EarnYourCert
ES EN
All exams › SC-200
Microsoft Certified Associate

SC-200 Practice Exam: Security Operations Analyst

Security operations, incident response and threat hunting with Microsoft Defender XDR and Microsoft Sentinel: 345 original questions with detailed explanations, smart review and progress tracking. Independent prep resource, not affiliated with Microsoft.

345
Questions
50
Per exam
70%
Pass mark
3
Domains

SC-200 exam domains

Manage a security operations environment
40-45%
Respond to security incidents
35-40%
Perform threat hunting
20-25%

Why practice with EarnYourCert

Detailed explanations on every question, not just the right answer.
Smart spaced-repetition review (SRS) to reinforce what you get wrong.
Progress tracking per domain and over time.
Free to start, no sign-up required.

SC-200 sample questions

Five real questions from our 345-question bank. Try to answer before revealing the solution.

1. Which connector ingests Exchange, SharePoint and Teams audit activity into Sentinel?

  1. Syslog via AMA from the Exchange servers
  2. Azure Firewall diagnostic logs connector
  3. Microsoft 365 (Office 365) connector
  4. TAXII
Show answer

Correct answer: C. It populates the OfficeActivity table.

2. Where do you read Microsoft's analysis of a new campaign, including mitigations and affected devices?

  1. Threat analytics in the Defender portal
  2. Entra audit logs for the application
  3. Teams admin center reports on call quality
  4. Intune device compliance reports per platform
Show answer

Correct answer: A. Threat analytics provides reports on emerging threats with exposure, impact and recommended actions.

3. Which Defender for Identity sensor detects lateral movement paths in on-premises Active Directory?

  1. The Azure Arc agent on file servers
  2. The Teams client
  3. The Intune Management Extension
  4. The sensor installed on domain controllers
Show answer

Correct answer: D. Defender for Identity monitors domain controller traffic and raises alerts, including lateral movement paths.

4. You need to return only the columns Timestamp, DeviceName and FileName. Which KQL operator should you use?

  1. union
  2. distinct only
  3. project
  4. join
Show answer

Correct answer: C. project chooses and renames columns.

5. Which table records sign-ins to devices, including logon type and account?

  1. EmailUrlInfo
  2. CloudAppEvents
  3. DeviceRegistryEvents
  4. DeviceLogonEvents
Show answer

Correct answer: D. DeviceLogonEvents is used to hunt for suspicious logons.

Frequently asked questions

How many questions does the SC-200 practice exam have?

The question bank has 345 original questions. Each practice exam draws 50 questions weighted by domain, just like the official exam.

What's the passing score for SC-200?

Microsoft's official SC-200 exam requires a score equivalent to 70% to pass. We use the same threshold in our practice exams so you train under realistic conditions.

What domains does the SC-200 exam cover?

Three domains: manage a security operations environment (40-45%), respond to security incidents (35-40%), and perform threat hunting (20-25%).

Is the SC-200 practice exam free?

Yes, you can practice for free without signing up. Creating a free account adds progress tracking and smart review (SRS); the Pro tier removes daily question limits.

Are these the official Microsoft exam questions?

No. These are original questions written based on Microsoft's official "Skills measured" guide for SC-200, not extracts from the real exam or "exam dumps".