Free Microsoft SC-200 Exam Actual Questions

The questions for SC-200 were last updated On Jan 16, 2025

Question No. 1

You need to implement the Defender for Cloud requirements.

What should you configure for Server2?

Show Answer Hide Answer
Correct Answer: D

Question No. 2

You need to implement the Defender for Cloud requirements.

Which subscription-level role should you assign to Group1?

Show Answer Hide Answer
Correct Answer: B

Question No. 3

You create a hunting query in Azure Sentinel.

You need to receive a notification in the Azure portal as soon as the hunting query detects a match on the query. The solution must minimize effort.

What should you use?

Show Answer Hide Answer
Correct Answer: C

Use livestream to run a specific query constantly, presenting results as they come in.


https://docs.microsoft.com/en-us/azure/sentinel/hunting

Question No. 4

You provision Azure Sentinel for a new Azure subscription. You are configuring the Security Events connector.

While creating a new rule from a template in the connector, you decide to generate a new alert for every event. You create the following rule query.

By which two components can you group alerts into incidents? Each correct answer presents a complete

solution.

NOTE: Each correct selection is worth one point.

Show Answer Hide Answer
Correct Answer: C, D

Question No. 5

You have a Microsoft 365 subscription that uses Microsoft 365 Defender.

You need to identify all the entities affected by an incident.

Which tab should you use in the Microsoft 365 Defender portal?

Show Answer Hide Answer
Correct Answer: C

The Evidence and Response tab shows all the supported events and suspicious entities in the alerts in the incident.