SC200 Microsoft Security Operations Analyst Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A security analyst is investigating a series of subtle anomalies within the network. Logs indicate a system administrator\'s account was used to execute a PowerShell script with heavily obfuscated parameters on a critical server. Shortly after, unusual outbound network traffic was observed from that server, utilizing a non-standard port and protocol to communicate with an external IP address. Further investigation reveals the same administrator account also accessed the server\'s registry remotely, modifying a specific key related to system services, immediately preceding the PowerShell execution. What fundamental detection methodology within Microsoft Sentinel would be most effective in identifying and correlating these disparate, yet behaviorally linked, activities to flag this potential \"living off the land\" attack?

User and Entity Behavior Analytics (UEBA)
Signature-based Intrusion Detection
Static File Hash Analysis
Vulnerability Scanning Correlation

About the SC200 Microsoft Security Operations Analyst Certification

These free practice questions are designed to help you assess your readiness for the SC200 Microsoft Security Operations Analyst exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.