Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your company uses Microsoft Sentinel to detect and respond to security threats. You have been asked to determine whether the Privilege Escalation tactic (and its related techniques) is already covered by your existing detections, hunting queries, and data sources, and to identify any gaps that require additional analytics rules or connectors. Which Microsoft Sentinel feature should you use to perform this analysis with the MITRE ATT&CK matrix view?
Open the built-in MITRE ATT&CK workbook from the Workbooks gallery and review its detection and data coverage matrices.
Open the Incidents blade and filter incidents by the Privilege Escalation tactic.
Use the Entity behavior blade to review user and host timelines for privilege-escalation anomalies.
Run the User and Entity Behavior Analytics (UEBA) workbook to list alerts related to privilege elevation.
The Microsoft Sentinel MITRE ATT&CK workbook surfaces your workspace's data connectors, analytics rules, and hunting queries on an interactive ATT&CK matrix. By opening this workbook you can immediately see which tactics and techniques (including Privilege Escalation techniques) are covered, and which cells have no associated detections or data sources-allowing you to pinpoint coverage gaps. The Incidents blade, Entity behavior blade, and UEBA workbook focus on investigations and entity analytics, not broad attack-surface coverage mapping.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the MITRE ATT&CK Matrix and why is it important in Microsoft Sentinel?
Open an interactive chat with Bash
What kind of data does the MITRE ATT&CK workbook analyze in Microsoft Sentinel?
Open an interactive chat with Bash
How are analytics rules and hunting queries connected to MITRE ATT&CK in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .