SC-200 · Associate

SC-200 Cheat Sheet 2026: Quick Reference

Every current domain condensed to a table, plus a Defender product map and a Sentinel data-tier guide for the exam's most-confused pairs.

Exam Snapshot

Questions: 40-60
Duration: 120 minutes
Passing score: 700 / 1000
Cost: $165 USD
Level: Associate
Last updated: 2026-07-28

Note: SC-200 was restructured from a product-based blueprint to the process-based one below. If you've seen SC-200 content organized by "Defender XDR / Sentinel / Defender for Cloud" instead, that reflects an earlier version of the exam.

1. Manage a Security Operations Environment (40-45%)

ConceptAreaQuick note
Email/alert notifications (Defender XDR)AutomationTuning, suppression, correlation
Defender for Endpoint features/rules/ASRAutomationEndpoint-specific configuration
Automated investigation & response, attack disruptionAutomationAI-driven remediation
Device groups, permissions, automation levelsAutomationScoping automated actions
Sentinel automation rules & playbooksAutomationSOAR-style response
Sentinel rolesSentinel platformWho can do what inside Sentinel
Data retention tiersSentinel platformSee the reference table below
Sentinel workbooksSentinel platformVisualization and reporting
SOC optimization recommendationsSentinel platformBuilt-in tuning guidance
Data connectors, AMA collection, WEF, Syslog/CEFIngestionGetting data into Sentinel
Threat indicators, custom log tablesIngestionEnrichment and custom sources
Custom detection rules (Advanced Hunting)DetectionsDefender XDR-native detections
Sentinel analytics rulesDetectionsScheduled, near-real-time, threat intelligence, and ML — four distinct types
MITRE ATT&CK coverage analysisDetectionsGap analysis against a known framework
Sentinel anomaliesDetectionsML-based deviation from baseline

2. Respond to Security Incidents (35-40%)

ConceptAreaQuick note
Defender for Office 365 + attack disruptionRespond (XDR)Email and collaboration threats
Purview-identified threatsRespond (XDR)Compliance-surfaced risks
Defender for Cloud workload alertsRespond (XDR)Cloud infrastructure risks
Defender for Cloud Apps risksRespond (XDR)SaaS and shadow IT risks
Entra ID compromised identitiesRespond (XDR)Identity-specific response
Defender for Identity alertsRespond (XDR)On-premises AD-specific signals
Sentinel alerts/incidentsRespond (XDR)SIEM-correlated incidents
Agentic AI investigation (Security Copilot)Respond (XDR)AI-assisted triage
Multi-stage, multi-domain, lateral movement attacksRespond (XDR)Complex attack chains
Case managementRespond (XDR)Incident workflow tracking
Device timelines, live response, investigation packagesEndpoint responseDevice-level actions
Evidence & entity investigationEndpoint responseForensic detail
Purview Audit, eDiscovery Content searchM365 investigationCompliance-tool-based investigation
Microsoft Graph activity logsM365 investigationAPI-level activity trail

3. Perform Threat Hunting (20-25%)

ConceptAreaQuick note
Identify the right KQL tableDefender XDR huntingTable selection before query-writing
KQL threat ID, Advanced Hunting queriesDefender XDR huntingCore hunting skill
Threat analytics interpretationDefender XDR huntingReading Microsoft's own threat intel
Hunting graphs incl. blast radiusDefender XDR huntingVisualizing attack spread
Sentinel Graph entity relationshipsDefender XDR huntingRelationship analysis across entities
Sentinel hunting queriesSentinel huntingSIEM-side hunting
KQL jobs in Data lakeSentinel huntingQuerying long-term-retention data
Summary rule tablesSentinel huntingPre-aggregated data for faster queries
Notebooks incl. Sentinel MCP ServerSentinel huntingCode-based hunting workflows

Defender Product Quick Map

The process-based domains above still route through specific products — this maps the signal to the tool:

Need to investigate/respond to…Use this
Email/collaboration threats (phishing, malware in O365)Microsoft Defender for Office 365
Compromised or risky user identitiesMicrosoft Entra ID / Microsoft Defender for Identity
Cloud workload alerts (VMs, containers, databases)Microsoft Defender for Cloud
Risky cloud app usage / shadow ITMicrosoft Defender for Cloud Apps
Endpoint device timeline / live responseMicrosoft Defender for Endpoint
Compliance-related threats or evidence (audit, eDiscovery)Microsoft Purview
Cross-signal correlated incidents, SIEM-scale huntingMicrosoft Sentinel

Sentinel Data Tier Quick Reference

TierBest for
AnalyticsData needing real-time analytics rules and fast queries — higher cost
Data lakeLarge volumes of long-term retention data, queried via KQL jobs — lower cost
XDR tierData already collected via Defender XDR, unified with Sentinel

Common Questions

Which Microsoft product handles which type of security signal?

Defender for Office 365 for email, Defender for Cloud for workloads, Defender for Cloud Apps for SaaS, Defender for Endpoint for devices, Defender for Identity/Entra ID for identities, Purview for compliance evidence, and Sentinel to correlate across all of them.

What's the difference between Sentinel's Analytics, Data lake, and XDR tiers?

Analytics suits real-time rules at higher cost. Data lake suits long-term retention queried via KQL jobs at lower cost. XDR tier is data already collected via Defender XDR.

Why do the domain names here look different from other SC-200 content?

SC-200 moved from a product-based blueprint to a process-based one. This page reflects the current, official structure.

Can I print this SC-200 cheat sheet?

Yes — every table here is plain HTML, so a browser print or "print to PDF" renders cleanly.

MSCertQuiz sells practice-exam access for SC-200 and other Microsoft certifications; this cheat sheet is written by the same team that builds those questions.

Related Resources

Reviewed the cheat sheet? Now drill it.

Start with free SC-200 questions covering every domain above.

Start Free SC-200 Practice