SC-200 practice questions

20 free SC-200 practice questions with answers and explanations, covering Microsoft Defender XDR, Microsoft Sentinel, KQL and incident response. Try each one before you open the answer: testing yourself is how it sticks.

Study the full SC-200 course, free to start.

SC-200 exam at a glance

Skills measured from 21 October 2026

Official SC-200 study guide on Microsoft Learn

20 free SC-200 practice questions

Mitigate threats using Microsoft Defender XDR

Question 1. A marketing agency legitimately sends newsletters as your domain, and EOP keeps flagging them as spoofing. What's the cleanest, properly-scoped fix?

  1. Add their domain to every user's Outlook Safe Senders
  2. Create a transport rule that skips filtering for their IP
  3. Add their IP to the connection-filter allow list
  4. Allow them as a permitted spoof pair in spoof intelligence
Show answer

Answer: D, Allow them as a permitted spoof pair in spoof intelligence. A legitimate third party sending as your domain is handled by allowing that spoof pair in spoof intelligence — a targeted allow. An IP allow list and transport-rule bypass switch off too much protection, and per-user Safe Senders don't scale or address spoof verdicts.

Question 2. Which Safe Attachments policy action delivers the message body immediately but withholds attachments until scanning completes, then reattaches clean ones?

  1. Monitor
  2. Dynamic Delivery
  3. Replace
  4. Block
Show answer

Answer: B, Dynamic Delivery. Dynamic Delivery sends the email right away and delivers attachments once they pass scanning, avoiding delays. Block/Replace/Monitor handle detonated mail differently.

Mitigate threats using Microsoft Security Copilot

Question 3. A SOC lead questions why grounding matters so much in a security AI tool. Why is grounding particularly important in Security Copilot?

  1. It reduces the amount of compute required to run the LLM
  2. It ensures responses are based on current, specific environment data rather than generic training knowledge
  3. It prevents the tool from accessing the internet during prompt processing
  4. It replaces the need for human analyst review of AI outputs
Show answer

Answer: B, It ensures responses are based on current, specific environment data rather than generic training knowledge. Security threats and incidents change constantly. Without grounding, Copilot would produce generic answers from training data — not answers specific to the actual environment. Grounding with live data from Sentinel, Defender XDR, and MDTI makes responses actionable.

Question 4. A colleague asks how a Security Copilot agent differs from a promptbook. What's the difference?

  1. Agents don't consume SCUs but promptbooks do
  2. A promptbook is autonomous; an agent must be run manually
  3. They are the same feature
  4. An agent is an autonomous, adaptive automation that acts on tasks; a promptbook replays a fixed prompt sequence you trigger
Show answer

Answer: D, An agent is an autonomous, adaptive automation that acts on tasks; a promptbook replays a fixed prompt sequence you trigger. Agents autonomously handle high-volume tasks and adapt from feedback (within Zero Trust); promptbooks are fixed, analyst-triggered prompt sequences. Both can consume SCUs.

Mitigate threats using Microsoft Purview

Question 5. Which insider risk detection identifies a departing user slowly leaking data over many days, where no single day is anomalous?

  1. Sequence detection
  2. Cumulative exfiltration detection
  3. Adaptive Protection
  4. Priority content scoring
Show answer

Answer: B, Cumulative exfiltration detection. Cumulative exfiltration detection uses ML to compare a user's total exfiltration over time against org and peer norms (30 days), catching low-and-slow leakage that wouldn't trigger a single-event alert.

Question 6. Investigating BEC persistence, which audit activity do you search for to find mailboxes where the attacker granted themselves access?

  1. UserLoggedIn
  2. Set-MailboxPermission
  3. FileDownloaded
  4. New-RetentionPolicy
Show answer

Answer: B, Set-MailboxPermission. Set-MailboxPermission reveals where Full Access or similar was granted — a common BEC persistence technique. The others relate to file access, sign-ins, and retention configuration.

Mitigate threats using Microsoft Defender for Endpoint

Question 7. An attacker takes the bait and interacts with a deception lure on an endpoint. What does that interaction generate?

  1. An automatic Secure Score increase
  2. A routine informational event analysts ignore
  3. A high-confidence alert indicating likely attacker activity
  4. A licensing warning
Show answer

Answer: C, A high-confidence alert indicating likely attacker activity. Because legitimate users never touch lures, interaction is a near-zero-false-positive signal of attacker activity.

Question 8. You grab the local onboarding script to quickly test MDE on a few machines. Roughly how many devices is that script intended for?

  1. Unlimited
  2. Exactly 50
  3. Up to 1,000
  4. Up to about 10 (for testing)
Show answer

Answer: D, Up to about 10 (for testing). The local script is for up to ~10 devices for testing. At scale you use Intune, Group Policy, or Configuration Manager.

Mitigate threats using Microsoft Defender for Cloud

Question 9. A Defender for SQL alert fires: 'Potential SQL injection: unusual string observed'. What is the most appropriate immediate response?

  1. Disable the affected database temporarily by taking it offline
  2. Dismiss the alert as SQL injection alerts are typically false positives from application testing
  3. Investigate the alert details to identify the source IP and the specific query pattern, then assess whether the web application has a SQL injection vulnerability to patch
  4. Enable Defender for Storage to gain additional visibility into the attack
Show answer

Answer: C, Investigate the alert details to identify the source IP and the specific query pattern, then assess whether the web application has a SQL injection vulnerability to patch. The correct response is investigation: review the alert details (source IP, query pattern, authentication method), determine whether the query pattern indicates an actual vulnerability in the web application, and then prioritise remediation — potentially patching the application or applying a WAF rule. Taking the database offline disrupts business. Dismissing ignores a potential breach.

Question 10. An Azure VM is exfiltrating data via DNS tunnelling. Which plan detects this?

  1. Microsoft Defender for Storage
  2. Microsoft Defender for App Service
  3. Microsoft Defender for DNS
  4. Microsoft Defender for SQL
Show answer

Answer: C, Microsoft Defender for DNS. Defender for DNS detects tunnelling, malicious-domain lookups, and crypto-mining/C2 DNS activity. (For new subscriptions it's bundled into Defender for Servers Plan 2.)

Create queries for Microsoft Sentinel using Kusto Query Language (KQL)

Question 11. Use DisplayName, but fall back to UPN, then 'unknown', when earlier ones are empty. Users | extend Name = ___(DisplayName, UserPrincipalName, 'unknown')

  1. isnotempty
  2. iff
  3. coalesce
  4. case
Show answer

Answer: C, coalesce. coalesce(a,b,c) returns the first non-null/non-empty argument, ideal for fallbacks. iff/case branch on predicates, and isnotempty tests a single value.

Question 12. Bucket each event to midnight of its day. SecurityEvent | extend Day = ___(TimeGenerated)

  1. format_datetime
  2. startofday
  3. datetime_diff
  4. bin
Show answer

Answer: B, startofday. startofday() returns midnight of that day (startofweek/startofmonth do the week/month). bin rounds to an interval, format_datetime formats, and datetime_diff subtracts.

Configure your Microsoft Sentinel environment

Question 13. A Sentinel deployment stops receiving logs from the AWS connector without generating any visible alerts or incidents. How should this ingestion gap be detected?

  1. Monitor the SecurityAlert table for AWS-sourced alerts, their absence indicates an ingestion problem
  2. Check the ThreatIntelIndicators table for AWS-specific indicators
  3. Query the SentinelHealth table or review the Sentinel Health workbook for connector status and last ingestion time
  4. Set up a custom analytics rule that alerts when no AWS events are received for 4 hours
Show answer

Answer: C, Query the SentinelHealth table or review the Sentinel Health workbook for connector status and last ingestion time. The SentinelHealth table records health events for all Sentinel components including data connectors — showing last successful ingestion time and any errors. The Sentinel Health workbook visualises this data. This is the designed mechanism for detecting silent connector failures. A custom rule (option 4) is a valid backup approach but SentinelHealth is the primary, purpose-built solution.

Question 14. You're building a Scheduled analytics rule and the wizard has several tabs. Which elements define such a rule?

  1. Only a KQL query
  2. Only a data connector
  3. Only a severity and a name
  4. A KQL query, run schedule/lookback, alert threshold, entity mapping, and incident-creation settings
Show answer

Answer: D, A KQL query, run schedule/lookback, alert threshold, entity mapping, and incident-creation settings. A Scheduled rule comprises the KQL, scheduling/lookback, threshold, event/alert grouping, entity mapping, and incident settings — far more than just a query.

Connect logs to Microsoft Sentinel

Question 15. After enabling the Microsoft Defender XDR connector in Sentinel with Advanced Hunting data enabled, an analyst wants to write a Sentinel analytics rule that detects when a device that received a phishing email later shows suspicious process execution. Which tables are needed?

  1. SecurityAlert and SecurityEvent, standard alert and Windows event correlation
  2. EmailEvents and DeviceProcessEvents, email delivery and endpoint process execution
  3. OfficeActivity and CommonSecurityLog, M365 audit and network events
  4. ThreatIntelIndicators and SigninLogs, TI matching against authentication
Show answer

Answer: B, EmailEvents and DeviceProcessEvents, email delivery and endpoint process execution. EmailEvents (from Defender XDR connector) contains phishing delivery events with recipient and device information. DeviceProcessEvents (from Defender XDR connector) contains process execution events including command lines and parent processes. Joining these on the device or user entity enables detecting the 'phishing delivery, then payload execution' attack chain in a single cross-product analytics rule.

Question 16. The Microsoft Defender XDR connector has three independent toggles. Which one integrates on-premises Active Directory identities (via Defender for Identity) into UEBA?

  1. Connect events
  2. Connect playbooks
  3. Connect entities
  4. Connect incidents & alerts
Show answer

Answer: C, Connect entities. 'Connect entities' brings on-prem AD identities into UEBA. 'Connect incidents & alerts' syncs the incident queue, and 'Connect events' streams raw advanced-hunting tables.

Create detections and perform investigations using Microsoft Sentinel

Question 17. An analyst investigating a compromised account incident wants to see all other incidents that have involved this same user account — without writing a KQL query. Which Sentinel feature provides this?

  1. The Hunting interface — allows searching for incidents by entity
  2. The IdentityInfo table — shows all identity attributes for the account
  3. The SentinelHealth table — shows all health events for entities
  4. The incident investigation graph — visually maps related incidents sharing the same Account entity
Show answer

Answer: D, The incident investigation graph — visually maps related incidents sharing the same Account entity. The incident investigation graph shows the incident at the centre with all mapped entities as nodes, and visually connects them to other incidents sharing those entities. Clicking the Account entity node reveals all other incidents involving the same user — without any KQL. The IdentityInfo table shows user attributes (department, risk level) but not related incidents. The investigation graph is specifically designed for cross-incident entity correlation.

Question 18. You need alert-level routing in a playbook rather than the whole incident. Which Sentinel trigger passes a single alert?

  1. The schedule trigger
  2. The alert trigger
  3. The entity trigger
  4. The incident trigger
Show answer

Answer: B, The alert trigger. The alert trigger receives one alert. The incident trigger passes the full incident (alerts + entities), and the entity trigger passes a single entity.

Perform threat hunting in Microsoft Sentinel

Question 19. An organisation needs complex iterative KQL analysis of 12-month-old network logs over a 2-week investigation. What is most appropriate?

  1. Use MSTICPy to query cold tier directly
  2. Restore the archived table for 14 days
  3. Extend interactive retention retroactively
  4. Multiple Search Jobs for each query
Show answer

Answer: B, Restore the archived table for 14 days. Restoring archived data brings it into the interactive tier for 7–365 days, enabling immediate full-KQL queries without Search Job submission latency. Better than Search Jobs when many different queries are needed over multiple days.

Question 20. A SOC leader reviews the Hunts metrics bar to justify the hunting programme. What can they demonstrate from it?

  1. Hunts run, hypotheses validated, and the analytics rules and incidents produced
  2. The number of licensed users
  3. Total data-ingestion cost
  4. The workspace's Azure region
Show answer

Answer: A, Hunts run, hypotheses validated, and the analytics rules and incidents produced. The metrics bar shows the programme's tangible output — hunts closed, hypotheses validated, and rules/incidents generated — proving the proactive programme's value.

A 6-week SC-200 study plan

Frequently asked questions

How hard is SC-200?

It's an associate-level exam aimed at people doing, or moving into, security operations work. Most candidates find KQL and Microsoft Sentinel take the most time, so plan extra study there.

How long should I study for SC-200?

Most people studying part-time plan six to eight weeks at 20 to 30 minutes a day. Use the skills outline weightings to decide where that time goes.

Are these real SC-200 exam questions?

No. Microsoft exam questions are confidential, and sharing them breaks the agreement every candidate accepts. These are original questions written to the published skills outline, so they test the same knowledge in the same style.

Is CertBuddi free?

You can enrol free with no card, and SC-200 includes a 7-day free trial with full access, mock exam included. After that, Pro (£9.99 a month, or £79.99 a year) keeps every module, the full timed mock exam and an adaptive study plan.

How should I use these practice questions?

Answer each one before you look at the explanation, and keep a list of the ones you get wrong. That list is your study plan: it's made of exactly the things you don't know yet.

CertBuddi is an independent study aid, not affiliated with or endorsed by Microsoft. These are original practice questions, not real exam questions.