Free Microsoft Certified: Security Operations Analyst Associate practice — 6 questions on Manage a security operations environment, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Manage a security operations environment
A SOC must retain 18 months of Azure Firewall network flow logs strictly for future threat hunting queries. The logs must NOT trigger analytics rules or count toward real-time detection costs, and the team wants the lowest-cost Microsoft Sentinel storage option that still supports full KQL hunting queries. Which configuration BEST meets these requirements?
The Data Lake tier is designed for cost-effective long-term storage that remains queryable with full KQL for hunting, without the higher cost or real-time analytics-rule triggering associated with the Analytics tier.
Question 2 of 6 · Manage a security operations environment
Your organization uses Microsoft Sentinel inside the unified Microsoft Defender portal. You need to grant a group of external MSSP analysts the ability to view and triage incidents for only specific device groups, without giving them access to advanced hunting or automation rule configuration. Which approach satisfies this with the LEAST privilege?
Unified RBAC in the Defender portal allows creating custom roles with granular workload permissions (such as incident triage) that can be scoped to specific device groups, giving precise least-privilege access.
Question 3 of 6 · Manage a security operations environment
Your SOC needs to ingest AWS CloudTrail management events into Microsoft Sentinel using the modern AWS connector, and organizational policy prohibits storing long-lived AWS access keys anywhere in Azure. Which authentication mechanism should you configure for the connector?
The modern Sentinel AWS connector uses OIDC-based federated authentication, where AWS trusts Sentinel's Azure AD application and the connector assumes a cross-account IAM role — eliminating the need for stored long-lived access keys.
Question 4 of 6 · Manage a security operations environment
Which combination of GCP resources must be configured together to stream Google Cloud Audit Logs into Microsoft Sentinel using the built-in GCP data connector?
The GCP connector reads audit log entries routed to a Pub/Sub topic through a subscription, and authenticates via workload identity federation to a GCP service account that has been granted Pub/Sub Subscriber permissions — avoiding static key export.
Question 5 of 6 · Manage a security operations environment
A Log Analytics table used by Microsoft Sentinel is configured with 90 days of interactive retention and 2 years of total retention (with the remainder archived). One hundred twenty days after ingestion, an analyst runs a hunting KQL query against the table and finds no results for data older than 90 days, even though the workspace shows the table's total retention as 2 years. What is the cause?
Once data ages past the interactive retention period, it moves into the Archive tier, where it is stored cheaply but is not directly queryable with ad hoc KQL — it must be recovered via a search job or a table restore operation before analysts can query it normally.
Question 6 of 6 · Manage a security operations environment
You want to proactively detect when a critical Microsoft Sentinel data connector silently stops ingesting data, so the SOC is alerted before dependent analytics rules fail to fire on missing data. Which approach BEST achieves this?
Sentinel health monitoring writes operational health events, including data connector ingestion failures, to the SentinelHealth table, which can be queried by a scheduled analytics rule to proactively alert the SOC on failures.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.