โ† All SC-900 Flashcard Decks

Security Operations & Threat Protection Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations & Threat Protection flashcards as text
  1. Which Microsoft Sentinel feature automatically groups related alerts into a single actionable item to reduce alert fatigue?

    Answer: Incidents

    Microsoft Sentinel groups related alerts into incidents, giving analysts a single consolidated item to investigate instead of many separate alerts.

  2. What does Microsoft Defender for Cloud use to provide a prioritized list of security recommendations?

    Answer: Secure Score

    Secure Score in Microsoft Defender for Cloud quantifies your security posture and provides prioritized recommendations to improve it.

  3. Which capability in Microsoft 365 Defender allows analysts to proactively search for threats using custom queries?

    Answer: Advanced Hunting

    Advanced Hunting lets security analysts write Kusto Query Language (KQL) queries to proactively search across Microsoft 365 data for threats.

  4. A company wants to simulate phishing attacks against its employees to improve security awareness. Which Microsoft tool should they use?

    Answer: Attack Simulation Training

    Attack Simulation Training in Microsoft 365 Defender lets organizations run simulated phishing and other attack scenarios to train employees.

  5. What is the primary function of Microsoft Defender for Office 365's Safe Attachments feature?

    Answer: Detonates attachments in a sandbox to detect malware

    Safe Attachments opens email attachments in a virtual sandbox environment to detect malicious behavior before delivering them to users.

  6. Which Microsoft Sentinel component uses Azure Logic Apps to automate responses to security threats?

    Answer: Playbooks

    Playbooks in Microsoft Sentinel are built on Azure Logic Apps and automate response actions when specific security events or alerts occur.

  7. Microsoft Defender for Endpoint's 'Threat & Vulnerability Management' capability primarily helps organizations do what?

    Answer: Discover and prioritize software vulnerabilities on endpoints

    Threat & Vulnerability Management continuously discovers, prioritizes, and helps remediate vulnerabilities and misconfigurations on enrolled endpoints.