Microsoft · SC-200
Validates expertise in investigating, responding to, and mitigating threats using Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Defender for Cloud.
Practice Questions
599
≈ 11 practice exams
Duration
100 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Jan 2026
Use this SC-200 practice exam to prepare for Microsoft Certified: Security Operations Analyst Associate (SC-200) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 599 questions for Microsoft SC-200, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Manage a security operations environment, Configure protections and detections, Manage incident response, Manage security threats, and Microsoft Sentinel. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Microsoft Certified: Security Operations Analyst Associate (SC-200) validates a practitioner's ability to reduce organizational risk by investigating, responding to, and hunting for threats across cloud and on-premises environments. The certification covers the full Microsoft security operations stack, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft Security Copilot, and third-party security integrations. Candidates demonstrate competency in performing triage, responding to incidents, executing threat hunts with Kusto Query Language (KQL), and mitigating risk through exposure management.
Last updated on January 22, 2026, the exam reflects current platform capabilities including automatic attack disruption, Microsoft Purview data loss prevention integration, Microsoft Entra ID identity investigations, and Security Copilot promptbook creation. The certification spans both reactive security operations—such as remediating ransomware and business email compromise—and proactive practices including behavioral analytics, MITRE ATT&CK coverage analysis, and custom detection rule authoring in Microsoft Sentinel.
This certification is designed for security operations analysts working in Security Operations Centers (SOC) who are responsible for monitoring, triaging, and remediating threats using Microsoft's security platform. It suits professionals in roles such as SOC Analyst (Tier 1–3), Threat Hunter, Incident Responder, and Cloud Security Analyst who operate day-to-day within Microsoft Defender and Sentinel environments.
Candidates typically have hands-on experience with Microsoft 365 and Azure services, and are comfortable working across Windows, Linux, and mobile operating systems. IT administrators and security engineers who manage Microsoft security tooling and are looking to validate their operational skills—as well as experienced professionals transitioning into dedicated security roles—will find this certification directly aligned with their work.
Microsoft does not enforce formal prerequisites for SC-200, but recommends that candidates have working familiarity with Microsoft 365, Azure cloud services, and common operating systems (Windows, Linux, mobile). Practical exposure to at least one of the core platform tools—Microsoft Sentinel, Microsoft Defender XDR, or Microsoft Defender for Cloud—is strongly advisable before sitting the exam.
Candidates with no prior security background should consider starting with SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) to build foundational knowledge. Approximately one year of hands-on experience in security monitoring or incident response, combined with working knowledge of KQL for log querying, is the realistic baseline for passing the exam without excessive remedial study.
SC-200 is a proctored exam delivered through Pearson VUE, available online or at a testing center. Candidates are allotted 100 minutes to complete the assessment. The exam may include a variety of question types: multiple choice, multi-select, drag-and-drop, and interactive lab-style components that simulate real tasks within Microsoft security portals. A passing score of 700 out of 1000 is required.
The exam is available in English, Japanese, Chinese (Simplified and Traditional), Korean, French, German, Spanish, Portuguese (Brazil), and Italian. Candidates taking a non-English version may request an additional 30 minutes. The certification is valid for 12 months and can be renewed at no cost by passing a free online renewal assessment on Microsoft Learn.
SC-200 certified professionals are positioned for roles including SOC Analyst, Threat Intelligence Analyst, Cloud Security Engineer, and Incident Responder at organizations running Microsoft's security stack—a category that includes the majority of enterprise environments globally. In the United States, security operations analysts with this certification typically earn between $107,000 and $145,000 annually, with variation based on seniority, industry, and geographic location. The credential is recognized by the U.S. Department of Defense COOL program and is aligned with roles requiring hands-on SIEM and XDR competency.
Compared to vendor-neutral alternatives such as CompTIA CySA+ or EC-Council CND, SC-200 offers deeper platform-specific validation that is directly applicable when an employer's security stack is Microsoft-centric. The certification is renewable annually at no cost via Microsoft Learn, keeping credential holders current as the platform evolves. With Microsoft Sentinel and Defender XDR adoption continuing to grow across enterprise and government sectors, demand for SC-200 certified analysts remains strong.
5 sample questions with answers and explanations. The full bank has 599 questions, enough for 11 full-length practice exams.
Preview — answers shown1. An organization wants to check all of its servers for missing security patches. What type of tool would be used to perform this task?
Explanation
A vulnerability scanner is the tool used for this purpose. These tools are designed to scan systems, networks, and applications to identify known security vulnerabilities, including missing patches, weak configurations, and common software flaws. The output of a vulnerability scan is a prioritized list of weaknesses that need to be remediated.
2. An analytics rule is configured to run every 5 minutes. This is an example of what type of analytics rule?
Explanation
This is a scheduled query rule. It is the most common type of analytics rule, where an analyst writes a specific KQL query and configures it to run on a recurring schedule (e.g., every 5 minutes, every hour, once a day). If the query returns results upon execution, an alert is generated. The other rule types are based on proprietary Microsoft ML models or specific threat intelligence feeds and do not have a user-configurable schedule.
3. A company policy mandates that all servers hosting sensitive data must have their file systems encrypted. Which type of security control is this?
Explanation
This is a preventative control. Preventative controls are designed to stop an undesirable event from happening in the first place. By encrypting the data at rest, the company prevents an attacker who gains physical or logical access to the disk from being able to read the sensitive information. A detective control would be an alert that fires when someone tries to access the data. A corrective control would be the action of revoking access after a breach is detected.
4. A security analyst needs to find all DNS queries for the domain 'malicious-site.com' that have occurred in the last 7 days. Which query language would they use in a Microsoft-based SIEM to perform this search?
Explanation
Kusto Query Language (KQL) is the language used to query data in Microsoft Sentinel and other Azure Monitor-based services. The analyst would write a KQL query against the DNS log table to filter for the specific domain and time range to find the relevant events.
5. Which of the following query languages is the standard for searching and analyzing log data in a Microsoft-based security analytics platform like Azure Sentinel?
Explanation
Kusto Query Language (KQL) is the powerful, read-only query language used to query the data stored in the underlying Log Analytics workspaces that power Microsoft Sentinel. It is designed for searching and analyzing large volumes of structured, semi-structured, and unstructured data, making it ideal for security investigations and threat hunting.
Microsoft Certified: Power Platform Fundamentals (PL-900)
PL-900 · 223 questions
Microsoft Certified: Power Platform Solution Architect Expert (PL-600)
PL-600 · 1080 questions
Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
SC-900 · 230 questions
Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-802)
AZ-802 · 600 questions
Microsoft 365 Certified: Administrator Expert (MS-102)
MS-102 · 965 questions
Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900)
AB-900 · 700 questions
$17.99
One-time access to this exam