VIP Exclusive

SC-200 Microsoft Security Operations Analyst VIP Certification Exam

SC-200 — The SC-200 (Microsoft Security Operations Analyst) is a Microsoft certification exam covering threat mitigation using Microsoft Sentinel, Microsoft Defender for Cloud, and Microsoft 365 Defender; it consists of 40–60 questions, has a 150-minute time limit, and requires a scaled score of 700/1000 (70%) to pass.

30
Questions
150m
Time Limit
70.00%
To Pass
Question 1 of 30👑 VIP

Your organization has deployed Microsoft Sentinel connected to a Log Analytics workspace. The SOC manager notices that alert volume from a custom analytics rule is overwhelming analysts with false positives. The rule fires whenever any sign-in from an unfamiliar country is detected, but many of these are legitimate business travelers. You need to reduce false positives without disabling the rule entirely. Which two actions should you take? (Choose two that together form the best approach.) A) Add an exclusion watchlist containing known traveler accounts and reference it in the rule query using the '_GetWatchlist' function. B) Delete the analytics rule and recreate it as a hunting query instead. C) Increase the rule's query frequency to run every 24 hours instead of every 5 minutes so fewer alerts fire. D) Tune the rule's entity mapping to exclude accounts tagged with the 'traveler' custom attribute stored in a watchlist.

Questions 2–30 and full explanations are VIP-exclusive.