Microsoft · SC-200 · Associate
Microsoft Security Operations Analyst (SC-200) — Practice Questions and Mock Exam
Practice real SC-200 questions, never dumps. Alex explains every answer, and your readiness score tells you when you're ready to pass.
Checked against Microsoft · July 2026Current exam version
Overview
About the exam
The SC-200 certification validates skills in threat detection, investigation, and response using Microsoft security technologies. It covers Microsoft Sentinel (SIEM), Microsoft Defender XDR (extended detection and response), Microsoft Defender for Endpoint, Microsoft Defender for Cloud, threat hunting with KQL, incident management, and security automation using playbooks and workbooks.
This certification is designed for security operations analysts who work in Security Operations Centers (SOCs) monitoring, identifying, investigating, and responding to threats. Candidates should have experience with Microsoft Sentinel, Defender products, KQL for threat hunting, and implementing automated response workflows to security incidents across hybrid environments.
Exam Domains
What's on the exam
The exam consists of 40–60 questions to be completed in approximately 100 minutes (100 minutes if labs are included). Question types include multiple-choice, multiple-select, drag-and-drop, hot area, and case study formats. Questions are scenario-based, presenting security incidents and asking you to investigate and respond using Sentinel and Defender tools. Expect KQL queries for threat hunting and questions about detection rule creation.
Configure automation for Microsoft Defender XDR and Microsoft Sentinel, configure the Microsoft Sentinel SIEM and platform, ingest data into the Microsoft Sentinel SIEM and platform, and configure detections
Respond to alerts and incidents in Microsoft Defender XDR, respond to alerts and incidents in Microsoft Defender for Endpoint, and investigate Microsoft 365 activities to identify threats
Detect threats using Microsoft Defender XDR and the Microsoft Sentinel platform with KQL queries and hunting graphs
SourceMicrosoft study guide
Format
What to expect
Watch out
Where candidates struggle
This exam requires hands-on security operations experience. Candidates who understand security concepts but haven't used Microsoft Sentinel for investigation and KQL for threat hunting often struggle with the practical scenarios.
- 01KQL Proficiency — Not knowing Kusto Query Language well enough to write threat hunting queries, create analytics rules, and parse security logs.
- 02Sentinel Configuration — Struggling with data connector setup, analytics rules, automation rules, and playbook (Logic Apps) configuration in Sentinel.
- 03Defender XDR — Confusing the capabilities and scopes of Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.
- 04Incident Management — Not understanding incident lifecycle management, evidence collection, and multi-stage attack investigation workflows.
- 05Automation Playbooks — Overlooking how to create and configure Logic Apps-based playbooks for automated incident response in Microsoft Sentinel.
Details
Exam logistics
Delivered via Pearson VUE online or at testing centers. Available in English, Japanese, Chinese, Korean, French, German, Spanish, and more. The certification is valid for 1 year with a free renewal assessment on Microsoft Learn.
SourceMicrosoft exam page
Before you book the exam
Would you pass SC-200 today?
Take the free readiness check. Answer real SC-200 questions and get your readiness score across every domain.
Take the free readiness check20 questions · freeReach 80% readiness by exam day. Pass, or your money back.