Practice Free SC-200 Exam Online Questions
You have a Microsoft 365 B5 subscription that contains two groups named Group! and Group2 and uses Microsoft Copilot for Security.
You need to configure Copilot for Security role assignments to meet the following requirements:
• Ensure that members of Group1 can run prompts and respond to Microsoft Defender XDR security incidents.
• Ensure that members of Group2 can run prompts.
• Follow the principle of least privilege.
You remove Everyone from the Copilot Contributor role.
Which two actions should you perform next? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . Assign the Copilot Contributor role to Group2.
- B . Assign the Security Operator role to Group1.
- C . Assign the Copilot Owner role to Group1.
- D . Assign the Security Operator role to Group2.
- E . Assign the Copilot Owner role to Group2.
The issue for which team can be resolved by using Microsoft Defender for Office 365?
- A . executive
- B . marketing
- C . security
- D . sales
The issue for which team can be resolved by using Microsoft Defender for Office 365?
- A . executive
- B . marketing
- C . security
- D . sales
You have two Azure subscriptions that use Microsoft Defender for Cloud.
You need to ensure that specific Defender for Cloud security alerts are suppressed at the root
management group level. The solution must minimize administrative effort.
What should you do in the Azure portal?
- A . Create an Azure Policy assignment.
- B . Modify the Workload protections settings in Defender for Cloud.
- C . Create an alert rule in Azure Monitor.
- D . Modify the alert settings in Defender for Cloud.
HOTSPOT
You need to create an advanced hunting query to investigate the executive team issue.
How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that uses Microsoft Copilot for Security.
You start a Copilot for Security session and enter five prompts that each provide responses.
You need to create a promptbook that will use the prompts but will NOT contain the responses. The solution must minimize administrative effort.
What should you do?
- A . Enter a new prompt that has the following input: Create a promptbook from my session prompts.
- B . Select each prompt, and then select Create promptbook.
- C . Share the session, and then select Create promptbook.
- D . Create a new promptbook and include each prompt.
HOTSPOT
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR and contains a Windows device named Device1.
You detect malicious activity on Device1.
You initiate a live response session on Device1.
You need to perform the following actions:
• Download a file from the live response library.
• Stop a process that is running on Device1.
Which live response command should you run for each action? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that contains two users named User1 and User2 and From the Copilot for Security portal, User1 starts a session and creates the following prompts:
• Prompt1: Provides access to the Entra plugin
• Prompt2: Provides access to the Intune plugin
• Prompt3: Provides access to the Entra plugin User1 shares the session with User2.
User2 does NOT have access to Microsoft Intune.
For which prompts can User2 view results during the shared session?
- A . Prompt1 only
- B . Prompt1 and Prompt2 only
- C . Prompt3 only
- D . Prompt1 and Prompt3 only
- E . Prompt1, Prompt2, and Prompt3
DRAG DROP
You have a Microsoft Sentinel workspace named Workspace1.
You need to run a KQL query as a search job.
Which five actions should you perform in Workspace 1 in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You need to correlate data from the SecurityEvent Log Anarytks table to meet the Microsoft Sentinel requirements for using UEBA.
Which Log Analytics table should you use?
- A . SentwlAuoNt
- B . AADRiskyUsers
- C . IdentityOirectoryEvents
- D . Identityinfo

