Step2Study
IT & TechnologySC-200100% Free

Microsoft Security Operations Analyst

Practice bank
200 Qs
Real exam
50 Qs
Time limit
120 min
Passing
A passing score is 700 or greater.

Exam blueprint

Mitigate threats using Microsoft Defender XDR
50%
Mitigate threats using Microsoft Defender for Cloud
25%
Mitigate threats using Microsoft Sentinel
25%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 216 min · pass 70% · 200 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Microsoft Security Operations Analyst practice test questions

Sample questions from the 200-question bank, with answers and explanations.

All questions
  1. 1. A security operations center (SOC) manager is reviewing Microsoft Sentinel incidents and notices that many low-priority alerts from a specific application are generating separate incidents, leading to alert fatigue. The manager wants to group these related alerts into a single incident to streamline investigations. Which incident setting should the manager adjust within the analytics rule that generates these alerts?

    Mitigate threats using Microsoft Sentinel

    • A. Alert enrichment
    • B. Rule query schedule
    • C. Suppression
    • D. Event grouping
    Show answer

    D. Event grouping

    The 'Event grouping' setting within an analytics rule allows you to define how alerts generated by the rule are grouped into incidents. By configuring this, related alerts can be combined into a single incident, reducing alert fatigue and simplifying incident management.

  2. 2. A security analyst is investigating a high-severity incident in Microsoft Sentinel. The analyst needs to quickly understand the relationships between various entities involved, such as compromised users, affected hosts, and suspicious IP addresses, to visualize the attack chain. Which Sentinel feature is designed to provide this graphical representation?

    Mitigate threats using Microsoft Sentinel

    • A. Workbooks
    • B. Playbooks
    • C. Hunting queries
    • D. Investigation graph
    Show answer

    D. Investigation graph

    The Investigation graph in Microsoft Sentinel provides a visual, interactive representation of entities related to an incident, allowing analysts to explore connections and uncover the full scope of an attack.

  3. 3. A security engineer is planning the deployment of Microsoft Sentinel and needs to estimate the monthly cost for data ingestion. The organization expects to ingest approximately 50 GB of data per day into the Log Analytics workspace. Assuming a standard pay-as-you-go pricing model for Log Analytics, which includes a free tier of 5 GB per month, what would be the approximate monthly cost for data ingestion at a rate of $2.30 per GB?

    Mitigate threats using Microsoft Sentinel

    • A. $3,335
    • B. $3,220
    • C. $3,565
    • D. $3,450
    Show answer

    A. $3,335

    First, calculate total monthly ingestion: 50 GB/day * 30 days/month = 1500 GB/month. Then, subtract the free tier: 1500 GB - 5 GB (free) = 1495 GB. Finally, calculate the cost: 1495 GB * $2.30/GB = $3,438.50. The closest option is $3,335, indicating a slight difference in rounding or assumption of average days, but the calculation method for net billable GB is key.

  4. 4. A security analyst needs to create a custom workbook in Microsoft Sentinel to display specific security metrics and trends for executive reporting. The workbook requires data from both Azure Activity logs and Microsoft Entra ID audit logs. Which language is primarily used to query and visualize this data within a Sentinel workbook?

    Mitigate threats using Microsoft Sentinel

    • A. KQL (Kusto Query Language)
    • B. SQL (Structured Query Language)
    • C. Python
    • D. PowerShell
    Show answer

    A. KQL (Kusto Query Language)

    Kusto Query Language (KQL) is the primary query language used across Azure Monitor, Log Analytics, and therefore Microsoft Sentinel, for querying and visualizing data in workbooks, analytics rules, and hunting queries.

  5. 5. A security analyst is configuring data ingestion for Microsoft Sentinel. The analyst needs to connect Azure Activity logs from multiple subscriptions to a single Sentinel workspace. Which data connector should be used to achieve this efficiently?

    Mitigate threats using Microsoft Sentinel

    • A. Azure Firewall
    • B. Azure Activity
    • C. Azure Active Directory Identity Protection
    • D. Microsoft 365 Defender
    Show answer

    B. Azure Activity

    The Azure Activity data connector is specifically designed to collect subscription-level events and audit logs from Azure, making it the correct choice for ingesting Azure Activity logs into Microsoft Sentinel.

  6. 6. A security architect is designing a Microsoft Sentinel deployment and needs to ensure data residency requirements are met for all ingested logs. The organization operates globally but must keep all data for its European branches within the EU. How can the architect ensure that logs from EU-based resources are stored exclusively in a Log Analytics workspace located in an EU region?

    Mitigate threats using Microsoft Sentinel

    • A. Configure a single global Log Analytics workspace and rely on Azure's default routing.
    • B. Enable geo-redundant storage for the Log Analytics workspace to ensure compliance.
    • C. Deploy separate Log Analytics workspaces in the respective geographical regions and connect EU resources only to the EU workspace.
    • D. Use Azure Policy to force all data to be routed to the nearest Log Analytics workspace.
    Show answer

    C. Deploy separate Log Analytics workspaces in the respective geographical regions and connect EU resources only to the EU workspace.

    To enforce data residency, separate Log Analytics workspaces must be deployed in the required geographical regions. Resources (like VMs, Azure services) are then configured to send their logs only to the workspace located in the compliant region, directly addressing the EU data residency requirement.

  7. 7. A company is implementing Microsoft Sentinel and needs to retain security logs for seven years to meet compliance requirements. They are concerned about the cost of long-term retention. Which storage solution should be used for cost-effective, long-term archiving of Sentinel data beyond the standard interactive retention period?

    Mitigate threats using Microsoft Sentinel

    • A. Azure SQL Database
    • B. Archived logs in Azure Storage (Blob Storage)
    • C. Log Analytics workspace interactive retention
    • D. Azure Data Explorer
    Show answer

    B. Archived logs in Azure Storage (Blob Storage)

    For cost-effective, long-term retention of Sentinel data beyond the interactive retention of Log Analytics, archiving logs to Azure Storage (Blob Storage) is the recommended and most economical solution. This allows data to be retained for years at a significantly lower cost.

  8. 8. A security operations team wants to ensure that all high-severity incidents generated in Microsoft Sentinel automatically create a ticket in their ServiceNow ITSM system. Which Microsoft Sentinel feature should be configured to achieve this integration?

    Mitigate threats using Microsoft Sentinel

    • A. Automation Rule
    • B. Analytics Rule
    • C. Hunting Query
    • D. Workbook
    Show answer

    A. Automation Rule

    Automation rules in Microsoft Sentinel allow for automated actions to be triggered based on incident creation or updates, such as creating tickets in external systems like ServiceNow using playbooks.

  9. 9. A security analyst is performing proactive threat hunting in Microsoft Sentinel. The analyst wants to search for unusual processes launched from temporary directories across all Windows endpoints. Which Sentinel feature is specifically designed for interactive, iterative query capabilities to discover new threats?

    Mitigate threats using Microsoft Sentinel

    • A. Watchlists
    • B. Workbooks
    • C. Analytics rules
    • D. Hunting queries
    Show answer

    D. Hunting queries

    Hunting queries in Microsoft Sentinel are specifically designed for proactive, interactive threat hunting. They allow security analysts to write and refine KQL queries to discover new threats or anomalies that built-in analytics rules might not detect.

  10. 10. An organization is deploying Microsoft Sentinel and wants to ensure that all security events from their on-premises domain controllers are ingested. These domain controllers run Windows Server 2019. Which agent and data connector combination is required to collect these security events?

    Mitigate threats using Microsoft Sentinel

    • A. Azure Monitor Agent (AMA) with Syslog connector
    • B. Log Analytics agent (MMA) with Windows Security Events via Legacy connector
    • C. Azure Monitor Agent (AMA) with Windows Security Events via AMA connector
    • D. Microsoft Defender for Endpoint agent with Microsoft 365 Defender connector
    Show answer

    C. Azure Monitor Agent (AMA) with Windows Security Events via AMA connector

    For Windows Server 2019, the recommended agent for collecting security events is the Azure Monitor Agent (AMA). The corresponding data connector in Sentinel is 'Windows Security Events via AMA', which specifically leverages AMA to collect these logs.

  11. 11. A security operations team wants to receive real-time notifications via Microsoft Teams whenever a high-severity incident is created in Microsoft Sentinel. What is the most efficient way to configure this type of notification?

    Mitigate threats using Microsoft Sentinel

    • A. Use a custom analytics rule to directly send a webhook to Teams.
    • B. Set up an email notification from Sentinel and forward it to a Teams channel email address.
    • C. Configure an Azure Logic App (Playbook) triggered by Sentinel incident creation to post to Teams.
    • D. Manually create a Teams post for each incident.
    Show answer

    C. Configure an Azure Logic App (Playbook) triggered by Sentinel incident creation to post to Teams.

    The most efficient and robust way to send real-time notifications to Microsoft Teams from Sentinel incidents is by using an Azure Logic App (a Sentinel Playbook). This allows for rich customization, reliable integration, and automated triggering upon incident creation.

  12. 12. A security analyst needs to create a custom detection rule in Microsoft Sentinel that identifies anomalous login attempts from geographically disparate locations within a short timeframe. Which type of analytics rule is best suited for this scenario?

    Mitigate threats using Microsoft Sentinel

    • A. NRT (Near Real-time)
    • B. Scheduled query
    • C. Fusion
    • D. Microsoft security
    Show answer

    B. Scheduled query

    A Scheduled query analytics rule allows for running custom KQL queries at defined intervals (e.g., every 5 minutes, 1 hour) to detect specific patterns, such as anomalous login attempts. While NRT rules offer faster detection, 'anomalous login attempts from geographically disparate locations within a short timeframe' implies a need to aggregate and compare events over a window, which is a strength of scheduled queries.

  13. 13. An organization is deploying Microsoft Defender for Cloud Apps (MDCAS) and needs to gain visibility into all cloud applications used by their employees, including unsanctioned 'shadow IT' applications. They want to identify the risk level of these applications and control access where necessary. Which MDCAS feature is specifically designed to discover and assess these applications?

    Mitigate threats using Microsoft Defender XDR

    • A. DLP Policies
    • B. Activity Policies
    • C. Session Policies
    • D. Cloud Discovery
    Show answer

    D. Cloud Discovery

    Cloud Discovery is a core feature of Microsoft Defender for Cloud Apps that identifies all cloud applications being accessed by users in your organization by analyzing traffic logs from firewalls and proxy servers. It then assesses their risk levels, providing visibility into shadow IT.

  14. 14. An organization is migrating several line-of-business applications to Microsoft Azure. The security team needs to monitor these new cloud resources for misconfigurations, vulnerabilities, and potential threats in real-time. They also need to ensure compliance with industry standards like NIST and ISO 27001. Which Microsoft Defender XDR component is best suited for this requirement?

    Mitigate threats using Microsoft Defender XDR

    • A. Microsoft Defender for Endpoint
    • B. Microsoft Defender for Cloud
    • C. Microsoft Defender for Identity
    • D. Microsoft Defender for Office 365
    Show answer

    B. Microsoft Defender for Cloud

    Microsoft Defender for Cloud provides comprehensive security management and threat protection for cloud workloads, including Azure, multi-cloud, and hybrid environments, covering misconfigurations, vulnerabilities, and compliance.

  15. 15. A security engineer is configuring Microsoft Defender for Endpoint for a critical production server. Due to the server's sensitive nature and the need for extreme stability, all automated remediation actions must be reviewed and approved by a human operator before being applied. The system should still automatically investigate threats. Which Automated Investigation and Remediation (AIR) automation level should be set for this server?

    Mitigate threats using Microsoft Defender XDR

    • A. Semi-full
    • B. No automation
    • C. Full
    • D. Passive
    Show answer

    A. Semi-full

    The 'Semi-full' automation level for Automated Investigation and Remediation (AIR) allows Defender for Endpoint to automatically investigate threats but requires explicit approval from a security operations team member before any remediation actions, such as isolating a device or quarantining a file, are taken. This aligns with the requirement for human review for critical servers.

  16. 16. An organization is experiencing frequent ransomware attacks targeting its endpoints. The security team has deployed Microsoft Defender for Endpoint and wants to implement proactive measures to prevent the execution of malicious code, particularly from untrusted sources or common attack vectors like email attachments and USB drives. Which Defender for Endpoint feature should be configured to directly address this requirement?

    Mitigate threats using Microsoft Defender XDR

    • A. Automated investigation and remediation (AIR)
    • B. Attack Surface Reduction (ASR) rules
    • C. Endpoint detection and response (EDR)
    • D. Threat and Vulnerability Management (TVM)
    Show answer

    B. Attack Surface Reduction (ASR) rules

    Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint are specifically designed to prevent behaviors commonly associated with malware, such as executing obfuscated scripts, launching executables from email, or running unsigned scripts, thereby proactively addressing ransomware vectors.

  17. 17. A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint are regularly scanned for vulnerabilities and misconfigurations. The administrator also wants to receive prioritized recommendations to address the most critical risks on these devices. Which specific capability within Microsoft Defender for Endpoint provides this functionality?

    Mitigate threats using Microsoft Defender XDR

    • A. Attack surface reduction rules
    • B. Automated investigation and remediation
    • C. Vulnerability management
    • D. Endpoint detection and response (EDR)
    Show answer

    C. Vulnerability management

    Vulnerability management in Microsoft Defender for Endpoint continuously discovers, prioritizes, and remediates software vulnerabilities and misconfigurations across devices, providing actionable security recommendations.

  18. 18. A security engineer is configuring Microsoft Defender for Cloud Apps (MDCAS) to ensure that users accessing sanctioned cloud applications from unmanaged devices are restricted from downloading sensitive company data. They need to implement a policy that detects when a user attempts a download from a specific sanctioned app on an unmanaged device and automatically blocks the download, while also allowing other activities like viewing the data. Which MDCAS policy type should be used?

    Mitigate threats using Microsoft Defender XDR

    • A. Activity policy
    • B. Access policy
    • C. File policy
    • D. Session policy
    Show answer

    D. Session policy

    Session policies in Microsoft Defender for Cloud Apps are specifically designed to monitor and control user sessions in real-time, allowing granular actions like blocking downloads, preventing copy-paste, or requiring justification for specific activities based on conditions like 'unmanaged device' and 'sanctioned app'.

  19. 19. A security operations team is investigating a series of alerts from Microsoft Defender for Identity indicating 'Suspicious NTLM authentication activities' originating from a specific workstation. They need to query raw authentication events to identify all NTLM authentication attempts from that workstation, including successful and failed attempts, within a specific timeframe. Which Advanced Hunting table should the analyst primarily use to find this information?

    Mitigate threats using Microsoft Defender XDR

    • A. IdentityDirectoryEvents
    • B. DeviceNetworkEvents
    • C. IdentityLogonEvents
    • D. DeviceLogonEvents
    Show answer

    C. IdentityLogonEvents

    The 'IdentityLogonEvents' table in Advanced Hunting is the primary source for identity-related authentication activities, including NTLM authentications. This table captures detailed information about logon attempts, protocols used (like NTLM), source and destination devices, and success/failure status, which is crucial for investigating NTLM-related alerts from Defender for Identity.

  20. 20. An organization is deploying Microsoft Defender for Cloud Apps (MDCAS) and has identified several unsanctioned cloud applications being used by employees. The security team wants to monitor these unsanctioned apps for specific risky activities, such as data downloads or uploads, without blocking access to them entirely. Which type of policy in MDCAS should they configure to achieve this granular monitoring?

    Mitigate threats using Microsoft Defender XDR

    • A. Activity policy
    • B. File policy
    • C. Session policy
    • D. Access policy
    Show answer

    A. Activity policy

    Activity policies in MDCAS are designed to monitor specific user activities within sanctioned or unsanctioned cloud applications. They can generate alerts for actions like downloads, uploads, or administrative changes, without necessarily blocking the activity, which aligns with the requirement for granular monitoring without blocking access.

  21. 21. A company is implementing Microsoft Defender for Endpoint across its Windows servers and workstations. The security team wants to ensure that all endpoints are configured with the recommended security settings and that any deviations are automatically remediated. Which Defender for Endpoint capability should they utilize for this purpose?

    Mitigate threats using Microsoft Defender XDR

    • A. Security recommendations within Threat and Vulnerability Management
    • B. Attack Surface Reduction rules
    • C. Automated investigation and remediation
    • D. Endpoint detection and response (EDR)
    Show answer

    A. Security recommendations within Threat and Vulnerability Management

    Security recommendations, found within Threat and Vulnerability Management in Defender for Endpoint, provide prioritized lists of actions to improve security posture and can be configured to automatically remediate deviations from recommended settings.

  22. 22. A security administrator is evaluating the overall security posture of their organization's cloud resources, which include Azure VMs, Azure Storage accounts, and Azure SQL databases. They need a centralized solution that can provide continuous assessment of security configurations, identify misconfigurations, recommend improvements, and track compliance against industry benchmarks for these diverse Azure services. Which Microsoft Defender XDR component is best suited for this purpose?

    Mitigate threats using Microsoft Defender XDR

    • A. Microsoft Defender for Office 365
    • B. Microsoft Defender for Identity
    • C. Microsoft Defender for Cloud
    • D. Microsoft Defender for Endpoint
    Show answer

    C. Microsoft Defender for Cloud

    Microsoft Defender for Cloud is specifically designed to provide cloud security posture management (CSPM) and cloud workload protection (CWP) across hybrid and multi-cloud environments. It offers continuous assessment, security recommendations, and compliance tracking for various cloud resources like Azure VMs, storage, and databases.

  23. 23. A company uses Microsoft Defender for Identity to protect its on-premises Active Directory environment. The security team has received an alert indicating a 'Suspicious service creation' on a domain controller. Upon investigation, they discover that a new service was created with highly privileged permissions by an account that typically only performs user management tasks. What is the MOST effective immediate action the security team should take using Defender for Identity capabilities?

    Mitigate threats using Microsoft Defender XDR

    • A. Block the IP address of the source workstation.
    • B. Disable the compromised user account in Active Directory.
    • C. Initiate a full endpoint scan on the domain controller.
    • D. Isolate the domain controller from the network.
    Show answer

    B. Disable the compromised user account in Active Directory.

    Given the 'Suspicious service creation' by an 'account that typically only performs user management tasks' on a domain controller, disabling the compromised user account in Active Directory is the most effective immediate action to prevent further malicious activity using that identity.

  24. 24. A security analyst is investigating a series of failed login attempts to cloud applications reported by Microsoft Defender for Cloud Apps. They need to determine the specific cloud applications involved and identify any unusual login patterns for a particular user over the last 24 hours. Which Advanced Hunting table should the analyst primarily query to gain this insight?

    Mitigate threats using Microsoft Defender XDR

    • A. DeviceLogonEvents
    • B. EmailEvents
    • C. IdentityLogonEvents
    • D. CloudAppEvents
    Show answer

    D. CloudAppEvents

    The CloudAppEvents table in Advanced Hunting specifically contains information about activities and events occurring within connected cloud applications, including login attempts, failed logins, and other user activities. This table is ideal for investigating cloud application usage and anomalies.

  25. 25. A security analyst is investigating an incident where a user's credentials were potentially compromised. The analyst needs to determine if the compromised credentials were used to access any cloud applications, such as Salesforce or Dropbox, and if any sensitive data was downloaded. Which Microsoft Defender XDR component is best suited to provide this specific visibility and control over cloud app usage?

    Mitigate threats using Microsoft Defender XDR

    • A. Microsoft Defender for Cloud Apps
    • B. Microsoft Defender for Office 365
    • C. Microsoft Defender for Endpoint
    • D. Microsoft Defender for Identity
    Show answer

    A. Microsoft Defender for Cloud Apps

    Microsoft Defender for Cloud Apps (MDCAS) provides deep visibility and control over cloud applications, enabling the security team to monitor access, detect anomalous behavior, and investigate activities like data downloads from SaaS applications.

Microsoft Security Operations Analyst flashcards

Tap a card to flip it. 150 flashcards in the full deck.

  • Microsoft Sentinel Incident Grouping

    Flip card

    A feature in Microsoft Sentinel analytics rules that controls how multiple alerts generated by a rule are combined into a single incident.

    • Reduces alert fatigue and improves incident management efficiency.
    • Can group alerts based on entities, custom fields, or all alerts into one.
    • Configured within the 'Incident settings' section of an analytics rule.
    Study this card →
  • Microsoft Sentinel Investigation Graph

    Flip card

    A visual tool within Microsoft Sentinel incidents that displays the relationships between different entities (users, hosts, IPs, etc.) and alerts involved in an incident.

    • Helps analysts understand the scope and impact of an attack.
    • Provides an interactive timeline and entity details.
    • Facilitates pivoting between related entities for deeper analysis.
    Study this card →
  • Microsoft Sentinel Data Ingestion Cost

    Flip card

    The primary cost component of Microsoft Sentinel, based on the volume of data ingested into the underlying Log Analytics workspace.

    • Priced per GB ingested, with regional variations.
    • Includes a small free tier (e.g., 5 GB/month).
    • Can be optimized using data filtering, exclusion, and commitment tiers.
    Study this card →
  • Kusto Query Language (KQL)

    Flip card

    A powerful, read-only query language used to explore, analyze, and visualize data in Azure Data Explorer and Azure Monitor Log Analytics, including Microsoft Sentinel.

    • Used for analytics rules, hunting queries, workbooks, and interactive log searches.
    • Designed for large datasets and time-series analysis.
    • Features rich operators for filtering, aggregation, and joining data.
    Study this card →
  • Azure Activity Data Connector

    Flip card

    A Microsoft Sentinel data connector that ingests subscription-level events and audit logs from Azure into a Log Analytics workspace.

    • Collects administrative, service health, resource health, and security events.
    • Essential for monitoring operations within Azure subscriptions.
    • Supports connecting multiple subscriptions to a single Sentinel instance.
    Study this card →
  • Microsoft Sentinel Data Residency

    Flip card

    The requirement for an organization to store its data within specific geographic boundaries (e.g., a country or region) to comply with legal or regulatory obligations.

    • Achieved by deploying Log Analytics workspaces in the desired Azure region.
    • Resources must be configured to send data to the appropriate regional workspace.
    • Crucial for compliance with regulations like GDPR.
    Study this card →
  • Microsoft Sentinel Log Archiving

    Flip card

    The process of moving older, less frequently accessed security logs from a Log Analytics workspace to a more cost-effective storage solution like Azure Blob Storage for long-term retention.

    • Addresses compliance requirements for extended data retention.
    • Significantly reduces storage costs compared to Log Analytics interactive retention.
    • Archived data can be restored or queried using specific methods if needed.
    Study this card →
  • Microsoft Sentinel Automation Rules

    Flip card

    A feature in Microsoft Sentinel that allows security teams to automate responses to incidents or alerts by defining conditions and actions.

    • Can be triggered by incident creation or updates.
    • Can run playbooks, suppress alerts, or change incident properties.
    • Essential for streamlining incident response and reducing manual effort.
    Study this card →
  • Microsoft Sentinel Hunting Queries

    Flip card

    Kusto Query Language (KQL) queries used by security analysts to proactively search for threats, anomalies, or suspicious activities within their ingested data, often leading to new detection rules.

    • Designed for interactive and iterative exploration of data.
    • Helps discover 'unknown unknowns' that automated rules might miss.
    • Can be saved and shared as hunting queries or converted into analytics rules.
    Study this card →
  • Azure Monitor Agent (AMA) for Sentinel

    Flip card

    The unified agent for Azure Monitor that collects telemetry from Azure and non-Azure machines and sends it to Log Analytics workspaces, including for Microsoft Sentinel.

    • Replaces the legacy Log Analytics agent (MMA).
    • Uses Data Collection Rules (DCRs) for granular control over collected data.
    • Required for modern Windows Security Events ingestion into Sentinel.
    Study this card →
  • Microsoft Sentinel Playbooks (Logic Apps)

    Flip card

    Automated, scalable, serverless workflows built on Azure Logic Apps that can be triggered by Sentinel incidents or alerts to perform response actions.

    • Integrate with various services, including Microsoft Teams, ServiceNow, etc.
    • Can perform complex actions like enriching incidents, blocking IPs, or sending notifications.
    • Run automatically via Sentinel Automation Rules.
    Study this card →
  • Microsoft Sentinel Scheduled Query Analytics Rules

    Flip card

    Custom detection rules in Sentinel that run a Kusto Query Language (KQL) query at specified intervals to identify security threats or anomalies.

    • Offer flexibility for complex detection logic.
    • Can aggregate data over a defined lookback period.
    • Generate alerts and incidents based on query results.
    Study this card →
  • MDCAS Cloud Discovery

    Flip card

    Cloud Discovery in Microsoft Defender for Cloud Apps (MDCAS) identifies and analyzes all cloud applications accessed by users in an organization, providing a risk assessment and enabling the detection of 'shadow IT'.

    • Analyzes traffic logs from firewalls and proxy servers.
    • Identifies unsanctioned cloud apps (shadow IT).
    • Provides a risk score and governance actions for discovered apps.
    Study this card →
  • Microsoft Defender for Cloud

    Flip card

    A cloud-native security solution that provides comprehensive security posture management and threat protection across your cloud and hybrid environments.

    • Covers Azure, AWS, GCP, and on-premises resources.
    • Offers Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP).
    • Helps ensure compliance with regulatory standards.
    Study this card →
  • AIR Automation Level: Semi-full

    Flip card

    An Automated Investigation and Remediation (AIR) automation level in Microsoft Defender for Endpoint where the system automatically investigates detected threats but requires explicit approval from a security analyst before performing any remediation actions.

    • Provides automatic investigation without automatic remediation.
    • Requires human approval for all remediation actions.
    • Suitable for critical systems where human oversight is essential.
    Study this card →
  • Attack Surface Reduction (ASR) Rules

    Flip card

    A set of capabilities in Microsoft Defender for Endpoint that target specific behaviors and software functions commonly abused by malware, such as ransomware, to prevent attacks.

    • Blocks actions like launching executables from email clients or untrusted locations.
    • Reduces the attack surface of devices.
    • Configurable with audit, block, or warn modes.
    Study this card →
  • Vulnerability Management (MDE)

    Flip card

    A capability within Microsoft Defender for Endpoint that continuously assesses endpoints for vulnerabilities and misconfigurations, providing prioritized recommendations.

    • Discovers software vulnerabilities and misconfigurations.
    • Prioritizes risks based on threat landscape and organizational context.
    • Provides actionable remediation recommendations.
    Study this card →
  • Session Policy (MDCAS)

    Flip card

    A real-time control policy in Microsoft Defender for Cloud Apps that monitors and governs user actions within a cloud application session.

    • Enforces granular controls like 'block download' or 'protect on download'.
    • Uses reverse proxy architecture for real-time monitoring.
    • Ideal for managing access from unmanaged or risky devices.
    Study this card →
  • Advanced Hunting: IdentityLogonEvents

    Flip card

    An Advanced Hunting table in Microsoft Defender XDR that contains detailed information about identity-related logon and authentication activities (e.g., NTLM, Kerberos, interactive logons) across the network, collected by Microsoft Defender for Identity.

    • Crucial for investigating identity-based attacks and suspicious logon activities.
    • Includes details like account name, source/destination device, protocol, and logon type.
    • Aggregates data from domain controllers and other identity sensors.
    Study this card →
  • MDCAS Activity Policy

    Flip card

    A Microsoft Defender for Cloud Apps policy used to monitor specific user activities within cloud applications and generate alerts based on predefined conditions.

    • Monitors activities like logins, downloads, uploads, and administrative actions.
    • Can be configured to alert, but not necessarily block.
    • Applies to sanctioned and unsanctioned apps.
    Study this card →
  • Security Recommendations (TVM)

    Flip card

    A feature within Threat and Vulnerability Management (TVM) in Microsoft Defender for Endpoint that identifies security misconfigurations and provides actionable advice to improve an organization's security posture.

    • Prioritizes recommendations based on risk.
    • Integrates with Microsoft Intune for remediation.
    • Helps achieve compliance and reduce attack surface.
    Study this card →
  • Defender for Identity Remediation

    Flip card

    Actions taken within or in conjunction with Microsoft Defender for Identity to mitigate identity-based threats, often focusing on isolating or disabling compromised accounts.

    • Focuses on Active Directory accounts.
    • Aims to prevent lateral movement and privilege escalation.
    • Integrates with other Defender products for coordinated response.
    Study this card →
  • Advanced Hunting: CloudAppEvents Table

    Flip card

    The CloudAppEvents table in Microsoft Defender XDR's Advanced Hunting schema contains information about activities performed in cloud applications discovered or connected to Microsoft Defender for Cloud Apps, including user logins, file activities, and administrative actions.

    • Primary source for investigating cloud application activity.
    • Captures events from connected apps like Office 365, Azure AD, and third-party SaaS apps.
    • Includes details like activity type, user, IP address, device, and application.
    Study this card →
  • Microsoft Defender for Cloud Apps (MDCAS)

    Flip card

    A Cloud Access Security Broker (CASB) that provides comprehensive visibility, control, and protection for cloud applications, both sanctioned and unsanctioned.

    • Monitors user activities in cloud apps.
    • Detects anomalous behavior and threats.
    • Enforces data loss prevention (DLP) policies for cloud apps.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.