MICROSOFT · SC-200

Microsoft SC-200 Exam Practice Questions

462 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 462 questions in this pack

Question 1

You need to receive a security alert when a user attempts to sign in from a location that was never used by the other users in your organization to sign in. Which anomaly detection policy should you use?

  1. Impossible travel
  2. Activity from anonymous IP addresses
  3. Activity from infrequent country
  4. Malware detection
Show answer and explanation

Correct answer: C. Activity from infrequent country

Activity from infrequent country detects when a user signs in from a location/country that is not typical for that user or uncommon across the organization. This is the policy designed to alert on sign-ins from geographically unusual locations that haven't been seen before in your tenant.

Why the other options are wrong

  • A. Impossible travel detects when a user travels between distant locations in an impossibly short time period, not about locations never used by other users.
  • B. Activity from anonymous IP addresses detects sign-ins from known anonymous proxies or VPNs, not about location frequency within the organization.
  • D. Malware detection identifies malicious software, not sign-in location anomalies.

Question 2

You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365. You have Microsoft SharePoint Online sites that contain sensitive documents. The documents contain customer account numbers that each consists of 32 alphanumeric characters. You need to create a data loss prevention (DLP) policy to protect the sensitive documents. What should you use to detect which documents are sensitive?

  1. SharePoint search
  2. a hunting query in Microsoft 365 Defender
  3. Azure Information Protection
  4. RegEx pattern matching
Show answer and explanation

Correct answer: D. RegEx pattern matching

RegEx pattern matching is the correct method to detect documents containing 32- character alphanumeric patterns (customer account numbers) in DLP policies. DLP uses regex patterns to identify and classify sensitive content for protection rules.

Why the other options are wrong

  • A. SharePoint search is a discovery tool but not the mechanism DLP uses to detect sensitive patterns.
  • B. Hunting queries in Microsoft 365 Defender are for threat investigation, not for DLP policy creation.
  • C. Azure Information Protection is a labeling and classification solution, not the detection method used within DLP policies for pattern matching.

Question 3

Your company uses Microsoft Defender for Endpoint. The company has Microsoft Word documents that contain macros. The documents are used frequently on the devices of the company's accounting team. You need to hide false positive in the Alerts queue, while maintaining the existing security posture. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  1. Resolve the alert automatically.
  2. Hide the alert.
  3. Create a suppression rule scoped to any device.
  4. Create a suppression rule scoped to a device group.
  5. Generate the alert.
Show answer and explanation

Correct answer: B, D, E

B. Hide the alert. D. Create a suppression rule scoped to a device group. E. Generate the alert. To hide false positives while maintaining security: Hide the alert (B) to remove it from the queue, create a suppression rule scoped to a device group (D) containing the accounting team devices to prevent future similar alerts on those specific devices, and enable/generate the alert mechanism (E) to ensure legitimate threats are still detected. Device group scoping maintains security posture by only suppressing on specific devices.

Why the other options are wrong

  • A. Resolving the alert automatically closes it but doesn't prevent future occurrences like a suppression rule does.
  • C. Creating a suppression rule scoped to any device would suppress the alert across all devices, reducing security posture.

See all 10 free questions Get the full pack, US$39

462 practice questions for Microsoft Security Operations Analyst (SC-200), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 462 questions across all three SC-200 domains
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed SC-200 attempt costs US$165 in the US, plus the weeks it takes to get ready again. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 462 questions. Aligned to the 28 July 2026 blueprint.

What makes the SC-200 hard

The SC-200 is Microsoft’s certification for security operations analysts, the people sitting in SOCs, triaging alerts, hunting threats and responding to incidents. This is not a theoretical exam.

Microsoft tests real scenarios: writing KQL queries, configuring Sentinel analytics rules, investigating incidents, and knowing which Defender product applies and when. The KQL questions specifically catch candidates who did not prepare for them: it is possible to know Defender XDR inside out and still lose marks on a query you have not seen before.

The blueprint was restructured on 28 July 2026. The old product-by-product split (Sentinel, then Defender XDR, then Defender for Cloud) is gone. The exam is now organised by what an analyst actually does: running the SOC environment, responding to incidents, and hunting. A study plan built around “50% Sentinel” is working from a blueprint that no longer exists.

About the exam

The SC-200 is Microsoft’s role-based certification for security operations analysts. It validates the ability to reduce organisational risk by triaging incidents, hunting threats and engineering detections using Microsoft’s native security stack: Microsoft Sentinel, Microsoft Defender XDR and Microsoft Defender for Cloud. Skills measured as of 28 July 2026. Renews annually via a free Microsoft Learn assessment.

Exam domains

  • Manage a security operations environment: 40 to 45%
  • Respond to security incidents: 35 to 40%
  • Perform threat hunting: 20 to 25%

40 to 60 questions, 120 minutes, passing score 700 out of 1000, US$165 in the US, priced by local currency elsewhere, online proctored and test centres, renews annually.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Microsoft SC-200 pack?

462 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.