dc dotCreds
Microsoft Security Operations Analyst

SC-200 Practice Test

Start today’s free 10-question SC-200 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 7, 2026, 10:05 AM CDT

Go Pro - One Time Unlock

Unlock the full SC-200 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 SC-200 questions

Use this SC-200 practice test to review Microsoft Security Operations Analyst. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Investigate Defender for Cloud workload and Defender for Cloud Apps alerts Respond to security incidents

An analyst closes a Defender for Cloud database alert, but the malicious login remains active in the database service. What additional step is required?

Concept tested:
Question 2 of 10
Objective Create Advanced Hunting queries and interpret threat analytics Perform threat hunting

A second analyst must reproduce a hunt for suspicious remote-service creation in Defender XDR. What should the original hunter provide?

Concept tested:
Question 3 of 10
Objective Create and configure Microsoft Sentinel automation rules Manage a security operations environment

A Sentinel automation rule should add a tag only during a 30-day incident-response exercise. How can the team prevent stale logic afterward?

Concept tested:
Question 4 of 10
Objective Create hunting graphs and analyze entity relationships with Sentinel Graph Perform threat hunting

A hunt returns an account, three devices, and several remote connections. The analyst must estimate which assets may be reachable from the suspected account, but only relationships supported by authentication or communication evidence may be used. What should the analyst build?

Concept tested:
Question 5 of 10
Objective Use summary rules and notebooks for Sentinel threat hunting Perform threat hunting

A standard portal query cannot perform the required iterative Python enrichment with an external library. The chosen Sentinel notebook opens but cannot query the workspace. What must be fixed?

Concept tested:
Question 6 of 10
Objective Configure Defender XDR notifications, tuning, suppression, and correlation Manage a security operations environment

The Tier 1 team must receive email when a high-severity Defender XDR incident contains a device from the Finance device group. It does not need notifications merely because a response action completed or a threat report changed. What should be configured?

Concept tested:
Question 7 of 10
Objective Perform endpoint evidence investigation and respond to disrupted attacks Respond to security incidents

The SOC permits live response scripts only after code review and signing. An analyst with appropriate RBAC needs to run a remediation script on one endpoint. Which approach respects the control?

Concept tested:
Question 8 of 10
Objective Investigate and manage incidents in Microsoft Sentinel Respond to security incidents

A Sentinel case contains several related alerts. The shift lead needs one place to review mapped entities and the timeline, assign an owner, add tasks and comments, and track the investigation. What should the lead use?

Concept tested:
Question 9 of 10
Objective Manage automated investigation, response, and automatic attack disruption Manage a security operations environment

Automatic attack disruption contains an account and device during a high-confidence active attack. Before analysts change containment, where should they verify the affected assets and current disruption state?

Concept tested:
Question 10 of 10
Objective Create Sentinel hunting queries and KQL jobs in the data lake Perform threat hunting

A weekly hunt scans a year of data-lake telemetry and must save recurring aggregates for later detection logic. Which KQL job design is most appropriate?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-200 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-200 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Access $6.99/month

Unlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams.

Why it fitsUnlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams, Includes current and future Microsoft practice banks on dotCreds, Best for learners taking more than one Microsoft exam, PDF downloads sold separately where available

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-200 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-200 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily SC-200 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 An analyst closes a Defender for Cloud database alert, but the malicious login remains active in the database service. What additional step is required?

Answer choices

  1. A. Assume closing the alert terminates every threat
  2. B. Change only the alert title
  3. C. Perform the required remediation in the protected database service and verify the threat is contained
  4. D. Delete all Defender recommendations

Correct answer

Perform the required remediation in the protected database service and verify the threat is contained

Closing an alert updates case state but may not remediate the protected workload. The analyst must take the required service-level action and verify containment.

Wrong-answer review

  • A. Assume closing the alert terminates every threat: Case closure does not automatically change every affected workload.
  • B. Change only the alert title: Renaming the alert has no containment effect in this scenario.
  • D. Delete all Defender recommendations: Recommendations are separate posture guidance and should not be deleted wholesale.

Extra learning features

Why this matters

Closing an alert does not automatically resolve the underlying threat, potentially leaving the system vulnerable. Immediate remediation is crucial to prevent further compromise and data loss, directly impacting operational security. This action is vital to contain the threat and prevent escalation. (34 words)

Objective/domain: Respond to security incidents

Source: Microsoft Defender for Cloud security alerts

Question 2 A second analyst must reproduce a hunt for suspicious remote-service creation in Defender XDR. What should the original hunter provide?

Answer choices

  1. A. The Advanced Hunting KQL plus its hypothesis, assumptions, time scope, exclusions, results, and next investigative actions
  2. B. Only a screenshot of the row count
  3. C. Only the incident severity
  4. D. An undocumented query with an unlimited time range

Correct answer

The Advanced Hunting KQL plus its hypothesis, assumptions, time scope, exclusions, results, and next investigative actions

Objective/domain: Perform threat hunting

Source: Advanced hunting query language in Microsoft Defender XDR

Question 3 A Sentinel automation rule should add a tag only during a 30-day incident-response exercise. How can the team prevent stale logic afterward?

Answer choices

  1. A. Rely on memory to delete it someday
  2. B. Set the automation rule expiration date to the exercise end
  3. C. Convert the rule to a permanent analytics rule
  4. D. Disable every automation rule in the workspace

Correct answer

Set the automation rule expiration date to the exercise end

Objective/domain: Manage a security operations environment

Source: Automation rules in Microsoft Sentinel

Question 4 A hunt returns an account, three devices, and several remote connections. The analyst must estimate which assets may be reachable from the suspected account, but only relationships supported by authentication or communication evidence may be used. What should the analyst build?

Answer choices

  1. A. A flat count of every entity sharing the same department
  2. B. A graph that links entities solely because their names have a common prefix
  3. C. An incident notification rule for each device
  4. D. A hunting graph with evidence-backed edges, followed by blast-radius analysis

Correct answer

A hunting graph with evidence-backed edges, followed by blast-radius analysis

Objective/domain: Perform threat hunting

Source: Hunting graph in Microsoft Defender advanced hunting

Question 5 A standard portal query cannot perform the required iterative Python enrichment with an external library. The chosen Sentinel notebook opens but cannot query the workspace. What must be fixed?

Answer choices

  1. A. Convert the notebook into an incident tag
  2. B. Use a workbook theme instead of Python
  3. C. Configure notebook authentication and workspace connection, then run the code-based analysis
  4. D. Disable Sentinel RBAC

Correct answer

Configure notebook authentication and workspace connection, then run the code-based analysis

Objective/domain: Perform threat hunting

Source: Jupyter notebooks with Microsoft Sentinel hunting capabilities

Question 6 The Tier 1 team must receive email when a high-severity Defender XDR incident contains a device from the Finance device group. It does not need notifications merely because a response action completed or a threat report changed. What should be configured?

Answer choices

  1. A. An incident notification rule scoped to high severity, the Finance device group, and the Tier 1 recipients
  2. B. An action notification rule for all automated and manual response actions
  3. C. A threat analytics notification rule for every updated threat report
  4. D. A suppression rule that hides all Finance device alerts

Correct answer

An incident notification rule scoped to high severity, the Finance device group, and the Tier 1 recipients

Objective/domain: Manage a security operations environment

Source: Configure email notifications in Microsoft Defender XDR

Question 7 The SOC permits live response scripts only after code review and signing. An analyst with appropriate RBAC needs to run a remediation script on one endpoint. Which approach respects the control?

Answer choices

  1. A. Enable unsigned-script execution for convenience
  2. B. Grant the analyst Global Administrator
  3. C. Upload and run the signed approved script through live response
  4. D. Run an unknown unsigned script outside the approved library

Correct answer

Upload and run the signed approved script through live response

Objective/domain: Respond to security incidents

Source: Live response in Microsoft Defender for Endpoint

Question 8 A Sentinel case contains several related alerts. The shift lead needs one place to review mapped entities and the timeline, assign an owner, add tasks and comments, and track the investigation. What should the lead use?

Answer choices

  1. A. The Microsoft Sentinel incident
  2. B. A data collection rule
  3. C. A custom log table
  4. D. An Azure Activity diagnostic setting

Correct answer

The Microsoft Sentinel incident

Objective/domain: Respond to security incidents

Source: Investigate incidents in Microsoft Sentinel

Question 9 Automatic attack disruption contains an account and device during a high-confidence active attack. Before analysts change containment, where should they verify the affected assets and current disruption state?

Answer choices

  1. A. Company branding
  2. B. A Purview content search
  3. C. Only the newest alert email
  4. D. The disrupted Defender XDR incident, including its graph and asset containment status

Correct answer

The disrupted Defender XDR incident, including its graph and asset containment status

Objective/domain: Manage a security operations environment

Source: Details and Results of an Automatic Attack Disruption Action

Question 10 A weekly hunt scans a year of data-lake telemetry and must save recurring aggregates for later detection logic. Which KQL job design is most appropriate?

Answer choices

  1. A. Run only an interactive analytics query and discard all output
  2. B. Store every raw event in an incident comment
  3. C. Schedule a data-lake KQL job whose output destination preserves the recurring results needed downstream
  4. D. Create a workbook parameter with no scheduled query

Correct answer

Schedule a data-lake KQL job whose output destination preserves the recurring results needed downstream

Objective/domain: Perform threat hunting

Source: KQL jobs in the Microsoft Sentinel data lake

Where to go after the daily web set

How are SC-200 questions generated?

dotCreds builds SC-200 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start SC-200 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.