EnglishDeutschFrançaisEspañolPortuguês

Microsoft · SC-200 · Associate

Microsoft Security Operations Analyst (SC-200) — Practice Questions and Mock Exam

Practice real SC-200 questions, never dumps. Alex explains every answer, and your readiness score tells you when you're ready to pass.

50Questions
100minTime Limit
700/ 1000Pass Score

Checked against Microsoft · July 2026Current exam version

About the exam

The SC-200 certification validates skills in threat detection, investigation, and response using Microsoft security technologies. It covers Microsoft Sentinel (SIEM), Microsoft Defender XDR (extended detection and response), Microsoft Defender for Endpoint, Microsoft Defender for Cloud, threat hunting with KQL, incident management, and security automation using playbooks and workbooks.

This certification is designed for security operations analysts who work in Security Operations Centers (SOCs) monitoring, identifying, investigating, and responding to threats. Candidates should have experience with Microsoft Sentinel, Defender products, KQL for threat hunting, and implementing automated response workflows to security incidents across hybrid environments.

What's on the exam

The exam consists of 40–60 questions to be completed in approximately 100 minutes (100 minutes if labs are included). Question types include multiple-choice, multiple-select, drag-and-drop, hot area, and case study formats. Questions are scenario-based, presenting security incidents and asking you to investigate and respond using Sentinel and Defender tools. Expect KQL queries for threat hunting and questions about detection rule creation.

Manage a security operations environment40–45%

Configure automation for Microsoft Defender XDR and Microsoft Sentinel, configure the Microsoft Sentinel SIEM and platform, ingest data into the Microsoft Sentinel SIEM and platform, and configure detections

Respond to security incidents35–40%

Respond to alerts and incidents in Microsoft Defender XDR, respond to alerts and incidents in Microsoft Defender for Endpoint, and investigate Microsoft 365 activities to identify threats

Perform threat hunting20–25%

Detect threats using Microsoft Defender XDR and the Microsoft Sentinel platform with KQL queries and hunting graphs

SourceMicrosoft study guide

What to expect

Multiple Choice31%
Drag & Drop13%
Command Line11%
Troubleshooting11%
Ordering9%
Multiple Response9%
Dropdown9%
True / False7%

Try it now

Practice real SC-200 questions

Five sample questions from our Microsoft Security Operations Analyst bank. Answer one — Alex, your AI tutor, explains the why. Real prep, never dumps.

Where candidates struggle

This exam requires hands-on security operations experience. Candidates who understand security concepts but haven't used Microsoft Sentinel for investigation and KQL for threat hunting often struggle with the practical scenarios.

  1. 01
    KQL Proficiency — Not knowing Kusto Query Language well enough to write threat hunting queries, create analytics rules, and parse security logs.
  2. 02
    Sentinel Configuration — Struggling with data connector setup, analytics rules, automation rules, and playbook (Logic Apps) configuration in Sentinel.
  3. 03
    Defender XDR — Confusing the capabilities and scopes of Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.
  4. 04
    Incident Management — Not understanding incident lifecycle management, evidence collection, and multi-stage attack investigation workflows.
  5. 05
    Automation Playbooks — Overlooking how to create and configure Logic Apps-based playbooks for automated incident response in Microsoft Sentinel.

Exam logistics

Delivered via Pearson VUE online or at testing centers. Available in English, Japanese, Chinese, Korean, French, German, Spanish, and more. The certification is valid for 1 year with a free renewal assessment on Microsoft Learn.

DeliveryPearson VUE online proctored or at authorized testing centers worldwide
Retake policy24-hour wait after the first attempt, 14 days between subsequent attempts, maximum 5 attempts per exam within a 12-month period
Validity1 year
Career outcomesSecurity Operations Analyst, SOC Analyst, Threat Hunter, Incident Response Analyst, Security Engineer
RenewalFree renewal assessment on Microsoft Learn, available starting 6 months before expiration. Must be completed before the certification expires.
Study time~50 hours
Official guideView on vendor site

SourceMicrosoft exam page

Before you book the exam

Would you pass SC-200 today?

Take the free readiness check. Answer real SC-200 questions and get your readiness score across every domain.

Take the free readiness check20 questions · free

Reach 80% readiness by exam day. Pass, or your money back.

Ready to commit? Own SC-200 for $29.99 →