SC-200STUDY GUIDEFree
Guides

SC-200 Study Guide

A curated learning path for the SC-200 exam: the best documentation, videos, blog posts and tutorials for every exam objective.

Microsoft Certified: Security Operations Analyst Associate


Exam at a Glance

SC-200 measures whether you can run a security operations center on the Microsoft stack: configuring Microsoft Sentinel and Microsoft Defender XDR, triaging and responding to incidents across identities, endpoints, email, cloud apps, and Azure workloads, and hunting for threats with Kusto Query Language (KQL). It is an operational exam: expect concrete scenarios that ask which table to query, which connector or rule to configure, and which response action to take.

SC-200Microsoft Security Operations Analyst
CertificationMicrosoft Certified: Security Operations Analyst Associate
LevelIntermediate (associate role-based exam)
PrerequisiteNone required, but the exam assumes hands-on familiarity with Microsoft 365, Azure, and the Microsoft security portfolio
Exam length100 minutes
QuestionsTypically 40 to 60; the number and format mix can vary
Passing score700 out of 1000
Question formatsMultiple choice, multiple select, drag and drop, build list, hot area, case studies
Microsoft Learn accessAvailable within the exam; browsing is restricted and the timer continues
Skills measured versionJuly 28, 2026
RenewalCertification expires annually; renew with a free online assessment on Microsoft Learn
CostDepends on your country or region; shown when you schedule

 

What the Exam Covers

The exam has three domains, and the first one is the heaviest: configuring the security operations environment carries close to half the score. The other two test what you do once the environment is running: responding to incidents and proactively hunting.

 

Manage a security operations environment — 40-45%

Automation across Microsoft Defender XDR and Microsoft Sentinel: email and alert notifications, tuning and suppression, Microsoft Defender for Endpoint advanced features, rules settings, custom data collection, attack surface reduction policies, automated investigation and response, automatic attack disruption, device groups and automation levels, and Sentinel automation rules and playbooks.

The Sentinel SIEM and platform (roles, data retention across the Analytics, Data lake, and XDR tiers, workbooks, SOC optimization recommendations) and data ingestion (choosing connectors, Windows Security events via the Azure Monitor agent and data collection rules, Windows Event Forwarding, Syslog and CEF via AMA, Azure activity through Azure Policy and diagnostic settings, threat indicators, custom log tables).

Detection engineering: custom detection rules from Advanced Hunting, Sentinel analytics rules of every kind, MITRE ATT&CK coverage analysis, and anomalies.

 

Respond to security incidents — 35-40%

Investigating and remediating what each product surfaces in the Defender portal (Microsoft Defender for Office 365 including automatic attack disruption, entities flagged by Microsoft Purview, Microsoft Defender for Cloud workload-protection alerts, Microsoft Defender for Cloud Apps risks, compromised identities from Microsoft Entra ID, Microsoft Defender for Identity alerts, and Sentinel incidents) plus agentic investigation with embedded Microsoft Security Copilot, complex multi-stage and lateral-movement attacks, and case management. On the endpoint side: device timelines, live response and investigation packages, evidence and entity investigation, and incidents produced by automatic attack disruption. For Microsoft 365 activity: Microsoft Purview Audit, Content search in eDiscovery, and Microsoft Graph activity logs.

 

Perform threat hunting — 20-25%

Using KQL in practical investigations: picking the right advanced hunting table, writing hunting queries, interpreting threat analytics, building hunting graphs including blast radius, and analyzing entity relationships with Sentinel Graph. On the Sentinel platform: hunting queries, KQL jobs in the data lake, Summary rule tables, and notebooks including the Sentinel MCP Server connection.

 

The full bullet-level list lives in the official study guide. Treat it as your checklist:

The Official SC-200 Study Guide

 

How This Maps to CertiAce Practice Modules

The CertiAce question bank is organized by the same ten learning paths Microsoft uses for the SC-200 course. Configuration-flavored modules feed the first domain, investigation-flavored modules the second, and the KQL and hunting modules the third, but questions are tagged by what they actually test, so a Defender for Endpoint question about live response counts toward responding to incidents, not managing the environment:

CertiAce practice moduleWhat you will drill there
Mitigate threats using Microsoft Defender XDRIncident handling across workloads, notifications and tuning, attack disruption, custom detections, Defender for Office 365, Defender for Cloud Apps, Defender for Identity, and Entra ID Protection investigations
Mitigate threats using Microsoft Security CopilotEmbedded Copilot in the Defender portal: incident summaries, guided response, script and file analysis, natural-language KQL, agentic triage
Mitigate threats using Microsoft PurviewPurview Audit searches, Content search in eDiscovery, Microsoft Graph activity logs, DLP and insider-risk alerts surfaced in Defender XDR
Mitigate threats using Microsoft Defender for EndpointAdvanced features, indicators and rules, attack surface reduction, device groups and automation levels, device timelines, live response, investigation packages
Mitigate threats using Microsoft Defender for CloudTriaging and remediating workload-protection alerts, workflow automation, just-in-time access as a remediation
Create queries for Microsoft Sentinel using Kusto Query Language (KQL)Table selection, operator semantics, query completion and ordering, parsing and joining log data
Configure your Microsoft Sentinel environmentRoles, data tiers and retention, workbooks, SOC optimization, watchlists, automation rules and playbooks
Connect logs to Microsoft SentinelConnector selection, AMA data collection rules, Windows Event Forwarding, Syslog and CEF, Azure Activity, threat intelligence, custom tables
Create detections and perform investigations using Microsoft SentinelScheduled, NRT, threat-intelligence, and ML analytics rules, entity mapping and incident grouping, MITRE coverage, anomalies, incident investigation
Perform threat hunting in Microsoft SentinelHunting queries and bookmarks, KQL jobs versus summary rules versus search jobs, hunting graphs and blast radius, Sentinel Graph, notebooks with the Sentinel MCP Server

 

Where SC-200 Fits

CertificationWhat it validatesWhen to take it
SC-900: Security, Compliance, and Identity FundamentalsThe vocabulary of Microsoft security, a gentle on-rampOptional first step if you are new to Microsoft security
SC-200: Security Operations Analyst Associate (this exam)Running detection, response, and hunting with Sentinel and Defender XDRYou are here: the core hands-on security operations certification
SC-100: Cybersecurity Architect ExpertDesigning end-to-end security architectureAfter SC-200, if you move toward architecture (passing SC-200 satisfies the SC-100 prerequisite)

SC-200 is also a stepping stone: to become a Microsoft Certified: Cybersecurity Architect Expert you must hold at least one of three associate certifications: Identity and Access Administrator Associate (exam SC-300), Security Operations Analyst Associate (exam SC-200), or Cloud and AI Security Engineer Associate (exam SC-500), in addition to passing SC-100. Earning SC-200 checks that box.

SC-200 has no prerequisite certifications, but it is not a beginner exam. The skills-measured list assumes you already know your way around Microsoft 365, Azure, Windows and Linux, and increasingly AI agents and Copilots. The exam tests operational judgment on top of that base.

Microsoft Certified: Security Operations Analyst Associate

 

Before You Start

The exam assumes you have worked with the tools rather than only read about them. Check yourself against this table. Anything unfamiliar is where your preparation should start:

AreaYou should be comfortable with
Microsoft Defender XDRWhat each Defender product covers, how incidents correlate alerts across them, and where you take response actions in the Defender portal
Microsoft SentinelWorkspaces, data connectors, analytics rules, and how Sentinel is operated inside the Defender portal
KQLReading and writing basic queries: where, project, extend, summarize, and joins across log tables
Identity and Microsoft 365Microsoft Entra ID sign-in and audit concepts, Exchange Online and SharePoint basics, how Microsoft Purview fits in
Operating systems and endpointsWindows and Linux fundamentals, process and network telemetry, what an EDR sensor collects

 


Step-by-Step Study Plan

How long you need depends on where you start. Treat these estimates as planning guidance and adjust them to your starting knowledge and weekly study hours:

Your starting pointSuggested prep time
Working in a SOC with Sentinel or Defender XDR today2 to 4 weeks
Security background, but new to Sentinel and KQL6 to 10 weeks

 

Step 1: Read the Official Study Guide

Skim the full skills-measured list once, and mark every bullet you could not confidently perform in a live tenant. That marked-up list is your personal syllabus: everything else in this plan exists to clear it. Notice how many bullets start with "configure", "investigate", or "create": the exam tests doing, not defining.

The Official Study Guide

 

Step 2: Schedule Your Exam

Choose a realistic target date after reviewing the skills list and your available study time. A date on the calendar turns studying into a countdown, so pick one using the prep-time table above and plan backwards from it.

Certification and Exam Details Page

 

Step 3: Work Through the Official Course Material

Complete the ten SC-200 learning paths on Microsoft Learn, the same ten the CertiAce modules mirror. Do the exercises in a trial tenant or lab where you can: onboarding a connector, writing an analytics rule, and running a live response session teach details that reading never will.

Official Learning Path Course Page

 

Step 4: Get Fluent in KQL

KQL shows up in every domain, not only the hunting one: analytics rules, custom detections, workbooks, summary rules, and KQL jobs are all queries. Work through the SC-200 KQL learning path, then practice against real tables until choosing between summarize, extend, and project (and between DeviceEvents, DeviceLogonEvents, and DeviceProcessEvents) is reflex rather than research.

 

Step 5: Benchmark Your Knowledge

Use CertiAce to benchmark your readiness module by module. The practice modules map to the exam domains as shown above, so use the module mapping and the topics behind your missed questions to identify the skills-measured areas to revisit. Microsoft also offers a free official practice assessment. Aim for consistent performance across every module, not one lucky high score; if a topic is unstable, go back to the docs for that capability.

CertiAce SC-200 Exam Practice

 

Step 6: Take the Exam

The day before, review only your weak topics: no brand-new material. On exam day, read each question for the requirement that discriminates: qualifiers like minimize administrative effort, minimize ingestion cost, or least privilege usually decide between two otherwise-plausible options. When a question shows a query, read it operator by operator before looking at the choices.

Worth knowing before you sit down:

  • Microsoft Learn is available during the exam in a split screen. Use it to check details you genuinely need: the timer keeps running, and the exam is deliberately too long to look up every answer. Browsing is limited to Microsoft Learn itself (no Q&A, practice assessments, or profile), and personal notes and other websites are unavailable.
  • You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
  • Case studies lock when you leave them: finish each one before moving on, because you cannot revisit its questions afterwards.
  • Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox

 


Additional Learning Resources

ResourceTypeWhy it is useful
Free Official Practice AssessmentPracticeMicrosoft's own question-style preview, free
Exam Readiness Zone: SC-200Video seriesMicrosoft Certified Trainer prep videos per exam domain
Microsoft Sentinel skill-up trainingTraining hubMicrosoft's structured Sentinel curriculum, from architecture to content creation and SOC operations
Microsoft Sentinel documentationDocs hubConnectors, analytics rules, automation, the data lake, and hunting (the heaviest exam area)
Microsoft Defender XDR documentationDocs hubIncidents, advanced hunting, automated investigation, attack disruption, and every Defender product
Microsoft Defender for Endpoint documentationDocs hubAdvanced features, attack surface reduction, device groups, live response, and investigation packages
Common tasks with KQL for Microsoft SentinelTutorialQuery structure, filtering, summarizing, and joining: the KQL patterns the exam reuses
Security, compliance, and identity community hubCommunityMicrosoft's official SCI community: announcements and discussions
READY TO TEST YOURSELF?
Practice what you just studied

Realistic SC-200 exam-style questions with instant feedback and detailed explanations.

Practice SC-200 now