Respond to alerts and incidents in Microsoft Defender XDR

7 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.

SC-200 S-grade

Using the Evidence and Response tab to see all entities affected by a Defender XDR incident

To identify all entities affected by a Microsoft Defender XDR incident, use the Evidence and Response tab, which aggregates every related entity (devi

15 comments
SC-200 S-grade

Containing a Defender for Identity pass-the-ticket alert by quarantining only the affected device

A Defender for Identity 'Suspected identity theft (pass-the-ticket)' alert on Device1 means a forged Kerberos ticket resides on that device; quarantin

14 comments
SC-200 A-grade

Identifying the incident remediation action that requires manual action despite full automation

With AIR in Defender for Office 365 and full automation in Defender for Endpoint, email remediation (soft/hard delete) and many device actions are aut

6 comments
SC-200 A-grade

Querying IdentityLogonEvents to hunt LDAP simple binds to AD DS domain controllers

To hunt LDAP simple binds to on-premises Active Directory Domain Services domain controllers in Defender for Identity advanced hunting, query the Iden

5 comments
SC-200 A-grade

Submitting only PE files for Microsoft Defender XDR deep analysis

In Microsoft Defender XDR deep analysis, only portable executable (PE) files (.exe and .dll) are supported; the PowerShell script File1.ps1 is not a P

5 comments
SC-200 A-grade

Using a Conditional Access policy to revoke or force re-authentication of a compromised Outlook on the web session

To ensure a compromised user's Outlook on the web session token can be revoked, configure a Microsoft Entra Conditional Access policy (for example, ba

3 comments
SC-200 A-grade

Using Defender XDR alert tuning rules to hide or resolve alerts and reduce alert fatigue

To tune alerts from a commonly used executable that causes alert fatigue in Defender XDR, an alert tuning rule can hide the alerts (remove them from t

3 comments