Skip to content

Latest commit

Β 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 

Repository files navigation

Microsoft Certified: Security Operations Analyst Associate (SC-200)

Microsoft Certification Exam Code Passing Score Practice Materials


πŸ“– Table of Contents

  1. Exam Overview
  2. How to Prepare
  3. Exam Blueprint & Skills Measured
  4. Practice & Preparation Materials
  5. 10 Realistic Demo Practice Questions & Answers
  6. Community Discussion & Study Group
  7. Detailed Topic Documentation Index
  8. Official Microsoft Learning Resources

🎯 Exam Overview

Exam SC-200 validates technical capability to mitigate threats using Microsoft Defender for Endpoint, Defender for Office 365, Defender for Cloud, and Microsoft Sentinel.

Quick Facts

Attribute Specification
Exam Code SC-200
Certification Name Microsoft Certified: Security Operations Analyst Associate (SC-200)
Passing Score 700 / 1000 (Scaled Score)
Official Portal Microsoft Learn Credentials

πŸš€ How to Prepare

  • πŸ”— Review the Exam SC-200 page for exam registration and other details:
    Visit the Official Microsoft Exam Registration Page to review scheduling options via Pearson VUE.

  • πŸ“š Explore the Official Study Guide:
    Review the official Microsoft study guide for an itemized breakdown of testable objectives.

  • πŸ‘₯ Connect with Microsoft Training Services Partners:
    Find authorized training partners worldwide at the Microsoft Training Services Partner Directory.


πŸ“Š Exam Blueprint & Skills Measured

Domain / Skill Area Weighting
Mitigate threats using Microsoft Defender for Endpoint 20–25%
Mitigate threats using Microsoft Defender for Office 365 and Microsoft Defender for Identity 15–20%
Mitigate threats using Microsoft Defender for Cloud 15–20%
Create and manage Microsoft Sentinel solutions 25–30%
Perform threat hunting in Microsoft Sentinel and Microsoft Defender 15–20%

πŸ’‘ Practice & Preparation Materials

For comprehensive practice tests, high-yield scenario questions, and full-length exam simulations, explore the dedicated practice resources for SC-200.


πŸ“ 10 Realistic Demo Practice Questions & Answers

Question 1 (Domain: Defender for Endpoint)

Scenario / Question: A workstation alerts for active ransomware execution. As a security analyst, you need to immediately prevent the malware from communicating over the network while maintaining connectivity to the Microsoft Defender cloud for Live Response investigation. Which action should you take?

  • A) Shutdown the physical computer
  • B) Isolate the Device (with App Execution / Cloud connectivity allowed)
  • C) Delete the device record from Entra ID
  • D) Format the hard drive
  • Correct Answer: B
  • Detailed Explanation: Isolating the device in Microsoft Defender for Endpoint cuts off all external/internal network communication while maintaining a secure tunnel to Defender for cloud-based Live Response investigation.

Question 2 (Domain: Microsoft Sentinel)

Scenario / Question: You are writing a custom Kusto Query Language (KQL) scheduled analytics rule in Microsoft Sentinel to detect 5 or more failed login attempts followed by a successful login for the same user account within 10 minutes. Which KQL operator is best suited to aggregate event counts over time buckets?

  • A) summarize count() by Account, bin(TimeGenerated, 10m)
  • B) order by TimeGenerated desc
  • C) distinct Account
  • D) take 10
  • Correct Answer: A
  • Detailed Explanation: summarize count() by Account, bin(TimeGenerated, 10m) aggregates event counts per user account into discrete 10-minute time bins.

Question 3 (Domain: Defender for Identity)

Scenario / Question: Which attack technique involves an adversary stealing Kerberos Ticket Granting Tickets (TGT) to generate an all-powerful counterfeit ticket that grants persistent enterprise domain admin access?

  • A) Golden Ticket Attack
  • B) Pass-the-Hash
  • C) DNS Hijacking
  • D) Cross-Site Scripting (XSS)
  • Correct Answer: A
  • Detailed Explanation: A Golden Ticket attack uses a compromised KRBTGT account password hash to forge Ticket Granting Tickets, allowing unlimited access across the Active Directory domain.

Question 4 (Domain: Defender for Office 365)

Scenario / Question: You need to protect users against malicious URLs embedded in emails by inspecting the destination webpage at the exact moment the user clicks the link (time-of-click verification). Which feature of Microsoft Defender for Office 365 provides this?

  • A) Safe Links
  • B) Safe Attachments
  • C) Anti-Spam Outbound Policy
  • D) Mail Flow Rule
  • Correct Answer: A
  • Detailed Explanation: Safe Links provides real-time time-of-click scanning of URLs in email messages and Office documents to protect against weaponized links.

Question 5 (Domain: Threat Hunting)

Scenario / Question: Which machine learning-based rule type in Microsoft Sentinel uses multi-stage attack correlation to combine low-fidelity alerts from diverse data sources into high-fidelity actionable security incidents?

  • A) Fusion Detection Rules
  • B) NRT (Near-Real-Time) Rules
  • C) Static Threshold Rules
  • D) Custom Event Hub Rules
  • Correct Answer: A
  • Detailed Explanation: Fusion technology in Microsoft Sentinel uses scalable machine learning algorithms to automatically correlate millions of low-fidelity alerts into high-confidence multi-stage attack incidents.

Question 6 (Domain: Defender for Cloud)

Scenario / Question: You need to prevent attackers from executing brute-force attacks against management ports (RDP 3389 and SSH 22) on Azure Virtual Machines while still allowing approved administrators to connect on-demand for 1 hour. Which feature should you enable?

  • A) Just-in-Time (JIT) VM Access
  • B) Leave ports open permanently
  • C) Disable Windows Firewall
  • D) NAT Gateway rule
  • Correct Answer: A
  • Detailed Explanation: JIT VM Access locks down inbound traffic to management ports by creating temporary NSG rules only when an authorized user requests and is approved for access.

Question 7 (Domain: Security Operations)

Scenario / Question: You want Microsoft Defender XDR to automatically contain active ransomware attacks across endpoints and user identities without human intervention when high-confidence signals are detected. What feature enables this?

  • A) Automatic Attack Disruption
  • B) Manual Ticket Creation
  • C) Weekly Audit Digest
  • D) DNS Forwarding
  • Correct Answer: A
  • Detailed Explanation: Automatic Attack Disruption uses correlated XDR signals to instantly neutralize active in-progress attacks (e.g., isolating compromised devices and disabling compromised user accounts).

Question 8 (Domain: Threat Intelligence)

Scenario / Question: In Microsoft Sentinel, you want to ingest Indicator of Compromise (IOC) threat intelligence feeds using the standardized STIX/TAXII protocols. Which data connector should you enable?

  • A) Threat Intelligence - TAXII Connector
  • B) Windows Event Forwarder
  • C) Azure Activity Log
  • D) Office 365 Connector
  • Correct Answer: A
  • Detailed Explanation: The Threat Intelligence - TAXII connector ingests threat intelligence feeds in STIX/TAXII format directly into the ThreatIntelligenceIndicator table in Sentinel.

Question 9 (Domain: Defender for Endpoint)

Scenario / Question: Which feature in Microsoft Defender for Endpoint blocks malicious behaviors, executable files, and scripts commonly used by malware (such as blocking Office applications from creating child processes)?

  • A) Attack Surface Reduction (ASR) Rules
  • B) Dynamic Host Configuration Protocol
  • C) BitLocker Key Backup
  • D) Azure Bastion
  • Correct Answer: A
  • Detailed Explanation: Attack Surface Reduction (ASR) rules target specific software behaviors often abused by attackers, such as launching executable files from Office apps or blocking obfuscated scripts.

Question 10 (Domain: Sentinel Workbooks)

Scenario / Question: Which interactive reporting feature in Microsoft Sentinel allows security analysts to visualize security metrics, incident trends, and KQL query results in customized charts and heatmaps?

  • A) Workbooks
  • B) Classic Excel files
  • C) Text files in Blob storage
  • D) Command prompt script
  • Correct Answer: A
  • Detailed Explanation: Microsoft Sentinel Workbooks provide rich, interactive graphical dashboards and visualizations powered by underlying KQL queries.

πŸ’¬ Community Discussion & Study Group

Have questions regarding SC-200 concepts, study plans, or exam strategies?

  • πŸ’¬ Ask a question or start a topic: GitHub Discussions
  • πŸ› Report corrections or suggest updates: GitHub Issues
  • 🀝 Contribute: Open a Pull Request to share study notes, architecture diagrams, and review materials.

πŸ“‚ Detailed Topic Documentation Index


🌐 Official Microsoft Learning Resources


πŸ›‘οΈ Disclaimer

This repository contains educational study notes, architecture summaries, and reference documentation compiled from publicly available official Microsoft Learn documentation. Microsoft, Azure, and Microsoft Entra are trademarks of the Microsoft group of companies.

About

Official Study Guide, Blueprint, Practice Materials & 10 Demo Questions for Exam SC-200: Microsoft Security Operations Analyst

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors