20 free SC-200 practice questions with answers and explanations, covering Microsoft Defender XDR, Microsoft Sentinel, KQL and incident response. Try each one before you open the answer: testing yourself is how it sticks.
Study the full SC-200 course, free to start.
Official SC-200 study guide on Microsoft Learn
Question 1. A marketing agency legitimately sends newsletters as your domain, and EOP keeps flagging them as spoofing. What's the cleanest, properly-scoped fix?
Answer: D, Allow them as a permitted spoof pair in spoof intelligence. A legitimate third party sending as your domain is handled by allowing that spoof pair in spoof intelligence — a targeted allow. An IP allow list and transport-rule bypass switch off too much protection, and per-user Safe Senders don't scale or address spoof verdicts.
Question 2. Which Safe Attachments policy action delivers the message body immediately but withholds attachments until scanning completes, then reattaches clean ones?
Answer: B, Dynamic Delivery. Dynamic Delivery sends the email right away and delivers attachments once they pass scanning, avoiding delays. Block/Replace/Monitor handle detonated mail differently.
Question 3. A SOC lead questions why grounding matters so much in a security AI tool. Why is grounding particularly important in Security Copilot?
Answer: B, It ensures responses are based on current, specific environment data rather than generic training knowledge. Security threats and incidents change constantly. Without grounding, Copilot would produce generic answers from training data — not answers specific to the actual environment. Grounding with live data from Sentinel, Defender XDR, and MDTI makes responses actionable.
Question 4. A colleague asks how a Security Copilot agent differs from a promptbook. What's the difference?
Answer: D, An agent is an autonomous, adaptive automation that acts on tasks; a promptbook replays a fixed prompt sequence you trigger. Agents autonomously handle high-volume tasks and adapt from feedback (within Zero Trust); promptbooks are fixed, analyst-triggered prompt sequences. Both can consume SCUs.
Question 5. Which insider risk detection identifies a departing user slowly leaking data over many days, where no single day is anomalous?
Answer: B, Cumulative exfiltration detection. Cumulative exfiltration detection uses ML to compare a user's total exfiltration over time against org and peer norms (30 days), catching low-and-slow leakage that wouldn't trigger a single-event alert.
Question 6. Investigating BEC persistence, which audit activity do you search for to find mailboxes where the attacker granted themselves access?
Answer: B, Set-MailboxPermission. Set-MailboxPermission reveals where Full Access or similar was granted — a common BEC persistence technique. The others relate to file access, sign-ins, and retention configuration.
Question 7. An attacker takes the bait and interacts with a deception lure on an endpoint. What does that interaction generate?
Answer: C, A high-confidence alert indicating likely attacker activity. Because legitimate users never touch lures, interaction is a near-zero-false-positive signal of attacker activity.
Question 8. You grab the local onboarding script to quickly test MDE on a few machines. Roughly how many devices is that script intended for?
Answer: D, Up to about 10 (for testing). The local script is for up to ~10 devices for testing. At scale you use Intune, Group Policy, or Configuration Manager.
Question 9. A Defender for SQL alert fires: 'Potential SQL injection: unusual string observed'. What is the most appropriate immediate response?
Answer: C, Investigate the alert details to identify the source IP and the specific query pattern, then assess whether the web application has a SQL injection vulnerability to patch. The correct response is investigation: review the alert details (source IP, query pattern, authentication method), determine whether the query pattern indicates an actual vulnerability in the web application, and then prioritise remediation — potentially patching the application or applying a WAF rule. Taking the database offline disrupts business. Dismissing ignores a potential breach.
Question 10. An Azure VM is exfiltrating data via DNS tunnelling. Which plan detects this?
Answer: C, Microsoft Defender for DNS. Defender for DNS detects tunnelling, malicious-domain lookups, and crypto-mining/C2 DNS activity. (For new subscriptions it's bundled into Defender for Servers Plan 2.)
Question 11. Use DisplayName, but fall back to UPN, then 'unknown', when earlier ones are empty. Users | extend Name = ___(DisplayName, UserPrincipalName, 'unknown')
Answer: C, coalesce. coalesce(a,b,c) returns the first non-null/non-empty argument, ideal for fallbacks. iff/case branch on predicates, and isnotempty tests a single value.
Question 12. Bucket each event to midnight of its day. SecurityEvent | extend Day = ___(TimeGenerated)
Answer: B, startofday. startofday() returns midnight of that day (startofweek/startofmonth do the week/month). bin rounds to an interval, format_datetime formats, and datetime_diff subtracts.
Question 13. A Sentinel deployment stops receiving logs from the AWS connector without generating any visible alerts or incidents. How should this ingestion gap be detected?
Answer: C, Query the SentinelHealth table or review the Sentinel Health workbook for connector status and last ingestion time. The SentinelHealth table records health events for all Sentinel components including data connectors — showing last successful ingestion time and any errors. The Sentinel Health workbook visualises this data. This is the designed mechanism for detecting silent connector failures. A custom rule (option 4) is a valid backup approach but SentinelHealth is the primary, purpose-built solution.
Question 14. You're building a Scheduled analytics rule and the wizard has several tabs. Which elements define such a rule?
Answer: D, A KQL query, run schedule/lookback, alert threshold, entity mapping, and incident-creation settings. A Scheduled rule comprises the KQL, scheduling/lookback, threshold, event/alert grouping, entity mapping, and incident settings — far more than just a query.
Question 15. After enabling the Microsoft Defender XDR connector in Sentinel with Advanced Hunting data enabled, an analyst wants to write a Sentinel analytics rule that detects when a device that received a phishing email later shows suspicious process execution. Which tables are needed?
Answer: B, EmailEvents and DeviceProcessEvents, email delivery and endpoint process execution. EmailEvents (from Defender XDR connector) contains phishing delivery events with recipient and device information. DeviceProcessEvents (from Defender XDR connector) contains process execution events including command lines and parent processes. Joining these on the device or user entity enables detecting the 'phishing delivery, then payload execution' attack chain in a single cross-product analytics rule.
Question 16. The Microsoft Defender XDR connector has three independent toggles. Which one integrates on-premises Active Directory identities (via Defender for Identity) into UEBA?
Answer: C, Connect entities. 'Connect entities' brings on-prem AD identities into UEBA. 'Connect incidents & alerts' syncs the incident queue, and 'Connect events' streams raw advanced-hunting tables.
Question 17. An analyst investigating a compromised account incident wants to see all other incidents that have involved this same user account — without writing a KQL query. Which Sentinel feature provides this?
Answer: D, The incident investigation graph — visually maps related incidents sharing the same Account entity. The incident investigation graph shows the incident at the centre with all mapped entities as nodes, and visually connects them to other incidents sharing those entities. Clicking the Account entity node reveals all other incidents involving the same user — without any KQL. The IdentityInfo table shows user attributes (department, risk level) but not related incidents. The investigation graph is specifically designed for cross-incident entity correlation.
Question 18. You need alert-level routing in a playbook rather than the whole incident. Which Sentinel trigger passes a single alert?
Answer: B, The alert trigger. The alert trigger receives one alert. The incident trigger passes the full incident (alerts + entities), and the entity trigger passes a single entity.
Question 19. An organisation needs complex iterative KQL analysis of 12-month-old network logs over a 2-week investigation. What is most appropriate?
Answer: B, Restore the archived table for 14 days. Restoring archived data brings it into the interactive tier for 7–365 days, enabling immediate full-KQL queries without Search Job submission latency. Better than Search Jobs when many different queries are needed over multiple days.
Question 20. A SOC leader reviews the Hunts metrics bar to justify the hunting programme. What can they demonstrate from it?
Answer: A, Hunts run, hypotheses validated, and the analytics rules and incidents produced. The metrics bar shows the programme's tangible output — hunts closed, hypotheses validated, and rules/incidents generated — proving the proactive programme's value.
It's an associate-level exam aimed at people doing, or moving into, security operations work. Most candidates find KQL and Microsoft Sentinel take the most time, so plan extra study there.
Most people studying part-time plan six to eight weeks at 20 to 30 minutes a day. Use the skills outline weightings to decide where that time goes.
No. Microsoft exam questions are confidential, and sharing them breaks the agreement every candidate accepts. These are original questions written to the published skills outline, so they test the same knowledge in the same style.
You can enrol free with no card, and SC-200 includes a 7-day free trial with full access, mock exam included. After that, Pro (£9.99 a month, or £79.99 a year) keeps every module, the full timed mock exam and an adaptive study plan.
Answer each one before you look at the explanation, and keep a list of the ones you get wrong. That list is your study plan: it's made of exactly the things you don't know yet.
CertBuddi is an independent study aid, not affiliated with or endorsed by Microsoft. These are original practice questions, not real exam questions.