CertavoPrepare. Certify. Excel.
Open menu
SC-200Microsoft

SC-200: Microsoft Security Operations Analyst

The exam is intended for security operations analysts who reduce organizational risk by performing triage, responding to incidents, hunting for threats, and engineering detections. Candidates monitor, identify, investigate, and respond to threats across multi-cloud and on-premises environments by using Microsoft security technologies, perform hunting with KQL, and automate threat responses. The role collaborates with business and security leadership and works across the organization to implement security standards, improve security posture, and raise security awareness.

What you get with membership

  • The full SC-200 question bank with detailed explanations
  • Readiness tracking by objective so you know when you're ready
  • Access to every other exam in the Certavo library
  • Content kept in step with the latest exam objectives

SC-200 exam objectives and study guide

The skills measured on the SC-200 exam, by objective domain. Percentages are the share of the exam each domain carries.

Manage a security operations environment

42.5% of the exam
  • Configure automation for Microsoft Defender XDR and Microsoft Sentinel
  • Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics
  • Configure alert notifications in Microsoft Defender XDR, including tuning, suppression, and correlation
  • Configure Microsoft Defender for Endpoint advanced features
  • Configure rules settings in Microsoft Defender for Endpoint
  • Configure custom data collection in Microsoft Defender for Endpoint
  • Configure security policies for Microsoft Defender for Endpoint, including attack surface reduction (ASR) rules
  • Manage automated investigation and response capabilities in Microsoft Defender XDR
  • Configure automatic attack disruption in Microsoft Defender XDR
  • Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint
  • Create and configure automation rules in Microsoft Sentinel
  • Create and configure Microsoft Sentinel playbooks
  • Configure the Microsoft Sentinel SIEM and platform
  • Specify Microsoft Sentinel roles
  • Manage data retention for XDR and Microsoft Sentinel tables, including Analytics, Data lake, and XDR tiers
  • Create and configure Microsoft Sentinel workbooks
  • Optimize the Microsoft Sentinel platform, including SOC optimization recommendations
  • Ingest data into the Microsoft Sentinel SIEM and platform
  • Select data connectors based on data source requirements, including Windows logs and security events
  • Configure collection of Windows Security events by using Windows Security Events via AMA, including data collection rules
  • Plan and configure collection of Windows Security events by using Windows Event Forwarding (WEF)
  • Plan and configure Syslog via AMA and Common Event Format (CEF) via AMA connectors
  • Configure collection of Azure activities by using Azure Policy and resource diagnostic settings
  • Ingest threat indicators into Microsoft Sentinel
  • Create custom log tables in the workspace to store ingested data
  • Configure detections
  • Create custom detection rules by using Advanced Hunting in Microsoft Defender XDR
  • Manage custom detection rules in Microsoft Defender XDR
  • Configure and manage analytics rules in Microsoft Sentinel SIEM, including scheduled, near-real time (NRT), threat intelligence, and machine learning
  • Analyze attack vector coverage by using the MITRE ATT&CK matrix
  • Configure anomalies in Microsoft Sentinel

Respond to security incidents

37.5% of the exam
  • Respond to alerts and incidents in Microsoft Defender XDR
  • Investigate and remediate threats by using Microsoft Defender for Office 365, including automatic attack disruption
  • Investigate and remediate threats or compromised entities identified by Microsoft Purview
  • Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud workload protections
  • Investigate and remediate security risks identified by Microsoft Defender for Cloud Apps
  • Investigate and remediate compromised identities that are identified by Microsoft Entra ID
  • Investigate and remediate security alerts from Microsoft Defender for Identity
  • Investigate and remediate alerts and incidents identified by Microsoft Sentinel
  • Investigate incidents by using agentic AI, including embedded Microsoft Security Copilot
  • Investigate complex attacks, such as multi-stage, multi-domain, and lateral movement
  • Manage security incidents by using case management
  • Respond to alerts and incidents in Microsoft Defender for Endpoint
  • Investigate device timelines
  • Perform actions on the device, including live response and collecting investigation packages
  • Perform evidence and entity investigation
  • Investigate and remediate incidents identified by automatic attack disruption
  • Investigate Microsoft 365 activities to identify threats
  • Investigate threats by using Microsoft Purview Audit
  • Investigate threats by using Content search in Microsoft Purview eDiscovery
  • Investigate threats by using Microsoft Graph activity logs

Perform threat hunting

22.5% of the exam
  • Detect threats by using Microsoft Defender XDR
  • Identify the appropriate table to use in a KQL query
  • Identify threats by using Kusto Query Language (KQL)
  • Create Advanced Hunting queries
  • Interpret threat analytics in Microsoft Defender XDR
  • Create hunting graphs, including blast radius
  • Analyze relationships between entities by using Sentinel Graph
  • Detect threats by using the Microsoft Sentinel platform
  • Create and monitor hunting queries
  • Create and manage KQL jobs in Data lake
  • Create and manage Summary rule tables for querying
  • Hunt for threats by using Notebooks, including connection to the Sentinel MCP Server

SC-200 practice questions and answers

10 free sample questions from the SC-200 bank, with the correct answer and a full explanation for each. These are original questions written to the Microsoft objective domains — not real exam content.

  1. Question 1Perform threat hunting

    Investigators can correlate suspicious sign-ins and device alerts in query results, but they need a visual view that shows possible attack propagation paths and business impact for the affected users, devices, IP addresses, and Azure resources. Which experience should they use to create and review the blast-radius hunting graph?

    • AUse Azure Resource Graph Explorer to query the affected Azure subscriptions and render the resource relationships.
    • BUse Microsoft Sentinel in the Microsoft Defender portal to open the incident graph and review blast radius analysis.
    • CUse Microsoft Sentinel in the Azure portal Hunting page to create bookmarks for each suspicious query result.
    • DUse Microsoft Defender Threat Intelligence to create an intel project for the observed indicators.
    Show answer and explanation

    Correct answer

    • Use Microsoft Sentinel in the Microsoft Defender portal to open the incident graph and review blast radius analysis.

    Explanation

    The correct choice is to use the investigation experience in the Microsoft Defender portal. Microsoft Sentinel in the Defender portal provides the attack story and incident graph with unified entity pages for users, devices, IP addresses, and Azure resources, including blast radius analysis.

    • Microsoft Sentinel in the Azure portal is primarily a log-centric Sentinel experience and does not provide the same unified SIEM/XDR incident graph and blast radius analysis.
    • Azure Resource Graph Explorer is useful for querying Azure resource inventory, but it is not the Microsoft Sentinel investigation graph for security incidents.
    • Microsoft Defender Threat Intelligence provides threat intelligence context, not the Sentinel incident graph used to assess blast radius.

    References:

  2. Question 2Perform threat hunting

    Coho Vineyard is onboarding Microsoft Sentinel data lake and Microsoft Sentinel graph so analysts can create a blast-radius hunting graph. The primary Microsoft Sentinel workspace is in North Europe and is connected to the Microsoft Defender portal. Workspace-A is in North Europe and connected to the Defender portal. Workspace-B is in North Europe but is not connected to the Defender portal. Workspace-C is in West Europe and connected to the Defender portal. Workspace-D is in North Europe and connected to the Defender portal. Which workspaces are attached to the data lake during onboarding?

    • AThe primary workspace, Workspace-A, and Workspace-D only.
    • BThe primary workspace, Workspace-A, Workspace-C, and Workspace-D only.
    • CThe primary workspace, Workspace-A, Workspace-B, and Workspace-D only.
    • DOnly the primary workspace until the other workspaces are manually attached.
    Show answer and explanation

    Correct answer

    • The primary workspace, Workspace-A, and Workspace-D only.

    Explanation

    The correct choice is the primary workspace plus Workspace-A and Workspace-D. When Microsoft Sentinel data lake is onboarded, it is provisioned in the same region as the primary Sentinel workspace and attaches workspaces that are both connected to the Defender portal and located in that same region.

    • Workspace-B is in the correct region, but it is not connected to the Defender portal, so it is not attached.
    • Workspace-C is connected to the Defender portal, but it is in West Europe, not the primary workspace region.
    • The attachment is not limited to only the primary workspace when other eligible workspaces exist.

    References:

  3. Question 3Perform threat hunting

    Lin, a SOC platform engineer, must enable graph-based hunting for blast-radius analysis from Microsoft Sentinel data lake. The only candidate primary workspace applies Customer-Managed Keys for data encryption, and governance requires any data available through the hunting graph to remain protected by the same Customer-Managed Keys. What should Lin conclude?

    • AProceed with onboarding because Microsoft Sentinel data lake inherits the workspace Customer-Managed Key automatically.
    • BSwitch the workspace tables to the data lake tier only because that tier preserves the workspace Customer-Managed Key.
    • CUse an Azure Subscription owner account because billing setup enables Customer-Managed Keys for graph storage.
    • DDo not onboard that workspace for this requirement because Microsoft Sentinel data lake does not support Customer-Managed Keys.
    Show answer and explanation

    Correct answer

    • Do not onboard that workspace for this requirement because Microsoft Sentinel data lake does not support Customer-Managed Keys.

    Explanation

    The correct conclusion is that the requirement cannot be met by onboarding that workspace to Microsoft Sentinel data lake and graph. Customer-Managed Keys are not supported for data stored in Microsoft Sentinel data lake, and Sentinel workspaces applying CMK are not accessible through data lake experiences. Data ingested into the data lake, including custom or transformed data, is encrypted with Microsoft-managed keys.

    • The data lake does not inherit the Log Analytics workspace CMK.
    • Choosing the data lake tier does not make CMK available for graph data.
    • Subscription permissions are required for billing setup, but they do not change the encryption support boundary.

    References:

  4. Question 4Perform threat hunting

    Sofia, a security operations manager, is estimating the cost of a pilot that creates custom Microsoft Sentinel hunting graph nodes and edges, and runs KQL enrichment queries over the data lake for blast-radius analysis. Which two cost items should she include for those data lake graph activities?

    • AAdvanced data insights charges for compute hours while building custom graph nodes and edges.
    • BData lake query charges for uncompressed data scanned by KQL queries or KQL jobs.
    • CA Microsoft Sentinel analytics commitment tier charge for each notebook pool selected for graph building.
    • DAzure Monitor long-term retention search charges for every data lake graph traversal.
    • EA Microsoft Defender XDR license charge before Microsoft Sentinel data lake can be used with Sentinel.
    Show answer and explanation

    Correct answers

    • Advanced data insights charges for compute hours while building custom graph nodes and edges.
    • Data lake query charges for uncompressed data scanned by KQL queries or KQL jobs.

    Explanation

    The correct answers are the data lake query charges and advanced data insights charges.

    • Data lake query charges apply per GB of uncompressed data scanned by KQL queries or KQL jobs.
    • Advanced data insights charges apply to compute hours used for notebook sessions, notebook jobs, and building nodes and edges for custom graphs.

    The Microsoft Sentinel analytics commitment tier is an ingestion pricing model that starts at 100 GB per day; it is not a charge per notebook pool. Long-term retention or search meters are not the data lake graph meters described for these activities. Microsoft Sentinel data lake with Sentinel in the Defender portal does not require a Microsoft Defender XDR license.

    References:

  5. Question 5Perform threat hunting

    Alpine Ski House retains firewall and identity telemetry in the Microsoft Sentinel data lake tier for long-running investigations. Every morning, incident responders need an analytics-tier summary of source IP addresses that exceeded the SOC threshold during the previous day. The existing incident workflow must consume the output in Microsoft Sentinel, the SOC wants to author the logic in KQL, and no notebook runtime or external compute can be managed. Which approach should the SOC use?

    • ACreate a scheduled Microsoft Sentinel data lake KQL job that summarizes the lake-tier records and promotes the result set to the analytics tier.
    • BCreate a Microsoft Sentinel scheduled analytics rule that queries the lake-tier tables and opens incidents from those records directly.
    • CSchedule a Microsoft Sentinel data lake Jupyter notebook that reads the lake data and writes promoted results by using Python.
    • DRun an Azure Monitor Logs search job over the Log Analytics workspace archive and have analysts review the search results table.
    • ERun the data lake KQL query manually each morning and export the summarized rows to a CSV file for responders.
    Show answer and explanation

    Correct answer

    • Create a scheduled Microsoft Sentinel data lake KQL job that summarizes the lake-tier records and promotes the result set to the analytics tier.

    Explanation

    The scheduled Microsoft Sentinel data lake KQL job is the only option that satisfies all constraints: it uses KQL, runs on data in the data lake tier, and promotes the summarized result set to the analytics tier where Microsoft Sentinel SIEM workflows can use it.

    • A scheduled analytics rule is attractive, but it is the wrong execution surface for querying long-term lake-tier data directly. The data lake KQL job is the documented mechanism for promoting lake results to the analytics tier.
    • A scheduled Jupyter notebook can analyze data lake data and promote results, but it violates the requirement to use KQL without managing a notebook runtime.
    • An Azure Monitor Logs search job is a real capability for searching Log Analytics data, but it is not a Microsoft Sentinel data lake KQL job and does not meet the stated KQL job promotion workflow.
    • A manual query and CSV export would use the data lake query editor, but it would not provide the required recurring managed job or analytics-tier promotion workflow.

    References:

  6. Question 6Perform threat hunting

    You need evidence that a Microsoft Sentinel data lake KQL job was edited and then run during the previous night. Which source should you review first?

    • AMicrosoft Sentinel data lake audit log
    • BAzure Activity log for the subscription
    • CMicrosoft Entra sign-in logs
    • DMicrosoft Defender XDR advanced hunting DeviceProcessEvents table
    Show answer and explanation

    Correct answer

    • Microsoft Sentinel data lake audit log

    Explanation

    Review the Microsoft Sentinel data lake audit log. Auditing is enabled by default for the Microsoft Sentinel data lake, and audited activities include creating, editing, running, and deleting jobs.

    • The Azure Activity log records subscription-level Azure Resource Manager operations, not the detailed Microsoft Sentinel data lake KQL job actions described in the requirement.
    • Microsoft Entra sign-in logs can show authentication activity, but they do not record data lake job edit and run events.
    • DeviceProcessEvents is an endpoint advanced hunting table and is unrelated to management actions for Microsoft Sentinel data lake KQL jobs.

    References:

  7. Question 7Respond to security incidents

    The malware lab must receive one suspicious file from a compromised laptop for reverse engineering: `C:\Users\Public\Libraries\updater.dat`. The incident owner does not approve remediation, antivirus scans, or collecting a broad investigation package because the device contains regulated client data. The device is online and onboarded to Microsoft Defender for Endpoint. Which action best meets the requirements?

    • AStart a live response session and run `getfile C:\Users\Public\Libraries\updater.dat`.
    • BSelect Collect investigation package from the device page and send the downloaded ZIP to the lab.
    • CStart a live response session and run `analyze C:\Users\Public\Libraries\updater.dat`.
    • DRun a Microsoft Defender Antivirus full scan from the device actions menu.
    • EInitiate automated investigation from the device page and export the results.
    Show answer and explanation

    Correct answer

    • Start a live response session and run `getfile C:\Users\Public\Libraries\updater.dat`.

    Explanation

    The best action is to start live response and run `getfile` for the exact path. This retrieves the specified file without running a scan, remediating the device, or collecting a broad predefined investigation package.

    • Collect investigation package is wrong because it gathers a predefined set of forensic artifacts and may collect more data than the approved single file.
    • `analyze` is wrong because it submits or evaluates an entity for a verdict; it is not the command used to download the file for reverse engineering.
    • Microsoft Defender Antivirus full scan is wrong because it is a scan/remediation-oriented response action and is explicitly disallowed.
    • Automated investigation is wrong because it can perform investigation and remediation workflow steps rather than simply retrieving one approved file.

    References:

  8. Question 8Respond to security incidents

    Best For You Organics' SOC is updating response runbooks for acquiring endpoint evidence in Microsoft Defender for Endpoint. Which two statements correctly distinguish Collect investigation package from live response?

    • ACollect investigation package is an asynchronous device response action that gathers predefined forensic artifacts for later download.
    • BLive response opens an interactive remote session that can run permitted commands such as `processes` and `getfile` on the device.
    • CCollect investigation package is the feature used to execute PowerShell scripts from the live response library.
    • DLive response unsigned script execution must be enabled before any live response session can be started.
    • EA Microsoft Defender Antivirus scan must complete before either action can collect endpoint data.
    Show answer and explanation

    Correct answers

    • Collect investigation package is an asynchronous device response action that gathers predefined forensic artifacts for later download.
    • Live response opens an interactive remote session that can run permitted commands such as `processes` and `getfile` on the device.

    Explanation

    The correct statements are that Collect investigation package is an asynchronous response action that gathers predefined forensic artifacts, and live response opens an interactive session for permitted commands such as processes and getfile.

    • Collect investigation package does not provide script execution from the live response library; running scripts is a live response capability.
    • Live response unsigned script execution is not required to start every live response session. It is only relevant when running unsigned scripts.
    • A Microsoft Defender Antivirus scan is not a prerequisite for either collecting an investigation package or using live response.

    References:

  9. Question 9Respond to security incidents

    Security reviewers find that several SharePoint Online files containing customer tax identifiers are exposed through anonymous links and to named external collaborators. A Microsoft Defender for Cloud Apps file policy alert identifies the specific files. The remediation must remove external exposure while keeping the files available to internal project members and preserving the files for evidence. Which two governance actions should you use?

    • ARemove public access from the identified files.
    • BRemove external users from the identified files.
    • CMake the identified files private.
    • DPut the identified files in admin quarantine.
    • ETag SharePoint Online as Unsanctioned.
    • FApply a sensitivity label that only adds a visual marking.
    Show answer and explanation

    Correct answers

    • Remove public access from the identified files.
    • Remove external users from the identified files.

    Explanation

    The correct actions are Remove public access and Remove external users. For a Defender for Cloud Apps file policy finding, these file governance actions remove the two external exposure paths while leaving the files in place for internal collaboration.

    • Make private is broader than required because it removes sharing and can disrupt internal collaborators, not only external exposure.
    • Put in admin quarantine preserves evidence but restricts access to the file, which violates the requirement to keep it available internally.
    • Tag the cloud app as Unsanctioned is a Cloud Discovery/app access control action; it does not change permissions on the identified SharePoint files.
    • Apply a sensitivity label that only adds a visual marking can help classification, but a visual marking does not remove existing anonymous links or external collaborators.

    References:

  10. Question 10Respond to security incidents

    Relecloud's security team investigates Microsoft Defender for Cloud Apps alerts showing repeated downloads of confidential SharePoint Online files from unmanaged devices. The team must prevent future browser downloads in real time from unmanaged devices while still allowing users to view SharePoint Online in the browser. Which control should be configured?

    • ACreate a Microsoft Entra Conditional Access policy that uses the session control for Defender for Cloud Apps, and create a session policy to block file downloads.
    • BCreate a Defender for Cloud Apps file policy that removes external users from matching SharePoint Online files after each scan.
    • CTag SharePoint Online as Unsanctioned in the cloud app catalog and enforce the tag through Microsoft Defender for Endpoint.
    • DCreate a Defender for Cloud Apps activity policy that generates an alert when unmanaged devices download files.
    • ECreate a Microsoft Purview Data Loss Prevention policy for SharePoint Online and leave the policy mode set to Audit.
    Show answer and explanation

    Correct answer

    • Create a Microsoft Entra Conditional Access policy that uses the session control for Defender for Cloud Apps, and create a session policy to block file downloads.

    Explanation

    The correct control is to route the SharePoint Online browser session through Microsoft Defender for Cloud Apps by using a Microsoft Entra Conditional Access session control, and then enforce a Defender for Cloud Apps session policy that blocks file downloads. This provides real-time session control while allowing browser viewing.

    • A Defender for Cloud Apps file policy with remove-external-user governance remediates sharing exposure after files are detected; it does not provide real-time browser download blocking.
    • Tagging SharePoint Online as Unsanctioned would block access to the app rather than allow viewing while preventing downloads.
    • A Defender for Cloud Apps activity policy can alert on download activity after it occurs; it is not a real-time inline control.
    • A Microsoft Purview DLP policy in audit mode records matches but does not enforce the stated block.

    References:

Membership includes 149 questions and explanations aligned to the SC-200 curriculum, including 7 case studies.

Other Microsoft certifications

Every one of these is included with the same membership as SC-200.

SC-200 exam FAQ

How many questions are on the SC-200 exam?+

The SC-200 (Microsoft Security Operations Analyst) exam has around 50 questions. Question counts vary slightly between exam forms, so treat this as the typical number rather than a guarantee.

How long is the SC-200 exam?+

You get 100 minutes for the SC-200 exam itself. Allow extra time at the test centre or for the online check-in process before the timer starts.

Are there free SC-200 practice questions?+

Yes. 10 free SC-200 practice questions are on this page, each with the correct answer and a full explanation. The complete bank of 149 questions is included with membership.

Are these real SC-200 exam questions?+

No. Every question is original, written to match the published SC-200 objective domains and question styles. Real exam content is confidential, and reusing it would breach Microsoft's exam policies.