Microsoft Security Operations AnalystStudy guide
The associate certification for detecting, investigating, responding to, and hunting threats with Microsoft Sentinel and Defender XDR (SC-200).
About Microsoft Security Operations Analyst (SC-200)
Microsoft Security Operations Analyst (SC-200) is a Associate-level certification from Microsoft. This page organizes the exam scope into a 5-chapter, 17-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Manage a security operations environment~42%
- Respond to security incidents~38%
- Perform threat hunting~20%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-200
1Automation in Defender XDR and Sentinel
- 1.1Defender XDR notifications and alert tuning
Understand configuring Microsoft Defender XDR email notifications (incidents/actions/threat analytics) and alert notifications, and tuning, suppressing, and correlating alerts.
- 1.2Configuring Defender for Endpoint and ASR
Understand Microsoft Defender for Endpoint advanced features, rule settings, custom data collection, security policies including attack surface reduction (ASR) rules, and device groups/permissions/automation levels.
- 1.3Automated investigation/response and automatic attack disruption
Understand managing automated investigation and response (AIR) in Microsoft Defender XDR and configuring automatic attack disruption.
- 1.4Sentinel automation rules and playbooks
Understand creating/configuring Microsoft Sentinel automation rules and playbooks (Azure Logic Apps), and automating incident response via SOAR.
2Sentinel SIEM platform and data ingestion
- 2.1Sentinel roles, data retention, and SOC optimization
Understand specifying Microsoft Sentinel roles, data retention across XDR/Sentinel tables (Analytics, Data lake, XDR tiers), creating workbooks, and SOC optimization recommendations.
- 2.2Data connectors and collecting Windows events
Understand selecting data connectors by source requirements, collecting via Windows Security Events through AMA (data collection rules, DCR), and planning/configuring Windows Event Forwarding (WEF).
- 2.3Syslog/CEF, Azure activities, and threat indicators
Understand Syslog via AMA and Common Event Format (CEF) via AMA connectors, collecting Azure activities (Azure Policy, resource diagnostic settings), ingesting threat indicators, and creating custom log tables.
3Configuring detections
- 3.1Custom detection rules in Defender XDR
Understand creating and managing custom detection rules using Advanced Hunting in Microsoft Defender XDR.
- 3.2Sentinel analytics rules and anomalies
Understand configuring/managing Microsoft Sentinel analytics rules (scheduled, near-real-time NRT, threat intelligence, machine learning) and Sentinel anomalies.
- 3.3Analyzing coverage with MITRE ATT&CK
Understand using the MITRE ATT&CK matrix to analyze attack-vector coverage from analytics rules and hunting queries, visualizing detection gaps.
4Responding to security incidents
- 4.1Investigating and remediating incidents in Defender XDR
Understand investigating and remediating alerts/incidents/compromised entities identified by Defender for Office 365, Microsoft Purview, Defender for Cloud workload protections, Defender for Cloud Apps, Microsoft Entra ID, Defender for Identity, and Microsoft Sentinel in Microsoft Defender XDR.
- 4.2Complex attacks, Security Copilot, and case management
Understand investigating incidents with agentic AI (embedded Microsoft Security Copilot), investigating complex attacks (multistage, multi-domain, lateral movement), and managing incidents via case management.
- 4.3Device response in Defender for Endpoint
Understand investigating device timelines, performing device actions (live response, collecting investigation packages), evidence/entity investigation, and responding to incidents identified by automatic attack disruption in Microsoft Defender for Endpoint.
- 4.4Investigating Microsoft 365 activities
Understand investigating threats from Microsoft 365 activities using Microsoft Purview Audit, Content search in Microsoft Purview eDiscovery, and Microsoft Graph activity logs.
5Performing threat hunting
- 5.1Hunting and KQL in Defender XDR
Understand selecting the appropriate table for a KQL query, identifying threats with Kusto Query Language (KQL), creating Advanced Hunting queries, and interpreting threat analytics in Microsoft Defender XDR.
- 5.2Hunting graphs and Sentinel Graph
Understand creating hunting graphs (including blast radius) and analyzing relationships between entities with Sentinel Graph.
- 5.3Hunting on the Sentinel platform
Understand creating/monitoring Microsoft Sentinel hunting queries, creating/managing KQL jobs in Data lake, creating/managing Summary rule tables, and hunting with Notebooks (including connecting to the Sentinel MCP Server).

