Microsoft

SC-200 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 346-question bank.

Provider
Microsoft
Question bank
346
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for SC-200, a certification listed under Microsoft. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Microsoft. The certification credential is issued by Microsoft, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    DRAG DROP - You are investigating an incident by using Microsoft 365 Defender. You need to create an advanced hunting query to count failed sign-in authentications on three devices named CFOLaptop, CEOLaptop, and COOLaptop. How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Select and Place:

    Choose an option for each prompt.

    Question illustration 1

    Select query table

    • DeviceEvents
    • DeviceLogonEvents

    Select filter

    • ActionType == "LogonFailed"
    • ActionType == FailureReason

    Select device filter

    • I where DeviceName in ("CFOLaptop", "CEOLaptop", "COOLaptop")
    • I summarize LogonFailures=count() by DeviceName, LogonType

    Select aggregation

    • I project LogonFailures=count()
    • I summarize LogonFailures=count() by DeviceName, LogonType
  2. Question 2 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Microsoft Defender for Identity integration with Active Directory. From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit. Solution: From Entity tags, you add the accounts as Honeytoken accounts. Does this meet the goal?

    Choose one answer.

    • Yes
    • No
  3. Question 3 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Microsoft Defender for Identity integration with Active Directory. From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit. Solution: From Azure AD Identity Protection, you configure the sign-in risk policy. Does this meet the goal?

    Choose one answer.

    • Yes
    • No
  4. Question 4 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Microsoft Defender for Identity integration with Active Directory. From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit. Solution: You add the accounts to an Active Directory group and add the group as a Sensitive group. Does this meet the goal?

    Choose one answer.

    • Yes
    • No
  5. Question 5 · 1

    You implement Safe Attachments policies in Microsoft Defender for Office 365. Users report that email messages containing attachments take longer than expected to be received. You need to reduce the amount of time it takes to deliver messages that contain attachments without compromising security. The attachments must be scanned for malware, and any messages that contain malware must be blocked. What should you configure in the Safe Attachments policies?

    Choose one answer.

    • Dynamic Delivery
    • Replace
    • Block and Enable redirect
    • Monitor and Enable redirect
  6. Question 6 · 1

    You receive a security bulletin about a potential attack that uses an image file. You need to create an indicator of compromise (IoC) in Microsoft Defender for Endpoint to prevent the attack. Which indicator type should you use?

    Choose one answer.

    • a URL/domain indicator that has Action set to Alert only
    • a URL/domain indicator that has Action set to Alert and block
    • a file hash indicator that has Action set to Alert and block
    • a certificate indicator that has Action set to Alert and block
  7. Question 7 · 1

    Your company deploys the following services: ✑ Microsoft Defender for Identity ✑ Microsoft Defender for Endpoint ✑ Microsoft Defender for Office 365 You need to provide a security analyst with the ability to use the Microsoft 365 security center. The analyst must be able to approve and reject pending actions generated by Microsoft Defender for Endpoint. The solution must use the principle of least privilege. Which two roles should assign to the analyst? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

    Choose all answers that apply.

    • the Compliance Data Administrator in Azure Active Directory (Azure AD)
    • the Active remediation actions role in Microsoft Defender for Endpoint
    • the Security Administrator role in Azure Active Directory (Azure AD)
    • the Security Reader role in Azure Active Directory (Azure AD)
  8. Question 8 · 1

    You need to configure Microsoft Cloud App Security to generate alerts and trigger remediation actions in response to external sharing of confidential files. Which two actions should you perform in the Cloud App Security portal? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

    Choose all answers that apply.

    • From Settings, select Information Protection, select Azure Information Protection, and then select Only scan files for Azure Information Protection classification labels and content inspection warnings from this tenant.
    • Select Investigate files, and then filter App to Office 365.
    • Select Investigate files, and then select New policy from search.
    • From Settings, select Information Protection, select Azure Information Protection, and then select Automatically scan new files for Azure Information Protection classification labels and content inspection warnings.
    • From Settings, select Information Protection, select Files, and then enable file monitoring.
    • Select Investigate files, and then filter File Type to Document.
  9. Question 9 · 1

    HOTSPOT - You purchase a Microsoft 365 subscription. You plan to configure Microsoft Cloud App Security. You need to create a custom template-based policy that detects connections to Microsoft 365 apps that originate from a botnet network. What should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1

    Policy template type

    • Access policy
    • Activity policy
    • Anomaly detection policy

    Filter based on

    • IP address tag
    • Source
    • User agent string
  10. Question 10 · 1

    You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in. Which anomaly detection policy should you use?

    Choose one answer.

    • Impossible travel
    • Activity from anonymous IP addresses
    • Activity from infrequent country
    • Malware detection
  11. Question 11 · 1

    Your company has a single office in Istanbul and a Microsoft 365 subscription. The company plans to use conditional access policies to enforce multi-factor authentication (MFA). You need to enforce MFA for all users who work remotely. What should you include in the solution?

    Choose one answer.

    • a fraud alert
    • a user risk policy
    • a named location
    • a sign-in user policy
  12. Question 12 · 1

    You are configuring Microsoft Cloud App Security. You have a custom threat detection policy based on the IP address ranges of your company's United States-based offices. You receive many alerts related to impossible travel and sign-ins from risky IP addresses. You determine that 99% of the alerts are legitimate sign-ins from your corporate offices. You need to prevent alerts for legitimate sign-ins from known locations. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

    Choose all answers that apply.

    • Configure automatic data enrichment.
    • Add the IP addresses to the corporate address range category.
    • Increase the sensitivity level of the impossible travel anomaly detection policy.
    • Add the IP addresses to the other address range category and add a tag.
    • Create an activity policy that has an exclusion for the IP addresses.
  13. Question 13 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Microsoft Defender for Identity integration with Active Directory. From the Microsoft Defender for identity portal, you need to configure several accounts for attackers to exploit. Solution: You add each account as a Sensitive account. Does this meet the goal?

    Choose one answer.

    • Yes
    • No
  14. Question 14 · 1

    You have a Microsoft 365 tenant that uses Microsoft Exchange Online and Microsoft Defender for Office 365. What should you use to identify whether zero-hour auto purge (ZAP) moved an email message from the mailbox of a user?

    Choose one answer.

    • the Threat Protection Status report in Microsoft Defender for Office 365
    • the mailbox audit log in Exchange
    • the Safe Attachments file types report in Microsoft Defender for Office 365
    • the mail flow report in Exchange
  15. Question 15 · 1

    You have a Microsoft 365 subscription that contains 1,000 Windows 10 devices. The devices have Microsoft Office 365 installed. You need to mitigate the following device threats: ✑ Microsoft Excel macros that download scripts from untrusted websites ✑ Users that open executable attachments in Microsoft Outlook ✑ Outlook rules and forms exploits What should you use?

    Choose one answer.

    • Microsoft Defender Antivirus
    • attack surface reduction rules in Microsoft Defender for Endpoint
    • Windows Defender Firewall
    • adaptive application control in Azure Defender

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free