Official Bank 0/370

Microsoft Security Operations Analyst (SC-200) - Microsoft Exam Questions

Last updated on June 22, 2026

97% Exam Compliance
370 Total Questions
1
Question
You need to configure Microsoft Cloud App Security to generate alerts and trigger remediation actions in response to external sharing of confidential files.

Which two actions should you perform in the Cloud App Security portal? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.
Options
A Select Investigate files, and then select New policy from search
B From Settings, select Information Protection, select Azure Information Protection, and then select
Automatically scan new files for Azure Information Protection classification labels and content inspection warnings
C Select Investigate files, and then filter File Type to Document.
D From Settings, select Information Protection, select Files, and then enable file monitoring.
E From Settings, select Information Protection, select Azure Information Protection, and then select
Only scan files for Azure Information Protection classification labels and content inspection warnings
from this tenant
F Select Investigate files, and then filter App to Office 365.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
You have a Microsoft 365 B5 subscription that contains two groups named Group! and Group2 and uses Microsoft Copilot for Security. You need to configure Copilot for Security role assignments to meet the following requirements:

• Ensure that members of Group1 can run prompts and respond to Microsoft Defender XDR security
incidents.

• Ensure that members of Group2 can run prompts.

• Follow the principle of least privilege.
You remove Everyone from the Copilot Contributor role.

Which two actions should you perform next? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.
Select 2
Options
A Assign the Copilot Owner role to Group1.
B Assign the Security Operator role to Group2.
C Assign the Copilot Contributor role to Group2.
D Assign the Security Operator role to Group1.
E Assign the Copilot Owner role to Group2.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
You have a Microsoft Sentine1 workspace that contains a custom workbook named Workbook1. HOTSPOT You need to create a visual in Workbook1 that will display the logon count for accounts that have logon event IDs of 4624 and 4634. How should you complete the query? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one point.

Exhibit
Reveal Only
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
You create a custom analytics rule to detect threats in Azure Sentinel. You discover that the rule fails intermittently.

What are two possible causes of the failures? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.
Options
A Permissions to the data sources of the rule query were modified.
B There are connectivity issues between the data sources and Log Analytics
C The rule query takes too long to run and times out.
D The target workspace was deleted.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
You use Azure Sentinel to monitor irregular Azure activity. HOTSPOT You create custom analytics rules to detect threats as shown in the following exhibit. 97/318

Exhibit

Home > Azure Sentinel workspaces > Azure Sentinel Analytics rule wizard - Edit existing rule General Set rule logic Incident settings Automated response Review and create Define the logic for your new analytics rule. Rule query Any time details set here will be within the scope defined below in the Query scheduling fields. Query scheduling AzureActivity
I where OperationName -- "Create or Update Virtual Machine"
or OperationName = "Create Deployment"
I where ActivityStatus - "Succeeded" I make-series dcount (ResourceId) default=0 on EventSubmissionTinestamp in range (ago (7d), now(), 1d) by Caller View sue D Map entities Map the entities recognized by Azure Sentinel to the appropriate columns available in your query results. This enables Azure Sentinel to recognize the entities that are part of the alerts for further analysis. Entity type must be a string. Entity Type Column Account Choose column Host Choose column IP Choose column URL Choose column FileHash Choose column Add Add Add Add Add Run query every • 5 Minutes Lookup data from the last* © Alert threshold Generate alert when number of query resuits Is greater than Event grouping Configure how rule query results are grouped into alerts

• Group all events into a single alert

• Trigger an alert for each event
Suppression Stop running query after alert is generated © On Off Stop running query for* 5 Hours 5 Hours Previous Next: Incident settings> You do NOT define any incident settings as part of the rule definition. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Exhibit
Reveal Only
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.