Free Practice Questions for Microsoft Security Operations Analyst (SC-200) Certification
Study with 353 exam-style practice questions designed to help you prepare for the Microsoft Security Operations Analyst (SC-200). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.
Exam experiencesNew
Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.
Start Practicing
All Domains
Practice with randomly mixed questions from all topics
Domain Mode
Practice questions from a specific topic area
Quiz History
Exam Details
Key information about Microsoft Security Operations Analyst (SC-200)
- Multiple choice
- Ordering
- Matching
- True/False
- Fill in the blank
Associate
English (and other localized versions)
Familiarity with Microsoft security, compliance, and identity solutions; Microsoft 365; Azure cloud services; AI agents and Copilots; Windows, Linux, and mobile operating systems.
Security operations analysts who reduce organizational risk by performing triage, responding to incidents, hunting for threats, and engineering detections.
July 28, 2026
Exam Topics & Skills Assessed
Skills measured (from the official study guide)
Domain 1: Manage a security operations environment
Subdomain 1.1: Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics
- Configure alert notifications in Microsoft Defender XDR, including tuning, suppression, and correlation - Configure Microsoft Defender for Endpoint advanced features - Configure rules settings in Microsoft Defender for Endpoint - Configure custom data collection in Microsoft Defender for Endpoint - Configure security policies for Microsoft Defender for Endpoint, including attack surface reduction (ASR) rules - Manage automated investigation and response capabilities in Microsoft Defender XDR - Configure automatic attack disruption in Microsoft Defender XDR - Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint - Create and configure automation rules in Microsoft Sentinel - Create and configure Microsoft Sentinel playbooks
Subdomain 1.2: Configure the Microsoft Sentinel SIEM and platform
Specify Microsoft Sentinel roles
- Manage data retention for XDR and Microsoft Sentinel tables, including Analytics, Data lake, and XDR tiers - Create and configure Microsoft Sentinel workbooks - Optimize the Microsoft Sentinel platform, including SOC optimization recommendations
Subdomain 1.3: Ingest data into the Microsoft Sentinel SIEM and platform
Select data connectors based on data source requirements, including Windows logs and security events
- Configure collection of Windows Security events by using Windows Security Events via AMA, including data collection rules - Plan and configure collection of Windows Security events by using Windows Event Forwarding (WEF) - Plan and configure Syslog via AMA and Common Event Format (CEF) via AMA connectors - Configure collection of Azure activities by using Azure Policy and resource diagnostic settings - Ingest threat indicators into Microsoft Sentinel - Create custom log tables in the workspace to store ingested data
Subdomain 1.4: Configure detections
Create custom detection rules by using Advanced Hunting in Microsoft Defender XDR
- Manage custom detection rules in Microsoft Defender XDR - Configure and manage analytics rules in Microsoft Sentinel SIEM, including scheduled, near-real time (NRT), threat intelligence, and machine learning - Analyze attack vector coverage by using the MITRE ATT&CK matrix - Configure anomalies in Microsoft Sentinel
Domain 2: Respond to security incidents
Subdomain 2.1: Respond to alerts and incidents in Microsoft Defender XDR
Investigate and remediate threats by using Microsoft Defender for Office 365, including automatic attack disruption
- Investigate and remediate threats or compromised entities identified by Microsoft Purview - Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud workload protections - Investigate and remediate security risks identified by Microsoft Defender for Cloud Apps - Investigate and remediate compromised identities that are identified by Microsoft Entra ID - Investigate and remediate security alerts from Microsoft Defender for Identity - Investigate and remediate alerts and incidents identified by Microsoft Sentinel - Investigate incidents by using agentic AI, including embedded Microsoft Security Copilot - Investigate complex attacks, such as multi-stage, multi-domain, and lateral movement - Manage security incidents by using case management
Subdomain 2.2: Respond to alerts and incidents in Microsoft Defender for Endpoint
Investigate device timelines
- Perform actions on the device, including live response and collecting investigation packages - Perform evidence and entity investigation - Investigate and remediate incidents identified by automatic attack disruption
Subdomain 2.3: Investigate Microsoft 365 activities to identify threats
Investigate threats by using Microsoft Purview Audit
- Investigate threats by using Content search in Microsoft Purview eDiscovery - Investigate threats by using Microsoft Graph activity logs
Domain 3: Perform threat hunting
Subdomain 3.1: Detect threats by using Microsoft Defender XDR
Identify the appropriate table to use in a KQL query
- Identify threats by using Kusto Query Language (KQL) - Create Advanced Hunting queries - Interpret threat analytics in Microsoft Defender XDR - Create hunting graphs, including blast radius - Analyze relationships between entities by using Sentinel Graph
Subdomain 3.2: Detect threats by using the Microsoft Sentinel platform
Create and monitor hunting queries
- Create and manage KQL jobs in Data lake - Create and manage Summary rule tables for querying - Hunt for threats by using Notebooks, including connection to the Sentinel MCP Server
Techniques & products