Top SC-200 Exam Questions and Patterns
The SC-200 question patterns candidates see most - Sentinel analytics rules, Defender XDR response actions, KQL hunting scenarios - with the reasoning for each answer.
SC-200 questions · 8 min read · updated 2026-09-05
SC-200 questions map to a small set of analyst decisions in Sentinel and Defender XDR. Learn to recognise the decision behind each question and the correct portal action becomes obvious.
Sentinel rule and connector questions
Which-rule-type questions are frequent: scheduled rules for recurring queries, near-real-time rules when minutes matter, fusion rules to correlate multiple low-fidelity signals across providers, and ML anomaly rules when you have no logic to write. Connector questions pair a data source with its ingestion method (AMA for agents, API connectors for cloud services) and cost considerations.
Incident-configuration questions test settings you must know: severity, tactics mapping for MITRE classification, automation rules versus playbooks (automation rules are simpler and run at incident creation; playbooks are Logic Apps triggered manually, automatically or on a schedule) and group-by options to merge related alerts into one incident.
Defender XDR response actions
Device questions map symptoms to actions: suspected malware isolation, containing a compromised user, collecting an investigation package, restricting an app execution until a decision is made. The exam wants the least disruptive action that stops the threat.
Email questions in Defender for Office 365 test purge options: soft delete moves to recoverable items, hard delete removes for admins, and block actions prevent delivery. For Identity and Cloud Apps, expect risk-based sign-in policies, session controls and activity policies.
KQL and advanced hunting scenarios
Reading queries is tested more than writing: given a query, which behaviour does it detect? Recognise summarize for aggregation (beaconing counts), join for correlating tables (processes against network events), and mv-expand for array fields like EmailAttachments.
Also expect questions on where data lives: DeviceProcessEvents for process trees, EmailEvents for message metadata, IdentityLogonEvents for sign-ins, CloudAppEvents for SaaS activity. The blast-radius question - what else has this identity or device touched - is answered by pivoting across those tables.
Frequently asked questions
- Does the SC-200 exam include hands-on labs?
- The exam includes lab-style and case-study items that simulate portal work - you may be asked to complete a task or read a portal state - plus traditional multiple choice. Practising in a trial tenant is the best preparation.
- Where can I practise free SC-200 questions?
- PassYour offers a free 10-question SC-200 quiz online with explanations, and the full 179-question bank with 24 lessons and three timed mock exams is included in the SC-200 track.
- How much KQL is actually on the SC-200 exam?
- You will read queries more than write them: scenarios present a KQL snippet and ask what it detects or which table to hunt in. Fluent reading of where, summarize, join and mv-expand is enough for the exam.
Keep reading for SC-200
PassYour is an independent study aid and is not affiliated with, endorsed by or sponsored by ISC2, CompTIA or Microsoft.
