โ† All SC-900 Flashcard Decks

Security Operations & Threat Protection Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations & Threat Protection flashcards as text
  1. Which Microsoft 365 Defender feature provides a visual representation of an attack's timeline and the entities involved to help analysts understand scope?

    Answer: Attack story / incident graph

    The incident graph (attack story) in Microsoft 365 Defender visually maps relationships between alerts, entities, and timelines within a single incident.

  2. What does 'Controlled Folder Access' in Microsoft Defender for Endpoint protect against?

    Answer: Ransomware encrypting files in protected folders

    Controlled Folder Access prevents untrusted applications from making changes to protected folders, blocking ransomware from encrypting user files.

  3. A SOC team wants to measure how their current security controls map against the MITRE ATT&CK framework. Which Microsoft Sentinel feature helps with this?

    Answer: MITRE ATT&CK coverage view in Sentinel

    Microsoft Sentinel's MITRE ATT&CK framework coverage view shows which TTPs are covered by active analytics rules, revealing detection gaps.

  4. Which Microsoft service is specifically designed to protect identities by detecting risks like leaked credentials and atypical sign-in behavior for Azure AD accounts?

    Answer: Microsoft Entra ID Protection

    Microsoft Entra ID Protection monitors cloud identity signals and detects risks such as anonymous IP usage, leaked credentials, and password spray attacks.

  5. What is the role of 'threat intelligence' in a security operations workflow?

    Answer: It provides context about known threats, attackers, and indicators of compromise to improve detection

    Threat intelligence enriches security data with context about known malicious IPs, domains, file hashes, and attacker TTPs to help analysts detect and prioritize threats.

  6. Which Microsoft Defender for Cloud feature provides a single view of the security state across Azure subscriptions, hybrid servers, and multicloud environments?

    Answer: Cloud Security Posture Management (CSPM)

    Cloud Security Posture Management (CSPM) in Defender for Cloud continuously assesses and visualizes the security posture of resources across all connected environments.

  7. An analyst wants to automatically close low-severity Microsoft Sentinel incidents that match a known benign pattern without manual review. What should they configure?

    Answer: An automation rule with a 'close incident' action

    Automation rules in Microsoft Sentinel can automatically triage, tag, assign, or close incidents based on conditions, reducing manual work for known benign patterns.