Exam Code: SC-200
Exam Questions: 373
Microsoft Security Operations Analyst
Updated: 18 Feb, 2026
Viewing Page : 1 - 38
Practicing : 1 - 5 of 373 Questions
Question 1

You need to configure Microsoft Defender for Cloud Apps to generate alerts and trigger remediation actions in response to external sharing of confidential files.

Which two actions should you perform in the Microsoft 365 Defender portal? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options :
Answer: B,F

Question 2

You have two Azure subscriptions that use Microsoft Defender for Cloud.
You need to ensure that specific Defender for Cloud security alerts are suppressed at the root management group level. The solution must minimize administrative effort.
What should you do in the Azure portal?

Options :
Answer: D

Question 3

You plan to review Microsoft Defender for Cloud alerts by using a third-party security information and event management (SIEM) solution.

You need to locate alerts that indicate the use of the Privilege Escalation MITRE ATT&CK tactic.

Which JSON key should you search?

Options :
Answer: A

Question 4

You need to implement the Defender for Cloud requirements. Which subscription-level role should you assign to Group1?  

Options :
Answer: D

Question 5

Your company uses Azure Security Center and Azure Defender.
The security operations team at the company informs you that it does NOT receive email notifications for security alerts.
What should you configure in Security Center to enable the email notifications?

Options :
Answer: C

Viewing Page : 1 - 38
Practicing : 1 - 5 of 373 Questions

© Copyrights FreePDFQuestions 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.