SC-200 Verified 2026 Edition

SC-200Practice Exam

Master the Microsoft Security Operations Analyst with the official PlanetCert Practice Test. Access real exam questions, professional-grade detailed explanations, and our advanced adaptive simulator. Pass your certification exam on the first attempt.

297 Total Questions
1 Included Version Get all versions for the price of one
English Edition
All-In-One Bundle
$79.99
$75.99
  • Interactive Simulator & AI
  • Detailed Explanations
  • Study, Timed & Flashcard Mode
  • Lifetime Access & Updates

Instant lifetime access • Secure checkout

Why Study with PlanetCert?

The Latest Questions

Practice questions and exam topics aligned with the current exam objectives.

Detailed Explanations

Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI

AI-Powered Insights

Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.

Exam Information

Official specifications published by Microsoft

Exam Format

120 min
40-60
700
Associate

Registration

$165 USD
Pearson VUE or online proctoring

Validity

1 year
Annual renewal assessment

SC-200 Exam Topics and Domains

SC-200 is organized into 4 weighted domains.

1

Manage a security operations environment

22%

Configure protections and detections (15–20%)

Configure and manage configure protections and detections (15–20%)

Manage incident response (25–30%)

Configure and manage manage incident response (25–30%)

Manage security threats (15–20%)

Configure and manage manage security threats (15–20%)

Configure alert and vulnerability notification rules

Configure and manage configure alert and vulnerability notification rules

Configure Microsoft Defender for Endpoint advanced features

Configure and manage configure microsoft defender for endpoint advanced features

Configure endpoint rules settings

Configure and manage configure endpoint rules settings

Manage automated investigation and response capabilities in Microsoft

Configure and manage manage automated investigation and response capabilities in microsoft

Configure automatic attack disruption in Microsoft Defender XDR

Configure and manage configure automatic attack disruption in microsoft defender xdr

Configure and manage device groups, permissions, and automation levels

Configure and manage configure and manage device groups, permissions, and automation levels

Identify unmanaged devices in Microsoft Defender for Endpoint

Configure and manage identify unmanaged devices in microsoft defender for endpoint

Discover unprotected resources by using Defender for Cloud

Configure and manage discover unprotected resources by using defender for cloud

Identify and remediate devices at risk by using Microsoft Defender

Configure and manage identify and remediate devices at risk by using microsoft defender

Mitigate risk by using Exposure Management in Microsoft Defender XDR

Configure and manage mitigate risk by using exposure management in microsoft defender xdr

Plan a Microsoft Sentinel workspace

Configure and manage plan a microsoft sentinel workspace

Configure Microsoft Sentinel roles

Configure and manage configure microsoft sentinel roles

Specify Azure RBAC roles for Microsoft Sentinel configuration

Configure and manage specify azure rbac roles for microsoft sentinel configuration

Design and configure Microsoft Sentinel data storage, including log

Configure and manage design and configure microsoft sentinel data storage, including log

Identify data sources to be ingested for Microsoft Sentinel

Configure and manage identify data sources to be ingested for microsoft sentinel

Implement and use Content hub solutions

Configure and manage implement and use content hub solutions

Configure and use Microsoft connectors for Azure resources, including

Configure and manage configure and use microsoft connectors for azure resources, including

Plan and configure Syslog and Common Event Format (CEF) event

Configure and manage plan and configure syslog and common event format (cef) event

Plan and configure collection of Windows Security events by using data

Configure and manage plan and configure collection of windows security events by using data

Create custom log tables in the workspace to store ingested data

Configure and manage create custom log tables in the workspace to store ingested data

Monitor and optimize data ingestion

Configure and manage monitor and optimize data ingestion

Configure policies for Microsoft Defender for Cloud Apps

Configure and manage configure policies for microsoft defender for cloud apps

Configure policies for Microsoft Defender for Office 365

Configure and manage configure policies for microsoft defender for office 365

Configure security policies for Microsoft Defender for Endpoints,

Configure and manage configure security policies for microsoft defender for endpoints,

Configure cloud workload protections in Microsoft Defender for Cloud

Configure and manage configure cloud workload protections in microsoft defender for cloud

Configure and manage custom detection rules

Configure and manage configure and manage custom detection rules

Manage alerts, including tuning, suppression, and correlation

Configure and manage manage alerts, including tuning, suppression, and correlation

Configure deception rules in Microsoft Defender XDR

Configure and manage configure deception rules in microsoft defender xdr

Classify and analyze data by using entities

Configure and manage classify and analyze data by using entities

Configure and manage analytics rules

Configure and manage configure and manage analytics rules

Query Microsoft Sentinel data by using ASIM parsers

Configure and manage query microsoft sentinel data by using asim parsers

Implement behavioral analytics

Configure and manage implement behavioral analytics

Investigate and remediate threats by using Microsoft Defender for

Configure and manage investigate and remediate threats by using microsoft defender for

Investigate and remediate ransomware and business email compromise

Configure and manage investigate and remediate ransomware and business email compromise

Investigate and remediate compromised entities identified by Microsoft

Configure and manage investigate and remediate compromised entities identified by microsoft

Investigate and remediate threats identified by Microsoft Purview

Configure and manage investigate and remediate threats identified by microsoft purview

Investigate and remediate alerts and incidents identified by Microsoft

Configure and manage investigate and remediate alerts and incidents identified by microsoft

Investigate and remediate security risks identified by Microsoft

Configure and manage investigate and remediate security risks identified by microsoft

Investigate and remediate compromised identities that are identified

Configure and manage investigate and remediate compromised identities that are identified

Investigate and remediate security alerts from Microsoft Defender for

Configure and manage investigate and remediate security alerts from microsoft defender for

Investigate device timelines

Configure and manage investigate device timelines

Perform actions on the device, including live response and collecting

Configure and manage perform actions on the device, including live response and collecting

Perform evidence and entity investigation

Configure and manage perform evidence and entity investigation

Investigate threats by using the unified audit log

Configure and manage investigate threats by using the unified audit log

Investigate threats by using Content Search

Configure and manage investigate threats by using content search

Investigate threats by using Microsoft Graph activity logs

Configure and manage investigate threats by using microsoft graph activity logs

Investigate and remediate incidents in Microsoft Sentinel

Configure and manage investigate and remediate incidents in microsoft sentinel

Create and configure automation rules

Configure and manage create and configure automation rules

Create and configure Microsoft Sentinel playbooks

Configure and manage create and configure microsoft sentinel playbooks

Run playbooks on on-premises resources

Configure and manage run playbooks on on-premises resources

Create and use promptbooks

Configure and manage create and use promptbooks

Manage sources for Security Copilot, including plugins and files

Configure and manage manage sources for security copilot, including plugins and files

Integrate Security Copilot by implementing connectors

Configure and manage integrate security copilot by implementing connectors

Manage permissions and roles in Security Copilot

Configure and manage manage permissions and roles in security copilot

Monitor Security Copilot capacity and cost

Configure and manage monitor security copilot capacity and cost

Identify threats and risks by using Security Copilot

Configure and manage identify threats and risks by using security copilot

Investigate incidents by using Security Copilot

Configure and manage investigate incidents by using security copilot

Identify threats by using Kusto Query Language (KQL)

Configure and manage identify threats by using kusto query language (kql)

Interpret threat analytics in the Microsoft Defender portal

Configure and manage interpret threat analytics in the microsoft defender portal

Create custom hunting queries by using KQL

Configure and manage create custom hunting queries by using kql

Analyze attack vector coverage by using the MITRE ATT&CK matrix

Configure and manage analyze attack vector coverage by using the mitre att&ck matrix

Manage and use threat indicators

Configure and manage manage and use threat indicators

Create and manage hunts

Configure and manage create and manage hunts

Create and monitor hunting queries

Configure and manage create and monitor hunting queries

Use hunting bookmarks for data investigations

Configure and manage use hunting bookmarks for data investigations

Retrieve and manage archived log data

Configure and manage retrieve and manage archived log data

Create and manage search jobs

Configure and manage create and manage search jobs

Activate and customize workbook templates

Configure and manage activate and customize workbook templates

Create custom workbooks that include KQL

Configure and manage create custom workbooks that include kql

Configure visualizations

Configure and manage configure visualizations

2

Configure protections and detections

17%

Manage incident response (25–30%)

Configure and manage manage incident response (25–30%)

Manage security threats (15–20%)

Configure and manage manage security threats (15–20%)

Configure alert and vulnerability notification rules

Configure and manage configure alert and vulnerability notification rules

Configure Microsoft Defender for Endpoint advanced features

Configure and manage configure microsoft defender for endpoint advanced features

Configure endpoint rules settings

Configure and manage configure endpoint rules settings

Manage automated investigation and response capabilities in Microsoft

Configure and manage manage automated investigation and response capabilities in microsoft

Configure automatic attack disruption in Microsoft Defender XDR

Configure and manage configure automatic attack disruption in microsoft defender xdr

Configure and manage device groups, permissions, and automation levels

Configure and manage configure and manage device groups, permissions, and automation levels

Identify unmanaged devices in Microsoft Defender for Endpoint

Configure and manage identify unmanaged devices in microsoft defender for endpoint

Discover unprotected resources by using Defender for Cloud

Configure and manage discover unprotected resources by using defender for cloud

Identify and remediate devices at risk by using Microsoft Defender

Configure and manage identify and remediate devices at risk by using microsoft defender

Mitigate risk by using Exposure Management in Microsoft Defender XDR

Configure and manage mitigate risk by using exposure management in microsoft defender xdr

Plan a Microsoft Sentinel workspace

Configure and manage plan a microsoft sentinel workspace

Configure Microsoft Sentinel roles

Configure and manage configure microsoft sentinel roles

Specify Azure RBAC roles for Microsoft Sentinel configuration

Configure and manage specify azure rbac roles for microsoft sentinel configuration

Design and configure Microsoft Sentinel data storage, including log

Configure and manage design and configure microsoft sentinel data storage, including log

Identify data sources to be ingested for Microsoft Sentinel

Configure and manage identify data sources to be ingested for microsoft sentinel

Implement and use Content hub solutions

Configure and manage implement and use content hub solutions

Configure and use Microsoft connectors for Azure resources, including

Configure and manage configure and use microsoft connectors for azure resources, including

Plan and configure Syslog and Common Event Format (CEF) event

Configure and manage plan and configure syslog and common event format (cef) event

Plan and configure collection of Windows Security events by using data

Configure and manage plan and configure collection of windows security events by using data

Create custom log tables in the workspace to store ingested data

Configure and manage create custom log tables in the workspace to store ingested data

Monitor and optimize data ingestion

Configure and manage monitor and optimize data ingestion

Configure policies for Microsoft Defender for Cloud Apps

Configure and manage configure policies for microsoft defender for cloud apps

Configure policies for Microsoft Defender for Office 365

Configure and manage configure policies for microsoft defender for office 365

Configure security policies for Microsoft Defender for Endpoints,

Configure and manage configure security policies for microsoft defender for endpoints,

Configure cloud workload protections in Microsoft Defender for Cloud

Configure and manage configure cloud workload protections in microsoft defender for cloud

Configure and manage custom detection rules

Configure and manage configure and manage custom detection rules

Manage alerts, including tuning, suppression, and correlation

Configure and manage manage alerts, including tuning, suppression, and correlation

Configure deception rules in Microsoft Defender XDR

Configure and manage configure deception rules in microsoft defender xdr

Classify and analyze data by using entities

Configure and manage classify and analyze data by using entities

Configure and manage analytics rules

Configure and manage configure and manage analytics rules

Query Microsoft Sentinel data by using ASIM parsers

Configure and manage query microsoft sentinel data by using asim parsers

Implement behavioral analytics

Configure and manage implement behavioral analytics

Investigate and remediate threats by using Microsoft Defender for

Configure and manage investigate and remediate threats by using microsoft defender for

Investigate and remediate ransomware and business email compromise

Configure and manage investigate and remediate ransomware and business email compromise

Investigate and remediate compromised entities identified by Microsoft

Configure and manage investigate and remediate compromised entities identified by microsoft

Investigate and remediate threats identified by Microsoft Purview

Configure and manage investigate and remediate threats identified by microsoft purview

Investigate and remediate alerts and incidents identified by Microsoft

Configure and manage investigate and remediate alerts and incidents identified by microsoft

Investigate and remediate security risks identified by Microsoft

Configure and manage investigate and remediate security risks identified by microsoft

Investigate and remediate compromised identities that are identified

Configure and manage investigate and remediate compromised identities that are identified

Investigate and remediate security alerts from Microsoft Defender for

Configure and manage investigate and remediate security alerts from microsoft defender for

Investigate device timelines

Configure and manage investigate device timelines

Perform actions on the device, including live response and collecting

Configure and manage perform actions on the device, including live response and collecting

Perform evidence and entity investigation

Configure and manage perform evidence and entity investigation

Investigate threats by using the unified audit log

Configure and manage investigate threats by using the unified audit log

Investigate threats by using Content Search

Configure and manage investigate threats by using content search

Investigate threats by using Microsoft Graph activity logs

Configure and manage investigate threats by using microsoft graph activity logs

Investigate and remediate incidents in Microsoft Sentinel

Configure and manage investigate and remediate incidents in microsoft sentinel

Create and configure automation rules

Configure and manage create and configure automation rules

Create and configure Microsoft Sentinel playbooks

Configure and manage create and configure microsoft sentinel playbooks

Run playbooks on on-premises resources

Configure and manage run playbooks on on-premises resources

Create and use promptbooks

Configure and manage create and use promptbooks

Manage sources for Security Copilot, including plugins and files

Configure and manage manage sources for security copilot, including plugins and files

Integrate Security Copilot by implementing connectors

Configure and manage integrate security copilot by implementing connectors

Manage permissions and roles in Security Copilot

Configure and manage manage permissions and roles in security copilot

Monitor Security Copilot capacity and cost

Configure and manage monitor security copilot capacity and cost

Identify threats and risks by using Security Copilot

Configure and manage identify threats and risks by using security copilot

Investigate incidents by using Security Copilot

Configure and manage investigate incidents by using security copilot

Identify threats by using Kusto Query Language (KQL)

Configure and manage identify threats by using kusto query language (kql)

Interpret threat analytics in the Microsoft Defender portal

Configure and manage interpret threat analytics in the microsoft defender portal

Create custom hunting queries by using KQL

Configure and manage create custom hunting queries by using kql

Analyze attack vector coverage by using the MITRE ATT&CK matrix

Configure and manage analyze attack vector coverage by using the mitre att&ck matrix

Manage and use threat indicators

Configure and manage manage and use threat indicators

Create and manage hunts

Configure and manage create and manage hunts

Create and monitor hunting queries

Configure and manage create and monitor hunting queries

Use hunting bookmarks for data investigations

Configure and manage use hunting bookmarks for data investigations

Retrieve and manage archived log data

Configure and manage retrieve and manage archived log data

Create and manage search jobs

Configure and manage create and manage search jobs

Activate and customize workbook templates

Configure and manage activate and customize workbook templates

Create custom workbooks that include KQL

Configure and manage create custom workbooks that include kql

Configure visualizations

Configure and manage configure visualizations

3

Manage incident response

27%

Manage security threats (15–20%)

Configure and manage manage security threats (15–20%)

Configure alert and vulnerability notification rules

Configure and manage configure alert and vulnerability notification rules

Configure Microsoft Defender for Endpoint advanced features

Configure and manage configure microsoft defender for endpoint advanced features

Configure endpoint rules settings

Configure and manage configure endpoint rules settings

Manage automated investigation and response capabilities in Microsoft

Configure and manage manage automated investigation and response capabilities in microsoft

Configure automatic attack disruption in Microsoft Defender XDR

Configure and manage configure automatic attack disruption in microsoft defender xdr

Configure and manage device groups, permissions, and automation levels

Configure and manage configure and manage device groups, permissions, and automation levels

Identify unmanaged devices in Microsoft Defender for Endpoint

Configure and manage identify unmanaged devices in microsoft defender for endpoint

Discover unprotected resources by using Defender for Cloud

Configure and manage discover unprotected resources by using defender for cloud

Identify and remediate devices at risk by using Microsoft Defender

Configure and manage identify and remediate devices at risk by using microsoft defender

Mitigate risk by using Exposure Management in Microsoft Defender XDR

Configure and manage mitigate risk by using exposure management in microsoft defender xdr

Plan a Microsoft Sentinel workspace

Configure and manage plan a microsoft sentinel workspace

Configure Microsoft Sentinel roles

Configure and manage configure microsoft sentinel roles

Specify Azure RBAC roles for Microsoft Sentinel configuration

Configure and manage specify azure rbac roles for microsoft sentinel configuration

Design and configure Microsoft Sentinel data storage, including log

Configure and manage design and configure microsoft sentinel data storage, including log

Identify data sources to be ingested for Microsoft Sentinel

Configure and manage identify data sources to be ingested for microsoft sentinel

Implement and use Content hub solutions

Configure and manage implement and use content hub solutions

Configure and use Microsoft connectors for Azure resources, including

Configure and manage configure and use microsoft connectors for azure resources, including

Plan and configure Syslog and Common Event Format (CEF) event

Configure and manage plan and configure syslog and common event format (cef) event

Plan and configure collection of Windows Security events by using data

Configure and manage plan and configure collection of windows security events by using data

Create custom log tables in the workspace to store ingested data

Configure and manage create custom log tables in the workspace to store ingested data

Monitor and optimize data ingestion

Configure and manage monitor and optimize data ingestion

Configure policies for Microsoft Defender for Cloud Apps

Configure and manage configure policies for microsoft defender for cloud apps

Configure policies for Microsoft Defender for Office 365

Configure and manage configure policies for microsoft defender for office 365

Configure security policies for Microsoft Defender for Endpoints,

Configure and manage configure security policies for microsoft defender for endpoints,

Configure cloud workload protections in Microsoft Defender for Cloud

Configure and manage configure cloud workload protections in microsoft defender for cloud

Configure and manage custom detection rules

Configure and manage configure and manage custom detection rules

Manage alerts, including tuning, suppression, and correlation

Configure and manage manage alerts, including tuning, suppression, and correlation

Configure deception rules in Microsoft Defender XDR

Configure and manage configure deception rules in microsoft defender xdr

Classify and analyze data by using entities

Configure and manage classify and analyze data by using entities

Configure and manage analytics rules

Configure and manage configure and manage analytics rules

Query Microsoft Sentinel data by using ASIM parsers

Configure and manage query microsoft sentinel data by using asim parsers

Implement behavioral analytics

Configure and manage implement behavioral analytics

Investigate and remediate threats by using Microsoft Defender for

Configure and manage investigate and remediate threats by using microsoft defender for

Investigate and remediate ransomware and business email compromise

Configure and manage investigate and remediate ransomware and business email compromise

Investigate and remediate compromised entities identified by Microsoft

Configure and manage investigate and remediate compromised entities identified by microsoft

Investigate and remediate threats identified by Microsoft Purview

Configure and manage investigate and remediate threats identified by microsoft purview

Investigate and remediate alerts and incidents identified by Microsoft

Configure and manage investigate and remediate alerts and incidents identified by microsoft

Investigate and remediate security risks identified by Microsoft

Configure and manage investigate and remediate security risks identified by microsoft

Investigate and remediate compromised identities that are identified

Configure and manage investigate and remediate compromised identities that are identified

Investigate and remediate security alerts from Microsoft Defender for

Configure and manage investigate and remediate security alerts from microsoft defender for

Investigate device timelines

Configure and manage investigate device timelines

Perform actions on the device, including live response and collecting

Configure and manage perform actions on the device, including live response and collecting

Perform evidence and entity investigation

Configure and manage perform evidence and entity investigation

Investigate threats by using the unified audit log

Configure and manage investigate threats by using the unified audit log

Investigate threats by using Content Search

Configure and manage investigate threats by using content search

Investigate threats by using Microsoft Graph activity logs

Configure and manage investigate threats by using microsoft graph activity logs

Investigate and remediate incidents in Microsoft Sentinel

Configure and manage investigate and remediate incidents in microsoft sentinel

Create and configure automation rules

Configure and manage create and configure automation rules

Create and configure Microsoft Sentinel playbooks

Configure and manage create and configure microsoft sentinel playbooks

Run playbooks on on-premises resources

Configure and manage run playbooks on on-premises resources

Create and use promptbooks

Configure and manage create and use promptbooks

Manage sources for Security Copilot, including plugins and files

Configure and manage manage sources for security copilot, including plugins and files

Integrate Security Copilot by implementing connectors

Configure and manage integrate security copilot by implementing connectors

Manage permissions and roles in Security Copilot

Configure and manage manage permissions and roles in security copilot

Monitor Security Copilot capacity and cost

Configure and manage monitor security copilot capacity and cost

Identify threats and risks by using Security Copilot

Configure and manage identify threats and risks by using security copilot

Investigate incidents by using Security Copilot

Configure and manage investigate incidents by using security copilot

Identify threats by using Kusto Query Language (KQL)

Configure and manage identify threats by using kusto query language (kql)

Interpret threat analytics in the Microsoft Defender portal

Configure and manage interpret threat analytics in the microsoft defender portal

Create custom hunting queries by using KQL

Configure and manage create custom hunting queries by using kql

Analyze attack vector coverage by using the MITRE ATT&CK matrix

Configure and manage analyze attack vector coverage by using the mitre att&ck matrix

Manage and use threat indicators

Configure and manage manage and use threat indicators

Create and manage hunts

Configure and manage create and manage hunts

Create and monitor hunting queries

Configure and manage create and monitor hunting queries

Use hunting bookmarks for data investigations

Configure and manage use hunting bookmarks for data investigations

Retrieve and manage archived log data

Configure and manage retrieve and manage archived log data

Create and manage search jobs

Configure and manage create and manage search jobs

Activate and customize workbook templates

Configure and manage activate and customize workbook templates

Create custom workbooks that include KQL

Configure and manage create custom workbooks that include kql

Configure visualizations

Configure and manage configure visualizations

4

Manage security threats

17%

Configure alert and vulnerability notification rules

Configure and manage configure alert and vulnerability notification rules

Configure Microsoft Defender for Endpoint advanced features

Configure and manage configure microsoft defender for endpoint advanced features

Configure endpoint rules settings

Configure and manage configure endpoint rules settings

Manage automated investigation and response capabilities in Microsoft

Configure and manage manage automated investigation and response capabilities in microsoft

Configure automatic attack disruption in Microsoft Defender XDR

Configure and manage configure automatic attack disruption in microsoft defender xdr

Configure and manage device groups, permissions, and automation levels

Configure and manage configure and manage device groups, permissions, and automation levels

Identify unmanaged devices in Microsoft Defender for Endpoint

Configure and manage identify unmanaged devices in microsoft defender for endpoint

Discover unprotected resources by using Defender for Cloud

Configure and manage discover unprotected resources by using defender for cloud

Identify and remediate devices at risk by using Microsoft Defender

Configure and manage identify and remediate devices at risk by using microsoft defender

Mitigate risk by using Exposure Management in Microsoft Defender XDR

Configure and manage mitigate risk by using exposure management in microsoft defender xdr

Plan a Microsoft Sentinel workspace

Configure and manage plan a microsoft sentinel workspace

Configure Microsoft Sentinel roles

Configure and manage configure microsoft sentinel roles

Specify Azure RBAC roles for Microsoft Sentinel configuration

Configure and manage specify azure rbac roles for microsoft sentinel configuration

Design and configure Microsoft Sentinel data storage, including log

Configure and manage design and configure microsoft sentinel data storage, including log

Identify data sources to be ingested for Microsoft Sentinel

Configure and manage identify data sources to be ingested for microsoft sentinel

Implement and use Content hub solutions

Configure and manage implement and use content hub solutions

Configure and use Microsoft connectors for Azure resources, including

Configure and manage configure and use microsoft connectors for azure resources, including

Plan and configure Syslog and Common Event Format (CEF) event

Configure and manage plan and configure syslog and common event format (cef) event

Plan and configure collection of Windows Security events by using data

Configure and manage plan and configure collection of windows security events by using data

Create custom log tables in the workspace to store ingested data

Configure and manage create custom log tables in the workspace to store ingested data

Monitor and optimize data ingestion

Configure and manage monitor and optimize data ingestion

Configure policies for Microsoft Defender for Cloud Apps

Configure and manage configure policies for microsoft defender for cloud apps

Configure policies for Microsoft Defender for Office 365

Configure and manage configure policies for microsoft defender for office 365

Configure security policies for Microsoft Defender for Endpoints,

Configure and manage configure security policies for microsoft defender for endpoints,

Configure cloud workload protections in Microsoft Defender for Cloud

Configure and manage configure cloud workload protections in microsoft defender for cloud

Configure and manage custom detection rules

Configure and manage configure and manage custom detection rules

Manage alerts, including tuning, suppression, and correlation

Configure and manage manage alerts, including tuning, suppression, and correlation

Configure deception rules in Microsoft Defender XDR

Configure and manage configure deception rules in microsoft defender xdr

Classify and analyze data by using entities

Configure and manage classify and analyze data by using entities

Configure and manage analytics rules

Configure and manage configure and manage analytics rules

Query Microsoft Sentinel data by using ASIM parsers

Configure and manage query microsoft sentinel data by using asim parsers

Implement behavioral analytics

Configure and manage implement behavioral analytics

Investigate and remediate threats by using Microsoft Defender for

Configure and manage investigate and remediate threats by using microsoft defender for

Investigate and remediate ransomware and business email compromise

Configure and manage investigate and remediate ransomware and business email compromise

Investigate and remediate compromised entities identified by Microsoft

Configure and manage investigate and remediate compromised entities identified by microsoft

Investigate and remediate threats identified by Microsoft Purview

Configure and manage investigate and remediate threats identified by microsoft purview

Investigate and remediate alerts and incidents identified by Microsoft

Configure and manage investigate and remediate alerts and incidents identified by microsoft

Investigate and remediate security risks identified by Microsoft

Configure and manage investigate and remediate security risks identified by microsoft

Investigate and remediate compromised identities that are identified

Configure and manage investigate and remediate compromised identities that are identified

Investigate and remediate security alerts from Microsoft Defender for

Configure and manage investigate and remediate security alerts from microsoft defender for

Investigate device timelines

Configure and manage investigate device timelines

Perform actions on the device, including live response and collecting

Configure and manage perform actions on the device, including live response and collecting

Perform evidence and entity investigation

Configure and manage perform evidence and entity investigation

Investigate threats by using the unified audit log

Configure and manage investigate threats by using the unified audit log

Investigate threats by using Content Search

Configure and manage investigate threats by using content search

Investigate threats by using Microsoft Graph activity logs

Configure and manage investigate threats by using microsoft graph activity logs

Investigate and remediate incidents in Microsoft Sentinel

Configure and manage investigate and remediate incidents in microsoft sentinel

Create and configure automation rules

Configure and manage create and configure automation rules

Create and configure Microsoft Sentinel playbooks

Configure and manage create and configure microsoft sentinel playbooks

Run playbooks on on-premises resources

Configure and manage run playbooks on on-premises resources

Create and use promptbooks

Configure and manage create and use promptbooks

Manage sources for Security Copilot, including plugins and files

Configure and manage manage sources for security copilot, including plugins and files

Integrate Security Copilot by implementing connectors

Configure and manage integrate security copilot by implementing connectors

Manage permissions and roles in Security Copilot

Configure and manage manage permissions and roles in security copilot

Monitor Security Copilot capacity and cost

Configure and manage monitor security copilot capacity and cost

Identify threats and risks by using Security Copilot

Configure and manage identify threats and risks by using security copilot

Investigate incidents by using Security Copilot

Configure and manage investigate incidents by using security copilot

Identify threats by using Kusto Query Language (KQL)

Configure and manage identify threats by using kusto query language (kql)

Interpret threat analytics in the Microsoft Defender portal

Configure and manage interpret threat analytics in the microsoft defender portal

Create custom hunting queries by using KQL

Configure and manage create custom hunting queries by using kql

Analyze attack vector coverage by using the MITRE ATT&CK matrix

Configure and manage analyze attack vector coverage by using the mitre att&ck matrix

Manage and use threat indicators

Configure and manage manage and use threat indicators

Create and manage hunts

Configure and manage create and manage hunts

Create and monitor hunting queries

Configure and manage create and monitor hunting queries

Use hunting bookmarks for data investigations

Configure and manage use hunting bookmarks for data investigations

Retrieve and manage archived log data

Configure and manage retrieve and manage archived log data

Create and manage search jobs

Configure and manage create and manage search jobs

Activate and customize workbook templates

Configure and manage activate and customize workbook templates

Create custom workbooks that include KQL

Configure and manage create custom workbooks that include kql

Configure visualizations

Configure and manage configure visualizations

How to study for this exam?

The most effective way to prepare for SC-200 is by using the PlanetCert Simulator to practice questions and review detailed explanations.

Practice with Precision

The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.

Launch Simulator

What's changed on this exam?

Current Status
  • ACTIVE
  • Last content update: 2024-07-15
Updates
Microsoft Sentinel Latest New SOAR capabilities likely in next update • Release date: 2024-08-01

Who should take this exam?

  • Experience with Microsoft 365 security
  • Knowledge of Microsoft Sentinel and KQL
  • Understanding of threat detection and response
  • Familiarity with security operations concepts

Your Complete Exam Solution

Best-In-Class Practice Tests

Authentic, regularly updated questions that mirror the real exam. Verified, current material — not recycled dumps.

Topical Breakdown

Study by domain, pinpoint weak areas, and focus your time where it matters most. Every topic mapped to the official syllabus.

Flashcard Mode

Rapid-fire review to reinforce key concepts. Flip through questions and answers at your own pace before exam day.

See How You Compare Against Yourself

✕
✕
✕

Other Exam Prep

  • Outdated question dumpsRecycled, often inaccurate material
  • No explanationsMemorize answers without understanding
  • Static PDF filesNo interactive practice or feedback
  • Subscription feesRecurring charges, access expires
✓
✓
✓

PlanetCert

  • Verified, current questionsUpdated weekly to match live exam objectives
  • Expert-written rationalesUnderstand every concept, not just the answer
  • Session tracking & exam progressTrack every attempt, see your growth over time
  • Lifetime access, one pricePay once — updates included forever
CERTIFIEDSC-200

Study Naturally, Study Responsibly

Join thousands of certified professionals who trusted PlanetCert to pass on the first attempt.

Try Free Demo
Secure Checkout Lifetime Access Money-back Guarantee