EnglishDeutschFrançaisEspañolPortuguês

Microsoft · SC-200 · Associate

Microsoft Security Operations Analyst (SC-200) — Practice Questions and Mock Exam

Prepare for SC-200 with original practice questions and clear answer explanations. Ask Alex, your AI tutor, when you need more detail, use your results to identify topics to review, and practice your pacing with timed mock exams.

50Mock exam questions
100minTime limit
700/ 1000Passing score

Checked against Microsoft · August 2026 · Current exam version

About the exam

The SC-200 certification validates skills in threat detection, investigation, and response using Microsoft security technologies. It covers Microsoft Sentinel (SIEM), Microsoft Defender XDR (extended detection and response), Microsoft Defender for Endpoint, Microsoft Defender for Cloud, threat hunting with KQL, incident management, and security automation using playbooks and workbooks.

This certification is designed for security operations analysts who work in Security Operations Centers (SOCs) monitoring, identifying, investigating, and responding to threats. Candidates should have experience with Microsoft Sentinel, Defender products, KQL for threat hunting, and implementing automated response workflows to security incidents across hybrid environments.

Try five SC-200 questions

Try five practice questions from the app’s current Microsoft Security Operations Analyst question bank, with answers and explanations.

Manage a security operations environment2 / 5

A security team wants to implement zero-day protection for email attachments. Which Defender for Office 365 feature provides this by detonating attachments in a sandboxed virtual environment?

AlexFull explanation from Alex

Safe Attachments in Microsoft Defender for Office 365 provides zero-day protection by detonating email attachments in a sandboxed virtual environment before delivery. The attachment is opened in a controlled VM where behavior is analyzed for malicious activity. Policy actions include Block (quarantine malicious attachments), Replace (deliver email without the attachment), and Dynamic Delivery (deliver email body immediately, reattach after scan completes). This catches malware that signature-based scanning cannot detect. Safe Links is a separate feature that protects against malicious URLs, not attachments. Anti-spam filtering and DLP policies do not provide sandbox detonation. Dynamic Delivery minimizes end-user delay while maintaining protection. Ref: learn.microsoft.com/microsoft-365/security/office-365-security/safe-attachments-about

Sourcelearn.microsoft.com

Perform threat hunting3 / 5

Which Microsoft Defender XDR table should you query in Advanced Hunting to find information about email-based threats including phishing and malware attachments?

AlexFull explanation from Alex

The EmailEvents table in Microsoft Defender XDR Advanced Hunting is the primary source for investigating email-based threats including phishing, malware, and spam. It contains sender/recipient information, subject lines, delivery actions (delivered, blocked, junked), and threat detection methods. Related tables provide additional detail: EmailAttachmentInfo for attachment metadata, EmailUrlInfo for URLs embedded in emails, and EmailPostDeliveryEvents for post-delivery actions like ZAP (Zero-hour Auto Purge). IdentityLogonEvents covers authentication events, CloudAppEvents covers SaaS activity, and DeviceProcessEvents covers endpoint process execution — none are email-specific. Ref: learn.microsoft.com/defender-xdr/advanced-hunting-emailevents-table

Sourcelearn.microsoft.com

Respond to security incidents4 / 5

Identify the correct Defender XDR portal location to review threat analytics reports about current active campaigns and emerging threats.

AlexFull explanation from Alex

Threat analytics in the Microsoft Defender XDR portal is an in-product threat intelligence solution from expert Microsoft security researchers. Each report covers active campaigns, emerging threats, and vulnerabilities with campaign descriptions, TTPs (tactics, techniques, procedures), indicators of compromise (IoCs), recommended mitigations, and organizational exposure assessments. Access it via the Threat analytics section in the Defender portal. It helps SOC teams understand their exposure to current threats and prioritize response. This is distinct from the Incidents queue or Secure Score, which serve different functions. Ref: learn.microsoft.com/defender-xdr/threat-analytics

Sourcelearn.microsoft.com

Respond to security incidents5 / 5

In Microsoft Defender XDR, what is the difference between an alert and an incident?

AlexFull explanation from Alex

Alert vs Incident in Defender XDR: An alert is a single detection signal (one suspicious event detected by one product). An incident groups related alerts together into a correlated investigation unit. One incident may contain multiple alerts from different Defender products, showing the full attack story. Example: phishing email alert + malware execution alert + lateral movement alert = one incident. Incidents reduce alert fatigue by correlating related signals. Exam tip: Alert = single detection. Incident = grouped related alerts. Incident = full attack story. Reduces alert fatigue.

Sourcelearn.microsoft.com

432 practice questions

The Pass-IT question pool gives you material to practice for SC-200. A Pass-IT mock exam uses 50 questions and a 100-minute time limit; these are practice settings.

Pool details: SC-200

Exam details checked against MicrosoftAugust 28, 2026

date of the last check against the official Microsoft source

Passing score700 / 1,000

as published by Microsoft

Objectives in the guide63 objectives listed in the official guide

across 3 domains in the official exam guide

Pool size432 questions

= The pool size is equivalent to 8 sets of 50 questions; this does not mean that each mock exam uses a separate set.

Blueprint domains3 domains in the exam blueprint

Manage a security operations environment 195 · Respond to security incidents 153 · Perform threat hunting 84

Recorded as checked against sources432 of 432

questions recorded as having their answer, options, and explanation checked against official Microsoft documentation

What's on the exam

Managing a security operations environment and responding to incidents together account for roughly 80% of the exam, at 40–45% and 35–40% respectively — Sentinel and Defender XDR configuration, data ingestion, detection rules, and incident investigation and response carry almost the entire blueprint. Threat hunting closes it out at 20–25%.

That concentration means SC-200 is primarily an incident-response exam with a hunting section attached, not three equal specialties. Candidates who are confident writing KQL for hunting but haven't configured Sentinel's data connectors, analytics rules, and automation playbooks from scratch are underprepared for the 40%-plus domain that anchors the exam.

Exam blueprint: SC-200

Manage a security operations environment40–45%

Configure automation for Microsoft Defender XDR and Microsoft Sentinel, configure the Microsoft Sentinel SIEM and platform, ingest data into the Microsoft Sentinel SIEM and platform, and configure detections

≈ 21 h
Respond to security incidents35–40%

Respond to alerts and incidents in Microsoft Defender XDR, respond to alerts and incidents in Microsoft Defender for Endpoint, and investigate Microsoft 365 activities to identify threats

≈ 19 h
Perform threat hunting20–25%

Detect threats using Microsoft Defender XDR and the Microsoft Sentinel platform with KQL queries and hunting graphs

≈ 10 h

Exam format and question types

The exam draws 40–60 questions from a mix of multiple-choice, multiple-select, drag-and-drop, hot-area, and case-study formats inside a 100-minute window. Most items present a security incident and ask you to investigate and respond using Sentinel and Defender tools, including KQL queries written against live log data. Detection-rule creation and automation-playbook configuration appear as frequently as the investigation scenarios themselves.

Question types: SC-200

Multiple Choice41%

Select the single answer that best meets the question’s requirements.

Drag & Drop17%

Move items into the slots, groups, or sequence specified by the task.

Ordering11%

Arrange the steps in the sequence needed to complete the process.

Multiple Response11%

Select multiple answers. Follow the question’s instructions on how many to choose.

Dropdown11%

Choose options from dropdown menus to complete a statement or configuration.

True / False9%

Decide whether a statement is true or false, paying attention to its conditions and wording.

See Microsoft for official question-format information. The shares shown describe the Pass-IT practice pool; they do not establish the proportions on the official exam.

Preparing for SC-200

The exam runs through Pearson VUE, either online with a remote proctor or at an authorized testing center, and is offered in English, Japanese, Chinese, Korean, French, German, Spanish, and several other languages. Certification holds for one year, and Microsoft opens a free renewal assessment on Learn starting six months before it expires.

Preparation and logistics: SC-200

Preparation

Illustrative study time30–75 h

illustrative planning range: 30 h with relevant experience to 75 h when starting out; your needs may fall outside this range

LevelAssociate

Taking and maintaining the certification

DeliveryPearson VUE online proctored or at authorized testing centers worldwide
Retake policy24-hour wait after the first attempt, 14 days between subsequent attempts, maximum 5 attempts per exam within a 12-month period
Certification validity1 year

Free renewal assessment on Microsoft Learn, available starting 6 months before expiration. Must be completed before the certification expires.

Common pitfalls

Topics to review: SC-200

  1. 01KQL Proficiency

    Not knowing Kusto Query Language well enough to write threat hunting queries, create analytics rules, and parse security logs.

  2. 02Sentinel Configuration

    Struggling with data connector setup, analytics rules, automation rules, and playbook (Logic Apps) configuration in Sentinel.

  3. 03Defender XDR

    Confusing the capabilities and scopes of Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.

  4. 04Incident Management

    Not understanding incident lifecycle management, evidence collection, and multi-stage attack investigation workflows.

  5. 05Automation Playbooks

    Overlooking how to create and configure Logic Apps-based playbooks for automated incident response in Microsoft Sentinel.

Frequently asked questions

How long is the Microsoft Security Operations Analyst exam?

The SC-200 exam has 50 questions and a 100-minute time limit.

What is the passing score for Microsoft Security Operations Analyst?

The passing score for the SC-200 exam is 700 / 1000.

Which pitfalls should I review when preparing for Microsoft Security Operations Analyst?

Topics to review include KQL Proficiency, Sentinel Configuration, Defender XDR, Incident Management, Automation Playbooks. Work through examples to check that you understand the distinctions and can explain your answer.

What does the SC-200 exam actually test?

Less product trivia than people expect and more KQL than they hope. Managing the security operations environment alone is roughly 42% of the exam, with incident response near 38% and threat hunting around 20%. Our guide goes through what that looks like question by question. Read what SC-200 tests

How often do you renew SC-200?

Every year, through Microsoft's free renewal assessment on Microsoft Learn. It opens six months before your expiry date and has to be finished before that date.

Which SC-200 topics carry the most marks?

Managing a security operations environment is the largest domain at roughly 42%, responding to incidents around 38% and threat hunting near 20%. With only three domains, this exam is more concentrated than most, and Sentinel configuration and KQL run through all three.

What should you take after SC-200?

SC-100 is the expert-level step if you are moving from running security operations to designing them. SC-300 covers identity and access, which pairs naturally with the operations work SC-200 tests.

What happens if you fail SC-200?

A retake is available after 24 hours. Each further attempt needs a 14-day wait, capped at five attempts in any 12 months.

One certification, 12 months

Practice for SC-200

Focus your practice on one certification, or choose Pro to practice across all certifications.

Start a free practice sessionTry the first 20 questions without a card to see whether the practice suits you.

For eligible purchases: money-back guarantee if you fail your exam.

View guarantee terms →