Free practice testSC-200

Free Microsoft Security Operations Analyst practice test

10 real SC-200 questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to Microsoft Azure’s own documentation.

Sample question 1 of 10

Automatic attack disruptionManage incident responseModerate

Investigation shows a device contained by attack disruption was running an authorized administration tool, not an attack. The device must come back online now. What do you do?

Sample question 2 of 10

Advanced hunting query optimizationManage security threatsHard

This hunt should list every message that carried the attachment, but returns only one message per file hash.

EmailAttachmentInfo
| where Timestamp > ago(1h)
| where Subject == "Document Attachment" and FileName == "Document.pdf"
| join (DeviceFileEvents | where Timestamp > ago(1h)) on SHA256

What causes that?

Sample question 3 of 10

Data connectors and costManage a security operations environmentModerate

Sentinel ingestion costs have doubled after onboarding verbose firewall logs that are needed for quarterly audits but almost never queried during investigations. What is the appropriate change?

Sample question 4 of 10

Defender for Endpoint responseConfigure protections and detectionsModerate

A device in Defender for Endpoint is confirmed compromised. You need to stop it reaching other systems while keeping the ability to investigate it from the portal. Which action fits?

Sample question 5 of 10

Microsoft Purview Audit investigationManage incident responseModerate

An investigation covers eleven months of activity for one account, and the records are within retention. How do you cover that period in Purview Audit?

Sample question 6 of 10

KQL huntingManage security threatsHard

This hunting query is meant to find accounts with repeated failed sign-ins followed by a success, but it returns nothing.

SigninLogs
| where TimeGenerated > ago(1d)
| where ResultType == 0 and ResultType != 0
| summarize count() by UserPrincipalName

What is wrong with it?

Sample question 7 of 10

Microsoft Sentinel roles and permissionsManage a security operations environmentModerate

An access review finds an analyst holding both Microsoft Sentinel Reader and Microsoft Sentinel Contributor on the same resource group. What can that analyst do?

Sample question 8 of 10

Microsoft Sentinel analytics rulesConfigure protections and detectionsModerate

A rule returns one row per affected mailbox, and the SOC wants each mailbox tracked and closed on its own. Which event grouping setting does that?

Sample question 9 of 10

Sentinel incidentsManage incident responseModerate

Microsoft Sentinel is raising a separate incident for every alert produced by one analytics rule during a password spray, flooding the queue. Which change consolidates them?

Sample question 10 of 10

AutomationManage security threatsModerate

You want every high severity Sentinel incident involving a specific tag to automatically disable the affected account and post to a Teams channel. Which combination does this?

Full SC-200 question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What this test covers

These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Manage incident response, Manage security threats, Manage a security operations environment, Configure protections and detections. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.

A ten-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 40 questions apportioned to the official domain weightings, sat under the real 100-minute clock and scored against the published cut score.

Keep reading

Every guide and cost breakdown, by vendor