Microsoft

SC-200 Free Practice Questions — Page 3

Question 21

HOTSPOT - You have a Microsoft 365 subscription named contoso.com that contains a Windows 11 device named Device1. Device1 is onboarded to Microsoft Defender for Endpoint. You perform the following actions: • From Defender for Endpoint, create the device groups shown in the following table. • Onboard an Android device named Device2 to Defender for Endpoint. To which device groups will each device be added? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-200 question 21 Illustration for SC-200 question 21
Show Answer
Correct Answer: Device1: Group2 only Device2: Group1 only
Explanation:
Device groups are evaluated by rank, and the first matching rule takes precedence. Device1 (Windows 11, name Device1, domain contoso.com) matches Group2 and Group3, but Group2 has higher priority. Device2 (Android) matches the Android group first and is placed in Group1.

Question 22

You have 1,000 on-premises Windows 11 Pro devices that are onboarded to Microsoft Defender for Endpoint. You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You identify that an attacker performed the following actions on a device: • Modified the file system path of a registry-based antivirus exclusion • Downloaded a malicious file to the file system path You initiate a live response session on the device. You need to remove the malicious file. Which command should you run?

A. collect
B. getfile
C. undo
D. remediate
Show Answer
Correct Answer: D
Explanation:
The correct Live Response command to remove a malicious file from the endpoint is `remediate`. `collect` gathers files for analysis, `getfile` copies a file from the device, and `undo` reverses certain remediation actions rather than deleting an identified malicious file.

Question 23

You have two Microsoft Entra tenants named Tenant1 and Tenant2. Each tenant is linked to an Azure subscription. Tenant1 contains a group named Group1. Tenant2 contains a group named Group2. You need to implement Microsoft Sentinel for each tenant. The solution must meet the following requirements: • Ensure that Group1 can manage security incidents for Tenant1 and Tenant2 in a single workspace. • Ensure that Group2 can manage security incidents only for Tenant2. • Minimize the use of guest accounts. • Minimize administrative effort. • Minimize costs. What should you include in the solution?

A. one workspace and Privileged Identity Management (PIM)
B. one workspace and multiple role-based access control (RBAC) role assignments
C. two workspaces and Azure Lighthouse
D. two workspaces and granular delegated admin privileges (GDAP)
Show Answer
Correct Answer: C
Explanation:
Use two Microsoft Sentinel workspaces, one in each tenant. Azure Lighthouse enables cross-tenant management so Group1 in Tenant1 can manage Sentinel resources, including incidents, across Tenant1 and Tenant2 without creating guest accounts, minimizing guest usage and administrative overhead. Group2 retains access only to the Tenant2 workspace through local RBAC. A single workspace cannot span two Microsoft Entra tenants in the way required, and PIM, RBAC assignments alone, or GDAP do not provide the needed cross-tenant resource delegation for Sentinel management.

Question 24

HOTSPOT - You have a Microsoft Sentinel workspace named Workspace1. The AzureActivity table in Workspace1 has the following retention periods: • Interactive: 180 days • Total: 180 days You need to modify the retention periods to meet the following requirements: • Minimize the costs associated with storing data in the table. • Maximize the period during which the table data remains available. How should you configure each retention period? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-200 question 24
Show Answer
Correct Answer: Interactive: 90 days Total: 2 years
Explanation:
AzureActivity includes 90 days of interactive retention at no additional charge. To minimize cost, keep interactive retention at 90 days. Set total retention to the maximum available (2 years) so older data is kept in long-term retention while maximizing availability.

Question 25

You have an Azure subscription that uses Microsoft Security Copilot. You need to temporarily increase the number of security compute units. What is the smallest interval of time you can be billed for?

A. 1 second
B. 1 minute
C. 1 hour
D. 1 day
Show Answer
Correct Answer: C
Explanation:
Microsoft Security Copilot provisioned Security Compute Units (SCUs) are billed in fixed hourly intervals. Capacity changes take effect for whole clock-hour billing periods, so the smallest billable interval when temporarily increasing SCUs is one hour.

Question 26

You have a Microsoft 365 E5 subscription that contains 500 Windows 11 devices. You have a Microsoft Defender for Endpoint deployment that has the following settings: • Discovery mode: Basic • Live Response: Disabled • Enable EDR in block mode: Off • Tamper Protection: Off You need to implement automatic attack disruption in Microsoft Defender XDR. What should you do?

A. Change Discovery mode to Standard discovery.
B. Set Live Response to On.
C. Set Tamper Protection to On.
D. Set Enable EDR in block mode to On.
Show Answer
Correct Answer: A
Explanation:
Automatic attack disruption in Microsoft Defender XDR has deployment prerequisites. For Microsoft Defender for Endpoint, device discovery must be configured to Standard discovery to enable automatic initiation of the Contain Device action. Live Response, Tamper Protection, and EDR in block mode are not prerequisites for enabling automatic attack disruption itself; attack disruption can operate regardless of Defender Antivirus being in active, passive, or EDR block mode.

Question 27

You have a Microsoft 365 subscription that uses Microsoft Security Copilot. You plan to configure a custom GPT plugin for Copilot. Which GPT model should you use?

A. gpt-4o
B. o1-mini
C. davinci-002
D. gpt-35-turbo
Show Answer
Correct Answer: A
Explanation:
For Microsoft Security Copilot custom GPT plugins, the manifest's ModelName supports gpt-4o. The other options are not the supported model for this plugin configuration.

Question 28

HOTSPOT - You have a Microsoft Sentinel workspace. You have a KQL query. The query returns Microsoft Sentinel incidents that are stored in the SecurityIncident table and occurred during the last 90 days. You need to create a Microsoft Sentinel workbook that will include a visualization of the query. To what should you set Data source and Resource type for the workbook? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-200 question 28
Show Answer
Correct Answer: Data source: Logs (Analytics) Resource type: Microsoft Sentinel
Explanation:
The SecurityIncident table is queried with KQL from the Log Analytics workspace, so the workbook data source is Logs (Analytics). Because the workbook targets Microsoft Sentinel incident data, the resource type is Microsoft Sentinel.

Question 30

You have a Microsoft 365 subscription. The subscription contains 500 Windows 11 devices that are onboarded to Microsoft Defender for Endpoint. You have 500 devices that run Linux. Users sign in to the Windows and Linux devices by using their Microsoft Entra credentials. You need to recommend a response process for Microsoft Defender XDR security incidents associated with a compromised Linux endpoint. The solution must ensure that the compromised device is prevented from communicating with all devices onboarded to Defender for Endpoint. Which response action should you include in the recommendation?

A. Contain user
B. Contain device
C. Isolate device
D. Confirm user compromised
Show Answer
Correct Answer: B
Explanation:
Contain device is the Microsoft Defender XDR response action designed to prevent a compromised device from communicating with other devices onboarded to Defender for Endpoint while allowing limited connectivity to Defender services. Isolate device instead disconnects the endpoint from the network more broadly. Because the requirement specifically states preventing communication with all devices onboarded to Defender for Endpoint, Contain device is the best match. Linux is supported for device containment in Microsoft Defender XDR.

Question 31

DRAG DROP - You have a Microsoft 365 E5 subscription that contains a Windows 11 device named Device1. Device1 is onboarded to Microsoft Defender XDR. You perform the following actions: • Create a PowerShell script named Script1.ps1. • From the Microsoft Defender XDR portal, establish a live response session to Device1. You need to ensure that you can run Script1.ps1 on Device1. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for SC-200 question 31
Show Answer
Correct Answer: From the Microsoft Defender XDR portal, select Advanced features. From the Microsoft Defender XDR portal, upload Script1.ps1 to the library. During the live response session, run the putfile command.
Explanation:
Live Response requires enabling the file library feature, then uploading the script to the library. The putfile command transfers the library file to the endpoint so it can be executed. The library command only lists library files, and getfile retrieves files from the device.

$19

Get all 383 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.