, which page should you use to create the query?
A. Threat analytics
B. Advanced Hunting
C. Explorer
D. Policies & rules
View answer
Correct Answer: B
Question #28
During failover testing, an engineer finds that the iSCSI connection failed over properlywhen a physical link was disconnected. The FC connection did NOT failover when aphysical link was disconnected.Which configuration is causing this issue?
A. iSCSI is in legacy port mode, andFC is in virtual port mode
B. iSCSI is in virtual port mode, and FC is in virtual port mode
C. iSCSI is in legacy port mode, and FC is in legacy port mode
D. iSCSI is in virtual port mode, and FC is in legacy port mode
View answer
Correct Answer: A
Question #29
You receive a security bulletin about a potential attack that uses an image file.You need to create an indicator of compromise (IoC) in Microsoft Defender for Endpoint to prevent the attack. Which indicator type should you use?
A. a URL/domain indicator that has Action set to Alert only
B. a URL/domain indicator that has Action set to Alert and block
C. a file hash indicator that has Action set to Alert and block
D. a certificate indicator that has Action set to Alert and block
View answer
Correct Answer: C
Question #30
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You need to implement deception rules. The solution must ensure that you can limit the scope of the rules. What should you create first?
A. device groups
B. device tags
C. honeytoken entity tags
D. sensitive entity tags
View answer
Correct Answer: B
Question #31
You need to recommend a solution to meet the technical requirements for the Azure virtual machines. What should you include in the recommendation?
A. just - in - time (JIT) access
B. Azure Defender
C. Azure Firewall
D. Azure Application Gateway
View answer
Correct Answer: B
Question #32
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint.You need to create a query that will link the AlertInfo, AlertEvidence, and DeviceLogonEvents tables. The solution must return all the rows in the tables.Which operator should you use?
A. search *
B. union kind = inner
C. join kind = inner
D. evaluate hint
View answer
Correct Answer: B
Question #33
You are investigating a potential attack that deploys a new ransomware strain.You have three custom device groups. The groups contain devices that store highly sensitive information. You plan to perform automated actions on all devices.You need to be able to temporarily group the machines to perform actions on the devices. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. Assign a tag to the device group
B. Add the device users to the admin role
C. Add a tag to the machines
D. Create a new device group that has a rank of 1
E. Create a new admin role
F. Create a new device group that has a rank of 4
View answer
Correct Answer: ACD
Question #34
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are configuring Microsoft Defender for Identity integration with Active Directory.From the Microsoft Defender portal, you need to configure several accounts for attackers to exploit. Solution: You add the accounts to an Active Directory group and add the group as a Sensitive group. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #35
You have an Azure subscription that uses Microsoft Sentinel and contains 100 Linux virtual machines. You need to monitor the virtual machines by using Microsoft Sentinel. The solution must meet the fallowing requirements: * Minimize administrative effort * Minimize the parsing required to read log data What should you configure?
A. AREST API integration
B. Ba SysJog connector
C. Ca Log Analytics Data Collector API
D. Da Common Event Format (CEF) connector
View answer
Correct Answer: D
Question #36
Your company uses line-of-business apps that contain Microsoft Office VBA macros.You plan to enable protection against downloading and running additional payloads from the Office VBA macros as additional child processes.You need to identify which Office VBA macros might be affected.Which two commands can you run to achieve the goal? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. Option A
B. Option B
C. Option C
D. Option D
View answer
Correct Answer: BC

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us