DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft SC-200 Practice Questions & Answers 2026 Part2 | Microsoft Security Operations Analyst

Are you preparing for the Microsoft SC-200 certification exam? SPOTO offers the Microsoft SC-200 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You configure Controlled folder access. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B

View The Updated SC-200 Exam Questions

SPOTO Provides 100% Real SC-200 Exam Questions for You to Pass Your SC-200 Exam!

Question #2
Note: This section contains one or more sets of questions with the same scenario and problem. Eachquestion presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You enable automated investigation and response (AIR). Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #3
Case studyThis is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.To start the case study To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.OverviewFabrikam, Inc. is a financial services company.The company has branch offices in New York, London, and Singapore. Fabrikam has remote users located across the globe. The remote users access company resources, including cloud resources, by using a VPN connection to a branch office.Existing EnvironmentIdentity EnvironmentThe network contains an Active Directory Domain Services (AD DS) forest named fabrikam.com that syncs with an Azure AD tenant named fabrikam.com. To sync the forest, Fabrikam uses Azure AD Connect with pass-through authentication enabled and password hash synchronization disabled.The fabrikam.com forest contains two global groups named Group1 and Group2.Microsoft 365 EnvironmentAll the users at Fabrikam are assigned a Microsoft 365 E5 license and an Azure Active Directory Premium Plan 2 license.Fabrikam implements Microsoft Defender for Identity and Microsoft Defender for Cloud Apps and enables log collectors.Azure EnvironmentFabrikam has an Azure subscription that contains the resources shown in the following table.Amazon Web Services (AWS) EnvironmentFabrikam has an Amazon Web Services (AWS) account named Account1. Account1 contains 100 Amazon Elastic Compute Cloud (EC2) instances that run a custom Windows Server 2022. The image includes Microsoft SQL Server 2019 and does NOT have any agents installed.Current IssuesWhen the users use the VPN connections, Microsoft 365 Defender raises a high volume of impossible travel alerts that are false positives.Defender for Identity raises a high volume of Suspected DCSync attack alerts that are false positives.RequirementsPlanned changesFabrikam plans to implement the following services:Microsoft Defender for CloudMicrosoft SentinelBusiness RequirementsFabrikam identifies the following business requirements:Use the principle of least privilege, whenever possible.Minimize administrative effort.Microsoft Defender for Cloud Apps RequirementsFabrikam identifies the following Microsoft Defender for Cloud Apps requirements:Ensure that impossible travel alert policies are based on the previous activities of each user.Reduce the amount of impossible travel alerts that are false positives.Microsoft Defender for Identity RequirementsMinimize the administrative effort required to investigate the false positive alerts.Microsoft Defender for Cloud RequirementsFabrikam identifies the following Microsoft Defender for Cloud requirements:Ensure that the members of Group2 can modify security policies.Ensure that the members of Group1 can assign regulatory compliance policy initiatives at the Azure subscription level.Automate the deployment of the Azure Connected Machine agent for Azure Arc-enabled servers to the existing and future resources of Account1.Minimize the administrative effort required to investigate the false positive alerts.Microsoft Sentinel RequirementsFabrikam identifies the following Microsoft Sentinel requirements:Query for NXDOMAIN DNS requests from the last seven days by using built-in Advanced Security Information Model (ASIM) unifying parsers.From AWS EC2 instances, collect Windows Security event log entries that include local group membership changes.Identify anomalous activities of Azure AD users by using User and Entity Behavior Analytics (UEBA).Evaluate the potential impact of compromised Azure AD user credentials by using UEBA.Ensure that App1 is available for use in Microsoft Sentinel automation rules.Identify the mean time to triage for incidents generated during the last 30 days.Identify the mean time to close incidents generated during the last 30 days.Ensure that the members of Group1 can create and run playbooks.Ensure that the members of Group1 can manage analytics rules.Run hunting queries on Pool1 by using Jupyter notebooks.Ensure that the members of Group2 can manage incidents.Maximize the performance of data queries.Minimize the amount of collected data.You need to identify which mean time metrics to use to meet the Microsoft Sentinel requirements.Which workbook should you use?
A. vent Analyzer
B. nvestigation Insights
C. ecurity Operations Efficiency
D. nalytics Efficiency
View answer
Correct Answer: C
Question #4
Note: This section contains one or more sets of questions with the same scenario and problem. Eachquestion presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You enable automated investigation and response (AIR). Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #5
Note: This section contains one or more sets of questions with the same scenario and problem. Eachquestion presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.You have a Microsoft 365 subscription.You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.You need to ensure that the devices are protected from malicious artifacts that were undetected by the third- party antivirus product.Solution: You enable automated investigation and response (AIR). Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #6
You need to modify the anomaly detection policy settings to meet the Cloud App Security requirements. Which policy should you modify?
A. Activity from suspicious IP addresses
B. Activity from anonymous IP addresses
C. Impossible travel
D. Risky sign-in
View answer
Correct Answer: C
Question #7
An engineer has mapped a volume to an existing Windows 2012 server. The engineer has configured zoning and confirmed that all paths are correctly configured.The operating system can only see one path within the MPIO software.Which step should the engineer take so that all paths are presented to the server?
A. ownload and install the MPIO Manager
B. un the command mpclaim
C. hange the Multipath IO (MPIO) policy to Round Robin within MPIO Manager
D. hange the operating system to Windows 2012 Pro MPIO within the server properties on Storage Center
View answer
Correct Answer: B
Question #8
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.You need to ensure that you can investigate threats by using data in the unified audit log of Microsoft Defender for Cloud Apps.What should you configure first?
A. the User enrichment settings
B. the Azure connector
C. the Microsoft 365 connector
D. the Automatic log upload settings
View answer
Correct Answer: C
Question #9
You need to configure Microsoft Defender for Cloud Apps to generate alerts and trigger remediation actions in response to external sharing of confidential files.Which two actions should you perform in the Microsoft Defender for Cloud Apps portal? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. From Settings, select Information Protection, select Azure Information Protection, and then select Only scan files for Azure Information Protection classification labels and content inspection warnings from this tenant
B. Select Investigate files, and then filter App to Office 365
C. Select Investigate files, and then select New policy from search
D. From Settings, select Information Protection, select Azure Information Protection, and then select Automatically scan new files for Azure Information Protection classification labels and content inspection warnings
E. From Settings, select Information Protection, select Files, and then enable file monitoring
F. Select Investigate files, and then filter File Type to Document
View answer
Correct Answer: DE
Question #10
You have a Microsoft Sentinel workspace. You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant: * App name: App1 * IP address: 192.168.1.2 * Computer name: Device1 * Used client app: Microsoft Edge * Email address: user1@company.com * Sign-in URL: https://www.company.com Which entities can be investigated by using UEBA? Microsoft Sentinel UEBA (User and Entity Behavior Analytics) focuses on users and hosts (devices) and enriches data with contextual information. When enabling UEBA with Audit logs and Signin logs, the only entities supported for investigation are: User accounts (email addresses) Hosts or devices (including IP addresses) Other values like App name, Used client app, and Sign-in URL are attributes in log data but not tracked entities in UEBA investigations. Answe r: B. IP address and email address only
A. app name, computer name, IP address, email address, and used client app only
B. IP address and email address only
C. used client app and app name only
D. IP address only
View answer
Correct Answer: B
Question #11
On the first day after the Storage Center is installed, the engineer begins copying data to it.The engineer uses the default Replay Profile and Data Progression settings. The engineernotices that the system did take replays, but no data has been restriped in Tier 1.What is the cause of the problem?
A. The volumes are NOT mapped to servers
B. Replays were created before Data Progression
C. The system can NOT restripe data because it has only one tier of storage
D. Data Progression occurred beforethe replays were created
View answer
Correct Answer: C
Question #12
You have an Azure virtual machine named VM1 that runs Windows Server. You onboard VM1 to Microsoft Sentinel by connecting VM1 to a Log Analytics workspace. You plan to run an automated response playbook based on an Azure logic app named LA1 directly from an incident in Microsoft Sentinel. You discover that the playbook fails to run against VM1. You need to ensure that the playbook can successfully execute actions on VM1. The solution must minimize administrative effort. What should you do?
A. Grant the playbook’s managed identity the required permissions on VM1
B. Onboard VM1 to Azure Automation
C. Assign a managed identity to VM1 and grant it access to LA1
D. Add a data connector to a Microsoft Sentinel workspace
View answer
Correct Answer: A
Question #13
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You discover that when Microsoft Defender for Endpoint generates alerts for a commonly used executable file, it causes alert fatigue.You need to tune the alerts.Which two actions can an alert tuning rule perform for the alerts? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. delete
B. hide
C. resolve
D. merge
E. assign
View answer
Correct Answer: BC
Question #14
You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in.Which anomaly detection policy should you use?
A. Impossible travel
B. Activity from anonymous IP addresses
C. Activity from infrequent country
D. Malware detection
View answer
Correct Answer: C
Question #15
An engineer has installed a Storage Array with a Tier 1 consisting of SSDs.What should the engineer do to optimize performance for I/O workloads utilizing this Tier?
A. Disable write cache on volumes
B. Convert Tier 1 to RAID 0
C. Segregate the SSDs to a separate disk folder
D. Change the sector size from 512 to 4K
View answer
Correct Answer: A
Question #16
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You are investigating an attacker that is known to use the Microsoft Graph API as an attack vector. The attacker performs the tactics shown the following table.You need to search for malicious activities in your organization.Which tactics can you analyze by using the MicrosoftGraphActivityLogs table?
A. actic2 only
B. actic1 and Tactic2 only
C. actic2 and Tactic3 only
D. actic1, Tactic2, and Tactic3
View answer
Correct Answer: B
Question #17
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.You need to implement deception rules. The solution must ensure that you can limit the scope of the rules. What should you create first?
A. device groups
B. device tags
C. honeytoken entity tags
D. sensitive entity tags
View answer
Correct Answer: B
Question #18
You have an Azure subscription that contains an Azure logic app named app1 and a Microsoft Sentinel workspace that has an Azure AD connector. You need to ensure that app1 launches when Microsoft Sentinel detects an Azure AD-generated alert. What should you create first?
A. Aa repository connection
B. Bawatchlist
C. Can analytics rule
D. Dan automation rule
View answer
Correct Answer: D
Question #19
You need to minimize the effort required to investigate the Microsoft Defender for Identity false positive alerts. What should you review?
A. the status update time
B. the resolution method of the source computer
C. the alert status
D. the certainty of the source computer
View answer
Correct Answer: D
Question #20
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You use Azure Security Center.You receive a security alert in Security Center.You need to view recommendations to resolve the alert in Security Center.Solution: From Security alerts, you select the alert, select Take Action, and then expand the Prevent future attacks section.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #21
You have the following advanced hunting query in Microsoft Defender XDR.You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender XDR during the last 24 hours.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. Create a detection rule
B. Create a suppression rule
C. Add | order by Timestamp to the query
D. Replace DeviceProcessEvents with DeviceNetworkEvents
E. Add DeviceId and ReportId to the output of the query
View answer
Correct Answer: AE
Question #22
You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in.Which anomaly detection policy should you use?
A. mpossible travel
B. ctivity from anonymous IP addresses
C. ctivity from infrequent country
D. alware detection
View answer
Correct Answer: C
Question #23
You have an Azure subscription that uses Microsoft Defender for Endpoint.You need to ensure that you can allow or block user-specified IP addresses and URLs.What should you enable first in the Advanced features from the Endpoints Settings in the Microsoft Defender portal?
A. custom network indicators
B. live response for servers
C. endpoint detection and response (EDR) in block mode
D. web content filtering
View answer
Correct Answer: A
Question #24
You are investigating a potential attack that deploys a new ransomware strain.You have three custom device groups. The groups contain devices that store highly sensitive information.You plan to perform automated actions on all devices.You need to be able to temporarily group the machines to perform actions on the devices.Which three actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. ssign a tag to the device group
B. dd the device users to the admin role
C. dd a tag to the machines
D. reate a new device group that has a rank of 1
E. reate a new admin role
F. reate a new device group that has a rank of 4
View answer
Correct Answer: ACD
Question #25
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.You need to add threat indicators for all the IP addresses in a range of 171.23.34.32-171.23.34.63. The solution must minimize administrative effort.What should you do in the Microsoft 365 Defender portal?
A. reate an import file that contains the individual IP addresses in the range
B. reate an import file that contains the IP address of 171
C. elect Add indicator and set the IP address to 171
D. elect Add indicator and set the IP address to 171
View answer
Correct Answer: A
Question #26
The issue for which team can be resolved by using Microsoft Defender for Office 365?
A. executive
B. marketing
C. security
D. sales
View answer
Correct Answer: B
Question #27
You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually. You deploy Azure Sentinel. You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first? In Microsoft Sentinel, playbooks are Azure Logic Apps that automate responses to alerts or incidents. To use an existing Logic App as a playbook in Sentinel, it must start with the ''Microsoft Sentinel alert'' trigger. This trigger allows Sentinel to call and pass alert details to the Logic App automatically. When an existing Logic App has a manual trigger, it cannot be invoked directly by Sentinel. Therefore, the first step is to modify the trigger to replace the manual trigger with the ''When a response to an Azure Sentinel alert is triggered'' trigger. After that, you can link it within Sentinel incidents or automation rules. This process is detailed in Microsoft Defender XDR and Sentinel documentation under ''Connect a Logic App to Sentinel as a playbook.'' Hence, the correct answer is D. Modify the trigger in the logic app.
A. And a new scheduled query rule
B. Add a data connector to Azure Sentinel
C. Configure a custom Threat Intelligence connector in Azure Sentinel
D. Modify the trigger in the logic app
View answer
Correct Answer: D
Question #28
An engineer needs to use a set of commands to initialize a new SC8000 with serial numbers 12345 & 12346 from the CLI.Which initial set of commands should the engineer choose?
A. ption B
B. ption A
C. ption C
D. ption D
View answer
Correct Answer: C
Question #29
How are replay scheduling rules applied to a particular volume?
A. replay profile may have multiple schedule rules, and a volume may belong to multiple replay profiles
B. replay profile may have multiple schedule rules, but a volume belongs to exactly one replay profile
C. replay profile has exactly one schedulerule, but a volume may belong to multiple replay profiles
D. replay profile has exactly one schedule rule, and a volume belongs to exactly one replay profile
View answer
Correct Answer: B
Question #30
You have the following advanced hunting query in Microsoft 365 Defender.You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. Create a detection rule
B. Create a suppression rule
C. Add | order by Timestamp to the query
D. Replace DeviceProcessEvents with DeviceNetworkEvents
E. Add DeviceId and ReportId to the output of the query
View answer
Correct Answer: AE
Question #31
You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.You have Microsoft SharePoint Online sites that contain sensitive documents. The documents contain customer account numbers that each consists of 32 alphanumeric characters.You need to create a data loss prevention (DLP) policy to protect the sensitive documents.What should you use to detect which documents are sensitive?
A. harePoint search
B. hunting query in Microsoft 365 Defender
C. zure Information Protection
D. egEx pattern matching
View answer
Correct Answer: D
Question #32
A storage array is configured with four front-end ports on each controller (in a dual-controller configuration) for server connectivity. The storage array runs in Legacy Portmode. An engineer needs to provide multi-pathed (2 fabrics) connectivity from the storagearray to the server.What is the minimum number of fault domains required?
A. 8
B. 2
C. 4
D. 6
View answer
Correct Answer: B
Question #33
The issue for which team can be resolved by using Microsoft Defender for Office 365?
A. executive
B. marketing
C. security
D. sales
View answer
Correct Answer: B
Question #34
You have a third-party security information and event management (SIEM) solution.You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign- events in near real time.What should you do to route events to the SIEM solution?
A. Create an Microsoft Sentinel workspace that has a Security Events connector
B. Configure the Diagnostics settings in Azure AD to stream to an event hub
C. Create an Microsoft Sentinel workspace that has an Azure Active Directory connector
D. Configure the Diagnostics settings in Azure AD to archive to a storage account
View answer
Correct Answer: B
Question #35
You create a hunting query in Azure Sentinel.You need to receive a notification in the Azure portal as soon as the hunting query detects a match on the query. The solution must minimize effort.What should you use?
A. bookmark
B. playbook
C. livestream
D. notebook
View answer
Correct Answer: C
Question #36
You receive an alert from Azure Defender for Key Vault. You discover that the alert is generated from multiple suspicious IP addresses. You need to reduce the potential of Key Vault secrets being leaked while you investigate the issue. The solution must be implemented as soon as possible and must minimize the impact on legitimate users. What should you do first? When Azure Defender for Key Vault (now part of Microsoft Defender for Cloud) raises an alert about suspicious access attempts from multiple unknown IP addresses, the immediate mitigation step---before deeper investigation---is to restrict network access to the Key Vault to reduce exposure. The Azure Key Vault firewall allows you to restrict access by: Allowing access only from trusted IP addresses, VNets, or private endpoints. Blocking all other traffic by enabling the firewall and disabling ''Allow access from all networks.'' Microsoft's official recommendation states: ''To reduce the likelihood of secrets being compromised while you investigate an alert, enable the Key Vault firewall and restrict access to trusted networks or specific virtual networks.'' ''Firewall and virtual network configuration can be applied immediately without affecting existing permissions or access policies.'' This step: Minimizes exposure to malicious IP addresses. Is quick to implement (through the Azure Portal or CLI). Has minimal impact on legitimate users if you properly whitelist trusted networks or VNets. Other options: A (Modify access control settings) or D (Modify access policy) would affect permissions and could disrupt legitimate users or service principals. C (Create an application security group) applies to network interfaces, not directly to Key Vault. Answe r: B. Enable the Key Vault firewall
A. Modify the access control settings for the key vault
B. Enable the Key Vault firewall
C. Create an application security group
D. Modify the access policy for the key vault
View answer
Correct Answer: B

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us