SC-200 Practice Questions & Exam Prep — Microsoft Security Operations Analyst
Get exam-ready for SC-200 (Microsoft Security Operations Analyst) on iPhone or iPad. Azure Mastery uses on-device AI to predict your readiness score across all three SC-200 domains, build a personalised study plan from your weak spots, and surface topics you're forgetting. Core study stays on-device and works offline; optional sync uses your private iCloud account.
The exam
What is the SC-200 exam?
SC-200 is the Microsoft Certified: Security Operations Analyst Associate exam — the credential hiring managers expect when posting "SOC Analyst", "Security Operations Engineer", "Threat Hunter", or "Incident Responder" roles on the Microsoft stack. SC-200 covers the SOC analyst's day-to-day in Microsoft Sentinel and Microsoft Defender XDR, plus the broader Defender product family. It pairs with SC-900 on the way in, and is one of the prereqs for SC-100 (Cybersecurity Architect Expert).
SC-200 is hands-on and KQL-aware. It validates that you can configure and manage Microsoft Sentinel (workspaces, data connectors, analytics rules, watchlists, automation, hunting), investigate incidents end-to-end across Microsoft Defender XDR (Defender for Endpoint, Identity, Office 365, Cloud Apps), use Microsoft Defender for Cloud for posture and workload protection, and write KQL queries to hunt threats and build custom detections. Expect scenario questions that show a KQL snippet, an alert payload, or an incident graph and ask what you'd do next.
Microsoft updated the SC-200 skills outline on 16 April 2026. Every question in Azure Mastery's SC-200 bank is mapped to the current outline — no leftover questions on retired services. Read the official outline at learn.microsoft.com.
Questions40–60 multiple choice
Duration100 minutes (120 min seat)
Pass score700 / 1000
CostUSD $165 (≈ £128 UK)
ValidityRenew annually (Associate)
FormatOnline or test centre
Skills measured · April 2026
SC-200 exam objectives
Three domains, with weights set by Microsoft's April 2026 update. Every domain summary below is paraphrased from the official skills outline; bullet-level objectives in Azure Mastery are tagged so you always know which domain you're being tested on and where your weak spots cluster.
Security skill mapIdentityProtectDetectGovern
Manage a security operations environment40–45%
Explore key topics
The largest domain by far. Configure Microsoft Sentinel end-to-end — workspaces, data connectors (Azure activity, Microsoft 365, Defender XDR, third-party CEF/Syslog), log retention and table tiers, RBAC for Sentinel and Defender XDR. Build analytics rules (scheduled, NRT, Microsoft incident creation, anomaly), watchlists, threat-intelligence integration, and automation rules with Logic App playbooks. Configure Microsoft Defender for Cloud — Secure Score, regulatory compliance, workload protection plans (Servers, App Service, Storage, SQL, Containers), JIT VM access, recommendations and exemptions. Around 16–27 questions per sitting.
Respond to security incidents35–40%
Explore key topics
The Defender XDR investigation surface. Triage and investigate incidents using Microsoft Defender for Endpoint (live response, automated investigation, response actions, device groups), Microsoft Defender for Identity (lateral movement, golden ticket, identity scoring), Microsoft Defender for Office 365 (anti-phishing, ZAP, attack-simulation training), and Microsoft Defender for Cloud Apps (CASB, anomaly detection, governance actions). Use the Defender XDR attack-story view and evidence graph to follow the kill chain. Around 14–24 questions.
Perform threat hunting20–25%
Explore key topics
Smallest domain by weight, but the most KQL-heavy. Hunt with Microsoft Sentinel hunting queries and bookmarks, run advanced-hunting queries across Microsoft 365 / Defender XDR tables, build custom detection rules from saved hunts, and run livestream hunting sessions. Map activity to MITRE ATT&CK tactics and techniques, write KQL with joins, parse operators, time windows, and summarise. Around 8–14 questions.
Designed for SC-200
How Azure Mastery helps you pass SC-200
Azure Mastery ships with 358 SC-200 practice questions, every one written specifically against the current (April 2026) skills outline. Each question carries a domain tag mapped to the official three domains (manage SecOps environment, respond to incidents, threat hunting), so you always know which area you're being tested on and where your weak spots are clustered. KQL snippets, alert payloads, Sentinel analytics rules, and Defender XDR incident graphs appear throughout — matching the format of the live exam.
The on-device Exam IQ engine predicts your SC-200 score before you sit the exam. After roughly 30 questions it has enough signal to give a confidence-scored prediction (e.g. "786 ±37, 68% confidence") — and tells you the specific topics that are dragging your readiness down. No vague "study more" advice; just a ranked list of objectives where improvement would move your score the furthest.
The adaptive study plan rebuilds itself from your answer history. Miss a Sentinel analytics-rule scenario? You'll see another rule-type question in the next session. Master "Defender for Endpoint vs Defender for Identity" three sessions running and the engine backs off, surfacing fresh KQL hunting or automation-playbook scenarios. The plan optimises for the gap between where you are and the 700 pass score, not for blind volume.
Knowledge decay tracking matters more for SC-200 than for foundational exams — three SOC-analyst domains pack a lot of Microsoft Defender / Sentinel / KQL surface into a small bank, and the rule template you mastered three weeks ago is the rule you'll forget by exam day if you stop revising. Azure Mastery tracks every topic's decay curve and flags topics approaching expiry. The padlock icon on the Today screen is your "revisit before you forget" cue, and weak-spot drills automatically pull from decayed topics first.
Real exam simulation mode runs at SC-200's actual length and time pressure: a randomised 40–60-question set drawn from the full 358-question bank, weighted by domain percentages from the April 2026 outline, with the 100-minute timer running and no jumping back to flag-and-review. It's the closest you can get to the live Pearson VUE / online-proctored experience without sitting the exam.
Answer Coach turns each missed answer into a private, grounded lesson: the misconception, key distinction, and rule to remember. It always uses authored certification guidance; on supported devices, an optional on-device model may rewrite the note only when it passes grounding checks.
During your first week, Aura adapts the next step as you go. Every session ends with a concise recap of what changed, what to focus on, and the best follow-up.
Everything essential runs on-device. Your answer history, readiness gauge, and coaching stay private. Optional sync uses your private iCloud account; there is no Azure Mastery account, tracking, or external processing server.
6-week study plan
Suggested SC-200 study plan
Most candidates pass SC-200 after four to eight weeks of focused study, depending on prior SOC and KQL experience. The six-week plan below maps onto the three SC-200 domains, Azure Mastery's adaptive sessions, and the in-app exam simulator. Adjust pace to taste — the readiness gauge tells you when you're done, not the calendar.
Manage the SecOps environment
Days 1–3: Microsoft Sentinel workspaces, data connectors (Azure activity, Microsoft 365, Defender XDR, third-party CEF/Syslog), log retention and table tiers, RBAC for Sentinel and Defender XDR.
Days 4–6: Analytics rules — scheduled, NRT, Microsoft incident creation, anomaly. Watchlists, threat-intelligence integration, custom UEBA where supported.
Days 7–10: Automation rules and Logic App playbooks — incident triage, alert enrichment, response actions. Workbooks and dashboards.
Days 11–14: Microsoft Defender for Cloud — Secure Score, regulatory compliance, workload protection plans (Servers, App Service, Storage, SQL, Containers), JIT VM access, recommendations and exemptions.
Respond to security incidents
Days 15–17: Microsoft Defender for Endpoint — live response, automated investigation, response actions, device groups, attack-surface reduction.
Days 18–20: Microsoft Defender for Identity — lateral movement, golden ticket detection, identity scoring, sensors and connectors.
Days 21–23: Microsoft Defender for Office 365 — anti-phishing, ZAP, Safe Links / Safe Attachments, attack-simulation training.
Days 24–28: Microsoft Defender for Cloud Apps — CASB, anomaly detection, governance actions. Defender XDR attack-story view, evidence graph, kill-chain analysis.
Threat hunting, sharpen, simulate
Days 29–32: KQL fundamentals — joins, parse operators, time windows, summarise, project, extend. Practise reading KQL snippets in scenario questions.
Days 33–36: Sentinel hunting — hunting queries, bookmarks, livestream sessions, custom detection rules from saved hunts. Advanced hunting in Defender XDR. MITRE ATT&CK mapping.
Days 37–40: Run Focus Weak Spots every morning. Manage-SecOps domain is 40–45% — weight your time accordingly.
Days 41–42: Two end-to-end Exam Simulator runs at full 100-minute length. Review carefully. If readiness gauge is 750+ with reasonable confidence, schedule the exam.
Inside the app
Every Microsoft question type, on iPhone
SC-200's question bank uses the same formats Microsoft puts on the live exam — not just multiple choice. Each visualisation below is a faithful mock of how the type renders inside Azure Mastery on iPhone and iPad. Exam-simulator mode runs all of them at full 100-minute length with no flag-and-review jumps, mirroring Pearson VUE.
What is the default audit log retention for most activities in Microsoft Purview Audit (Standard)?
30 days
90 days
180 days
1 year
Multiple choice
A real SC-200 question-bank example with one correct answer. The app explains every option after you answer.
Exam-specific sample
Which Microsoft Sentinel features support proactive threat hunting? (Choose four.)
Hunting queries
Livestream
Bookmarks
Notebooks
Azure Policy
Multi-select
A real SC-200 multi-select item. Every required selection must be correct to earn the mark.
All-or-nothing
Order the phases of responding to a Defender XDR incident.
⋮⋮1Triage the incident by severity and confirm it is a true positive
⋮⋮2Investigate the attack story across the correlated entities
⋮⋮3Contain the threat by isolating devices or disabling accounts
⋮⋮4Remediate by removing malicious artifacts and restoring affected…
Drag-and-drop
A real SC-200 interactive-format prompt, rendered for touch on iPhone and iPad.
Interactive item
Select the workbook parameter control that lets analysts filter tiles by a user-selected time range.
Hotspot
A real SC-200 prompt that tests recognition inside a visual or contextual interface.
Tap target
Fabrikam SOC — Standing up Microsoft Sentinel Fabrikam is deploying Microsoft Sentinel to centralize detection and response. The SOC must ingest the right sources, detect threats with appropriate analytics,…
1How should Fabrikam capture Azure subscription control-plane activity in Sentinel?
2How should Fabrikam collect Windows Security events from its servers?
3Which analytics rule type fits detecting a known malicious pattern on a regular…
4How should the SOC automatically handle repetitive false-positive incidents?
Case studies
A real SC-200 case-study scenario with linked questions that share the same requirements and environment.
Multi-question
✕Your answer: 30 days
✨ Answer Coach:30 days was an older default for some Audit (Standard) activity, but it is no longer the standard retention period for most activities, so it understates how long events remain searchable.
— grounded in authored certification guidance
Answer Coach
Answer Coach uses the bank's authored rationale to explain the misconception, key distinction, and rule to remember. On supported devices, an optional on-device model may rewrite the note only when it passes grounding checks.
App exclusive
Frequently asked
SC-200 FAQs
How much does the SC-200 exam cost?
The SC-200 voucher is USD $165 in the United States. Pricing varies by region — in the UK it's typically around £128. Microsoft sometimes runs free-voucher promotions during events such as Microsoft Build or Microsoft Ignite, so check your Microsoft Learn profile for any active offers before booking. SC-200 also requires annual renewal (free, online), so factor that into long-term cost planning.
Does the SC-200 certification expire?
Yes. Microsoft Associate certifications including SC-200 expire annually. Renewal is free — a 25–30 question online assessment on Microsoft Learn within the six-month window before your expiration date. The renewal targets recent skills outline updates, so staying current is straightforward if you remain broadly active in the role. (Fundamentals certifications such as AZ-900 are different — those don't expire.)
What is the SC-200 retake policy if I fail?
The first retake is allowed after 24 hours. Second and third retakes each require a 14-day wait. Microsoft caps retakes at five attempts per 12-month rolling period. Each attempt requires a new voucher purchase.
How long should I study for SC-200?
Most candidates plan four to eight weeks with security-operations experience. Spend hands-on time in Microsoft Defender XDR and Microsoft Sentinel: investigate incidents, build KQL queries and analytics rules, hunt threats, automate response, and manage exposure. Azure Mastery's readiness gauge tells you when you're exam-ready.
SC-200 vs SC-900 — which should I take first?
SC-900 first if security concepts are new to you. SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) builds the cross-cutting Microsoft security vocabulary — Defender family, Microsoft Sentinel, Microsoft Entra, Microsoft Purview — without expecting hands-on triage. SC-200 is the role-based Associate exam: it expects you to investigate incidents in Defender XDR and write KQL hunting queries. Most candidates pass SC-900 in a few weeks then spend two to three months on SC-200.
SC-200 vs SC-500 — different security roles?
Different angles on Microsoft security. SC-500 implements security controls across cloud and AI workloads; SC-200 runs detection, investigation, hunting, and incident response in Microsoft Defender XDR and Sentinel. Choose SC-500 for cloud security engineering and SC-200 for security operations.
Where SC-200 fits
Certification paths that include SC-200
SC-200 is the Microsoft Security Operations Analyst Associate cert. It pairs with SC-900 as recommended fundamentals and is one of the prereqs for SC-100 (Cybersecurity Architect Expert). Tap any linked exam below to see its dedicated study app page.
SC-200 sits at the SOC-analyst Associate tier. SC-900 builds the cross-cutting Microsoft security vocabulary; SC-100 is the Expert next step. SC-500 is the current sibling for cloud-security-focused candidates.
Ready to pass SC-200?
Download Azure Mastery free. 358 SC-200 practice questions across all three domains, AI score prediction, full-length exam simulator, adaptive study plan. iPhone & iPad.