CertSafari

    Free Practice Questions for Microsoft Security Operations Analyst (SC-200) Certification

    🔄 Last checked for updates August 19th, 2026

    Study with 353 exam-style practice questions designed to help you prepare for the Microsoft Security Operations Analyst (SC-200). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.

    Exam experiencesNew

    Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.

    View exam experiences

    Start Practicing

    All Domains

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Domain Mode

    Practice questions from a specific topic area

    Quiz History

    Exam Details

    Key information about Microsoft Security Operations Analyst (SC-200)

    Official study guide

    View

    Question formats CertSafari offers
    • Multiple choice
    • Ordering
    • Matching
    • True/False
    • Fill in the blank
    level:

    Associate

    language:

    English (and other localized versions)

    prerequisites:

    Familiarity with Microsoft security, compliance, and identity solutions; Microsoft 365; Azure cloud services; AI agents and Copilots; Windows, Linux, and mobile operating systems.

    target audience:

    Security operations analysts who reduce organizational risk by performing triage, responding to incidents, hunting for threats, and engineering detections.

    skills measured as of:

    July 28, 2026

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    Domain 1: Manage a security operations environment

    Subdomain 1.1: Configure automation for Microsoft Defender XDR and Microsoft Sentinel

    Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics

    - Configure alert notifications in Microsoft Defender XDR, including tuning, suppression, and correlation - Configure Microsoft Defender for Endpoint advanced features - Configure rules settings in Microsoft Defender for Endpoint - Configure custom data collection in Microsoft Defender for Endpoint - Configure security policies for Microsoft Defender for Endpoint, including attack surface reduction (ASR) rules - Manage automated investigation and response capabilities in Microsoft Defender XDR - Configure automatic attack disruption in Microsoft Defender XDR - Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint - Create and configure automation rules in Microsoft Sentinel - Create and configure Microsoft Sentinel playbooks

    Subdomain 1.2: Configure the Microsoft Sentinel SIEM and platform

    Specify Microsoft Sentinel roles

    - Manage data retention for XDR and Microsoft Sentinel tables, including Analytics, Data lake, and XDR tiers - Create and configure Microsoft Sentinel workbooks - Optimize the Microsoft Sentinel platform, including SOC optimization recommendations

    Subdomain 1.3: Ingest data into the Microsoft Sentinel SIEM and platform

    Select data connectors based on data source requirements, including Windows logs and security events

    - Configure collection of Windows Security events by using Windows Security Events via AMA, including data collection rules - Plan and configure collection of Windows Security events by using Windows Event Forwarding (WEF) - Plan and configure Syslog via AMA and Common Event Format (CEF) via AMA connectors - Configure collection of Azure activities by using Azure Policy and resource diagnostic settings - Ingest threat indicators into Microsoft Sentinel - Create custom log tables in the workspace to store ingested data

    Subdomain 1.4: Configure detections

    Create custom detection rules by using Advanced Hunting in Microsoft Defender XDR

    - Manage custom detection rules in Microsoft Defender XDR - Configure and manage analytics rules in Microsoft Sentinel SIEM, including scheduled, near-real time (NRT), threat intelligence, and machine learning - Analyze attack vector coverage by using the MITRE ATT&CK matrix - Configure anomalies in Microsoft Sentinel

    Domain 2: Respond to security incidents

    Subdomain 2.1: Respond to alerts and incidents in Microsoft Defender XDR

    Investigate and remediate threats by using Microsoft Defender for Office 365, including automatic attack disruption

    - Investigate and remediate threats or compromised entities identified by Microsoft Purview - Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud workload protections - Investigate and remediate security risks identified by Microsoft Defender for Cloud Apps - Investigate and remediate compromised identities that are identified by Microsoft Entra ID - Investigate and remediate security alerts from Microsoft Defender for Identity - Investigate and remediate alerts and incidents identified by Microsoft Sentinel - Investigate incidents by using agentic AI, including embedded Microsoft Security Copilot - Investigate complex attacks, such as multi-stage, multi-domain, and lateral movement - Manage security incidents by using case management

    Subdomain 2.2: Respond to alerts and incidents in Microsoft Defender for Endpoint

    Investigate device timelines

    - Perform actions on the device, including live response and collecting investigation packages - Perform evidence and entity investigation - Investigate and remediate incidents identified by automatic attack disruption

    Subdomain 2.3: Investigate Microsoft 365 activities to identify threats

    Investigate threats by using Microsoft Purview Audit

    - Investigate threats by using Content search in Microsoft Purview eDiscovery - Investigate threats by using Microsoft Graph activity logs

    Domain 3: Perform threat hunting

    Subdomain 3.1: Detect threats by using Microsoft Defender XDR

    Identify the appropriate table to use in a KQL query

    - Identify threats by using Kusto Query Language (KQL) - Create Advanced Hunting queries - Interpret threat analytics in Microsoft Defender XDR - Create hunting graphs, including blast radius - Analyze relationships between entities by using Sentinel Graph

    Subdomain 3.2: Detect threats by using the Microsoft Sentinel platform

    Create and monitor hunting queries

    - Create and manage KQL jobs in Data lake - Create and manage Summary rule tables for querying - Hunt for threats by using Notebooks, including connection to the Sentinel MCP Server

    Techniques & products

    Microsoft Defender XDR
    Microsoft Sentinel
    Microsoft Entra ID
    Microsoft Purview
    Microsoft Defender for Cloud
    Microsoft Defender for Office 365
    Microsoft Defender for Endpoint
    Microsoft Defender for Cloud Apps
    Microsoft Defender for Identity
    Microsoft Security Copilot
    Kusto Query Language (KQL)
    Advanced Hunting
    MITRE ATT&CK matrix
    Windows logs
    Security events
    Windows Security Events via AMA
    Windows Event Forwarding (WEF)
    Syslog via AMA
    Common Event Format (CEF) via AMA
    Azure Policy
    Resource diagnostic settings
    Threat indicators
    Custom log tables
    Automation rules
    Playbooks
    Workbooks
    Live response
    Investigation packages
    Content search
    Microsoft Graph activity logs
    Data lake
    Notebooks
    SOC optimization recommendations
    Attack surface reduction (ASR) rules
    Automated investigation and response
    Automatic attack disruption
    Device groups
    Permissions
    Automation levels
    Analytics rules
    Anomalies
    Case management
    Agentic AI
    Multi-stage attacks
    Multi-domain attacks
    Lateral movement attacks
    Device timelines
    Evidence investigation
    Entity investigation
    Hunting graphs
    Blast radius
    Sentinel Graph
    KQL jobs
    Summary rule tables
    Microsoft 365
    Azure cloud services
    AI agents
    Copilots
    Windows operating systems
    Linux operating systems
    Mobile operating systems

    CertSafari is not affiliated with, endorsed by, or officially connected to Microsoft Corporation. Full disclaimer