Security operations, incident response and threat hunting with Microsoft Defender XDR and Microsoft Sentinel: 345 original questions with detailed explanations, smart review and progress tracking. Independent prep resource, not affiliated with Microsoft.
Five real questions from our 345-question bank. Try to answer before revealing the solution.
1. Which connector ingests Exchange, SharePoint and Teams audit activity into Sentinel?
Correct answer: C. It populates the OfficeActivity table.
2. Where do you read Microsoft's analysis of a new campaign, including mitigations and affected devices?
Correct answer: A. Threat analytics provides reports on emerging threats with exposure, impact and recommended actions.
3. Which Defender for Identity sensor detects lateral movement paths in on-premises Active Directory?
Correct answer: D. Defender for Identity monitors domain controller traffic and raises alerts, including lateral movement paths.
4. You need to return only the columns Timestamp, DeviceName and FileName. Which KQL operator should you use?
Correct answer: C. project chooses and renames columns.
5. Which table records sign-ins to devices, including logon type and account?
Correct answer: D. DeviceLogonEvents is used to hunt for suspicious logons.
The question bank has 345 original questions. Each practice exam draws 50 questions weighted by domain, just like the official exam.
Microsoft's official SC-200 exam requires a score equivalent to 70% to pass. We use the same threshold in our practice exams so you train under realistic conditions.
Three domains: manage a security operations environment (40-45%), respond to security incidents (35-40%), and perform threat hunting (20-25%).
Yes, you can practice for free without signing up. Creating a free account adds progress tracking and smart review (SRS); the Pro tier removes daily question limits.
No. These are original questions written based on Microsoft's official "Skills measured" guide for SC-200, not extracts from the real exam or "exam dumps".