Microsoft Security Operations Analyst practice questions
200 free questions with answers and explanations.
- 1.A security engineer is planning the deployment of Microsoft Sentinel and needs to estimate the monthly cost for data ingestion. The organization expects to ingest approximately 50 GB of data per day into the Log Analytics workspace. Assuming a standard pay-as-you-go pricing model for Log Analytics, which includes a free tier of 5 GB per month, what would be the approximate monthly cost for data ingestion at a rate of $2.30 per GB?Mitigate threats using Microsoft Sentinel
- 2.A security analyst needs to create a custom workbook in Microsoft Sentinel to display specific security metrics and trends for executive reporting. The workbook requires data from both Azure Activity logs and Microsoft Entra ID audit logs. Which language is primarily used to query and visualize this data within a Sentinel workbook?Mitigate threats using Microsoft Sentinel
- 3.A security operations team wants to ensure that all high-severity incidents generated in Microsoft Sentinel automatically create a ticket in their ServiceNow ITSM system. Which Microsoft Sentinel feature should be configured to achieve this integration?Mitigate threats using Microsoft Sentinel
- 4.A company is implementing Microsoft Sentinel and needs to retain security logs for seven years to meet compliance requirements. They are concerned about the cost of long-term retention. Which storage solution should be used for cost-effective, long-term archiving of Sentinel data beyond the standard interactive retention period?Mitigate threats using Microsoft Sentinel
- 5.A security analyst is performing proactive threat hunting in Microsoft Sentinel. The analyst wants to search for unusual processes launched from temporary directories across all Windows endpoints. Which Sentinel feature is specifically designed for interactive, iterative query capabilities to discover new threats?Mitigate threats using Microsoft Sentinel
- 6.A security operations center (SOC) manager is reviewing Microsoft Sentinel incidents and notices that many low-priority alerts from a specific application are generating separate incidents, leading to alert fatigue. The manager wants to group these related alerts into a single incident to streamline investigations. Which incident setting should the manager adjust within the analytics rule that generates these alerts?Mitigate threats using Microsoft Sentinel
- 7.A security analyst is configuring data ingestion for Microsoft Sentinel. The analyst needs to connect Azure Activity logs from multiple subscriptions to a single Sentinel workspace. Which data connector should be used to achieve this efficiently?Mitigate threats using Microsoft Sentinel
- 8.An organization is deploying Microsoft Sentinel and wants to ensure that all security events from their on-premises domain controllers are ingested. These domain controllers run Windows Server 2019. Which agent and data connector combination is required to collect these security events?Mitigate threats using Microsoft Sentinel
- 9.A security analyst is investigating a high-severity incident in Microsoft Sentinel. The analyst needs to quickly understand the relationships between various entities involved, such as compromised users, affected hosts, and suspicious IP addresses, to visualize the attack chain. Which Sentinel feature is designed to provide this graphical representation?Mitigate threats using Microsoft Sentinel
- 10.A security analyst needs to create a custom detection rule in Microsoft Sentinel that identifies anomalous login attempts from geographically disparate locations within a short timeframe. Which type of analytics rule is best suited for this scenario?Mitigate threats using Microsoft Sentinel
- 11.A security architect is designing a Microsoft Sentinel deployment and needs to ensure data residency requirements are met for all ingested logs. The organization operates globally but must keep all data for its European branches within the EU. How can the architect ensure that logs from EU-based resources are stored exclusively in a Log Analytics workspace located in an EU region?Mitigate threats using Microsoft Sentinel
- 12.A security operations team wants to receive real-time notifications via Microsoft Teams whenever a high-severity incident is created in Microsoft Sentinel. What is the most efficient way to configure this type of notification?Mitigate threats using Microsoft Sentinel
- 13.A security analyst is investigating a series of suspicious login attempts originating from unusual geographic locations for several users. The analyst needs to quickly identify all users who have exhibited similar anomalous login patterns over the past week and determine if any of these logins resulted in successful access. Which Microsoft Defender for Identity feature should the analyst use for this investigation?Mitigate threats using Microsoft Defender XDR
- 14.A security analyst is investigating an incident where a user's credentials were potentially compromised. The analyst needs to determine if the compromised credentials were used to access any cloud applications, such as Salesforce or Dropbox, and if any sensitive data was downloaded. Which Microsoft Defender XDR component is best suited to provide this specific visibility and control over cloud app usage?Mitigate threats using Microsoft Defender XDR
- 15.A security engineer is configuring Microsoft Defender for Cloud Apps (MDCAS) to ensure that users accessing sanctioned cloud applications from unmanaged devices are restricted from downloading sensitive company data. They need to implement a policy that detects when a user attempts a download from a specific sanctioned app on an unmanaged device and automatically blocks the download, while also allowing other activities like viewing the data. Which MDCAS policy type should be used?Mitigate threats using Microsoft Defender XDR
- 16.A security analyst is investigating a series of failed login attempts to cloud applications reported by Microsoft Defender for Cloud Apps. They need to determine the specific cloud applications involved and identify any unusual login patterns for a particular user over the last 24 hours. Which Advanced Hunting table should the analyst primarily query to gain this insight?Mitigate threats using Microsoft Defender XDR
- 17.A company uses Microsoft Defender for Identity to protect its on-premises Active Directory environment. The security team has received an alert indicating a 'Suspicious service creation' on a domain controller. Upon investigation, they discover that a new service was created with highly privileged permissions by an account that typically only performs user management tasks. What is the MOST effective immediate action the security team should take using Defender for Identity capabilities?Mitigate threats using Microsoft Defender XDR
- 18.A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint are regularly scanned for vulnerabilities and misconfigurations. The administrator also wants to receive prioritized recommendations to address the most critical risks on these devices. Which specific capability within Microsoft Defender for Endpoint provides this functionality?Mitigate threats using Microsoft Defender XDR
- 19.An organization is migrating several line-of-business applications to Microsoft Azure. The security team needs to monitor these new cloud resources for misconfigurations, vulnerabilities, and potential threats in real-time. They also need to ensure compliance with industry standards like NIST and ISO 27001. Which Microsoft Defender XDR component is best suited for this requirement?Mitigate threats using Microsoft Defender XDR
- 20.A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint are continuously assessed for software vulnerabilities and misconfigurations. They also want to receive actionable recommendations to prioritize and remediate the most critical issues based on their potential impact on the organization. Which specific Microsoft Defender for Endpoint capability directly provides this functionality?Mitigate threats using Microsoft Defender XDR
- 21.A security engineer is configuring Microsoft Defender for Endpoint for a critical server that hosts sensitive financial data. Due to the high sensitivity and strict compliance requirements, the engineer wants to ensure that any detected threats are immediately quarantined with minimal human intervention, but also wants to prevent any automated actions that might disrupt the server's critical operations without prior approval. Which Automated Investigation and Remediation (AIR) automation level should be configured for this server group?Mitigate threats using Microsoft Defender XDR
- 22.A security administrator is evaluating the overall security posture of their organization's cloud resources, which include Azure VMs, Azure Storage accounts, and Azure SQL databases. They need a centralized solution that can provide continuous assessment of security configurations, identify misconfigurations, recommend improvements, and track compliance against industry benchmarks for these diverse Azure services. Which Microsoft Defender XDR component is best suited for this purpose?Mitigate threats using Microsoft Defender XDR
- 23.A security operations center (SOC) team is using Microsoft Defender XDR. They have identified a new, highly sophisticated phishing campaign targeting their organization. This campaign uses unique, never-before-seen file hashes for malicious attachments. The SOC needs to quickly block these specific file hashes across all endpoints managed by Microsoft Defender for Endpoint. Which type of Indicator of Compromise (IoC) should they create in Microsoft Defender XDR?Mitigate threats using Microsoft Defender XDR
- 24.A security operations team wants to ensure that all endpoints within their organization are configured to automatically investigate and remediate security threats without requiring manual intervention for common incidents. Which Microsoft Defender for Endpoint capability should be explicitly enabled and configured to achieve this goal?Mitigate threats using Microsoft Defender XDR
- 25.A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers an alert when a specific PowerShell command containing a base64 encoded string is executed on any endpoint. The rule should identify the command line, the user, and the device involved. Which Advanced Hunting table is most appropriate for querying process execution events to extract this information?Mitigate threats using Microsoft Defender XDR
- 26.A security analyst is investigating an alert from Microsoft Defender for Identity indicating 'Suspicious service creation' on a domain controller. Upon reviewing the alert details, the analyst determines that a legitimate administrator performed the action as part of a planned maintenance window. To prevent similar false positive alerts in the future for this specific legitimate activity, while still maintaining detection for truly malicious service creations, what action should the analyst take within Microsoft Defender for Identity?Mitigate threats using Microsoft Defender XDR
- 27.An organization is implementing Microsoft Defender for Identity to protect its on-premises Active Directory environment. They have several legacy applications and services that perform legitimate administrative actions using service accounts with elevated privileges, which often trigger benign alerts in Defender for Identity due to their unusual behavior patterns. The security team wants to prevent these specific, known-good activities from generating alerts without compromising the overall detection capabilities for actual threats. Which configuration should they implement in Defender for Identity?Mitigate threats using Microsoft Defender XDR
- 28.A security operations center (SOC) team uses Microsoft Defender XDR. They have identified a sophisticated phishing campaign that uses a newly registered domain ('malicious-domain.com') to host credential harvesting pages. To immediately block all network connections to this domain across all endpoints, regardless of the application attempting the connection, which Microsoft Defender for Endpoint capability should the SOC team configure?Mitigate threats using Microsoft Defender XDR
- 29.A security analyst needs to create a custom detection rule in Microsoft Defender XDR to identify instances where a specific, highly sensitive executable (named 'SecretProject.exe') is launched from a non-standard directory on any endpoint. The rule should trigger an alert whenever this executable is run from any location other than 'C:\Program Files\SecretProject\' or 'C:\Program Files (x86)\SecretProject\'. Which KQL table and operator combination should the analyst primarily use for this Advanced Hunting query?Mitigate threats using Microsoft Defender XDR
- 30.A global organization uses Microsoft 365. The security team needs to implement a data loss prevention (DLP) policy to prevent sensitive financial reports, identified by specific keywords and patterns, from being shared externally via email. However, internal sharing of these reports should be allowed. Which type of DLP policy in Microsoft Defender for Office 365 should be configured?Mitigate threats using Microsoft Defender XDR
- 31.A security analyst is investigating a suspected credential stuffing attack against several cloud applications. The analyst needs to identify users who have attempted to log in from unusual locations or with an unusually high number of failed login attempts. Which type of policy in Microsoft Defender for Cloud Apps (MDCAS) is best suited to detect these anomalies?Mitigate threats using Microsoft Defender XDR
- 32.A security analyst is investigating a suspected phishing campaign targeting several users within the organization. The analyst has identified a malicious URL that was included in the phishing emails. To prevent further compromise, the analyst needs to quickly block access to this specific URL across all endpoints and email clients. Which Microsoft Defender XDR component should be used to create a custom indicator to block this malicious URL?Mitigate threats using Microsoft Defender XDR
- 33.A company is implementing Microsoft Defender for Endpoint across its Windows servers and workstations. The security team wants to ensure that all endpoints are configured with the recommended security settings and that any deviations are automatically remediated. Which Defender for Endpoint capability should they utilize for this purpose?Mitigate threats using Microsoft Defender XDR
- 34.An organization is experiencing frequent ransomware attacks targeting its endpoints. The security team has deployed Microsoft Defender for Endpoint and wants to implement proactive measures to prevent the execution of malicious code, particularly from untrusted sources or common attack vectors like email attachments and USB drives. Which Defender for Endpoint feature should be configured to directly address this requirement?Mitigate threats using Microsoft Defender XDR
- 35.A security engineer is configuring Microsoft Defender for Cloud Apps (MDCAS) to enforce strict data governance. The organization requires that users are prevented from downloading sensitive financial documents from unapproved cloud storage services, even if they are logged into their corporate accounts. Instead, they should be redirected to an approved service. Which type of policy and associated action in MDCAS should the engineer implement to meet this requirement?Mitigate threats using Microsoft Defender XDR
- 36.An organization uses Microsoft Defender for Cloud Apps (MDCAS) to monitor cloud application usage. They have identified several unapproved cloud storage applications being used by employees. They want to prevent sensitive corporate data from being uploaded to these unapproved cloud storage apps, while still allowing access to sanctioned cloud apps. Which MDCAS control should be configured to enforce this policy?Mitigate threats using Microsoft Defender XDR
- 37.A security analyst is investigating a potential insider threat scenario. An employee, who recently submitted their resignation, accessed a highly sensitive SharePoint Online document library and downloaded a large number of files. The organization has Microsoft Defender for Cloud Apps (MDCAS) integrated with SharePoint Online. The analyst needs to review a detailed log of all activities performed by this specific user within SharePoint Online, including file access, downloads, and any modifications, to understand the full scope of their actions. Which MDCAS portal feature provides this detailed activity log?Mitigate threats using Microsoft Defender XDR
- 38.An organization is using Microsoft Defender XDR. A security analyst receives an alert indicating a 'Suspicious process injection' on a critical server protected by Defender for Endpoint. The analyst needs to quickly understand if this activity is part of a larger attack chain involving other assets or identities within the organization. Which unified capability within the Microsoft Defender Portal allows the analyst to see the full scope of related alerts and affected entities across different Defender products?Mitigate threats using Microsoft Defender XDR
- 39.A security analyst is reviewing alerts from Microsoft Defender for Identity related to a potential 'Pass-the-Hash' attack. The alerts indicate suspicious NTLM authentication activities from a workstation. To further investigate, the analyst needs to query specific NTLM authentication events, including the source workstation, target server, and authentication type. Which Advanced Hunting table in Microsoft 365 Defender is most appropriate for this investigation?Mitigate threats using Microsoft Defender XDR
- 40.A financial services company uses Microsoft Defender for Office 365. They need to ensure that all email attachments are scanned for malware and zero-day threats before delivery to user mailboxes. If a threat is detected, the attachment should be quarantined, and the email body delivered with a placeholder. Which Defender for Office 365 policy configuration should be implemented to achieve this outcome?Mitigate threats using Microsoft Defender XDR
- 41.A security auditor requires proof that all endpoints managed by Microsoft Defender for Endpoint are regularly checking for and applying the latest security updates and configurations. The auditor specifically wants to see a report detailing the security posture and compliance of devices against Microsoft's recommended security baselines. Which feature within Microsoft Defender for Endpoint should the security team leverage to meet this audit requirement?Mitigate threats using Microsoft Defender XDR
- 42.A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint are consistently configured according to a predefined set of security policies and best practices. They want a solution that can automatically identify deviations from these baselines and provide recommendations for remediation. Which Microsoft Defender for Endpoint capability is best suited for this requirement?Mitigate threats using Microsoft Defender XDR
- 43.A security engineer is configuring Microsoft Defender for Endpoint for a critical server farm. Due to the sensitive nature of the applications running on these servers, any potential false positive from automated remediation could cause significant operational disruption. The engineer wants to ensure that while threats are detected and investigated automatically, any remediation actions explicitly require approval from the security team before being applied. Which automation level for automated investigation and remediation (AIR) should be set for these servers?Mitigate threats using Microsoft Defender XDR
- 44.A security analyst is investigating a potential insider threat where an employee is suspected of exfiltrating sensitive intellectual property. The analyst needs to understand the user's activities across various cloud applications, including file access, download patterns, and unusual login locations, over the past month. Which Microsoft Defender for Cloud Apps (MDCAS) feature provides the most comprehensive historical record of user activities across all connected cloud applications?Mitigate threats using Microsoft Defender XDR
- 45.A global organization uses Microsoft Defender for Identity to protect its hybrid Active Directory environment. A security analyst frequently observes alerts related to 'Suspicious Kerberos authentication activity' (Event ID 4769) originating from legacy applications that perform legitimate, high-volume Kerberos ticket requests. These alerts are generating significant noise and are not indicative of actual threats. The analyst needs to reduce these false positives without disabling the detection for other critical systems. What is the most appropriate action for the analyst to take in Microsoft Defender for Identity?Mitigate threats using Microsoft Defender XDR
- 46.A security analyst is investigating a suspicious file detected on an endpoint by Microsoft Defender for Endpoint. The analyst needs to determine the file's reputation, see if it has been observed in other organizations globally, and identify any associated behaviors or indicators of compromise (IOCs). Which view within the Microsoft 365 Defender portal should the analyst use to gather this comprehensive information about the file?Mitigate threats using Microsoft Defender XDR
- 47.A security team is analyzing a series of alerts generated by Microsoft Defender for Identity related to potential credential theft. They observe multiple instances of 'Kerberos ticket requested with unusual encryption type' (Event ID 4769). To investigate these alerts effectively, which KQL table in Advanced Hunting should they primarily query to find detailed information about these specific Kerberos tickets?Mitigate threats using Microsoft Defender XDR
- 48.A company uses Microsoft Defender for Office 365. The security team has observed a new, highly sophisticated phishing campaign where attackers are using zero-day exploits embedded in PDF attachments to bypass traditional signature-based detection. These attachments are disguised as legitimate financial statements. The team needs to implement a policy to detonate and analyze all suspicious attachments in a sandbox environment before they reach user mailboxes, specifically targeting this new threat vector. Which policy type should the administrator configure?Mitigate threats using Microsoft Defender XDR
- 49.A security operations center (SOC) needs to ensure that all security events from Microsoft Defender for Endpoint are ingested into their existing third-party Security Information and Event Management (SIEM) system for centralized logging and correlation. They want to avoid using Azure Event Hubs as an intermediary due to existing architectural constraints. Which direct integration method should the SOC team prioritize for connecting Defender for Endpoint to their SIEM?Mitigate threats using Microsoft Defender XDR
- 50.A security engineer is configuring a new Microsoft Defender for Endpoint deployment. The organization has several legacy applications that are known to perform actions (e.g., modifying specific registry keys or accessing certain network shares) that might be flagged as suspicious by Defender for Endpoint but are legitimate for these applications. To prevent excessive false positives, the engineer needs to ensure these specific actions are ignored by Defender for Endpoint while maintaining protection for all other activities. Which of the following should the engineer implement?Mitigate threats using Microsoft Defender XDR