Instiq

Microsoft Security Operations AnalystStudy guide

The associate certification for detecting, investigating, responding to, and hunting threats with Microsoft Sentinel and Defender XDR (SC-200).

About Microsoft Security Operations Analyst (SC-200)

Microsoft Security Operations Analyst (SC-200) is a Associate-level certification from Microsoft. This page organizes the exam scope into a 5-chapter, 17-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Manage a security operations environment~42%
  • Respond to security incidents~38%
  • Perform threat hunting~20%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-200

1Automation in Defender XDR and Sentinel

2Sentinel SIEM platform and data ingestion

3Configuring detections

4Responding to security incidents

  • 4.1Investigating and remediating incidents in Defender XDR

    Understand investigating and remediating alerts/incidents/compromised entities identified by Defender for Office 365, Microsoft Purview, Defender for Cloud workload protections, Defender for Cloud Apps, Microsoft Entra ID, Defender for Identity, and Microsoft Sentinel in Microsoft Defender XDR.

  • 4.2Complex attacks, Security Copilot, and case management

    Understand investigating incidents with agentic AI (embedded Microsoft Security Copilot), investigating complex attacks (multistage, multi-domain, lateral movement), and managing incidents via case management.

  • 4.3Device response in Defender for Endpoint

    Understand investigating device timelines, performing device actions (live response, collecting investigation packages), evidence/entity investigation, and responding to incidents identified by automatic attack disruption in Microsoft Defender for Endpoint.

  • 4.4Investigating Microsoft 365 activities

    Understand investigating threats from Microsoft 365 activities using Microsoft Purview Audit, Content search in Microsoft Purview eDiscovery, and Microsoft Graph activity logs.

5Performing threat hunting

  • 5.1Hunting and KQL in Defender XDR

    Understand selecting the appropriate table for a KQL query, identifying threats with Kusto Query Language (KQL), creating Advanced Hunting queries, and interpreting threat analytics in Microsoft Defender XDR.

  • 5.2Hunting graphs and Sentinel Graph

    Understand creating hunting graphs (including blast radius) and analyzing relationships between entities with Sentinel Graph.

  • 5.3Hunting on the Sentinel platform

    Understand creating/monitoring Microsoft Sentinel hunting queries, creating/managing KQL jobs in Data lake, creating/managing Summary rule tables, and hunting with Notebooks (including connecting to the Sentinel MCP Server).