Microsoft Security Operations Analyst (SC-200) Exam Blueprint

SC-200

40Questions
100 minDuration
700/1-1000Passing Score
$165Price
12Languages
Practice Microsoft Security Operations Analyst on QuizForge

Exam Domains

1.0 Manage a security operations environment 40%
  • 1.1Configure automation for Microsoft Defender XDR and Microsoft Sentinel
  • 1.2Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics
  • 1.3Configure alert notifications in Microsoft Defender XDR, including tuning, suppression, and correlation
  • 1.4Configure Microsoft Defender for Endpoint advanced features
  • 1.5Configure rules settings in Microsoft Defender for Endpoint
  • 1.6Configure custom data collection in Microsoft Defender for Endpoint
  • 1.7Configure security policies for Microsoft Defender for Endpoint, including attack surface reduction (ASR) rules
  • 1.8Manage automated investigation and response capabilities in Microsoft Defender XDR
  • 1.9Configure automatic attack disruption in Microsoft Defender XDR
  • 1.10Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint
  • 1.11Create and configure automation rules in Microsoft Sentinel
  • 1.12Create and configure Microsoft Sentinel playbooks
  • 1.13Configure the Microsoft Sentinel SIEM and platform
  • 1.14Specify Microsoft Sentinel roles
  • 1.15Manage data retention for XDR and Microsoft Sentinel tables, including Analytics, Data lake, and XDR tiers
  • 1.16Create and configure Microsoft Sentinel workbooks
  • 1.17Optimize the Microsoft Sentinel platform, including SOC optimization recommendations
  • 1.18Ingest data into the Microsoft Sentinel SIEM and platform
  • 1.19Select data connectors based on data source requirements, including Windows logs and security events
  • 1.20Configure collection of Windows Security events by using Windows Security Events via AMA, including data collection rules
  • 1.21Plan and configure collection of Windows Security events by using Windows Event Forwarding (WEF)
  • 1.22Plan and configure Syslog via AMA and Common Event Format (CEF) via AMA connectors
  • 1.23Configure collection of Azure activities by using Azure Policy and resource diagnostic settings
  • 1.24Ingest threat indicators into Microsoft Sentinel
  • 1.25Create custom log tables in the workspace to store ingested data
2.0 Respond to security incidents 35%
  • 2.1Respond to alerts and incidents in Microsoft Defender XDR
  • 2.2Investigate and remediate threats by using Microsoft Defender for Office 365, including automatic attack disruption
  • 2.3Investigate and remediate threats or compromised entities identified by Microsoft Purview
  • 2.4Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud workload protections
  • 2.5Investigate and remediate security risks identified by Microsoft Defender for Cloud Apps
  • 2.6Investigate and remediate compromised identities that are identified by Microsoft Entra ID
  • 2.7Investigate and remediate security alerts from Microsoft Defender for Identity
  • 2.8Investigate and remediate alerts and incidents identified by Microsoft Sentinel
  • 2.9Investigate incidents by using agentic AI, including embedded Copilot for Security
  • 2.10Investigate complex attacks, such as multi-stage, multi-domain, and lateral movement
  • 2.11Manage security incidents by using case management
  • 2.12Respond to alerts and incidents in Microsoft Defender for Endpoint
  • 2.13Investigate device timelines
  • 2.14Perform actions on the device, including live response and collecting investigation packages
  • 2.15Perform evidence and entity investigation
  • 2.16Investigate and remediate incidents identified by automatic attack disruption
  • 2.17Investigate Microsoft 365 activities to identify threats
  • 2.18Investigate threats by using Audit from Microsoft Purview
  • 2.19Investigate threats by using Content Search in Microsoft Purview
  • 2.20Investigate threats by using Microsoft Graph activity logs
3.0 Perform threat hunting 20%
  • 3.1Detect threats by using Microsoft Defender XDR
  • 3.2Identify the appropriate table to use in a KQL query
  • 3.3Identify threats by using Kusto Query Language (KQL)
  • 3.4Create Advanced Hunting queries
  • 3.5Interpret threat analytics in Microsoft Defender XDR
  • 3.6Create hunting graphs, including blast radius
  • 3.7Analyze relationships between entities by using Sentinel Graph
  • 3.8Detect threats by using the Microsoft Sentinel platform
  • 3.9Create and monitor hunting queries
  • 3.10Create and manage KQL jobs in Data lake
  • 3.11Create and manage Summary rule tables for querying
  • 3.12Hunt for threats by using Notebooks, including connection to the Sentinel MCP Server

Exam Details

Question TypesMultiple Choice, Multiple Response, Drag and Drop, Case Study, Build List, Hot Area, Repeated Answer Choices
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID. Name on ID must match registration. For online: webcam required, room must be clear of people and materials.
RenewalRequired -- Microsoft certifications (Associate/Expert/Specialty) are renewed annually for free via a short renewal assessment on Microsoft Learn. Renewal assessment available 6 months before expiry. Fundamentals certifications do not expire.
PrerequisitesExperience with Microsoft security, compliance, and identity solutions, Microsoft 365, Azure cloud services, AI agents and Copilots, Windows, Linux, and mobile operating systems.
Retake PolicyNo waiting period for first retake if score >= 500 on failed attempt. If score < 500: 14-day waiting period before retake. Maximum 5 attempts per exam per year (365 days). Free retake voucher sometimes included in official instructor-led training.
LanguagesEnglish, Simplified Chinese, Traditional Chinese, French, German, Japanese, Korean, Portuguese, Russian, Spanish, Arabic, Indonesian

Official Study Resources