Free practice test

SC-200

Free Microsoft Security Operations Analyst practice test

10 original Security Operations Analyst questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to the authoritative documentation behind it.

Sample question 1 of 10

Manage incident response

Investigation shows a device contained by attack disruption was running an authorized administration tool, not an attack. The device must come back online now. What do you do?

Sample question 2 of 10

Manage security threats

This hunt should list every message that carried the attachment, but returns only one message per file hash.

KQL
EmailAttachmentInfo| where Timestamp > ago(1h)| where Subject == "Document Attachment" and FileName == "Document.pdf"| join (DeviceFileEvents | where Timestamp > ago(1h)) on SHA256

What causes that?

Sample question 3 of 10

Manage a security operations environment

Sentinel ingestion costs have doubled after onboarding verbose firewall logs that are needed for quarterly audits but almost never queried during investigations. What is the appropriate change?

Sample question 4 of 10

Configure protections and detections

A device in Defender for Endpoint is confirmed compromised. You need to stop it reaching other systems while keeping the ability to investigate it from the portal. Which action fits?

Sample question 5 of 10

Manage incident response

An investigation covers eleven months of activity for one account, and the records are within retention. How do you cover that period in Purview Audit?

Sample question 6 of 10

Manage security threats

This hunting query is meant to find accounts with repeated failed sign-ins followed by a success, but it returns nothing.

KQL
SigninLogs| where TimeGenerated > ago(1d)| where ResultType == 0 and ResultType != 0| summarize count() by UserPrincipalName

What is wrong with it?

Sample question 7 of 10

Manage a security operations environment

An access review finds an analyst holding both Microsoft Sentinel Reader and Microsoft Sentinel Contributor on the same resource group. What can that analyst do?

Sample question 8 of 10

Configure protections and detections

A rule returns one row per affected mailbox, and the SOC wants each mailbox tracked and closed on its own. Which event grouping setting does that?

Sample question 9 of 10

Manage incident response

Microsoft Sentinel is raising a separate incident for every alert produced by one analytics rule during a password spray, flooding the queue. Which change consolidates them?

Sample question 10 of 10

Manage security threats

You want every high severity Sentinel incident involving a specific tag to automatically disable the affected account and post to a Teams channel. Which combination does this?

Full Security Operations Analyst question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What this test covers

These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Manage incident response, Manage security threats, Manage a security operations environment, Configure protections and detections. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.

A 10-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 40 questions apportioned to the official domain weightings, sat under the real 100-minute clock and scored against the published cut score.

Other free Microsoft Azure practice tests

AZ-900AZ-104SC-900SC-300AZ-305AZ-400AZ-700AZ-140AZ-800AZ-801SC-100AI-901DP-900DP-300DP-420DP-700MD-102AZ-500

Keep reading

Cheat sheets

Printable reference tables, free.

Compared with

Side by side on cost, difficulty, and which one to take first.

Every guide and cost breakdown, by vendor