Exam Code: SC-200
Exam Questions: 394
Microsoft Security Operations Analyst
Updated: 03 Sep, 2026
Viewing Page : 1 - 40
Practicing : 1 - 5 of 394 Questions
Question 1

You have an Azure subscription that uses Microsoft Defender for Cloud. You need to filter the security alerts view to show the following alerts:
* Unusual user accessed a key vault
* Log on from an unusual location
* Impossible travel activity
Which severity should you use?

Options :
Answer: C

Question 2

You have 50 Microsoft Sentinel workspaces.

You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort.

Which page should you use in the Azure portal?

Options :
Answer: D

Question 3

You have an Azure subscription that contains a Microsoft Sentinel workspace. The workspace contains a Microsoft Defender for Cloud data connector.
You need to customize which details will be included when an alert is created for a specific event.
What should you do?

Options :
Answer: D

Question 4

You need to assign a role-based access control (RBAC) role to admin1 to meet the Azure Sentinel requirements and the business requirements.
Which role should you assign?

Options :
Answer: C

Question 5

A company uses Azure Sentinel.
You need to create an automated threat response.
What should you use?

Options :
Answer: B

Viewing Page : 1 - 40
Practicing : 1 - 5 of 394 Questions

© Copyrights FreePDFQuestions 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.