โ† All SC-900 Flashcard Decks

Security Operations & Threat Protection Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations & Threat Protection flashcards as text
  1. What type of signal does Microsoft Defender for Identity primarily analyze to detect suspicious activity?

    Answer: Active Directory Domain Services logs and traffic

    Microsoft Defender for Identity monitors Active Directory Domain Services traffic and logs to detect identity-based attacks such as pass-the-hash and lateral movement.

  2. Which Microsoft 365 Defender portal feature provides a unified view of incidents across endpoints, email, identities, and apps?

    Answer: Incidents queue

    The Incidents queue in the Microsoft 365 Defender portal aggregates correlated alerts from across all Microsoft 365 Defender products into unified incidents.

  3. What does the 'Kill Chain' framework help security analysts understand?

    Answer: The stages an attacker follows from initial access to achieving their goal

    The Cyber Kill Chain describes the sequential stages of a cyberattack, helping analysts understand attacker progression and identify where to intervene.

  4. A security analyst notices an alert that a user's credentials were used to sign in from two countries within 30 minutes. Which Microsoft service most likely generated this alert?

    Answer: Microsoft Entra ID Protection

    Microsoft Entra ID Protection (formerly Azure AD Identity Protection) detects risky sign-ins such as impossible travel and generates risk alerts.

  5. Which SIEM capability allows Microsoft Sentinel to ingest logs from non-Microsoft sources such as firewalls and Linux servers?

    Answer: Data connectors

    Data connectors in Microsoft Sentinel enable log ingestion from hundreds of sources including non-Microsoft devices, services, and platforms.

  6. What is the purpose of Microsoft Defender for Cloud Apps' 'Shadow IT Discovery' feature?

    Answer: Identifies cloud apps being used without IT approval

    Shadow IT Discovery analyzes network traffic logs to identify cloud applications employees are using without official IT approval or security review.

  7. Which Microsoft tool provides Threat Intelligence reports to help analysts understand active threat actors and campaigns targeting their industry?

    Answer: Microsoft Sentinel Threat Intelligence

    Microsoft Sentinel's built-in Threat Intelligence features, including MITRE ATT&CK integration and threat actor reports, help analysts contextualize threats relevant to their environment.