Microsoft Certified:Security Operations Analyst Associate
The Microsoft Certified: Security Operations Analyst Associate certification validates your ability to investigate, search for, and mitigate threats using Microsoft Sentinel, Microsoft Defender for Cloud, and Microsoft 365 Defender. It is aimed at security operations analysts who monitor, identify, investigate, and respond to threats in multi-cloud and on-premises environments.
304 practice questions · Updated 2026-07-28
3Domains
9Objectives
70Concepts
304Questions
SC-200 Curriculum
Every domain, objective, and concept the SC-200 exam measures.
- Email Notifications Configuration
- Alert Notifications Tuning
- Advanced Features Configuration
- Rules Settings Configuration
- Custom Data Collection
- Security Policies Configuration
- Automated Investigation Management
- Automatic Attack Disruption
- Device Groups and Permissions Management
- Automation Rules in Sentinel
- Sentinel Playbooks Configuration
- Understand Microsoft Sentinel Roles
- Manage Data Retention Policies
- Create Microsoft Sentinel Workbooks
- Configure Microsoft Sentinel Workbooks
- Optimize Microsoft Sentinel Platform
- Data Connector Selection
- Windows Security Events via AMA
- Windows Event Forwarding Configuration
- Syslog and CEF via AMA
- Azure Activities Collection
- Threat Indicators Ingestion
- Custom Log Tables Creation
- Advanced Hunting Queries
- Custom Detection Rule Management
- Scheduled Analytics Rules
- Near-Real Time Analytics
- Threat Intelligence Analytics
- Machine Learning Analytics
- MITRE ATT&CK Analysis
- Anomaly Configuration
- Microsoft Defender for Office 365 Threat Investigation
- Microsoft Purview Threat Investigation
- Microsoft Defender for Cloud Workload Protections
- Microsoft Defender for Cloud Apps Security Risks
- Microsoft Entra ID Compromised Identities
- Microsoft Defender for Identity Alerts
- Microsoft Sentinel Alerts and Incidents
- Agentic AI and Microsoft Security Copilot
- Complex Attack Investigation
- Case Management for Security Incidents
- Device Timeline Investigation
- Live Response Actions
- Investigation Package Collection
- Evidence Investigation
- Entity Investigation
- Automatic Attack Disruption Analysis
- Incident Remediation
- Microsoft Purview Audit Basics
- Accessing Audit Logs
- Search and Filter Audit Logs
- Content Search in eDiscovery
- eDiscovery Search Queries
- Microsoft Graph Activity Logs Overview
- Accessing Microsoft Graph Logs
- Analyzing Graph Activity Logs
- KQL Table Identification
- Threat Detection with KQL
- Advanced Hunting Queries
- Threat Analytics Interpretation
- Hunting Graph Creation
- Entity Relationship Analysis
- Hunting Query Creation
- Hunting Query Monitoring
- KQL Job Creation
- KQL Job Management
- Summary Rule Table Creation
- Summary Rule Table Management
- Threat Hunting with Notebooks
- Sentinel MCP Server Connection
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SC-200, so none is invented.