Free Microsoft Security Operations Analyst practice test
10 real SC-200 questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to Microsoft Azure’s own documentation.
Sample question 1 of 10
Investigation shows a device contained by attack disruption was running an authorized administration tool, not an attack. The device must come back online now. What do you do?
Sample question 2 of 10
This hunt should list every message that carried the attachment, but returns only one message per file hash.
EmailAttachmentInfo
| where Timestamp > ago(1h)
| where Subject == "Document Attachment" and FileName == "Document.pdf"
| join (DeviceFileEvents | where Timestamp > ago(1h)) on SHA256What causes that?
Sample question 3 of 10
Sentinel ingestion costs have doubled after onboarding verbose firewall logs that are needed for quarterly audits but almost never queried during investigations. What is the appropriate change?
Sample question 4 of 10
A device in Defender for Endpoint is confirmed compromised. You need to stop it reaching other systems while keeping the ability to investigate it from the portal. Which action fits?
Sample question 5 of 10
An investigation covers eleven months of activity for one account, and the records are within retention. How do you cover that period in Purview Audit?
Sample question 6 of 10
This hunting query is meant to find accounts with repeated failed sign-ins followed by a success, but it returns nothing.
SigninLogs
| where TimeGenerated > ago(1d)
| where ResultType == 0 and ResultType != 0
| summarize count() by UserPrincipalNameWhat is wrong with it?
Sample question 7 of 10
An access review finds an analyst holding both Microsoft Sentinel Reader and Microsoft Sentinel Contributor on the same resource group. What can that analyst do?
Sample question 8 of 10
A rule returns one row per affected mailbox, and the SOC wants each mailbox tracked and closed on its own. Which event grouping setting does that?
Sample question 9 of 10
Microsoft Sentinel is raising a separate incident for every alert produced by one analytics rule during a password spray, flooding the queue. Which change consolidates them?
Sample question 10 of 10
You want every high severity Sentinel incident involving a specific tag to automatically disable the affected account and post to a Teams channel. Which combination does this?
Full SC-200 question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
What this test covers
These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Manage incident response, Manage security threats, Manage a security operations environment, Configure protections and detections. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.
A ten-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 40 questions apportioned to the official domain weightings, sat under the real 100-minute clock and scored against the published cut score.
Keep reading
SC-200 practice questions
Free sample questions with the full explanation on every answer.
SC-200 passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is SC-200?
An honest difficulty read from the format, the clock and the weights.