SC-200
Microsoft Security Operations Analyst AssociateAzure Associate
General Information
- Total questions: 200
- Recommended duration: 2 hours
- Minimum score: 70%
- Type: Multiple choice
- Order: Configurable (random or sequential)
Statistics
- Total attempts: 0
- No statistics available yet
Domains Distribution
- Manage a security operations environment: 83
- Respond to security incidents: 73
- Perform threat hunting: 44
Training Materials
Exam guide
MSLearn Courses
- https://learn.microsoft.com/en-us/training/modules/analyze-data-in-sentinel/
- https://learn.microsoft.com/en-us/training/modules/analyze-results-kusto-query-language/
- https://learn.microsoft.com/en-us/training/modules/automation-microsoft-sentinel/
- https://learn.microsoft.com/en-us/training/modules/build-multi-table-statements-kusto-query-language/
- https://learn.microsoft.com/en-us/training/modules/configure-manage-automation-microsoft-defender-for-endpoint/
- https://learn.microsoft.com/en-us/training/modules/configure-settings-for-alerts-detections-microsoft-defender-for-endpoint/
- https://learn.microsoft.com/en-us/training/modules/connect-azure-assets-to-azure-defender/
- https://learn.microsoft.com/en-us/training/modules/connect-common-event-format-logs-to-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/connect-data-to-azure-sentinel-with-data-connectors/
- https://learn.microsoft.com/en-us/training/modules/connect-microsoft-defender-365-to-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/connect-microsoft-services-to-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/connect-non-azure-machines-to-azure-defender/
- https://learn.microsoft.com/en-us/training/modules/connect-syslog-data-sources-to-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/connect-threat-indicators-to-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/connect-windows-hosts-to-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/construct-kusto-query-language-statements/
- https://learn.microsoft.com/en-us/training/modules/create-manage-azure-sentinel-workspaces/
- https://learn.microsoft.com/en-us/training/modules/data-normalization-microsoft-sentinel/
- https://learn.microsoft.com/en-us/training/modules/deploy-microsoft-defender-for-endpoints-environment/
- https://learn.microsoft.com/en-us/training/modules/fundamentals-generative-ai/
- https://learn.microsoft.com/en-us/training/modules/hunt-threats-sentinel/
- https://learn.microsoft.com/en-us/training/modules/implement-windows-10-security-enhancements-with-microsoft-defender-for-endpoint/
- https://learn.microsoft.com/en-us/training/modules/incident-management-sentinel/
- https://learn.microsoft.com/en-us/training/modules/integrate-microsoft-defender-xdr-with-microsoft-sentinel/
- https://learn.microsoft.com/en-us/training/modules/intro-to-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/introduction-microsoft-365-threat-protection/
- https://learn.microsoft.com/en-us/training/modules/m365-security-threat-protect/
- https://learn.microsoft.com/en-us/training/modules/m365-threat-remediate/
- https://learn.microsoft.com/en-us/training/modules/m365-threat-safeguard/
- https://learn.microsoft.com/en-us/training/modules/manage-azure-active-directory-identity-protection/
- https://learn.microsoft.com/en-us/training/modules/manage-cloud-security-posture-management/
- https://learn.microsoft.com/en-us/training/modules/manage-content-microsoft-sentinel/
- https://learn.microsoft.com/en-us/training/modules/microsoft-cloud-app-security/
- https://learn.microsoft.com/en-us/training/modules/mitigate-incidents-microsoft-365-defender/
- https://learn.microsoft.com/en-us/training/modules/perform-actions-device-microsoft-defender-for-endpoint/
- https://learn.microsoft.com/en-us/training/modules/perform-device-investigations-microsoft-defender-for-endpoints/
- https://learn.microsoft.com/en-us/training/modules/perform-evidence-entities-investigations-microsoft-defender-for-endpoint/
- https://learn.microsoft.com/en-us/training/modules/perform-threat-hunting-sentinel-with-notebooks/
- https://learn.microsoft.com/en-us/training/modules/purview-audit-search-investigate/
- https://learn.microsoft.com/en-us/training/modules/purview-data-loss-prevention-alerts/
- https://learn.microsoft.com/en-us/training/modules/purview-ediscovery-search/
- https://learn.microsoft.com/en-us/training/modules/purview-insider-risk-investigate-alerts/
- https://learn.microsoft.com/en-us/training/modules/query-data-sentinel/
- https://learn.microsoft.com/en-us/training/modules/query-logs-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/remediate-azure-defender-security-alerts/
- https://learn.microsoft.com/en-us/training/modules/security-copilot-describe-core-features/
- https://learn.microsoft.com/en-us/training/modules/security-copilot-embedded-experiences/
- https://learn.microsoft.com/en-us/training/modules/security-copilot-getting-started/
- https://learn.microsoft.com/en-us/training/modules/security-copilot-interactive-guides/
- https://learn.microsoft.com/en-us/training/modules/threat-response-sentinel-playbooks/
- https://learn.microsoft.com/en-us/training/modules/understand-azure-defender-cloud-workload-protection/
- https://learn.microsoft.com/en-us/training/modules/use-entity-behavior-analytics-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/use-search-jobs-microsoft-sentinel/
- https://learn.microsoft.com/en-us/training/modules/use-threat-vulnerability-management-microsoft-defender-for-endpoint/
- https://learn.microsoft.com/en-us/training/modules/use-watchlists-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/utilize-threat-intelligence-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/what-is-azure-defender/
- https://learn.microsoft.com/en-us/training/modules/what-is-threat-hunting-azure-sentinel/
- https://learn.microsoft.com/en-us/training/modules/work-with-data-kusto-query-language/
- https://learn.microsoft.com/en-us/training/paths/sc-200-configure-azure-sentinel-environment/
- https://learn.microsoft.com/en-us/training/paths/sc-200-connect-logs-to-azure-sentinel/
- https://learn.microsoft.com/en-us/training/paths/sc-200-create-detections-perform-investigations-azure-sentinel/
- https://learn.microsoft.com/en-us/training/paths/sc-200-mitigate-threats-using-azure-defender/
- https://learn.microsoft.com/en-us/training/paths/sc-200-mitigate-threats-using-microsoft-365-defender/
- https://learn.microsoft.com/en-us/training/paths/sc-200-mitigate-threats-using-microsoft-copilot-for-security/
- https://learn.microsoft.com/en-us/training/paths/sc-200-mitigate-threats-using-microsoft-defender-for-endpoint/
- https://learn.microsoft.com/en-us/training/paths/sc-200-mitigate-threats-using-microsoft-purview/
- https://learn.microsoft.com/en-us/training/paths/sc-200-perform-threat-hunting-azure-sentinel/
- https://learn.microsoft.com/en-us/training/paths/sc-200-utilize-kql-for-azure-sentinel/
Exam Tips
- Read every question carefully
- Rule out the obviously wrong options
- Manage your time
- Review the explanations at the end
- Practise regularly