SC-200: Predict your score.
Know what to study next.
See your predicted score, follow a study plan based on your answers, and revisit topics you're starting to forget. It all runs on your device.
374 practice questions
AI score prediction
100% offline
Download free
iPhone & iPad · Free to startOn your Mac? Scan to install
SC-200Microsoft Security Operations Analyst
SC-200 · 30 days left ›
PREDICTED786 ±37✓ Exam Ready · 87% confidence
SC-200 Practice Questions & Exam Prep — Microsoft Security Operations Analyst
Get exam-ready for SC-200 (Microsoft Security Operations Analyst) on iPhone or iPad. Azure Mastery uses on-device AI to predict your readiness score across all three SC-200 domains, build a personalised study plan from your weak spots, and surface topics you're forgetting. Core study stays on-device and works offline; optional sync uses your private iCloud account.
The exam
What is the SC-200 exam?
SC-200 is the Microsoft Certified: Security Operations Analyst Associate exam — the credential hiring managers expect when posting "SOC Analyst", "Security Operations Engineer", "Threat Hunter", or "Incident Responder" roles on the Microsoft stack.
SC-200 covers the SOC analyst's day-to-day in Microsoft Sentinel and Microsoft Defender XDR, plus the broader Defender product family. It pairs with SC-900 on the way in, and is one of the prereqs for SC-100 (Cybersecurity Architect Expert).
SC-200 is hands-on and KQL-aware. It validates that you can:
Configure and manage Microsoft Sentinel — workspaces, data connectors, analytics rules, watchlists, automation, hunting
Investigate incidents end-to-end across Microsoft Defender XDR (Defender for Endpoint, Identity, Office 365, Cloud Apps)
Use Microsoft Defender for Cloud for posture and workload protection
Write KQL queries to hunt threats and build custom detections
Expect scenario questions that show a KQL snippet, an alert payload, or an incident graph and ask what you'd do next.
Microsoft updated the SC-200 skills outline on 28 July 2026. Every question in Azure Mastery's SC-200 bank is mapped to the current outline — no leftover questions on retired services. Read the official outline at learn.microsoft.com.
Questions40–60 multiple choice
Duration100 minutes (120 min seat)
Pass score700 / 1000
CostUSD $165 (≈ £128 UK)
ValidityRenew annually (Associate)
FormatOnline or test centre
Skills measured · 28 July 2026
SC-200 exam objectives
SC-200 has three domains, weighted by Microsoft's 28 July 2026 update. Each summary below follows the official skills outline; the counts are the questions in the app tagged to that domain.
Security skill mapIdentityProtectDetectGovern
Manage a security operations environmentPublished weight 40–45%
162 exam-scoped practice questions in the app
Explore SecOps topics
Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Configure the Microsoft Sentinel SIEM and platform
Ingest data into the Microsoft Sentinel SIEM and platform
Configure detections
This domain tests configuring Sentinel end-to-end and picking the right ingestion connector for a described log source.
Candidates memorise connector names but mix up which topology, AMA, WEF, or Syslog/CEF, actually fits a given source.
Match a described source and network topology to its one correct connector before touching other domain content.
Respond to security incidentsPublished weight 35–40%
132 exam-scoped practice questions in the app
Explore Incidents topics
Respond to alerts and incidents in Microsoft Defender XDR
Respond to alerts and incidents in Microsoft Defender for Endpoint
Investigate Microsoft 365 activities to identify threats
Investigating and remediating across the whole Defender XDR surface, now including agentic AI tooling, is the real focus here.
Case management and the evidence graph often get treated as one feature, though one tracks tasks and the other traces movement.
Reach for the attack-story graph specifically whenever a scenario asks how an attack actually moved.
Perform threat huntingPublished weight 20–25%
80 exam-scoped practice questions in the app
Explore Hunt topics
Detect threats by using Microsoft Defender XDR
Detect threats by using the Microsoft Sentinel platform
This domain is the most KQL-heavy: picking the right table and writing a query that actually returns results.
Syntactically correct KQL against the wrong table returns an empty result that's hard to explain.
Identify the correct table for a described signal before writing any KQL; that choice is itself assessed.
Common traps
Where SC-200 candidates slip
Five recurring misconceptions that trip up otherwise well-prepared SC-200 candidates, grounded in the current skills outline.
Defender for Cloud measures posture; Defender XDR handles response
Defender for Cloud surfacing an alert doesn't make the follow-up question a posture-management one.
Use Defender XDR for cross-product incident investigation; use Defender for Cloud for cloud posture and workload-protection findings, with integrations connecting the two workflows.
Treat Defender for Cloud as where risk is measured and Defender XDR as where an active incident gets handled.
Analytics rules, automation rules, and playbooks are three separate layers
Candidates reach for an analytics rule when a scenario actually needs automated remediation of an existing incident.
An analytics rule detects, an automation rule routes, and only a playbook actually remediates.
Pick a playbook whenever the scenario names a remediation action like isolating a device or disabling an account.
The right data connector depends on the source, not habit
AMA, WEF, and Syslog/CEF connectors all bring log data into Sentinel, so candidates default to whichever they know best.
Matching a described source and topology to its one purpose-built connector is what earns the mark here.
Pick WEF for centralised on-premises forwarding and CEF/Syslog for third-party appliances, not whichever connector feels familiar.
KQL table choice changes what a query can even see
Correct KQL syntax against the wrong table still returns an empty or misleading result.
Naming the table that actually holds the described telemetry is itself a scored step, before any query gets written.
Name the correct table first; treat that identification as a scored step, not a formality before the real answer.
Case management tracks the incident; the graph explains it
Candidates reach for case management when a scenario is actually asking how an attack moved between hosts.
A lateral-movement question calls for the evidence and attack-story graph, or Sentinel Graph, not the case list.
Save case management for tracking tasks and status; use the graph whenever the question is about how an attack spread.
Designed for SC-200
How Azure Mastery helps you pass SC-200
Exam-specific practice
374 SC-200 practice questions, each tagged to one of the three official domains.
Coverage weights security operations management heaviest at 40–45%, the widest domain by product surface.
Practise reading a KQL snippet or alert payload and deciding what to do next, the exam's real test.
Predicted score
Exam IQ forecasts your SC-200 score on-device after about 30 questions, with a confidence range.
It names the specific Sentinel rule type or KQL pattern actually holding your score down.
Track which of the three domains lags behind before you commit to a booking date.
Adaptive study plan
Your plan leans hardest on managing the SecOps environment, the domain Microsoft weights heaviest at 40–45%.
Miss a Sentinel automation-rule question and the next session surfaces another configuration question from the same domain.
Master a Defender-product distinction across three sessions and the plan moves toward hunting or incident-response scenarios.
Knowledge decay
Three SOC-analyst domains pack a lot of Sentinel and KQL surface; a rule template fades fast if unrevised.
Fading topics get flagged on the Today screen well before you'd forget them outright.
Weak Spots sessions pull decayed Sentinel or Defender topics back into rotation automatically.
Exam rehearsal
Rehearse a full 100-minute session with no jumping back to flag-and-review, like the real booking.
The domain split matches the published weighting, drawn entirely from Azure Mastery's own bank.
Microsoft alone decides the live SC-200 interface and its exact question order.
Answer Coach
Untangles SC-200's near-identical layers: analytics vs automation rules, and which Defender product owns a given remediation.
Get one wrong and Answer Coach names the exact layer or table the scenario was testing.
Every explanation is authored first; an eligible device may reword one on-device only after it passes grounding checks.
Aura guidance
Aura adjusts its recommendations through your first week of SC-200 practice as your patterns emerge.
Each session closes with a short summary: what changed, what's still shaky, what to do next.
Private by design
Your SC-200 answers, readiness gauge, and coaching notes live on your device unless you turn on sync.
There's no Azure Mastery account and nothing gets processed on an external server.
Turning on sync routes everything through your own private iCloud account, nothing else.
6-week study plan
Suggested SC-200 study plan
Build the SecOps environment, practise incident response, then develop your threat-hunting skills. Use the final blocks of this six-week route for focused review and rehearsal.
Sentinel foundations
Configure workspaces and data connectors.
Review retention and table tiers.
Compare Sentinel and Defender XDR role assignments.
Detection and intelligence
Compare analytics rule types.
Review watchlists and threat-intelligence integration.
Explore user and entity behaviour analytics where supported.
Automate incident handling
Configure automation rules and Logic App playbooks.
Practise triage, enrichment and response actions.
Build workbooks and dashboards.
Defender for Cloud
Review Secure Score and regulatory compliance.
Compare workload protection plans.
Explore JIT access, recommendations and exemptions.
Endpoint response
Review live response and automated investigation.
Practise response actions.
Explore device groups and attack-surface reduction.
Identity threats
Review lateral movement and golden-ticket detection.
Explore identity scoring.
Understand sensors and connectors.
Email and collaboration threats
Review anti-phishing and zero-hour auto purge.
Compare Safe Links and Safe Attachments.
Explore attack-simulation training.
Cloud apps and XDR
Review Cloud Apps anomaly detection and governance actions.
Use the XDR attack-story view and evidence graph.
Practise kill-chain analysis.
KQL practice
Review joins, parsing and time windows.
Use summarise, project and extend.
Interpret KQL snippets in scenarios.
Threat hunting
Explore Sentinel queries, bookmarks and livestream sessions.
Review custom detections and Defender XDR advanced hunting.
Map findings to MITRE ATT&CK.
Target weaker topics
Run Focus Weak Spots sessions.
Revisit SecOps environment decisions.
Review explanations for missed questions.
Timed rehearsal
Complete two 100-minute Exam Simulator sessions.
Review each run carefully.
Use the results to plan further study.
Inside the app
Nine interactive practice formats, on iPhone
Azure Mastery has nine interactive formats for exam practice. The examples below show original SC-200 practice questions in Azure Mastery on iPhone and iPad. The exam simulator uses timed sessions with the published domain weights. Microsoft's live interface and question mix may differ.
What is the default audit log retention for most activities in Microsoft Purview Audit (Standard)?
90 days
180 days
1 year
30 days
Multiple choice
An original SC-200 practice question with one correct answer. The app explains every option after you answer.
Exam-specific sample
Which Microsoft Sentinel features support proactive threat hunting? (Choose four.)
Azure Policy
Bookmarks
Hunting queries
Livestream
Notebooks
Multi-select
An original SC-200 multi-select question. Select all the correct options to earn the mark.
All-or-nothing
A SOC is defining a baseline response workflow for a Defender XDR incident that is not actively spreading. Order the four listed activities for this…
⋮⋮1Triage the incident by severity and validate the initial alert
⋮⋮2Investigate the available attack story and correlated entities
⋮⋮3Contain confirmed impact by isolating affected devices or disabling…
⋮⋮4Remediate malicious artifacts and restore affected entities
Drag-and-drop
An original SC-200 ordering question you can answer by touch on iPhone and iPad.
Interactive item
Select the workbook parameter control that lets analysts filter tiles by a user-selected time range.
Hotspot
An original SC-200 question with a visual prompt, designed for touch on iPhone and iPad.
Tap target
Fabrikam SOC — Standing up Microsoft Sentinel Fabrikam is deploying Microsoft Sentinel to centralize detection and response. The SOC must ingest the right sources, detect threats with appropriate analytics,…
1How should Fabrikam capture Azure subscription control-plane activity in Sentinel?
2How should Fabrikam collect Windows Security events from its servers?
3Which analytics rule type fits detecting a known malicious pattern on a regular…
4How should the SOC automatically handle repetitive false-positive incidents?
Case studies
An original SC-200 case study with several questions about the same requirements and environment.
Multi-question
✕Your answer: 90 days
✨ Answer Coach:90 days is a common retention figure in other Microsoft services, but it is not the default audit-log retention applied to most activities in Purview Audit (Standard).
— grounded in authored certification guidance
Answer Coach
Answer Coach explains why the answer is correct and, where available, why each option is right or wrong. It helps you understand a mistake and remember the distinction. Read explanations after each question or at the end of a practice test. On supported devices, optional AI can reword a note on your device after checking it against the written guidance.
App exclusive
Frequently asked
SC-200 FAQs
Do I need to know KQL before starting SC-200?
Not on day one, but learn it early: threat hunting is 20–25% of the exam and KQL shows up in the other domains too. Start by reading and modifying existing queries before writing from scratch; the exam tests picking the right table and interpreting results more than raw syntax.
SC-900 first if security concepts are new to you: it builds the cross-cutting vocabulary without expecting hands-on triage. SC-200 is the role-based Associate exam, investigating incidents in Defender XDR and writing KQL hunting queries. Most candidates pass SC-900 in weeks, then spend two to three months on SC-200.
What question formats show up on SC-200?
40–60 questions, with formats that vary by sitting. Azure Mastery's bank mirrors that mix: mostly single-answer, a meaningful share of scenario and multi-select questions in roughly equal measure, a smaller set of yes/no, dropdown, hotspot, and drag-to-match items, and a handful of case studies.
What's the SC-200 voucher price, and is renewal extra?
SC-200's voucher runs USD $165 in the United States, roughly £128 in the UK, with Microsoft occasionally offering free vouchers around Build or Ignite. Renewal itself costs nothing beyond a short annual assessment, so the voucher is the only real ongoing expense.
Does an SC-200 pass last forever, or do I need to renew?
No, it needs renewing. Associate certifications including SC-200 expire annually; renewal is a free, short online assessment within six months of expiry, targeting recent outline updates. Fundamentals certifications such as AZ-900 differ: those never expire.
Sentinel automation or Defender XDR native response — how does SC-200 test the choice?
SC-200 scenarios give you an incident that could plausibly be handled either way, and expect you to pick based on where the signal originates and how broad the response needs to be, not personal preference. Answer Coach spells out which property of the scenario should have driven the call.
I need to retake SC-200 — what's the wait?
24 hours covers the wait before your first retake.
First retake: 24-hour wait.
Second and third retakes: 14-day wait each.
Microsoft limits you to five attempts in any rolling 12-month window, a new voucher required each time.
Can I try Azure Mastery's SC-200 bank before paying?
Yes. The app is free to download with a free allowance of SC-200 questions so you can try every feature. The full 374-question bank unlocks with a one-time exam-pack purchase, or a subscription unlocks every exam in the catalogue.
Can I hunt through SC-200 practice scenarios with no connection?
Yes. Practice sessions, scoring, and the readiness prediction all run on-device, so they work with no connection at all. There's no account to sign into, and data stays local unless you turn on optional, private iCloud sync.
Free study guides
Free guides that pair with SC-200
Where SC-200 fits
Certification paths that include SC-200
SC-200 is the Microsoft Security Operations Analyst Associate cert. It pairs with SC-900 as recommended fundamentals and is one of the prereqs for SC-100 (Cybersecurity Architect Expert). Tap any linked exam below to see its dedicated study app page.
SC-200 sits at the SOC-analyst Associate tier. SC-900 builds the cross-cutting Microsoft security vocabulary; SC-100 is the Expert next step. SC-500 is the current sibling for cloud-security-focused candidates.
Ready to pass SC-200?
Download Azure Mastery free. 374 SC-200 practice questions across all three domains, AI score prediction, full-length exam simulator, adaptive study plan. iPhone & iPad.