SC-200
Security Operations Analyst Associate — flashcards, study guide, and practice exam.
Completion0%0 of 250 cards studied
Know00% of Study Deck
Unsure00% of Study Deck
Missed00% of Study Deck
Recommended Study Strategy
Round 1
Full Assessment
Go through all 250 Study Deck cards in order and grade each one Know, Unsure, or Missed. This sets your baseline.
Start Round 1Round 2
Review Deck
Study only the cards you graded Unsure or Missed. A card you grade Know leaves the Review Deck the next time you start a session.
Open Review DeckRound 3
Mastery Shuffle
Shuffle the full Study Deck and grade from memory to test what you really know.
Start Round 3Study by Exam Domain
Exam Day Checklist
- Match the question to the right hunting table: Device tables for endpoints, EmailEvents and UrlClickEvents for mail and Safe Links clicks, IdentityLogonEvents for Active Directory sign-ins, and AlertInfo with AlertEvidence for alerts.
- Know the retention tiers: the Analytics tier keeps data ready for detections and hunting, while the Data lake tier stores it for up to 12 years and is reached through KQL jobs, Spark jobs, or summary rules.
- Automation rules change incidents directly (status, severity, owner, tags, and tasks); anything that reaches another system needs a playbook, which is an Azure Logic Apps workflow.
- Pick the ingestion path: Windows Security Events via AMA with a data collection rule for Windows hosts, and a forwarder with CEF via AMA (CommonSecurityLog) or Syslog via AMA (Syslog) for appliances.
- Expect retired and moved features: Sentinel livestreams are gone (use KQL jobs, analytics rules, or playbooks), and Content search now lives inside eDiscovery.
- Read the final sentence of a long scenario first to find the actual question.
- Watch for qualifiers such as NOT, BEST, and MOST appropriate.
- You have 100 minutes and need 700 to pass. Flag hard questions and come back; change an answer only with a clear reason.
Official Microsoft Links
Exam SC-200 study guide (skills measured as of July 28, 2026)Microsoft Certified: Security Operations Analyst Associate (includes the practice assessment)Exam sandbox (try the exam interface)Exam SC-200 prep videos (published February 2026, before the July 28, 2026 update)Course SC-200T00: Defend against cyberthreats with Microsoft's security operations platformLearning path: Mitigate threats using Microsoft Defender XDRLearning path: Mitigate threats using Microsoft Security CopilotLearning path: Mitigate threats using Microsoft PurviewLearning path: Mitigate threats using Microsoft Defender for EndpointLearning path: Mitigate threats using Microsoft Defender for CloudLearning path: Create queries for Microsoft Sentinel using Kusto Query Language (KQL)Learning path: Configure your Microsoft Sentinel environmentLearning path: Connect logs to Microsoft SentinelLearning path: Create detections and perform investigations using Microsoft SentinelLearning path: Perform threat hunting in Microsoft Sentinel