SC-900 Security Operations & Threat Protection 2 — Questions and Answers
Question 1: Which Microsoft Sentinel feature automatically groups related alerts into a single actionable item to reduce alert fatigue?
- Playbooks
- Incidents (Correct answer)
- Workbooks
- Hunting queries
Correct answer: Incidents
Microsoft Sentinel groups related alerts into incidents, giving analysts a single consolidated item to investigate instead of many separate alerts.
Question 2: What does Microsoft Defender for Cloud use to provide a prioritized list of security recommendations?
- Threat Intelligence feeds
- Secure Score (Correct answer)
- Compliance dashboard
- Sentinel incidents
Correct answer: Secure Score
Secure Score in Microsoft Defender for Cloud quantifies your security posture and provides prioritized recommendations to improve it.
Question 3: Which capability in Microsoft 365 Defender allows analysts to proactively search for threats using custom queries?
- Advanced Hunting (Correct answer)
- Automated Investigation
- Attack Simulation Training
- Safe Links
Correct answer: Advanced Hunting
Advanced Hunting lets security analysts write Kusto Query Language (KQL) queries to proactively search across Microsoft 365 data for threats.
Question 4: A company wants to simulate phishing attacks against its employees to improve security awareness. Which Microsoft tool should they use?
- Microsoft Defender for Identity
- Attack Simulation Training (Correct answer)
- Microsoft Sentinel
- Defender for Endpoint
Correct answer: Attack Simulation Training
Attack Simulation Training in Microsoft 365 Defender lets organizations run simulated phishing and other attack scenarios to train employees.
Question 5: What is the primary function of Microsoft Defender for Office 365's Safe Attachments feature?
- Encrypts email attachments at rest
- Detonates attachments in a sandbox to detect malware (Correct answer)
- Blocks all attachments from external senders
- Scans attachments for sensitive data
Correct answer: Detonates attachments in a sandbox to detect malware
Safe Attachments opens email attachments in a virtual sandbox environment to detect malicious behavior before delivering them to users.
Question 6: Which Microsoft Sentinel component uses Azure Logic Apps to automate responses to security threats?
- Workbooks
- Playbooks (Correct answer)
- Analytics rules
- Data connectors
Correct answer: Playbooks
Playbooks in Microsoft Sentinel are built on Azure Logic Apps and automate response actions when specific security events or alerts occur.
Question 7: Microsoft Defender for Endpoint's 'Threat & Vulnerability Management' capability primarily helps organizations do what?
- Monitor network traffic for intrusions
- Discover and prioritize software vulnerabilities on endpoints (Correct answer)
- Block ransomware in real time
- Audit user sign-in activity
Correct answer: Discover and prioritize software vulnerabilities on endpoints
Threat & Vulnerability Management continuously discovers, prioritizes, and helps remediate vulnerabilities and misconfigurations on enrolled endpoints.
Which Microsoft Sentinel feature automatically groups related alerts into a single actionable item to reduce alert fatigue?