dc dotCreds
Microsoft Security Operations Analyst

SC-200 Practice Test

Start today’s free 10-question SC-200 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 12, 2026, 3:38 PM CDT

Go Pro - One Time Unlock

Unlock the full SC-200 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 SC-200 questions

Use this SC-200 practice test to review Microsoft Security Operations Analyst. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Investigate Defender for Cloud workload and Defender for Cloud Apps alerts Respond to security incidents

Defender for Cloud Apps raises a session-policy alert for a risky download by a user whose device also has suspicious activity. Which response is most appropriate?

Concept tested:
Question 2 of 10
Objective Use summary rules and notebooks for Sentinel threat hunting Perform threat hunting

A summary table shows a sudden authentication spike, and a notebook model labels it malicious. What should happen before the SOC declares an incident?

Concept tested:
Question 3 of 10
Objective Perform endpoint evidence investigation and respond to disrupted attacks Respond to security incidents

An investigator needs an organization-wide record of automatic attack-disruption and predictive-shielding actions across several incidents. Which evidence should be queried first?

Concept tested:
Question 4 of 10
Objective Create and manage custom detections in Microsoft Defender XDR Manage a security operations environment

A custom detection finds malicious IP connections and is configured to isolate matching devices, but the response never runs because results identify only the IP. What should the query return?

Concept tested:
Question 5 of 10
Objective Investigate compromised identities with Entra ID Protection and Defender for Identity Respond to security incidents

A risky sign-in was investigated and found to be blocked, but other evidence confirms the user account was taken over and used on an endpoint. How should remediation be scoped?

Concept tested:
Question 6 of 10
Objective Configure Microsoft Sentinel roles and data retention tiers Manage a security operations environment

An auditor must view Sentinel incidents, workbooks, and security data but must not change incidents or create Sentinel content. Which built-in role is the least-privileged fit?

Concept tested:
Question 7 of 10
Objective Create Advanced Hunting queries and interpret threat analytics Perform threat hunting

A hunter is tracking a threat actor whose IP addresses rotate frequently but whose process chain remains consistent. What should the hunt design emphasize?

Concept tested:
Question 8 of 10
Objective Collect Windows Security events with AMA, DCRs, and Windows Event Forwarding Manage a security operations environment

Hundreds of branch computers forward selected events to one Windows Event Collector. AMA is installed only on that collector, but its DCR is associated with unrelated servers. How should collection be corrected?

Concept tested:
Question 9 of 10
Objective Create Sentinel hunting queries and KQL jobs in the data lake Perform threat hunting

A scheduled KQL job finds historical indicator matches in the data lake. Analysts need selected fields available in the analytics tier for further advanced queries while controlling cost. What should the job do?

Concept tested:
Question 10 of 10
Objective Manage automated investigation, response, and automatic attack disruption Manage a security operations environment

An analyst wants to review the disruption actions for one incident and then query disruption actions across the entire organization. Which two views should be used?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-200 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-200 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Security Bundle $9.99 one-time

Unlock all 6 active Microsoft Security Bundle practice banks in one permanent purchase.

What’s includedSC-900, SC-200, SC-300, SC-401, SC-500, SC-100
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-200 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-200 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily SC-200 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 Defender for Cloud Apps raises a session-policy alert for a risky download by a user whose device also has suspicious activity. Which response is most appropriate?

Answer choices

  1. A. Suspend every tenant user because one session was risky, for the described technical objective and its associated operational control requirements, as described.
  2. B. Revoke permissions from an unrelated application, for the described technical objective and its associated operational control requirements, as the primary implementation for the described business requirement.
  3. C. Ignore the device and identity context, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements.
  4. D. Correlate the session, identity, and device evidence, then apply a governance action to the validated user or application that matches the risk, for this requirement.

Correct answer

Correlate the session, identity, and device evidence, then apply a governance action to the validated user or application that matches the risk, for this requirement.

A session-policy alert should be evaluated with identity and device context. Governance actions must target the entity actually validated by the investigation.

Wrong-answer review

  • A. Suspend every tenant user because one session was risky, for the described technical objective and its associated operational control requirements, as described.: A tenant-wide suspension is disproportionate and unsupported by one user’s evidence.
  • B. Revoke permissions from an unrelated application, for the described technical objective and its associated operational control requirements, as the primary implementation for the described business requirement.: Revoking an unrelated application does not contain the validated risky entity.
  • C. Ignore the device and identity context, for the described technical objective and its associated operational control requirements, for the described technical objective and its associated operational control requirements.: The supporting device and identity signals are necessary to assess the session accurately.

Extra learning features

Interview question

Q: A Defender for Cloud Apps session-policy alert flags a risky download linked to suspicious device activity. How should an analyst respond to this situation? Strong answer: Correlate the session, identity, and device evidence, then apply a governance action to the validated user or application that matches the risk.

  • identity
  • device
  • evidence
  • governance action
  • risk

Caution: Avoid simply restating the multiple-choice options; focus on the reasoning behind the correct approach.

Why this matters

Correctly correlating evidence and applying targeted governance actions minimizes disruption and ensures responses are proportionate to the risk. This protects legitimate users and operations while efficiently addressing security concerns. A misdirected action wastes resources and disrupts business.

Objective/domain: Respond to security incidents

Source: Create Microsoft Defender for Cloud Apps session policies

Question 2 A summary table shows a sudden authentication spike, and a notebook model labels it malicious. What should happen before the SOC declares an incident?

Answer choices

  1. A. Accept the model label without examining source evidence, for the described technical objective and its associated operational control requirements.
  2. B. Delete the raw events because the summary exists, for the described technical objective and its associated operational control requirements, as described.
  3. C. Validate the notebook finding against the aggregated pattern and relevant source evidence before reaching an incident conclusion, within the stated policy framework.
  4. D. Replace the summary rule with an email notification, as the recommended implementation across the complete governed service lifecycle.

Correct answer

Validate the notebook finding against the aggregated pattern and relevant source evidence before reaching an incident conclusion, within the stated policy framework.

Objective/domain: Perform threat hunting

Source: Jupyter notebooks with Microsoft Sentinel hunting capabilities

Question 3 An investigator needs an organization-wide record of automatic attack-disruption and predictive-shielding actions across several incidents. Which evidence should be queried first?

Answer choices

  1. A. Only the current incident title, for the described technical objective and its associated operational control requirements, as selected.
  2. B. The DisruptionAndResponseEvents table, then correlate each event with the incident or asset record, under the documented operational and governance requirements.
  3. C. Only the device inventory last-seen time, as the proposed design for the complete governed operational workflow.
  4. D. A Purview mailbox search, as the recommended implementation across the complete governed service lifecycle.

Correct answer

The DisruptionAndResponseEvents table, then correlate each event with the incident or asset record, under the documented operational and governance requirements.

Objective/domain: Respond to security incidents

Source: Details and Results of an Automatic Attack Disruption Action

Question 4 A custom detection finds malicious IP connections and is configured to isolate matching devices, but the response never runs because results identify only the IP. What should the query return?

Answer choices

  1. A. Only a textual description of the IP, for the described technical objective and its associated operational control requirements, as described.
  2. B. The required timestamp plus the supported device-identifying entity columns, under the documented operational and governance requirements.
  3. C. Only a chart of counts, for the required operational result and control objective.
  4. D. No entity information to preserve privacy, for the required operational result and control objective.

Correct answer

The required timestamp plus the supported device-identifying entity columns, under the documented operational and governance requirements.

Objective/domain: Manage a security operations environment

Source: Custom detections in Microsoft Defender XDR

Question 5 A risky sign-in was investigated and found to be blocked, but other evidence confirms the user account was taken over and used on an endpoint. How should remediation be scoped?

Answer choices

  1. A. Dismiss the user as safe because one sign-in was blocked, for the described technical objective and its associated operational control requirements, within the defined security and accountability boundaries.
  2. B. Erase the incident evidence after resetting the password, for the described technical objective and its associated operational control requirements, for the specified implementation requirement.
  3. C. Remediate the compromised identity and affected assets while retaining evidence; do not treat the single sign-in result as the entire compromise determination, as the organization’s selected response.
  4. D. Mark every user in the tenant as compromised, for the described technical objective and its associated operational control requirements, for the stated requirement.

Correct answer

Remediate the compromised identity and affected assets while retaining evidence; do not treat the single sign-in result as the entire compromise determination, as the organization’s selected response.

Objective/domain: Respond to security incidents

Source: Investigate risk in Microsoft Entra ID Protection

Question 6 An auditor must view Sentinel incidents, workbooks, and security data but must not change incidents or create Sentinel content. Which built-in role is the least-privileged fit?

Answer choices

  1. A. Microsoft Sentinel Responder, as the proposed manage a security operations environment approach.
  2. B. Microsoft Sentinel Reader, in this situation.
  3. C. Microsoft Sentinel Contributor, for the stated implementation and support requirements.
  4. D. Owner on the Log Analytics workspace, as selected.

Correct answer

Microsoft Sentinel Reader, in this situation.

Objective/domain: Manage a security operations environment

Source: Roles and permissions in Microsoft Sentinel

Question 7 A hunter is tracking a threat actor whose IP addresses rotate frequently but whose process chain remains consistent. What should the hunt design emphasize?

Answer choices

  1. A. Combine current indicators with the stable behavioral pattern, and document assumptions, time scope, exclusions, results, and next actions
  2. B. Match only one historical IP address indefinitely, for the described technical objective and its associated operational control requirements, in practice.
  3. C. Search without a time scope or recorded hypothesis, for the described technical objective and its associated operational control requirements, under the proposed approach.
  4. D. Treat every matching process name as confirmed compromise, for the described technical objective and its associated operational control requirements, in practice.

Correct answer

Combine current indicators with the stable behavioral pattern, and document assumptions, time scope, exclusions, results, and next actions

Objective/domain: Perform threat hunting

Source: Advanced hunting query language in Microsoft Defender XDR

Question 8 Hundreds of branch computers forward selected events to one Windows Event Collector. AMA is installed only on that collector, but its DCR is associated with unrelated servers. How should collection be corrected?

Answer choices

  1. A. Install a workbook on every branch computer, for the described technical objective and its associated operational control requirements.
  2. B. Remove the WEF subscription and collect no events, for the described technical objective and its associated operational control requirements.
  3. C. Associate the AMA DCR with the collector that consolidates the forwarded events and target the Sentinel workspace, for the described technical objective.
  4. D. Create an incident tag for the collector, as the recommended implementation across the complete governed service lifecycle.

Correct answer

Associate the AMA DCR with the collector that consolidates the forwarded events and target the Sentinel workspace, for the described technical objective.

Objective/domain: Manage a security operations environment

Source: Windows Security Events via AMA connector

Question 9 A scheduled KQL job finds historical indicator matches in the data lake. Analysts need selected fields available in the analytics tier for further advanced queries while controlling cost. What should the job do?

Answer choices

  1. A. Promote every column and row without filtering, for the described technical objective and its associated operational control requirements, in practice.
  2. B. Delete the data-lake results, for the described technical objective and its associated operational control requirements.
  3. C. Email only a screenshot of the matches, for the described technical objective and its associated operational control requirements, within the proposed design.
  4. D. Project and filter the needed results, then write those selected results to an analytics-tier table, for the affected environment.

Correct answer

Project and filter the needed results, then write those selected results to an analytics-tier table, for the affected environment.

Objective/domain: Perform threat hunting

Source: KQL jobs in the Microsoft Sentinel data lake

Question 10 An analyst wants to review the disruption actions for one incident and then query disruption actions across the entire organization. Which two views should be used?

Answer choices

  1. A. Only the company branding page, for the described technical objective and its associated operational control requirements, as described.
  2. B. Only a Purview audit search, within the documented operational, security, ownership, and validation requirements.
  3. C. Only the device inventory count, for the described technical objective and its associated operational control requirements, in this situation.
  4. D. The disrupted incident’s asset status for the case and DisruptionAndResponseEvents for organization-wide analysis, as described.

Correct answer

The disrupted incident’s asset status for the case and DisruptionAndResponseEvents for organization-wide analysis, as described.

Objective/domain: Manage a security operations environment

Source: Details and Results of an Automatic Attack Disruption Action

Where to go after the daily web set

How are SC-200 questions generated?

dotCreds builds SC-200 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start SC-200 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.