Microsoft Security Operations Analyst practice questions

200 free questions with answers and explanations.

Practice test
  1. 151.A security engineer is investigating a high-severity alert in Microsoft Defender for Cloud indicating 'Suspicious RDP activity from an unusual location' on an Azure VM. The VM is critical for a production application. After initial investigation, the engineer suspects the RDP port (3389) might be exposed to the internet. Which immediate action should the engineer take within Defender for Cloud to mitigate the potential threat while minimizing disruption to legitimate users who occasionally need RDP access?Mitigate threats using Microsoft Defender for Cloud
  2. 152.A security engineer is implementing a security baseline for Azure Kubernetes Service (AKS) clusters using Microsoft Defender for Cloud. The organization requires continuous monitoring for misconfigurations, deviations from best practices, and runtime threats within the Kubernetes environment, including pods, containers, and nodes. Which Defender for Cloud plan should be enabled to provide this comprehensive protection for AKS clusters?Mitigate threats using Microsoft Defender for Cloud
  3. 153.A security engineer is reviewing the secure score for an Azure subscription in Microsoft Defender for Cloud. They notice a recommendation to "Enable MFA on subscriptions" with a high impact on the secure score. The organization has a strict policy to enforce Multi-Factor Authentication (MFA) for all administrative accounts accessing Azure resources. The engineer wants to implement an Azure Policy that not only identifies non-compliant accounts but also automatically enforces MFA for them. Which Azure Policy capability should be used to achieve this automatic enforcement?Mitigate threats using Microsoft Defender for Cloud
  4. 154.A security architect is designing a strategy to manage security recommendations across multiple Azure subscriptions within their organization. They want to aggregate and review all security posture recommendations from Microsoft Defender for Cloud for all subscriptions under a single view and apply consistent security policies. Which Azure management construct should they leverage to achieve this centralized management?Mitigate threats using Microsoft Defender for Cloud
  5. 155.A security engineer is analyzing a recommendation in Microsoft Defender for Cloud that suggests enabling 'Adaptive Application Controls' for several virtual machines. What is the primary benefit of implementing Adaptive Application Controls?Mitigate threats using Microsoft Defender for Cloud
  6. 156.A company has enabled Microsoft Defender for Cloud for their Azure environment. They are particularly concerned about potential misconfigurations of Azure Storage accounts that could lead to data exposure. They want to ensure that all storage accounts are continuously monitored for security best practices, such as encryption at rest, secure transfer required, and public access settings. Which specific Defender for Cloud plan directly addresses these concerns for Azure Storage accounts?Mitigate threats using Microsoft Defender for Cloud
  7. 157.A security analyst is monitoring the security posture of an Azure subscription using Microsoft Defender for Cloud. They observe a critical recommendation stating, 'SQL databases should have auditing enabled.' The recommendation provides a 'Quick fix' option. What is the most likely underlying technology that enables this 'Quick fix' to automatically remediate the auditing setting for Azure SQL Databases?Mitigate threats using Microsoft Defender for Cloud
  8. 158.A security engineer is configuring Microsoft Defender for Cloud for a new Azure subscription. The organization requires that all virtual machines (VMs) deployed in this subscription must have a specific set of security extensions installed, such as the Log Analytics agent and Azure Disk Encryption. The engineer wants to ensure that these extensions are automatically deployed to any new or existing VM that does not have them. Which Defender for Cloud capability, leveraging Azure Policy, should be used?Mitigate threats using Microsoft Defender for Cloud
  9. 159.A company uses Microsoft Defender for Cloud and has several Azure virtual machines running sensitive applications. They need to ensure that these VMs are hardened according to a specific organizational security baseline that includes custom security configurations not covered by default Defender for Cloud recommendations. Which feature in Microsoft Defender for Cloud should the security administrator use to enforce and monitor compliance with this custom baseline?Mitigate threats using Microsoft Defender for Cloud
  10. 160.A security engineer is reviewing the secure score for an Azure subscription in Microsoft Defender for Cloud. They notice a recommendation to 'Enable multifactor authentication (MFA) on accounts with owner permissions on your subscription'. The engineer needs to implement a solution that automatically enforces this recommendation for all existing and new owner accounts across the subscription. Which of the following is the MOST appropriate action to take within Microsoft Defender for Cloud?Mitigate threats using Microsoft Defender for Cloud
  11. 161.A security operations center (SOC) team is using Microsoft Defender for Cloud for threat detection and response. They frequently receive alerts for known benign activities, such as penetration testing exercises or specific administrative scripts that are part of their routine operations. These alerts generate noise and distract analysts from real threats. The SOC team wants to reduce this noise by preventing these specific, known benign activities from generating alerts in Defender for Cloud. Which feature should they use?Mitigate threats using Microsoft Defender for Cloud
  12. 162.A financial services company uses Microsoft Defender for Cloud to monitor its Azure environment. They have a critical requirement to ensure that all sensitive data stored in Azure Storage accounts, including Blob storage and Azure Files, is continuously protected against malware, ransomware, and other advanced threats. They need a solution that integrates seamlessly with Defender for Cloud and provides agentless threat detection. Which Microsoft Defender for Cloud plan should be enabled for this purpose?Mitigate threats using Microsoft Defender for Cloud
  13. 163.A security operations team is using Microsoft Defender for Cloud to manage the security posture of their Azure environment. They have defined several custom security standards based on internal corporate policies. The team needs to ensure that all Azure resources are continuously assessed against these custom standards and that any non-compliance generates a high-priority alert. Which feature in Microsoft Defender for Cloud should be configured to achieve this goal?Mitigate threats using Microsoft Defender for Cloud
  14. 164.A security analyst is investigating a high-severity alert in Microsoft Defender for Cloud for an Azure virtual machine. The alert indicates a potential brute-force attack against an RDP port. The analyst wants to quickly restrict inbound access to the RDP port for this specific VM to only authorized IP addresses for a limited time, without permanently changing the Network Security Group (NSG) rules. Which Microsoft Defender for Cloud feature can achieve this temporary, on-demand restriction?Mitigate threats using Microsoft Defender for Cloud
  15. 165.A security engineer is configuring Microsoft Defender for Cloud for a sensitive Azure subscription. They need to ensure that any virtual machine deployed in this subscription is automatically configured with the Azure Monitor Agent (AMA) for data collection to support Defender for Cloud's recommendations and threat detection. Which Azure Policy effect should be used to achieve this automatic deployment for new VMs?Mitigate threats using Microsoft Defender for Cloud
  16. 166.A company is onboarding a new Azure subscription to Microsoft Defender for Cloud. They have a strict compliance requirement to ensure that all newly created Azure SQL Servers automatically have Microsoft Defender for SQL enabled. They want to implement this using an Azure Policy that will automatically remediate non-compliant resources. Which Azure Policy effect should the security engineer use to fulfill this requirement?Mitigate threats using Microsoft Defender for Cloud
  17. 167.A security analyst is reviewing the 'Recommendations' blade in Microsoft Defender for Cloud for a new Azure subscription. They notice a recommendation to 'Enable System Updates' for several virtual machines. Upon further investigation, they find that these VMs are running an older operating system version that is no longer supported by Microsoft for automatic updates. What action should the analyst recommend to address this security finding effectively?Mitigate threats using Microsoft Defender for Cloud
  18. 168.A security architect is designing a multi-cloud security strategy using Microsoft Defender for Cloud. The organization has virtual machines running on AWS and Google Cloud Platform (GCP) and needs to onboard them to Defender for Cloud for central security posture management, vulnerability assessment, and threat detection. Which service is essential for connecting these non-Azure VMs to Microsoft Defender for Cloud?Mitigate threats using Microsoft Defender for Cloud
  19. 169.A security engineer is configuring Microsoft Defender for Cloud for an Azure Kubernetes Service (AKS) cluster. They need to ensure that container images are scanned for vulnerabilities at the time of deployment and that runtime protection is enabled for the cluster nodes. Additionally, they want to monitor for suspicious activities within the containers themselves. Which Microsoft Defender for Cloud plan should the engineer enable to achieve comprehensive security for the AKS cluster and its containers?Mitigate threats using Microsoft Defender for Cloud
  20. 170.A security engineer needs to implement a solution to automatically protect newly provisioned Azure Kubernetes Service (AKS) clusters from common container-based threats, such as vulnerable container images, runtime attacks, and suspicious network activity within the cluster. The solution must integrate seamlessly with Microsoft Defender for Cloud. Which Defender for Cloud plan should the engineer enable for this purpose?Mitigate threats using Microsoft Defender for Cloud
  21. 171.A security engineer is tasked with onboarding a new Azure subscription to Microsoft Defender for Cloud. The subscription contains several virtual machines (VMs) and Azure SQL Databases. The engineer needs to ensure that security recommendations and threat detection capabilities are enabled for all resources with minimal administrative effort and without requiring manual agent installation on each VM. Which Defender for Cloud plan should the engineer enable for this subscription?Mitigate threats using Microsoft Defender for Cloud
  22. 172.A security operations center (SOC) team is investigating a series of malicious file detections originating from a specific Azure Storage account within Microsoft Defender for Cloud. They need to automate the response to immediately quarantine any future detected malicious files in this storage account. Which feature in Defender for Cloud, integrated with other Azure services, should they configure?Mitigate threats using Microsoft Defender for Cloud
  23. 173.A financial services company uses Microsoft Defender for Cloud to monitor its Azure environment. Due to strict regulatory requirements, they must ensure that all Azure SQL Databases are encrypted at rest with customer-managed keys (CMK) from Azure Key Vault. The security team wants to enforce this policy and automatically remediate any non-compliant SQL databases. Which Azure Policy effect, when assigned at the subscription level, can achieve this enforcement and auto-remediation goal?Mitigate threats using Microsoft Defender for Cloud
  24. 174.A security operations team wants to integrate Microsoft Defender for Cloud alerts with their existing Security Information and Event Management (SIEM) system, which is a third-party solution. The team requires a near real-time, continuous stream of all security alerts, recommendations, and secure score changes from Defender for Cloud to be exported to a custom endpoint. Which Defender for Cloud feature allows them to configure this integration?Mitigate threats using Microsoft Defender for Cloud
  25. 175.A security engineer is configuring a new Azure subscription for a development team. They need to ensure that all virtual machines provisioned in this subscription are automatically onboarded to Microsoft Defender for Servers Plan 2, including the installation of necessary agents. The solution should be scalable and require minimal manual intervention. Which Defender for Cloud setting should the engineer configure?Mitigate threats using Microsoft Defender for Cloud
  26. 176.A global enterprise is implementing Microsoft Defender for Cloud across its diverse Azure environment, which includes multiple subscriptions organized under management groups. The enterprise needs to define a consistent security baseline and assign security policies at a high level to ensure all child subscriptions inherit these settings, while still allowing for some granular overrides at the subscription level where necessary. Which hierarchical structure in Azure should the security team primarily leverage for this purpose?Mitigate threats using Microsoft Defender for Cloud
  27. 177.A security engineer is configuring a new Azure subscription to meet strict compliance requirements. They need to ensure that all virtual machines provisioned in this subscription are automatically encrypted with Azure Disk Encryption (ADE) and that any VM deployed without ADE is flagged as non-compliant. Which combination of Microsoft Defender for Cloud and Azure Policy capabilities should the engineer use to enforce this requirement efficiently?Mitigate threats using Microsoft Defender for Cloud
  28. 178.A security analyst is investigating a high-severity alert in Microsoft Defender for Cloud indicating 'Suspicious activity detected in an Azure Storage account'. The alert details show numerous failed authentication attempts from various IP addresses, followed by a successful authentication from one of those IP addresses. The storage account is configured for public access. Which Defender for Cloud capability directly contributed to detecting this specific pattern of attack?Mitigate threats using Microsoft Defender for Cloud
  29. 179.A security operations team uses Microsoft Defender for Cloud and Azure Sentinel for their security monitoring and incident response. They want to ensure that all security alerts generated by Defender for Cloud are automatically ingested into Azure Sentinel for centralized analysis and automated playbooks. Which feature in Microsoft Defender for Cloud should be configured to achieve this integration?Mitigate threats using Microsoft Defender for Cloud
  30. 180.A company is using Microsoft Defender for Cloud to manage the security posture of its Azure environment. They have a strict policy requiring all critical Azure SQL Databases to have Transparent Data Encryption (TDE) enabled. Defender for Cloud identifies several databases where TDE is disabled. The security team wants to automatically remediate this finding without manual intervention. Which remediation type should they look for in Defender for Cloud for this specific recommendation?Mitigate threats using Microsoft Defender for Cloud
  31. 181.A security engineer is configuring Microsoft Defender for Cloud for a new Azure subscription. The engineer wants to ensure that all virtual machines provisioned in this subscription automatically have the Defender for Servers Plan 2 enabled. Which configuration method should the engineer use to achieve this?Mitigate threats using Microsoft Defender for Cloud
  32. 182.A global enterprise has implemented Microsoft Defender for Cloud across all its Azure subscriptions, which are organized into several management groups. The security team needs to ensure that a specific set of security recommendations, defined by a custom Azure Policy, is applied consistently to all new and existing Linux virtual machines across all subscriptions within a particular management group. How should the security team achieve this with minimal administrative overhead?Mitigate threats using Microsoft Defender for Cloud
  33. 183.A security architect is designing a multi-cloud security strategy for an organization that uses Azure, AWS, and Google Cloud Platform (GCP). The architect wants to centralize security posture management, threat protection, and regulatory compliance monitoring across all these environments within a single platform. Which Microsoft Defender for Cloud feature set is best suited for this requirement?Mitigate threats using Microsoft Defender for Cloud
  34. 184.A company is using Microsoft Defender for Cloud to monitor the security posture of its Azure environment. They have several Azure SQL Databases that store highly sensitive customer data. The security team needs to ensure that these databases are protected against common SQL injection attacks, brute-force attacks, and other database-specific threats. Which Defender for Cloud plan should be enabled to provide this specialized protection?Mitigate threats using Microsoft Defender for Cloud
  35. 185.A security operations team wants to integrate Microsoft Defender for Cloud alerts with their existing Security Information and Event Management (SIEM) system, Microsoft Sentinel, for centralized incident management and correlation. The team needs to ensure that all high-severity security alerts from Defender for Cloud are automatically streamed to Sentinel in near real-time. Which Defender for Cloud feature should be configured to achieve this integration?Mitigate threats using Microsoft Defender for Cloud
  36. 186.A security administrator needs to monitor the security posture of an on-premises server fleet alongside their Azure resources within Microsoft Defender for Cloud. The on-premises servers run Windows Server 2019. Which component or agent must be deployed on these on-premises servers to integrate them with Defender for Cloud for security recommendations and threat detection?Mitigate threats using Microsoft Defender for Cloud
  37. 187.A security engineer is reviewing the recommendations in Microsoft Defender for Cloud and finds one stating, 'Endpoint protection solution should be installed on virtual machines'. The organization uses a specific third-party endpoint detection and response (EDR) solution. The engineer needs to ensure that Defender for Cloud accurately reflects the security posture of VMs running this EDR without flagging them as non-compliant for a missing Microsoft-specific solution. How can the engineer achieve this?Mitigate threats using Microsoft Defender for Cloud
  38. 188.A security architect is designing a strategy to monitor and protect Azure Key Vaults across multiple subscriptions within their organization. They need to ensure that any suspicious activities, such as unusual access patterns or excessive secret retrieval attempts, are detected and alerted upon. Which Microsoft Defender for Cloud plan should be enabled to provide this specific protection for Azure Key Vaults?Mitigate threats using Microsoft Defender for Cloud
  39. 189.A security engineer is investigating a series of alerts in Microsoft Defender for Cloud related to suspicious network activity originating from several Azure virtual machines. The alerts indicate potential command and control (C2) communication. The engineer needs to quickly determine which outbound network connections are allowed from these VMs and identify any unexpected open ports that could be facilitating this communication. Which Microsoft Defender for Cloud capability, leveraging machine learning, provides recommendations to restrict unnecessary network access based on actual traffic patterns?Mitigate threats using Microsoft Defender for Cloud
  40. 190.A company is onboarding several Azure subscriptions to Microsoft Defender for Cloud. They want to ensure that all virtual machines within these subscriptions are continuously scanned for vulnerabilities and misconfigurations. They also need integrated vulnerability assessment tools. Which Defender for Cloud plan should be enabled to meet these requirements comprehensively for VMs?Mitigate threats using Microsoft Defender for Cloud
  41. 191.A security engineer is reviewing the security recommendations in Microsoft Defender for Cloud for an Azure subscription. They notice a recommendation stating "Vulnerabilities in your virtual machine images should be remediated". Upon investigation, they find several Linux virtual machines with known vulnerabilities reported by a vulnerability assessment solution. The engineer needs to quickly deploy a vulnerability assessment solution to these machines to get detailed reports and track remediation. Which of the following Microsoft Defender for Cloud capabilities should the engineer utilize first?Mitigate threats using Microsoft Defender for Cloud
  42. 192.A security engineer is tasked with onboarding an on-premises Windows Server to Microsoft Defender for Cloud to extend its security monitoring capabilities to their hybrid environment. The server needs to be assessed for security vulnerabilities, comply with Azure policies, and receive threat protection. Which two Azure services are primarily required to enable Microsoft Defender for Cloud to manage and protect this on-premises server?Mitigate threats using Microsoft Defender for Cloud
  43. 193.A security engineer is reviewing the security recommendations in Microsoft Defender for Cloud and finds a recommendation stating, 'Virtual machines should be migrated to a supported operating system version'. The engineer determines that several legacy applications running on these VMs cannot be updated and require the older OS versions. To avoid this recommendation negatively impacting the secure score without addressing the underlying OS, what action should the engineer take within Defender for Cloud?Mitigate threats using Microsoft Defender for Cloud
  44. 194.A security operations center (SOC) team is using Microsoft Defender for Cloud for threat detection and incident response. They frequently receive alerts for benign activities, such as internal vulnerability scans from approved tools, which generate noise and distract analysts from critical threats. The team wants to suppress these specific alerts automatically based on their source IP address and alert type for a period of 90 days. Which Defender for Cloud feature should they use?Mitigate threats using Microsoft Defender for Cloud
  45. 195.A security engineer is investigating a series of alerts in Microsoft Defender for Cloud related to suspicious network activity originating from several Azure virtual machines. The alerts indicate attempts to communicate with known malicious IP addresses. The engineer needs to quickly block outbound communication from these compromised VMs to the identified malicious IPs without manual intervention for each new alert. Which Defender for Cloud capability, integrated with Azure networking, should be configured?Mitigate threats using Microsoft Defender for Cloud
  46. 196.A security engineer is configuring Microsoft Defender for Cloud for an Azure subscription that hosts critical web applications. The engineer needs to ensure that all network traffic to and from the web application servers is continuously analyzed for malicious activity, including port scanning, brute-force attacks, and network-level exploits. This analysis must also extend to the DNS layer to detect suspicious domain requests. Which two Defender for Cloud plans should the engineer enable to meet these requirements?Mitigate threats using Microsoft Defender for Cloud
  47. 197.A security engineer is configuring threat protection for an Azure subscription in Microsoft Defender for Cloud. The organization has multiple Azure Storage accounts, including Blob storage for backups, File shares for internal documents, and Queue storage for application messaging. The engineer wants to ensure that all these storage types are protected from malware uploads, suspicious access patterns, and data exfiltration attempts. Which Defender for Cloud plan should be enabled at the subscription level to cover all these storage services comprehensively?Mitigate threats using Microsoft Defender for Cloud
  48. 198.A security engineer is integrating an on-premises Linux server into Microsoft Defender for Cloud for security monitoring. The server needs to be assessed for security vulnerabilities, receive threat protection, and have its security posture continuously monitored. The organization uses Azure Arc for hybrid cloud management. Which agent should the engineer deploy on the Linux server to enable these Defender for Cloud capabilities?Mitigate threats using Microsoft Defender for Cloud
  49. 199.A security operations team is configuring Microsoft Sentinel to automatically enrich incidents with threat intelligence data from a custom feed. They also want to automatically assign these enriched incidents to a specific analyst group if the incident severity is high. Which Microsoft Sentinel feature should be used to achieve this automation?Mitigate threats using Microsoft Sentinel
  50. 200.A security engineer is designing a Microsoft Sentinel deployment for a hybrid environment. The organization requires all on-premises Windows server security events to be ingested into Sentinel. Due to network segmentation, these servers cannot directly access the internet. Which component should the engineer deploy to facilitate the ingestion of these logs?Mitigate threats using Microsoft Sentinel