✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Manage a security operations environment
A security team lead wants to grant a new SOC Tier 1 analyst the ability to view and manage incidents and alerts across both Microsoft Defender XDR and Microsoft Sentinel, without granting rights to modify automation rules, playbooks, or workspace settings. Which unified RBAC configuration should the lead use in the Microsoft Defender portal?
Unified RBAC in the Defender portal separates permission groups such as 'Security operations' (incident/alert management) from 'Authorization and settings' (connectors, automation, workspace config). Granting Manage on Security operations only gives exactly the required scope across both Defender XDR and connected Sentinel workspaces.
Question 2 of 12 · Configure protections and detections
A SOC needs an alert to fire within one minute of a suspicious impossible-travel sign-in so analysts can respond before the session token is used elsewhere. Which Microsoft Sentinel analytics rule type BEST meets this requirement?
NRT rules run once every minute against the most recent data, delivering the fastest possible detection latency of any Sentinel analytics rule type - the only option that can realistically meet a one-minute requirement.
Question 3 of 12 · Manage incident response
A Microsoft Defender XDR incident shows a device actively encrypting files consistent with ransomware. Which response action should the analyst take FIRST to prevent further damage?
Device isolation immediately cuts the compromised host off from the network, stopping lateral movement and further encryption while investigation continues — this is the standard first containment step for active ransomware.
Question 4 of 12 · Manage security threats
During an active incident investigation in Microsoft Sentinel, an analyst runs a hunting query and finds three suspicious process-creation events buried among thousands of results. The analyst wants to save these three specific events with contextual notes, tag them to entities, and later attach them directly to the incident for the investigation team. Which Sentinel feature should the analyst use?
Bookmarks let an analyst mark specific query result rows, add notes, link them to entities, and attach them to an incident for later investigation — exactly the described requirement.
Question 5 of 12 · Manage a security operations environment
A company onboards 500 new Windows servers into Microsoft Defender for Endpoint. The SOC wants any device tagged 'Finance' to automatically be placed into a scope so only the Finance security team can see and remediate alerts on those machines. What should the SOC configure?
Device groups in Microsoft Defender for Endpoint/XDR support automatic membership rules (based on tag, name, domain) and can be tied to RBAC role assignments so only specific teams see alerts/devices in that group.
Question 6 of 12 · Configure protections and detections
An organization wants Microsoft Sentinel to automatically correlate multiple low-fidelity signals from different products (e.g., a suspicious sign-in from Microsoft Entra ID and unusual PowerShell activity from Defender for Endpoint) into a single high-confidence incident representing a possible multistage attack. Which analytics rule type should be enabled?
Fusion uses Microsoft's ML-based correlation engine to combine multiple low-fidelity signals from different data sources into a single high-confidence incident, specifically targeting multistage attack detection.
Question 7 of 12 · Manage incident response
An analyst is assigned a Microsoft Defender XDR incident containing 40 correlated alerts spanning email, endpoint, and identity. Rather than reading every alert manually, they want a fast natural-language overview of what happened, the affected entities, and the attack timeline. Which Security Copilot capability should they use?
Security Copilot's incident summarization capability ingests all correlated alerts and entities in an incident and produces a natural-language narrative of the attack, timeline, and impacted assets, dramatically speeding up triage.
Question 8 of 12 · Manage security threats
An analyst is writing a KQL hunting query to detect anomalous spikes in failed sign-in counts over a 30-day period. After building a time-bucketed series with make-series, which function should be applied to automatically flag statistical anomalies in that series?
series_decompose_anomalies() is the KQL function specifically designed to analyze a time series (typically produced with make-series) and score/flag data points as anomalies, which is a core technique tested for KQL-based hunting.
Question 9 of 12 · Manage a security operations environment
A Microsoft Sentinel analyst needs to run frequent scheduled analytics rules against Windows Security Event data for near real-time detection, while also retaining that data for 400 days for compliance audits at the lowest reasonable cost. Which configuration should be used?
Only the Analytics tier supports scheduled analytics rules for near real-time detection, and its interactive retention can be extended beyond the free 90 days (up to 2 years interactive, longer via archive) to satisfy the 400-day compliance need.
Question 10 of 12 · Configure protections and detections
Two automation rules in Microsoft Sentinel are both triggered when an incident is created for a specific analytics rule: one adds a tag and assigns an owner, the other runs a playbook that automatically closes false positives. The team wants the tagging rule to run before the playbook rule. What must be configured to guarantee this?
Automation rules triggered by the same event execute in the order specified by their numeric 'order' value, with the lowest order number running first - this is the only guaranteed way to control sequencing.
Question 11 of 12 · Manage incident response
A device group in Microsoft Defender for Endpoint has automated investigation and response (AIR) configured with automation level 'Full – remediate threats automatically.' When AIR determines a file on a device in this group is malicious, what happens?
At the 'Full – remediate threats automatically' automation level, AIR applies remediation actions (e.g., quarantine, removal) immediately without waiting for analyst sign-off, which is the level's defining behavior.
Question 12 of 12 · Manage security threats
A threat intelligence indicator imported into Microsoft Sentinel should stop being matched against incoming logs automatically after 30 days, without the analyst needing to manually delete it. Which property of the threat indicator should be configured to accomplish this?
The expirationDateTime (shown as 'Valid Until' in the Sentinel UI) field defines when a threat indicator is automatically considered expired and stops being used for matching, without requiring manual deletion.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.
The exam fee is approximately $165 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 4 domains: Manage a security operations environment (40-45%), Configure protections and detections (15-20%), Manage incident response (25-30%), Manage security threats (15-20%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
How do I get the discount?
Use code FREETEST33 at checkout for $34.99 (list undefined) through Oct 6 — the enroll button applies it automatically.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.