SC-200 · Associate

SC-200 Study Guide 2026: Security Operations Analyst Exam Prep

Updated August 202618 min read

SC-200 was restructured in 2026 from a product-based blueprint to a process-based one — this guide covers the current three domains, a 6-week plan, and the Security Copilot, Sentinel data lake, and MCP Server content most SC-200 material still hasn't caught up with.

Quick Summary

  • • SC-200 is an Associate-level exam: 40–60 questions, 120 minutes, 700/1000 passing score, $165 USD
  • • Three domains: Manage a security operations environment (40–45%), Respond to security incidents (35–40%), Perform threat hunting (20–25%)
  • • Microsoft Sentinel and Defender XDR are the tools tested throughout — they are no longer separate domains, they cut across all three
  • • New in the 2026 revision: agentic AI investigation via Security Copilot, Sentinel data lake/Analytics/XDR retention tiers, SOC optimization recommendations, and the Sentinel MCP Server

If you've seen SC-200 material organized as “Defender XDR / Microsoft Sentinel / Defender for Cloud”, that reflects an earlier version of the exam. Microsoft moved to the process-based structure below in the study guide revision dated July 28, 2026 — the underlying products are the same, but what's tested and how it's grouped has changed, and some old Defender for Cloud posture-management content (Secure Score prioritization, CSPM vs. CWPP, multi-cloud connectors) is no longer called out in the current objectives.

What Is the SC-200 Exam?

SC-200 is the required exam for Microsoft Certified: Security Operations Analyst Associate. Microsoft's official study guide describes the audience as a security operations analyst who reduces organizational risk through triage, incident response, threat hunting, and detection engineering — monitoring and responding to threats across multi-cloud and on-premises environments using Defender XDR, Sentinel, Entra ID, Purview, and Defender for Cloud workload protections.

You're expected to be familiar with Microsoft security, compliance, and identity solutions, Microsoft 365, Azure cloud services, AI agents and Copilots, and Windows/Linux/mobile operating systems. KQL (Kusto Query Language) is a practical requirement — it's woven through detection configuration and threat hunting rather than isolated in one domain.

DetailInformation
Exam CodeSC-200
Credential EarnedSecurity Operations Analyst Associate
Number of Questions~40–60 questions
Time Limit120 minutes
Passing Score700 out of 1000
Exam Price$165 USD
Exam LevelAssociate
PrerequisitesNone formal (SC-900 or SOC experience recommended)
RenewalAnnual free online renewal assessment
Skills measured as ofJuly 28, 2026

SC-200 Exam Domains & What They Actually Test

Three domains, each cutting across both Defender XDR and Sentinel rather than mapping one-to-one with a product.

Domain 1: Manage a Security Operations Environment

40–45%
  • Configure automation for Defender XDR and Sentinel: email and alert notifications (tuning, suppression, correlation), Defender for Endpoint advanced features, rules, custom data collection, and ASR (attack surface reduction) rule policies
  • Manage automated investigation and response (AIR) and automatic attack disruption in Defender XDR, including device groups, permissions, and automation levels
  • Create and configure Sentinel automation rules and playbooks (Logic Apps)
  • Configure the Sentinel SIEM platform: Sentinel roles, data retention across the Analytics, Data lake, and XDR tiers, Sentinel workbooks, and SOC optimization recommendations
  • Ingest data: select the right data connectors, configure Windows Security event collection via AMA and Windows Event Forwarding (WEF), Syslog/CEF via AMA, Azure activity via Policy and diagnostic settings, threat indicator ingestion, and custom log tables
  • Configure detections: custom detection rules via Advanced Hunting in Defender XDR, Sentinel analytics rules (scheduled, near-real-time, threat intelligence, and machine learning), MITRE ATT&CK coverage analysis, and Sentinel anomalies

Domain 2: Respond to Security Incidents

35–40%
  • Investigate and remediate threats identified by Defender for Office 365 (including automatic attack disruption), Microsoft Purview, Defender for Cloud workload protections, Defender for Cloud Apps, Entra ID, Defender for Identity, and Sentinel
  • Investigate incidents by using agentic AI, including embedded Microsoft Security Copilot
  • Investigate complex attacks — multi-stage, multi-domain, and lateral movement — and manage them through case management
  • Respond to Defender for Endpoint alerts: device timelines, live response and investigation packages, evidence and entity investigation, and remediation from automatic attack disruption
  • Investigate Microsoft 365 activity: Purview Audit, eDiscovery Content search, and Microsoft Graph activity logs

Domain 3: Perform Threat Hunting

20–25%
  • Detect threats using Defender XDR: identify the right KQL table, write Advanced Hunting queries, interpret threat analytics, build hunting graphs including blast radius, and analyze entity relationships with Sentinel Graph
  • Detect threats using the Sentinel platform: create and monitor hunting queries, run KQL jobs against the Data lake tier, use Summary rule tables for faster querying, and hunt using Notebooks including the Sentinel MCP Server

Ready to test yourself?

Try 40 Free SC-200 Practice Questions

Scenario-based questions weighted to the current three domains. No credit card required.

Start Free Practice →

How Hard Is SC-200?

One of the harder Associate-level exams in the Microsoft security portfolio, for the same underlying reason as before the restructure: it requires hands-on SOC experience, not conceptual recall. The 2026 content additions raise the bar further for anyone studying from older material.

Why candidates fail SC-200

  • Studying from the old product-based blueprint: material organized around “Defender XDR / Sentinel / Defender for Cloud” misses how questions are actually framed now — around managing, responding, and hunting
  • Missing the new content entirely: Security Copilot-assisted investigation, Sentinel's three data tiers, SOC optimization, and MCP Server notebooks don't appear in most existing prep material
  • Weak KQL skills: KQL questions appear in both detection configuration (Domain 1) and threat hunting (Domain 3) — skipping KQL practice costs marks in two domains, not one
  • Confusing configuration with response: setting up an automation rule (Domain 1) and investigating what it triggered (Domain 2) are tested as distinct skills

6-Week SC-200 Study Plan

This plan allocates the most time to Domain 1 given its 40–45% weight, and front-loads Sentinel platform basics since Domains 2 and 3 both build on them. A free Sentinel trial or developer tenant is strongly recommended for hands-on labs.

Week 1–2: Manage a Security Operations Environment (Domain 1)

  • Week 1: Defender XDR automation — email/alert notification tuning, Defender for Endpoint rules and ASR policies, automated investigation and response, automatic attack disruption configuration, device groups and automation levels.
  • Week 2: Sentinel platform setup — roles, data connectors, AMA/WEF/Syslog/CEF ingestion, custom log tables, data retention across the Analytics/Data lake/XDR tiers, workbooks, and SOC optimization recommendations. Configure detections: Advanced Hunting custom rules, Sentinel analytics rules (scheduled, NRT, TI, ML), and MITRE ATT&CK coverage analysis.

Week 3–4: Respond to Security Incidents (Domain 2)

  • Week 3: Investigating and remediating alerts across Defender for Office 365, Purview, Defender for Cloud workload protections, Defender for Cloud Apps, Entra ID, and Defender for Identity. Practice agentic AI investigation with embedded Security Copilot — summarizing incidents and suggesting next steps.
  • Week 4: Complex multi-stage/multi-domain attack investigation and case management. Defender for Endpoint response — device timelines, live response, investigation packages. Microsoft 365 investigation via Purview Audit, eDiscovery Content search, and Graph activity logs.

Week 5: Perform Threat Hunting (Domain 3)

  • KQL fundamentals — where, project, extend, summarize, join, ago(). Advanced Hunting queries and threat analytics interpretation in Defender XDR. Hunting graphs including blast radius, and Sentinel Graph entity relationships. Sentinel hunting queries, KQL jobs against the Data lake tier, Summary rule tables, and notebook-based hunting via the Sentinel MCP Server.

Week 6: Mock Exams & Review

  • Days 1–2: Full-length practice questions across all three domains, weighted 40/40/20. Review every incorrect answer.
  • Day 3: Full 120-minute timed mock exam.
  • Days 4–5: Targeted review of any domain below 70%, with extra KQL drills if that's the weak spot.
  • Day 6: Second full mock exam — aim for 80%+.
  • Day 7: Light review only. Book the exam if consistently 80%+.

Best SC-200 Study Resources

Microsoft's own documentation and the current study guide are the only resources guaranteed to reflect the 2026 revision — most third-party SC-200 material online still teaches the old product-based structure:

For exam-style practice, MSCertQuiz maintains SC-200 practice questions weighted to the current three domains — see the practice questions and cheat sheet that go with this guide.

SC-200 Exam Day Tips

Do

  • • For KQL questions, identify the correct table first (TimeGenerated vs. Timestamp fields differ between Sentinel and Defender XDR Advanced Hunting)
  • • Distinguish configuring a control (Domain 1) from investigating what it caught (Domain 2) from proactively searching for it (Domain 3)
  • • When a scenario mentions agentic AI or Copilot, think investigation assistance inside Defender XDR, not a separate product to configure
  • • For retention questions, remember there are now three tiers — Analytics (fast, expensive), Data lake (cheap, KQL-job queried), and XDR (already collected via Defender XDR)

Don't

  • • Don't default to Defender for Cloud posture-management answers (Secure Score, JIT VM access, CSPM/CWPP) — that content is no longer itemized in the current objectives; Defender for Cloud now appears mainly as a workload-alert source you investigate and remediate
  • • Don't confuse automation rules (trigger logic) with playbooks (the Logic App that actually runs) — both live in Domain 1
  • • Don't skip case management — complex multi-domain incidents are explicitly tracked through it in Domain 2
  • • Don't assume old practice material with 50%+ weight on “the Sentinel domain” is current — that domain doesn't exist anymore

Frequently Asked Questions

What is the SC-200 exam?

SC-200 is Microsoft's Associate-level Security Operations Analyst certification. It validates skills in managing a security operations environment, responding to security incidents, and hunting for threats using Microsoft Sentinel and Microsoft Defender XDR. As of the July 2026 study guide revision, the exam is organized around these three processes rather than around individual security products.

Did SC-200 change recently?

Yes. Microsoft restructured SC-200 from a product-based blueprint (separate domains for Defender XDR, Microsoft Sentinel, and Defender for Cloud) to a process-based one: manage the environment, respond to incidents, hunt for threats. The content also grew — agentic AI investigation through embedded Security Copilot, Sentinel's Analytics/Data lake/XDR retention tiers, SOC optimization recommendations, and the Sentinel MCP Server for notebook-based hunting are all now explicitly in scope.

How much KQL do I need to know for SC-200?

More than most candidates expect. KQL is not its own domain anymore — it runs through Domain 1's detection configuration and Domain 3's threat hunting, including querying the Sentinel Data lake tier and Summary rule tables. You need to recognize and write basic query patterns (where, project, summarize, extend, join, ago()), not necessarily memorize every operator.

What is Security Copilot's role on SC-200?

Domain 2 explicitly tests "investigating incidents by using agentic AI, including embedded Microsoft Security Copilot." You should understand how Security Copilot assists incident investigation inside Defender XDR — summarizing an incident, suggesting next investigation steps, and accelerating triage — as a capability you invoke during response, not a separate product to study in isolation.

What is the passing score for SC-200?

You need 700 out of 1000 on Microsoft's scaled scoring system. Case studies and scenario questions can carry more weight than simple recall items, so treat 80%+ on full-length practice exams as your real target.

Do I need SC-900 before SC-200?

No, it is not a prerequisite. If you are new to Microsoft security products, SC-900 gives useful conceptual grounding first. If you already work in IT security or a SOC, you can go straight to SC-200.

Does the SC-200 certification expire?

Yes, annually, renewed free through a Microsoft Learn assessment available starting six months before expiration — the standard policy for Microsoft associate certifications.

Ready to Practice SC-200?

500 scenario-based questions across all three current domains. Practice mode with explanations + timed exam simulation.

Start Free Practice →