SC-900 Security Operations & Threat Protection 5 — Questions and Answers
Question 1: Which Microsoft 365 Defender feature provides a visual representation of an attack's timeline and the entities involved to help analysts understand scope?
- Secure Score
- Attack story / incident graph (Correct answer)
- Compliance Manager
- Threat analytics
Correct answer: Attack story / incident graph
The incident graph (attack story) in Microsoft 365 Defender visually maps relationships between alerts, entities, and timelines within a single incident.
Question 2: What does 'Controlled Folder Access' in Microsoft Defender for Endpoint protect against?
- Brute force attacks on Active Directory accounts
- Ransomware encrypting files in protected folders (Correct answer)
- Phishing emails reaching the inbox
- Unauthorized VPN connections
Correct answer: Ransomware encrypting files in protected folders
Controlled Folder Access prevents untrusted applications from making changes to protected folders, blocking ransomware from encrypting user files.
Question 3: A SOC team wants to measure how their current security controls map against the MITRE ATT&CK framework. Which Microsoft Sentinel feature helps with this?
- Data connectors
- MITRE ATT&CK coverage view in Sentinel (Correct answer)
- Diagnostic settings
- Activity log analytics
Correct answer: MITRE ATT&CK coverage view in Sentinel
Microsoft Sentinel's MITRE ATT&CK framework coverage view shows which TTPs are covered by active analytics rules, revealing detection gaps.
Question 4: Which Microsoft service is specifically designed to protect identities by detecting risks like leaked credentials and atypical sign-in behavior for Azure AD accounts?
- Microsoft Defender for Identity
- Microsoft Entra ID Protection (Correct answer)
- Microsoft Defender for Cloud Apps
- Microsoft Sentinel
Correct answer: Microsoft Entra ID Protection
Microsoft Entra ID Protection monitors cloud identity signals and detects risks such as anonymous IP usage, leaked credentials, and password spray attacks.
Question 5: What is the role of 'threat intelligence' in a security operations workflow?
- It automatically patches vulnerabilities on endpoints
- It provides context about known threats, attackers, and indicators of compromise to improve detection (Correct answer)
- It blocks all external email attachments by default
- It enforces multi-factor authentication for all users
Correct answer: It provides context about known threats, attackers, and indicators of compromise to improve detection
Threat intelligence enriches security data with context about known malicious IPs, domains, file hashes, and attacker TTPs to help analysts detect and prioritize threats.
Question 6: Which Microsoft Defender for Cloud feature provides a single view of the security state across Azure subscriptions, hybrid servers, and multicloud environments?
- Compliance dashboard
- Cloud Security Posture Management (CSPM) (Correct answer)
- Just-in-time VM access
- Adaptive application controls
Correct answer: Cloud Security Posture Management (CSPM)
Cloud Security Posture Management (CSPM) in Defender for Cloud continuously assesses and visualizes the security posture of resources across all connected environments.
Question 7: An analyst wants to automatically close low-severity Microsoft Sentinel incidents that match a known benign pattern without manual review. What should they configure?
- A new data connector
- An automation rule with a 'close incident' action (Correct answer)
- A Workbook visualization
- A new analytics rule with high severity
Correct answer: An automation rule with a 'close incident' action
Automation rules in Microsoft Sentinel can automatically triage, tag, assign, or close incidents based on conditions, reducing manual work for known benign patterns.
Which Microsoft 365 Defender feature provides a visual representation of an attack's timeline and the entities involved to help analysts understand scope?