Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
You have 50 Microsoft Sentinel workspaces.
You need to view all the incidents from all the workspaces on a single page in the Azure portal. The solution must minimize administrative effort.
Which page should you use in the Azure portal?
To view incidents across multiple Sentinel workspaces (50 in this case), the central view is provided from the Microsoft Sentinel page in the Azure portal. This page provides a multi-workspace incident view, allowing SOC analysts to see all incidents across all connected workspaces without switching manually.
Microsoft Sentinel -- Incidents shows incidents from a single workspace only.
Microsoft Sentinel -- Workbooks used for analytics visualization.
Log Analytics workspaces only for log storage and queries, not consolidated incident management.
Correct Answe r: C. Microsoft Sentinel
Your on-premises network contains two Active Directory Domain Services (AD DS) domains named contoso.com and fabrikam.com. Contoso.com contains a group named Group1. Fabrikam.com contains a group named Group2.
You have a Microsoft Sentinel workspace named WS1 that contains a scheduled query rule named Rule1. Rule1 generates alerts in response to anomalous AD DS security events. Each alert creates an incident.
You need to implement an incident triage solution that meets the following requirements:
* Security incidents from contoso.com must be assigned to Group1.
* Security incidents from fabrikam.com must be assigned to Group2.
* Administrative effort must be minimized.
What should you include in the solution?
According to Microsoft Sentinel documentation, automation rules are used to automatically assign, tag, or close incidents as soon as they are created. Automation rules can filter incidents based on attributes such as alert name, severity, or source, and then perform specific actions like assigning incidents to users or groups.
In this scenario, incidents are generated by Rule1 from two different AD DS domains --- contoso.com and fabrikam.com --- and each must be routed to a specific security group for triage. The most efficient approach is to create two automation rules, each filtering incidents by domain (one for contoso.com and one for fabrikam.com) and automatically assigning them to Group1 and Group2 respectively. This approach minimizes administrative overhead because automation rules are easy to maintain and don't require the complexity of a playbook.
A playbook (Logic App) could technically achieve the same outcome, but it introduces more administrative management, permissions, and maintenance. Hence, per Microsoft Sentinel best practices, multiple automation rules provide a lightweight and direct automation layer for incident assignment.
Correct Answe r: C. two automation rules assigned to Rule1
You have an Azure subscription that contains a Log Analytics workspace.
You need to enable just-in-time (JIT) VM access and network detections for Azure resources.
Where should you enable Azure Defender?
Just-in-time (JIT) VM access and network layer threat detections are features of Microsoft Defender for Cloud (formerly Azure Security Center ''Azure Defender'' plans). These capabilities are enabled by turning on the relevant Defender plans at the subscription level, which then apply to resources in that subscription. Workspace- or individual resource--level enablement won't activate JIT or the broad network detections across your estate.
You have an Azure subscription that contains a user named User1 and a Microsoft Sentinel workspace named WS1. WS1 uses Microsoft Defender for Cloud.
You have the Microsoft security analytics rules shown in the following table.

User1 performs an action that matches Rule1, Rule2, Rule3, and Rule4. How many incidents will be created in WS1?
Microsoft Sentinel ''Microsoft security'' analytics rules (for products like Defender for Cloud) create incidents from alerts generated by that product. Even if multiple identical Microsoft security rules exist for the same product, a single incoming alert will result in one incident in the workspace, not one per rule.
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 1 and contains a macOS device named Device1.
You need to investigate a Defender for Endpoint agent alert on Device1. The solution must meet the following requirements:
* Identify all the active network connections on Device1.
* Identify all the running processes on Device1.
* Retrieve the login history of Device1.
* Minimize administrative effort.
What should you do first from the Microsoft Defender portal?
In Microsoft Defender for Endpoint, Live Response provides an interactive remote shell for investigating a device directly from the Microsoft Defender portal. It allows security analysts to run commands, collect data, inspect processes, and perform incident response tasks without manually logging into the endpoint.
For this scenario, you must:
Identify all active network connections.
Identify all running processes.
Retrieve login history.
All of these can be achieved efficiently through a Live Response session. Once connected, you can use built-in commands such as:
netstat to view active network connections,
ps to list running processes,
cat or less to review log files containing login history.
According to Microsoft Defender for Endpoint documentation, ''Live response enables analysts to perform in-depth investigation on a device remotely to collect forensic data, run scripts, and remediate threats.'' It is the least administrative-intensive way to gather this information compared to collecting an investigation package, which is more time-consuming and primarily for offline forensic analysis.
Option A (disable authenticated telemetry) is unrelated to investigation tasks.
Option B (enable unsigned script execution) is only needed for running custom scripts, not built-in commands.
Option C (collect investigation package) gathers data for offline review and does not allow interactive analysis.
Option D (initiate live response) gives immediate, interactive insight into processes, connections, and logs --- satisfying all requirements with minimal effort.
Therefore, the correct first step is to initiate a live response session on Device1.
391 questions covering all exam domains, starting from $20
Exam domains verified against: Official Microsoft SC-200 exam guide, last checked September 2026.
Set up automated detections and playbooks in Microsoft Defender XDR and Microsoft Sentinel. Configure alerts, incidents, email notifications, device groups, and attack disruption capabilities. Manage data retention, workspace roles, workbooks, and platform optimization across XDR and Sentinel tiers.
Investigate and remediate threats across Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Cloud, Sentinel, and Entra ID. Triage alerts and incidents, perform device timelines and live response, manage evidence and entities, and use case management tools to handle complex multi-stage attacks.
Create and execute Advanced Hunting queries and KQL jobs across Microsoft Defender XDR and Microsoft Sentinel. Build hunting graphs, analyze entity relationships, interpret threat analytics, create summary rules, and hunt using notebooks with connections to the Sentinel MCP Server.
Common questions about the exam itself