{"id":15803,"date":"2026-09-18T09:44:25","date_gmt":"2026-09-18T09:44:25","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15803"},"modified":"2026-09-18T09:44:25","modified_gmt":"2026-09-18T09:44:25","slug":"microsoft-sc-200-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-200-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"Microsoft SC-200 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-200-exam-dumps\"><b>Microsoft SC-200 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 101<\/b><\/h3>\n<p><b>Which Microsoft Defender for Endpoint feature allows an analyst to execute commands directly on an affected device during an investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Live response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device discovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Live response provides security analysts with a remote command-line capability for investigating and responding to devices in Microsoft Defender for Endpoint. Depending on permissions and available commands, analysts can collect files, inspect processes, investigate artifacts, and perform supported response actions. This capability is particularly useful when an endpoint requires immediate investigation without waiting for physical access. Analysts should use live response carefully because commands can affect the device. Actions should be documented and performed according to organizational incident-response procedures and assigned permissions.<\/span><\/p>\n<h3><b>Question 102<\/b><\/h3>\n<p><b>An analyst wants to identify which processes created a suspicious file on an endpoint. Which Microsoft Defender for Endpoint capability should be examined first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device timeline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack simulation training<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The device timeline provides a chronological view of activities associated with a device. Analysts can use it to investigate processes, files, network connections, and other events surrounding suspicious activity. By examining events before and after a file was created, an analyst may identify the process responsible for creating it and determine whether additional related activity occurred. This timeline-based investigation can help establish the sequence of events during an incident. Analysts should correlate the timeline with alerts, file information, user activity, and other available evidence.<\/span><\/p>\n<h3><b>Question 103<\/b><\/h3>\n<p><b>Which Microsoft Defender for Office 365 feature is designed to analyze potentially malicious email attachments before they reach users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat Explorer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack simulation training<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Safe Attachments helps protect users by analyzing email attachments for malicious content. Attachments can be examined using Microsoft Defender for Office 365 protection mechanisms before messages are delivered according to the organization&#8217;s configured policies. This helps reduce the risk of users opening malicious files delivered through email. Analysts investigating suspicious messages can also use Defender for Office 365 investigation capabilities to review related detections and message activity. Safe Attachments focuses specifically on attachment-based threats, while Safe Links addresses potentially dangerous URLs contained in messages.<\/span><\/p>\n<h3><b>Question 104<\/b><\/h3>\n<p><b>Which capability can an analyst use to investigate potentially malicious URLs found in email messages?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat Explorer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Identity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat Explorer in Microsoft Defender for Office 365 provides investigation capabilities for analyzing email-related threats, including messages containing suspicious URLs. Analysts can search and filter email activity to identify affected users, messages, sender information, URLs, and other relevant details. This can help determine whether a malicious link was delivered broadly or targeted at specific users. Analysts can combine Threat Explorer findings with Safe Links information and other security signals. The resulting evidence can support decisions about message remediation, user notification, and further investigation.<\/span><\/p>\n<h3><b>Question 105<\/b><\/h3>\n<p><b>Which Microsoft Sentinel component allows analysts to visualize security data through interactive dashboards and charts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automation rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbook<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlist<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel workbooks provide interactive visualizations for security and operational data. Analysts can use charts, tables, graphs, and other visual elements to examine trends and summarize information from connected data sources. Workbooks can be based on existing templates or customized to meet organizational monitoring requirements. They are useful for presenting information such as incident trends, authentication activity, and security events. Unlike analytics rules, workbooks do not primarily detect threats. Their main purpose is to help analysts visualize, explore, and communicate information contained in the underlying data.<\/span><\/p>\n<h3><b>Question 106<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability can automatically modify an incident when specific conditions are met?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automation rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbook<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlist<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hunting query<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automation rules allow Microsoft Sentinel to automatically perform actions on incidents when defined conditions are satisfied. For example, a rule can assign an incident to a specific analyst, change its status, add a tag, or trigger other configured actions. Automation helps standardize repetitive incident-management tasks and can reduce manual workload for security operations teams. Rules should be configured carefully so that conditions are specific enough to avoid unintended actions. Analysts should regularly review automation behavior to ensure that incident workflows continue to match operational requirements.<\/span><\/p>\n<h3><b>Question 107<\/b><\/h3>\n<p><b>An organization needs to compare incoming events against a maintained list of known malicious IP addresses. Which Sentinel capability is suitable for storing the reference list?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbook<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbook<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlist<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Microsoft Sentinel watchlist can store reference information such as IP addresses, domains, usernames, or other values that analysts may need during security monitoring. A watchlist can be referenced from KQL queries to compare incoming or historical data against the maintained list. This is useful when an organization regularly maintains a collection of known indicators or business-specific reference values. Watchlists should be maintained carefully because outdated or inaccurate entries can produce misleading results. Analysts should periodically review their contents and remove indicators that are no longer relevant.<\/span><\/p>\n<h3><b>Question 108<\/b><\/h3>\n<p><b>Which Microsoft Defender XDR capability can help identify suspicious activities associated with user identities in an on-premises Active Directory environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender for Identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender for Office 365<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel workbook<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Identity monitors identity-related signals from on-premises Active Directory environments and helps security teams identify suspicious identity activity. It can provide detections involving techniques such as credential theft, reconnaissance, lateral movement, and other identity-related threats. Analysts can use its alerts and investigation information to understand potentially compromised accounts and suspicious behavior. Defender for Identity complements endpoint, email, and cloud security capabilities rather than replacing them. Correlating identity findings with endpoint and authentication evidence can provide a more complete view of an attack.<\/span><\/p>\n<h3><b>Question 109<\/b><\/h3>\n<p><b>Which KQL operator is used to select specific columns and remove unwanted columns from query results?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">summarize<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">join<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">extend<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">project<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The KQL <\/span><span style=\"font-weight: 400;\">project<\/span><span style=\"font-weight: 400;\"> operator controls which columns appear in the final query results. Analysts commonly use it to focus output on fields that are relevant to an investigation, such as timestamps, usernames, IP addresses, device names, or process information. Reducing unnecessary columns can make query results easier to read and review. The <\/span><span style=\"font-weight: 400;\">project<\/span><span style=\"font-weight: 400;\"> operator differs from <\/span><span style=\"font-weight: 400;\">extend<\/span><span style=\"font-weight: 400;\">, which creates calculated columns. Analysts should select fields that provide sufficient context for the investigation while avoiding unnecessary output that makes results harder to interpret.<\/span><\/p>\n<h3><b>Question 110<\/b><\/h3>\n<p><b>A security analyst wants to combine records from two KQL tables using a shared field. Which operator should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">where<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">join<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">project<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">order by<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The KQL <\/span><span style=\"font-weight: 400;\">join<\/span><span style=\"font-weight: 400;\"> operator combines rows from two tables based on matching values in specified columns. This is useful when relevant investigation information is distributed across different datasets. For example, an analyst may join related records using a device identifier, account name, or another common field. Different join strategies can affect which records are returned, so analysts should choose the appropriate type for the investigation. Queries should also be tested with manageable time ranges because joins across large datasets can increase query complexity and processing requirements.<\/span><\/p>\n<h3><b>Question 111<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability allows an organization to ingest security events from supported external data sources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automation rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel data connectors provide mechanisms for bringing data from supported Microsoft services and external solutions into the Sentinel environment. Depending on the connector, organizations can ingest security events, logs, alerts, and other relevant telemetry. Proper ingestion is essential because analytics rules and hunting queries depend on available data. Analysts should verify that connectors are enabled, authenticated, and receiving expected events. They should also monitor ingestion health and configuration because missing or delayed data can create gaps in detection and negatively affect incident investigations.<\/span><\/p>\n<h3><b>Question 112<\/b><\/h3>\n<p><b>Which Microsoft Defender for Endpoint action can restrict a compromised device from communicating with the network while allowing limited Defender connectivity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Collect investigation package<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Live response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device discovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device isolation is a response action in Microsoft Defender for Endpoint that can restrict a compromised device&#8217;s network communication. The purpose is to limit an attacker&#8217;s ability to communicate with or move through the environment while maintaining the connectivity required for Defender-related management and response activities. Isolation can be valuable when an endpoint is actively compromised or exhibiting serious malicious behavior. Analysts should consider business impact before isolating critical systems and should document the reason for the action. The device can be restored when appropriate after investigation.<\/span><\/p>\n<h3><b>Question 113<\/b><\/h3>\n<p><b>Which Microsoft Defender for Office 365 feature can help security teams investigate and analyze email messages across an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device timeline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat Explorer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Live response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exposure management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat Explorer provides investigation capabilities for email-related security activity in Microsoft Defender for Office 365. Analysts can search and filter message information to investigate suspicious email campaigns, affected recipients, senders, URLs, attachments, and related detection information. This is particularly useful when determining the scope of a phishing campaign or identifying whether similar messages reached multiple users. Analysts can use the results to support remediation and incident response. Access to relevant message and threat information depends on the organization&#8217;s licensing, configuration, permissions, and available telemetry.<\/span><\/p>\n<h3><b>Question 114<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability is specifically designed to execute automated response workflows after a security event occurs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Watchlist<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbook<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbook<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Content hub<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Microsoft Sentinel playbook executes an automated workflow that can respond to security events or incidents. Playbooks are based on Azure Logic Apps and can perform actions such as sending notifications, creating tickets, enriching indicators, or interacting with supported security services. They are useful for reducing repetitive manual response tasks and enforcing consistent procedures. Organizations should carefully define the triggers, permissions, and actions within each playbook. Automated response can have operational consequences, so workflows should be tested and reviewed before being used for sensitive production actions.<\/span><\/p>\n<h3><b>Question 115<\/b><\/h3>\n<p><b>Which Microsoft Defender XDR capability provides information about active threats, attack techniques, and related security research?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device discovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Live response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device isolation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat analytics provides information about important active or emerging threats and can help security teams understand relevant attack techniques and affected security areas. Analysts can use this information to determine whether their organization may be exposed to a particular threat and review available recommendations or related detections. Threat analytics supports threat awareness and investigation but does not replace direct examination of organizational telemetry. Analysts should validate whether the described threat applies to their environment and then use appropriate Defender or Sentinel data to investigate potentially related activity.<\/span><\/p>\n<h3><b>Question 116<\/b><\/h3>\n<p><b>What is the primary purpose of a Microsoft Sentinel analytics rule?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Display data in a dashboard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store indicator lists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detect potentially suspicious activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign incidents to analysts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The primary purpose of a Microsoft Sentinel analytics rule is to detect potentially suspicious or otherwise important activity within collected security data. Analytics rules evaluate data according to configured detection logic and can generate alerts when matching conditions are identified. Many rules use KQL to define the activity that should be detected. Proper rule configuration is important because poorly tuned detections can generate excessive false positives or miss meaningful activity. Security teams should periodically review rule performance, tune thresholds, and verify that the required data sources remain available.<\/span><\/p>\n<h3><b>Question 117<\/b><\/h3>\n<p><b>Which KQL operator is commonly used to calculate statistics such as event counts for grouped records?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">summarize<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">where<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">project<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">extend<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The KQL <\/span><span style=\"font-weight: 400;\">summarize<\/span><span style=\"font-weight: 400;\"> operator performs aggregation operations across records. Analysts can use it to calculate counts, minimum or maximum values, averages, and other statistics, often grouped by fields such as usernames, IP addresses, devices, or event types. For example, an analyst can summarize authentication events by account to identify unusually high numbers of failed attempts. Aggregation can significantly reduce a large dataset into useful investigative patterns. Analysts should select appropriate grouping fields and time ranges so that the resulting statistics accurately represent the activity being investigated.<\/span><\/p>\n<h3><b>Question 118<\/b><\/h3>\n<p><b>An analyst discovers a suspicious executable on a device and needs additional evidence about files, processes, and related activity. Which action can help collect a set of investigation artifacts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Collect investigation package<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automation rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The investigation package capability in Microsoft Defender for Endpoint can collect a set of forensic and diagnostic information from a device to support investigation. Depending on the available collection capabilities, the package can provide information about processes, files, network activity, and other relevant system artifacts. This can be useful when an analyst needs additional evidence beyond the information immediately visible in an alert or device timeline. Analysts should handle collected investigation data securely because it may contain sensitive information. The package should be reviewed alongside other incident evidence.<\/span><\/p>\n<h3><b>Question 119<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability can be used to install and manage packaged solution content for security products and scenarios?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Content hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat Explorer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Live response<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft Sentinel content hub provides packaged solution content that can support specific products, services, and security scenarios. Depending on the solution, available content may include data connectors, analytics rules, hunting queries, workbooks, parsers, and other components. Using packaged content can accelerate deployment of commonly required security capabilities. Administrators should review prerequisites and configuration requirements before enabling a package. They should also keep deployed content maintained because updates may improve detection logic, add functionality, or address changes in the supported Microsoft or third-party service.<\/span><\/p>\n<h3><b>Question 120<\/b><\/h3>\n<p><b>A security analyst wants to identify repeated failed authentication attempts by user and determine which accounts have unusually high failure counts. Which KQL approach is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use <\/span><span style=\"font-weight: 400;\">project<\/span><span style=\"font-weight: 400;\"> to display every available field<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use <\/span><span style=\"font-weight: 400;\">extend<\/span><span style=\"font-weight: 400;\"> without aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use <\/span><span style=\"font-weight: 400;\">summarize<\/span><span style=\"font-weight: 400;\"> with a count grouped by user<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use <\/span><span style=\"font-weight: 400;\">join<\/span><span style=\"font-weight: 400;\"> without specifying a common field<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Using <\/span><span style=\"font-weight: 400;\">summarize<\/span><span style=\"font-weight: 400;\"> with a count grouped by user is an effective KQL approach for identifying repeated failed authentication attempts. The analyst can first filter the relevant authentication events and then aggregate them by account to determine how many failures occurred for each user. This makes it easier to identify accounts with unusually high failure volumes. Additional fields, such as source IP addresses and timestamps, can provide context for investigation. Analysts should consider normal authentication patterns and legitimate causes before treating a high failure count as evidence of an attack.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-200 Exam Dumps and Practice Test Dumps. &nbsp; Question 101 Which Microsoft Defender for Endpoint feature allows an analyst to execute commands directly on an affected device during an investigation? Live response Device discovery Threat analytics Secure Score Correct Answer: 1 Explanation Live response provides security analysts with a remote command-line capability [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15803"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15803"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15803\/revisions"}],"predecessor-version":[{"id":15832,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15803\/revisions\/15832"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}