🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 11 hours remaining!

Microsoft Security Operations Analyst Associate SC-200 Practice Question

You are reviewing a "Potential data theft by departing employee" alert in Microsoft Purview insider risk management. You must inspect the individual files and emails that triggered the policy so you can confirm the user's intent before deciding whether to escalate the alert to an eDiscovery (Premium) case. Which section of the alert page should you use to view the chronological list of risky activities and open each item in the built-in content viewer?

  • The Overview tab of the insider risk alert

  • The User activity tab of the insider risk alert

  • Content explorer in the Data classification workload

  • Activity explorer in Microsoft Purview Data Loss Prevention

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot