SC-200 Cheat Sheet 2026: Quick Reference
Every current domain condensed to a table, plus a Defender product map and a Sentinel data-tier guide for the exam's most-confused pairs.
Exam Snapshot
Note: SC-200 was restructured from a product-based blueprint to the process-based one below. If you've seen SC-200 content organized by "Defender XDR / Sentinel / Defender for Cloud" instead, that reflects an earlier version of the exam.
1. Manage a Security Operations Environment (40-45%)
| Concept | Area | Quick note |
|---|---|---|
| Email/alert notifications (Defender XDR) | Automation | Tuning, suppression, correlation |
| Defender for Endpoint features/rules/ASR | Automation | Endpoint-specific configuration |
| Automated investigation & response, attack disruption | Automation | AI-driven remediation |
| Device groups, permissions, automation levels | Automation | Scoping automated actions |
| Sentinel automation rules & playbooks | Automation | SOAR-style response |
| Sentinel roles | Sentinel platform | Who can do what inside Sentinel |
| Data retention tiers | Sentinel platform | See the reference table below |
| Sentinel workbooks | Sentinel platform | Visualization and reporting |
| SOC optimization recommendations | Sentinel platform | Built-in tuning guidance |
| Data connectors, AMA collection, WEF, Syslog/CEF | Ingestion | Getting data into Sentinel |
| Threat indicators, custom log tables | Ingestion | Enrichment and custom sources |
| Custom detection rules (Advanced Hunting) | Detections | Defender XDR-native detections |
| Sentinel analytics rules | Detections | Scheduled, near-real-time, threat intelligence, and ML — four distinct types |
| MITRE ATT&CK coverage analysis | Detections | Gap analysis against a known framework |
| Sentinel anomalies | Detections | ML-based deviation from baseline |
2. Respond to Security Incidents (35-40%)
| Concept | Area | Quick note |
|---|---|---|
| Defender for Office 365 + attack disruption | Respond (XDR) | Email and collaboration threats |
| Purview-identified threats | Respond (XDR) | Compliance-surfaced risks |
| Defender for Cloud workload alerts | Respond (XDR) | Cloud infrastructure risks |
| Defender for Cloud Apps risks | Respond (XDR) | SaaS and shadow IT risks |
| Entra ID compromised identities | Respond (XDR) | Identity-specific response |
| Defender for Identity alerts | Respond (XDR) | On-premises AD-specific signals |
| Sentinel alerts/incidents | Respond (XDR) | SIEM-correlated incidents |
| Agentic AI investigation (Security Copilot) | Respond (XDR) | AI-assisted triage |
| Multi-stage, multi-domain, lateral movement attacks | Respond (XDR) | Complex attack chains |
| Case management | Respond (XDR) | Incident workflow tracking |
| Device timelines, live response, investigation packages | Endpoint response | Device-level actions |
| Evidence & entity investigation | Endpoint response | Forensic detail |
| Purview Audit, eDiscovery Content search | M365 investigation | Compliance-tool-based investigation |
| Microsoft Graph activity logs | M365 investigation | API-level activity trail |
3. Perform Threat Hunting (20-25%)
| Concept | Area | Quick note |
|---|---|---|
| Identify the right KQL table | Defender XDR hunting | Table selection before query-writing |
| KQL threat ID, Advanced Hunting queries | Defender XDR hunting | Core hunting skill |
| Threat analytics interpretation | Defender XDR hunting | Reading Microsoft's own threat intel |
| Hunting graphs incl. blast radius | Defender XDR hunting | Visualizing attack spread |
| Sentinel Graph entity relationships | Defender XDR hunting | Relationship analysis across entities |
| Sentinel hunting queries | Sentinel hunting | SIEM-side hunting |
| KQL jobs in Data lake | Sentinel hunting | Querying long-term-retention data |
| Summary rule tables | Sentinel hunting | Pre-aggregated data for faster queries |
| Notebooks incl. Sentinel MCP Server | Sentinel hunting | Code-based hunting workflows |
Defender Product Quick Map
The process-based domains above still route through specific products — this maps the signal to the tool:
| Need to investigate/respond to… | Use this |
|---|---|
| Email/collaboration threats (phishing, malware in O365) | Microsoft Defender for Office 365 |
| Compromised or risky user identities | Microsoft Entra ID / Microsoft Defender for Identity |
| Cloud workload alerts (VMs, containers, databases) | Microsoft Defender for Cloud |
| Risky cloud app usage / shadow IT | Microsoft Defender for Cloud Apps |
| Endpoint device timeline / live response | Microsoft Defender for Endpoint |
| Compliance-related threats or evidence (audit, eDiscovery) | Microsoft Purview |
| Cross-signal correlated incidents, SIEM-scale hunting | Microsoft Sentinel |
Sentinel Data Tier Quick Reference
| Tier | Best for |
|---|---|
| Analytics | Data needing real-time analytics rules and fast queries — higher cost |
| Data lake | Large volumes of long-term retention data, queried via KQL jobs — lower cost |
| XDR tier | Data already collected via Defender XDR, unified with Sentinel |
Common Questions
Which Microsoft product handles which type of security signal?
Defender for Office 365 for email, Defender for Cloud for workloads, Defender for Cloud Apps for SaaS, Defender for Endpoint for devices, Defender for Identity/Entra ID for identities, Purview for compliance evidence, and Sentinel to correlate across all of them.
What's the difference between Sentinel's Analytics, Data lake, and XDR tiers?
Analytics suits real-time rules at higher cost. Data lake suits long-term retention queried via KQL jobs at lower cost. XDR tier is data already collected via Defender XDR.
Why do the domain names here look different from other SC-200 content?
SC-200 moved from a product-based blueprint to a process-based one. This page reflects the current, official structure.
Can I print this SC-200 cheat sheet?
Yes — every table here is plain HTML, so a browser print or "print to PDF" renders cleanly.
MSCertQuiz sells practice-exam access for SC-200 and other Microsoft certifications; this cheat sheet is written by the same team that builds those questions.
Related Resources
A 6-week plan and deeper walkthrough of the exam.
25 scenario questions with detailed explanations.
How the SOC analyst exam differs from the identity administrator exam.
Full exam details and the complete 500-question practice bank.
Reviewed the cheat sheet? Now drill it.
Start with free SC-200 questions covering every domain above.
Start Free SC-200 Practice