Online Access Free SC-200 Practice Test
| Exam Code: | SC-200 | 
| Exam Name: | Microsoft Security Operations Analyst | 
| Certification Provider: | Microsoft | 
| Free Question Number: | 370 | 
| Posted: | Oct 24, 2025 | 
You have a Microsoft 365 E5 subscription that uses Microsoft Exchange Online.
You need to identify phishing email messages.
Which three cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.
You need to implement the Defender for Cloud requirements.
Which subscription-level role should you assign to Group1?
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.
You need to create a hunting query in KQL that meets the following requirements:
* Identifies any devices That received an email containing an attachment named File1 .pdf during the last 12 hours and opened the attachment.
* Minimizes the resources required to run the query.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
You have a Microsoft 365 subscription that uses Microsoft 365 Defender A remediation action for an automated investigation quarantines a file across multiple devices. You need to mark the file as safe and remove the file from quarantine on the devices. What should you use m the Microsoft 365 Defender portal?
You deploy Azure Sentinel.
You need to implement connectors in Azure Sentinel to monitor Microsoft Teams and Linux virtual machines in Azure. The solution must minimize administrative effort.
Which data connector type should you use for each workload? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
 
            



