SC-200 Study Guide
A curated learning path for the SC-200 exam: the best documentation, videos, blog posts and tutorials for every exam objective.A curated learning path for the SC-200 exam: the best documentation, videos, blog posts and tutorials for every exam objective, in the order worth studying them.
Microsoft Certified: Security Operations Analyst Associate
Exam at a Glance
SC-200 measures whether you can run a security operations center on the Microsoft stack: configuring Microsoft Sentinel and Microsoft Defender XDR, triaging and responding to incidents across identities, endpoints, email, cloud apps, and Azure workloads, and hunting for threats with Kusto Query Language (KQL). It is an operational exam: expect concrete scenarios that ask which table to query, which connector or rule to configure, and which response action to take.
| SC-200 | Microsoft Security Operations Analyst |
|---|---|
| Certification | Microsoft Certified: Security Operations Analyst Associate |
| Level | Intermediate (associate role-based exam) |
| Prerequisite | None required, but the exam assumes hands-on familiarity with Microsoft 365, Azure, and the Microsoft security portfolio |
| Exam length | 100 minutes |
| Questions | Typically 40 to 60; the number and format mix can vary |
| Passing score | 700 out of 1000 |
| Question formats | Multiple choice, multiple select, drag and drop, build list, hot area, case studies |
| Microsoft Learn access | Available within the exam; browsing is restricted and the timer continues |
| Skills measured version | July 28, 2026 |
| Renewal | Certification expires annually; renew with a free online assessment on Microsoft Learn |
| Cost | Depends on your country or region; shown when you schedule |
What the Exam Covers
The exam has three domains, and the first one is the heaviest: configuring the security operations environment carries close to half the score. The other two test what you do once the environment is running: responding to incidents and proactively hunting.
Manage a security operations environment — 40-45%
Automation across Microsoft Defender XDR and Microsoft Sentinel: email and alert notifications, tuning and suppression, Microsoft Defender for Endpoint advanced features, rules settings, custom data collection, attack surface reduction policies, automated investigation and response, automatic attack disruption, device groups and automation levels, and Sentinel automation rules and playbooks.
The Sentinel SIEM and platform (roles, data retention across the Analytics, Data lake, and XDR tiers, workbooks, SOC optimization recommendations) and data ingestion (choosing connectors, Windows Security events via the Azure Monitor agent and data collection rules, Windows Event Forwarding, Syslog and CEF via AMA, Azure activity through Azure Policy and diagnostic settings, threat indicators, custom log tables).
Detection engineering: custom detection rules from Advanced Hunting, Sentinel analytics rules of every kind, MITRE ATT&CK coverage analysis, and anomalies.
Respond to security incidents — 35-40%
Investigating and remediating what each product surfaces in the Defender portal (Microsoft Defender for Office 365 including automatic attack disruption, entities flagged by Microsoft Purview, Microsoft Defender for Cloud workload-protection alerts, Microsoft Defender for Cloud Apps risks, compromised identities from Microsoft Entra ID, Microsoft Defender for Identity alerts, and Sentinel incidents) plus agentic investigation with embedded Microsoft Security Copilot, complex multi-stage and lateral-movement attacks, and case management. On the endpoint side: device timelines, live response and investigation packages, evidence and entity investigation, and incidents produced by automatic attack disruption. For Microsoft 365 activity: Microsoft Purview Audit, Content search in eDiscovery, and Microsoft Graph activity logs.
Perform threat hunting — 20-25%
Using KQL in practical investigations: picking the right advanced hunting table, writing hunting queries, interpreting threat analytics, building hunting graphs including blast radius, and analyzing entity relationships with Sentinel Graph. On the Sentinel platform: hunting queries, KQL jobs in the data lake, Summary rule tables, and notebooks including the Sentinel MCP Server connection.
The full bullet-level list lives in the official study guide. Treat it as your checklist:
The Official SC-200 Study Guide
How This Maps to CertiAce Practice Modules
The CertiAce question bank is organized by the same ten learning paths Microsoft uses for the SC-200 course. Configuration-flavored modules feed the first domain, investigation-flavored modules the second, and the KQL and hunting modules the third, but questions are tagged by what they actually test, so a Defender for Endpoint question about live response counts toward responding to incidents, not managing the environment:
| CertiAce practice module | What you will drill there |
|---|---|
| Mitigate threats using Microsoft Defender XDR | Incident handling across workloads, notifications and tuning, attack disruption, custom detections, Defender for Office 365, Defender for Cloud Apps, Defender for Identity, and Entra ID Protection investigations |
| Mitigate threats using Microsoft Security Copilot | Embedded Copilot in the Defender portal: incident summaries, guided response, script and file analysis, natural-language KQL, agentic triage |
| Mitigate threats using Microsoft Purview | Purview Audit searches, Content search in eDiscovery, Microsoft Graph activity logs, DLP and insider-risk alerts surfaced in Defender XDR |
| Mitigate threats using Microsoft Defender for Endpoint | Advanced features, indicators and rules, attack surface reduction, device groups and automation levels, device timelines, live response, investigation packages |
| Mitigate threats using Microsoft Defender for Cloud | Triaging and remediating workload-protection alerts, workflow automation, just-in-time access as a remediation |
| Create queries for Microsoft Sentinel using Kusto Query Language (KQL) | Table selection, operator semantics, query completion and ordering, parsing and joining log data |
| Configure your Microsoft Sentinel environment | Roles, data tiers and retention, workbooks, SOC optimization, watchlists, automation rules and playbooks |
| Connect logs to Microsoft Sentinel | Connector selection, AMA data collection rules, Windows Event Forwarding, Syslog and CEF, Azure Activity, threat intelligence, custom tables |
| Create detections and perform investigations using Microsoft Sentinel | Scheduled, NRT, threat-intelligence, and ML analytics rules, entity mapping and incident grouping, MITRE coverage, anomalies, incident investigation |
| Perform threat hunting in Microsoft Sentinel | Hunting queries and bookmarks, KQL jobs versus summary rules versus search jobs, hunting graphs and blast radius, Sentinel Graph, notebooks with the Sentinel MCP Server |
Where SC-200 Fits
| Certification | What it validates | When to take it |
|---|---|---|
| SC-900: Security, Compliance, and Identity Fundamentals | The vocabulary of Microsoft security, a gentle on-ramp | Optional first step if you are new to Microsoft security |
| SC-200: Security Operations Analyst Associate (this exam) | Running detection, response, and hunting with Sentinel and Defender XDR | You are here: the core hands-on security operations certification |
| SC-100: Cybersecurity Architect Expert | Designing end-to-end security architecture | After SC-200, if you move toward architecture (passing SC-200 satisfies the SC-100 prerequisite) |
SC-200 is also a stepping stone: to become a Microsoft Certified: Cybersecurity Architect Expert you must hold at least one of three associate certifications: Identity and Access Administrator Associate (exam SC-300), Security Operations Analyst Associate (exam SC-200), or Cloud and AI Security Engineer Associate (exam SC-500), in addition to passing SC-100. Earning SC-200 checks that box.
SC-200 has no prerequisite certifications, but it is not a beginner exam. The skills-measured list assumes you already know your way around Microsoft 365, Azure, Windows and Linux, and increasingly AI agents and Copilots. The exam tests operational judgment on top of that base.
Microsoft Certified: Security Operations Analyst Associate
Before You Start
The exam assumes you have worked with the tools rather than only read about them. Check yourself against this table. Anything unfamiliar is where your preparation should start:
| Area | You should be comfortable with |
|---|---|
| Microsoft Defender XDR | What each Defender product covers, how incidents correlate alerts across them, and where you take response actions in the Defender portal |
| Microsoft Sentinel | Workspaces, data connectors, analytics rules, and how Sentinel is operated inside the Defender portal |
| KQL | Reading and writing basic queries: where, project, extend, summarize, and joins across log tables |
| Identity and Microsoft 365 | Microsoft Entra ID sign-in and audit concepts, Exchange Online and SharePoint basics, how Microsoft Purview fits in |
| Operating systems and endpoints | Windows and Linux fundamentals, process and network telemetry, what an EDR sensor collects |
Step-by-Step Study Plan
How long you need depends on where you start. Treat these estimates as planning guidance and adjust them to your starting knowledge and weekly study hours:
| Your starting point | Suggested prep time |
|---|---|
| Working in a SOC with Sentinel or Defender XDR today | 2 to 4 weeks |
| Security background, but new to Sentinel and KQL | 6 to 10 weeks |
Step 1: Read the Official Study Guide
Skim the full skills-measured list once, and mark every bullet you could not confidently perform in a live tenant. That marked-up list is your personal syllabus: everything else in this plan exists to clear it. Notice how many bullets start with "configure", "investigate", or "create": the exam tests doing, not defining.
Step 2: Schedule Your Exam
Choose a realistic target date after reviewing the skills list and your available study time. A date on the calendar turns studying into a countdown, so pick one using the prep-time table above and plan backwards from it.
Certification and Exam Details Page
Step 3: Work Through the Official Course Material
Complete the ten SC-200 learning paths on Microsoft Learn, the same ten the CertiAce modules mirror. Do the exercises in a trial tenant or lab where you can: onboarding a connector, writing an analytics rule, and running a live response session teach details that reading never will.
Official Learning Path Course Page
Step 4: Get Fluent in KQL
KQL shows up in every domain, not only the hunting one: analytics rules, custom detections, workbooks, summary rules, and KQL jobs are all queries. Work through the SC-200 KQL learning path, then practice against real tables until choosing between summarize, extend, and project (and between DeviceEvents, DeviceLogonEvents, and DeviceProcessEvents) is reflex rather than research.
- SC-200: Create queries for Microsoft Sentinel using KQL
- Common tasks with KQL for Microsoft Sentinel
Step 5: Benchmark Your Knowledge
Use CertiAce to benchmark your readiness module by module. The practice modules map to the exam domains as shown above, so use the module mapping and the topics behind your missed questions to identify the skills-measured areas to revisit. Microsoft also offers a free official practice assessment. Aim for consistent performance across every module, not one lucky high score; if a topic is unstable, go back to the docs for that capability.
Step 6: Take the Exam
The day before, review only your weak topics: no brand-new material. On exam day, read each question for the requirement that discriminates: qualifiers like minimize administrative effort, minimize ingestion cost, or least privilege usually decide between two otherwise-plausible options. When a question shows a query, read it operator by operator before looking at the choices.
Worth knowing before you sit down:
- Microsoft Learn is available during the exam in a split screen. Use it to check details you genuinely need: the timer keeps running, and the exam is deliberately too long to look up every answer. Browsing is limited to Microsoft Learn itself (no Q&A, practice assessments, or profile), and personal notes and other websites are unavailable.
- You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
- Case studies lock when you leave them: finish each one before moving on, because you cannot revisit its questions afterwards.
- Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox
Additional Learning Resources
| Resource | Type | Why it is useful |
|---|---|---|
| Free Official Practice Assessment | Practice | Microsoft's own question-style preview, free |
| Exam Readiness Zone: SC-200 | Video series | Microsoft Certified Trainer prep videos per exam domain |
| Microsoft Sentinel skill-up training | Training hub | Microsoft's structured Sentinel curriculum, from architecture to content creation and SOC operations |
| Microsoft Sentinel documentation | Docs hub | Connectors, analytics rules, automation, the data lake, and hunting (the heaviest exam area) |
| Microsoft Defender XDR documentation | Docs hub | Incidents, advanced hunting, automated investigation, attack disruption, and every Defender product |
| Microsoft Defender for Endpoint documentation | Docs hub | Advanced features, attack surface reduction, device groups, live response, and investigation packages |
| Common tasks with KQL for Microsoft Sentinel | Tutorial | Query structure, filtering, summarizing, and joining: the KQL patterns the exam reuses |
| Security, compliance, and identity community hub | Community | Microsoft's official SCI community: announcements and discussions |
Realistic SC-200 exam-style questions with instant feedback and detailed explanations.
Practice SC-200 now