Security Operations Analyst
Associate
The Microsoft security operations certification. Defender XDR, Sentinel, KQL hunting, incident response, and detection engineering โ explained with real SOC scenarios.
Study Guide
28 interactive modules
KQL Foundations, Advanced Hunting, and Incident Triage modules + 15 practice questions. No account needed.
Start Free โPractice Exam
200 exam-style questions
Study mode with explanations + timed exam simulation. 15 free questions.
Try Free Questions โ28
Modules
200
Questions
3
Domains
Free
Domain 3 included
๐ Sample Question
A Sentinel analytics rule needs to detect admin logins from new countries within 60 seconds. The logic involves only the SigninLogs table. Which rule type should you use?
๐ What you'll cover
What you'll learn
๐ก๏ธ
Defender XDR & Sentinel
The two products that dominate the exam. Configure workspaces, data connectors, analytics rules, and automation โ with real SOC scenarios.
โก
KQL Threat Hunting
Write hunting queries that find what your detections missed. Cross-table joins, Advanced Hunting patterns, and Data Lake queries.
๐
Incident Response
Triage, investigate, and remediate incidents across endpoints, identity, email, cloud apps, and Purview. Copilot for Security included.
๐ฏ
Detection Engineering
Build custom detections, analytics rules, threat intel matching, and MITRE ATT&CK coverage analysis. The full detection lifecycle.
Full Curriculum
28 interactive modules across 3 exam domains
1 Manage a Security Operations Environment
12 modules
Premium
Manage a Security Operations Environment
12 modules
Configure Microsoft Sentinel workspace, roles, and data retention. Set up data connectors for Windows, Syslog, CEF, and Azure. Configure Defender for Endpoint, ASR rules, alert tuning, automated investigation, and detection engineering with MITRE ATT&CK coverage.
- 1Sentinel Workspace
- 2Windows Connectors
- 3Syslog/CEF/Azure
- 4MDE Core Setup
- 5ASR & Security Policies
- 6XDR Alert Tuning
- 7Auto Investigation
- 8Sentinel Automation
- 9Custom Detections
- 10Analytics & Threat Intel
- 11MITRE & Anomalies
- 12Detection Engineering
2 Respond to Security Incidents
10 modules
Premium
Respond to Security Incidents
10 modules
Triage incidents in Defender XDR, investigate threats from Purview, Defender for Cloud, identity, and cloud apps. Use Copilot for Security for AI-assisted investigation. Handle complex multi-stage attacks, endpoint forensics with live response, and M365 audit investigations.
- 1Incident Triage
- 2Purview & Cloud Threats
- 3Identity Threats
- 4Cloud App Security
- 5Sentinel Incidents
- 6Copilot for Security
- 7Complex Attacks
- 8Timeline & Live Response
- 9Evidence & Entities
- 10M365 Investigations
3 Perform Threat Hunting
6 modules
Free
Perform Threat Hunting
6 modules
Master KQL for threat hunting. Write Advanced Hunting queries across Defender XDR. Build Sentinel hunting queries with bookmarks and livestream. Use threat analytics, hunting graphs, Data Lake KQL jobs, and notebooks with the Sentinel MCP Server.
- 1KQL Foundations
- 2Advanced Hunting
- 3Sentinel Hunting
- 4Threat Analytics & Graphs
- 5Data Lake & Summary Rules
- 6Notebooks & MCP Server
Practice Exam Lab
200 original questions โ two study modes
Study Mode
Learn as you go
- โ See explanation after each question
- โ "Why wrong" for every option
- โ Real-world context & exam tips
- โ Microsoft Learn links
Exam Mode
Simulate the real thing
- โ 120 minutes timed session
- โ Randomised question order
- โ Score breakdown by domain
- โ Pass/fail against 700 / 1000
1Manage a Security Operations Environment
90 questions ยท Exam weight: 40-45%
0 Free
Manage a Security Operations Environment
90 questions ยท Exam weight: 40-45%
27
Easy
40
Medium
23
Hard
Every question includes a scenario, detailed explanation, and a link to Microsoft Learn.
Preview Questions 2Respond to Security Incidents
70 questions ยท Exam weight: 35-40%
5 Free
Respond to Security Incidents
70 questions ยท Exam weight: 35-40%
21
Easy
32
Medium
17
Hard
Every question includes a scenario, detailed explanation, and a link to Microsoft Learn.
Try Free Questions โ 3Perform Threat Hunting
40 questions ยท Exam weight: 20-25%
10 Free
Perform Threat Hunting
40 questions ยท Exam weight: 20-25%
12
Easy
18
Medium
10
Hard
Every question includes a scenario, detailed explanation, and a link to Microsoft Learn.
Try Free Questions โ๐ Free tier: 15 questions. No account needed.
Choose your path
Start free. Upgrade when you're ready.
Practice Exam
$14
one-time purchase
- โ 200 exam-style questions
- โ Study mode + Exam mode
- โ Detailed explanations
Study Guide
$19
one-time purchase
- โ 28 interactive modules
- โ Flashcards & ELI5
- โ Progress tracking
Complete Bundle
$29
save $4
- โ Everything in both
- โ Best value
๐ Free tier: KQL Foundations, Advanced Hunting, and Incident Triage modules + 15 practice questions. No account needed. No account needed.
About the SC-200 Exam
- Exam code
- SC-200
- Duration
- 120 minutes
- Passing score
- 700 / 1000
- Question types
- MCQ, multi-select, case studies
- Cost
- $165 USD
Exam Domains & Weights
Frequently Asked Questions
What is SC-200?
How much KQL do I need to know?
What's in the free tier?
Is this harder than SC-900?
Is this a one-time purchase?
Can I study on my phone?
Ready to start?
Try the free tier. Upgrade when you're ready to pass.