Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Microsoft
Exam Format
Registration
Validity
SC-200 Exam Topics and Domains
SC-200 is organized into 4 weighted domains.
Manage a security operations environment
Configure protections and detections (15–20%)
Configure and manage configure protections and detections (15–20%)
Manage incident response (25–30%)
Configure and manage manage incident response (25–30%)
Manage security threats (15–20%)
Configure and manage manage security threats (15–20%)
Configure alert and vulnerability notification rules
Configure and manage configure alert and vulnerability notification rules
Configure Microsoft Defender for Endpoint advanced features
Configure and manage configure microsoft defender for endpoint advanced features
Configure endpoint rules settings
Configure and manage configure endpoint rules settings
Manage automated investigation and response capabilities in Microsoft
Configure and manage manage automated investigation and response capabilities in microsoft
Configure automatic attack disruption in Microsoft Defender XDR
Configure and manage configure automatic attack disruption in microsoft defender xdr
Configure and manage device groups, permissions, and automation levels
Configure and manage configure and manage device groups, permissions, and automation levels
Identify unmanaged devices in Microsoft Defender for Endpoint
Configure and manage identify unmanaged devices in microsoft defender for endpoint
Discover unprotected resources by using Defender for Cloud
Configure and manage discover unprotected resources by using defender for cloud
Identify and remediate devices at risk by using Microsoft Defender
Configure and manage identify and remediate devices at risk by using microsoft defender
Mitigate risk by using Exposure Management in Microsoft Defender XDR
Configure and manage mitigate risk by using exposure management in microsoft defender xdr
Plan a Microsoft Sentinel workspace
Configure and manage plan a microsoft sentinel workspace
Configure Microsoft Sentinel roles
Configure and manage configure microsoft sentinel roles
Specify Azure RBAC roles for Microsoft Sentinel configuration
Configure and manage specify azure rbac roles for microsoft sentinel configuration
Design and configure Microsoft Sentinel data storage, including log
Configure and manage design and configure microsoft sentinel data storage, including log
Identify data sources to be ingested for Microsoft Sentinel
Configure and manage identify data sources to be ingested for microsoft sentinel
Implement and use Content hub solutions
Configure and manage implement and use content hub solutions
Configure and use Microsoft connectors for Azure resources, including
Configure and manage configure and use microsoft connectors for azure resources, including
Plan and configure Syslog and Common Event Format (CEF) event
Configure and manage plan and configure syslog and common event format (cef) event
Plan and configure collection of Windows Security events by using data
Configure and manage plan and configure collection of windows security events by using data
Create custom log tables in the workspace to store ingested data
Configure and manage create custom log tables in the workspace to store ingested data
Monitor and optimize data ingestion
Configure and manage monitor and optimize data ingestion
Configure policies for Microsoft Defender for Cloud Apps
Configure and manage configure policies for microsoft defender for cloud apps
Configure policies for Microsoft Defender for Office 365
Configure and manage configure policies for microsoft defender for office 365
Configure security policies for Microsoft Defender for Endpoints,
Configure and manage configure security policies for microsoft defender for endpoints,
Configure cloud workload protections in Microsoft Defender for Cloud
Configure and manage configure cloud workload protections in microsoft defender for cloud
Configure and manage custom detection rules
Configure and manage configure and manage custom detection rules
Manage alerts, including tuning, suppression, and correlation
Configure and manage manage alerts, including tuning, suppression, and correlation
Configure deception rules in Microsoft Defender XDR
Configure and manage configure deception rules in microsoft defender xdr
Classify and analyze data by using entities
Configure and manage classify and analyze data by using entities
Configure and manage analytics rules
Configure and manage configure and manage analytics rules
Query Microsoft Sentinel data by using ASIM parsers
Configure and manage query microsoft sentinel data by using asim parsers
Implement behavioral analytics
Configure and manage implement behavioral analytics
Investigate and remediate threats by using Microsoft Defender for
Configure and manage investigate and remediate threats by using microsoft defender for
Investigate and remediate ransomware and business email compromise
Configure and manage investigate and remediate ransomware and business email compromise
Investigate and remediate compromised entities identified by Microsoft
Configure and manage investigate and remediate compromised entities identified by microsoft
Investigate and remediate threats identified by Microsoft Purview
Configure and manage investigate and remediate threats identified by microsoft purview
Investigate and remediate alerts and incidents identified by Microsoft
Configure and manage investigate and remediate alerts and incidents identified by microsoft
Investigate and remediate security risks identified by Microsoft
Configure and manage investigate and remediate security risks identified by microsoft
Investigate and remediate compromised identities that are identified
Configure and manage investigate and remediate compromised identities that are identified
Investigate and remediate security alerts from Microsoft Defender for
Configure and manage investigate and remediate security alerts from microsoft defender for
Investigate device timelines
Configure and manage investigate device timelines
Perform actions on the device, including live response and collecting
Configure and manage perform actions on the device, including live response and collecting
Perform evidence and entity investigation
Configure and manage perform evidence and entity investigation
Investigate threats by using the unified audit log
Configure and manage investigate threats by using the unified audit log
Investigate threats by using Content Search
Configure and manage investigate threats by using content search
Investigate threats by using Microsoft Graph activity logs
Configure and manage investigate threats by using microsoft graph activity logs
Investigate and remediate incidents in Microsoft Sentinel
Configure and manage investigate and remediate incidents in microsoft sentinel
Create and configure automation rules
Configure and manage create and configure automation rules
Create and configure Microsoft Sentinel playbooks
Configure and manage create and configure microsoft sentinel playbooks
Run playbooks on on-premises resources
Configure and manage run playbooks on on-premises resources
Create and use promptbooks
Configure and manage create and use promptbooks
Manage sources for Security Copilot, including plugins and files
Configure and manage manage sources for security copilot, including plugins and files
Integrate Security Copilot by implementing connectors
Configure and manage integrate security copilot by implementing connectors
Manage permissions and roles in Security Copilot
Configure and manage manage permissions and roles in security copilot
Monitor Security Copilot capacity and cost
Configure and manage monitor security copilot capacity and cost
Identify threats and risks by using Security Copilot
Configure and manage identify threats and risks by using security copilot
Investigate incidents by using Security Copilot
Configure and manage investigate incidents by using security copilot
Identify threats by using Kusto Query Language (KQL)
Configure and manage identify threats by using kusto query language (kql)
Interpret threat analytics in the Microsoft Defender portal
Configure and manage interpret threat analytics in the microsoft defender portal
Create custom hunting queries by using KQL
Configure and manage create custom hunting queries by using kql
Analyze attack vector coverage by using the MITRE ATT&CK matrix
Configure and manage analyze attack vector coverage by using the mitre att&ck matrix
Manage and use threat indicators
Configure and manage manage and use threat indicators
Create and manage hunts
Configure and manage create and manage hunts
Create and monitor hunting queries
Configure and manage create and monitor hunting queries
Use hunting bookmarks for data investigations
Configure and manage use hunting bookmarks for data investigations
Retrieve and manage archived log data
Configure and manage retrieve and manage archived log data
Create and manage search jobs
Configure and manage create and manage search jobs
Activate and customize workbook templates
Configure and manage activate and customize workbook templates
Create custom workbooks that include KQL
Configure and manage create custom workbooks that include kql
Configure visualizations
Configure and manage configure visualizations
Configure protections and detections
Manage incident response (25–30%)
Configure and manage manage incident response (25–30%)
Manage security threats (15–20%)
Configure and manage manage security threats (15–20%)
Configure alert and vulnerability notification rules
Configure and manage configure alert and vulnerability notification rules
Configure Microsoft Defender for Endpoint advanced features
Configure and manage configure microsoft defender for endpoint advanced features
Configure endpoint rules settings
Configure and manage configure endpoint rules settings
Manage automated investigation and response capabilities in Microsoft
Configure and manage manage automated investigation and response capabilities in microsoft
Configure automatic attack disruption in Microsoft Defender XDR
Configure and manage configure automatic attack disruption in microsoft defender xdr
Configure and manage device groups, permissions, and automation levels
Configure and manage configure and manage device groups, permissions, and automation levels
Identify unmanaged devices in Microsoft Defender for Endpoint
Configure and manage identify unmanaged devices in microsoft defender for endpoint
Discover unprotected resources by using Defender for Cloud
Configure and manage discover unprotected resources by using defender for cloud
Identify and remediate devices at risk by using Microsoft Defender
Configure and manage identify and remediate devices at risk by using microsoft defender
Mitigate risk by using Exposure Management in Microsoft Defender XDR
Configure and manage mitigate risk by using exposure management in microsoft defender xdr
Plan a Microsoft Sentinel workspace
Configure and manage plan a microsoft sentinel workspace
Configure Microsoft Sentinel roles
Configure and manage configure microsoft sentinel roles
Specify Azure RBAC roles for Microsoft Sentinel configuration
Configure and manage specify azure rbac roles for microsoft sentinel configuration
Design and configure Microsoft Sentinel data storage, including log
Configure and manage design and configure microsoft sentinel data storage, including log
Identify data sources to be ingested for Microsoft Sentinel
Configure and manage identify data sources to be ingested for microsoft sentinel
Implement and use Content hub solutions
Configure and manage implement and use content hub solutions
Configure and use Microsoft connectors for Azure resources, including
Configure and manage configure and use microsoft connectors for azure resources, including
Plan and configure Syslog and Common Event Format (CEF) event
Configure and manage plan and configure syslog and common event format (cef) event
Plan and configure collection of Windows Security events by using data
Configure and manage plan and configure collection of windows security events by using data
Create custom log tables in the workspace to store ingested data
Configure and manage create custom log tables in the workspace to store ingested data
Monitor and optimize data ingestion
Configure and manage monitor and optimize data ingestion
Configure policies for Microsoft Defender for Cloud Apps
Configure and manage configure policies for microsoft defender for cloud apps
Configure policies for Microsoft Defender for Office 365
Configure and manage configure policies for microsoft defender for office 365
Configure security policies for Microsoft Defender for Endpoints,
Configure and manage configure security policies for microsoft defender for endpoints,
Configure cloud workload protections in Microsoft Defender for Cloud
Configure and manage configure cloud workload protections in microsoft defender for cloud
Configure and manage custom detection rules
Configure and manage configure and manage custom detection rules
Manage alerts, including tuning, suppression, and correlation
Configure and manage manage alerts, including tuning, suppression, and correlation
Configure deception rules in Microsoft Defender XDR
Configure and manage configure deception rules in microsoft defender xdr
Classify and analyze data by using entities
Configure and manage classify and analyze data by using entities
Configure and manage analytics rules
Configure and manage configure and manage analytics rules
Query Microsoft Sentinel data by using ASIM parsers
Configure and manage query microsoft sentinel data by using asim parsers
Implement behavioral analytics
Configure and manage implement behavioral analytics
Investigate and remediate threats by using Microsoft Defender for
Configure and manage investigate and remediate threats by using microsoft defender for
Investigate and remediate ransomware and business email compromise
Configure and manage investigate and remediate ransomware and business email compromise
Investigate and remediate compromised entities identified by Microsoft
Configure and manage investigate and remediate compromised entities identified by microsoft
Investigate and remediate threats identified by Microsoft Purview
Configure and manage investigate and remediate threats identified by microsoft purview
Investigate and remediate alerts and incidents identified by Microsoft
Configure and manage investigate and remediate alerts and incidents identified by microsoft
Investigate and remediate security risks identified by Microsoft
Configure and manage investigate and remediate security risks identified by microsoft
Investigate and remediate compromised identities that are identified
Configure and manage investigate and remediate compromised identities that are identified
Investigate and remediate security alerts from Microsoft Defender for
Configure and manage investigate and remediate security alerts from microsoft defender for
Investigate device timelines
Configure and manage investigate device timelines
Perform actions on the device, including live response and collecting
Configure and manage perform actions on the device, including live response and collecting
Perform evidence and entity investigation
Configure and manage perform evidence and entity investigation
Investigate threats by using the unified audit log
Configure and manage investigate threats by using the unified audit log
Investigate threats by using Content Search
Configure and manage investigate threats by using content search
Investigate threats by using Microsoft Graph activity logs
Configure and manage investigate threats by using microsoft graph activity logs
Investigate and remediate incidents in Microsoft Sentinel
Configure and manage investigate and remediate incidents in microsoft sentinel
Create and configure automation rules
Configure and manage create and configure automation rules
Create and configure Microsoft Sentinel playbooks
Configure and manage create and configure microsoft sentinel playbooks
Run playbooks on on-premises resources
Configure and manage run playbooks on on-premises resources
Create and use promptbooks
Configure and manage create and use promptbooks
Manage sources for Security Copilot, including plugins and files
Configure and manage manage sources for security copilot, including plugins and files
Integrate Security Copilot by implementing connectors
Configure and manage integrate security copilot by implementing connectors
Manage permissions and roles in Security Copilot
Configure and manage manage permissions and roles in security copilot
Monitor Security Copilot capacity and cost
Configure and manage monitor security copilot capacity and cost
Identify threats and risks by using Security Copilot
Configure and manage identify threats and risks by using security copilot
Investigate incidents by using Security Copilot
Configure and manage investigate incidents by using security copilot
Identify threats by using Kusto Query Language (KQL)
Configure and manage identify threats by using kusto query language (kql)
Interpret threat analytics in the Microsoft Defender portal
Configure and manage interpret threat analytics in the microsoft defender portal
Create custom hunting queries by using KQL
Configure and manage create custom hunting queries by using kql
Analyze attack vector coverage by using the MITRE ATT&CK matrix
Configure and manage analyze attack vector coverage by using the mitre att&ck matrix
Manage and use threat indicators
Configure and manage manage and use threat indicators
Create and manage hunts
Configure and manage create and manage hunts
Create and monitor hunting queries
Configure and manage create and monitor hunting queries
Use hunting bookmarks for data investigations
Configure and manage use hunting bookmarks for data investigations
Retrieve and manage archived log data
Configure and manage retrieve and manage archived log data
Create and manage search jobs
Configure and manage create and manage search jobs
Activate and customize workbook templates
Configure and manage activate and customize workbook templates
Create custom workbooks that include KQL
Configure and manage create custom workbooks that include kql
Configure visualizations
Configure and manage configure visualizations
Manage incident response
Manage security threats (15–20%)
Configure and manage manage security threats (15–20%)
Configure alert and vulnerability notification rules
Configure and manage configure alert and vulnerability notification rules
Configure Microsoft Defender for Endpoint advanced features
Configure and manage configure microsoft defender for endpoint advanced features
Configure endpoint rules settings
Configure and manage configure endpoint rules settings
Manage automated investigation and response capabilities in Microsoft
Configure and manage manage automated investigation and response capabilities in microsoft
Configure automatic attack disruption in Microsoft Defender XDR
Configure and manage configure automatic attack disruption in microsoft defender xdr
Configure and manage device groups, permissions, and automation levels
Configure and manage configure and manage device groups, permissions, and automation levels
Identify unmanaged devices in Microsoft Defender for Endpoint
Configure and manage identify unmanaged devices in microsoft defender for endpoint
Discover unprotected resources by using Defender for Cloud
Configure and manage discover unprotected resources by using defender for cloud
Identify and remediate devices at risk by using Microsoft Defender
Configure and manage identify and remediate devices at risk by using microsoft defender
Mitigate risk by using Exposure Management in Microsoft Defender XDR
Configure and manage mitigate risk by using exposure management in microsoft defender xdr
Plan a Microsoft Sentinel workspace
Configure and manage plan a microsoft sentinel workspace
Configure Microsoft Sentinel roles
Configure and manage configure microsoft sentinel roles
Specify Azure RBAC roles for Microsoft Sentinel configuration
Configure and manage specify azure rbac roles for microsoft sentinel configuration
Design and configure Microsoft Sentinel data storage, including log
Configure and manage design and configure microsoft sentinel data storage, including log
Identify data sources to be ingested for Microsoft Sentinel
Configure and manage identify data sources to be ingested for microsoft sentinel
Implement and use Content hub solutions
Configure and manage implement and use content hub solutions
Configure and use Microsoft connectors for Azure resources, including
Configure and manage configure and use microsoft connectors for azure resources, including
Plan and configure Syslog and Common Event Format (CEF) event
Configure and manage plan and configure syslog and common event format (cef) event
Plan and configure collection of Windows Security events by using data
Configure and manage plan and configure collection of windows security events by using data
Create custom log tables in the workspace to store ingested data
Configure and manage create custom log tables in the workspace to store ingested data
Monitor and optimize data ingestion
Configure and manage monitor and optimize data ingestion
Configure policies for Microsoft Defender for Cloud Apps
Configure and manage configure policies for microsoft defender for cloud apps
Configure policies for Microsoft Defender for Office 365
Configure and manage configure policies for microsoft defender for office 365
Configure security policies for Microsoft Defender for Endpoints,
Configure and manage configure security policies for microsoft defender for endpoints,
Configure cloud workload protections in Microsoft Defender for Cloud
Configure and manage configure cloud workload protections in microsoft defender for cloud
Configure and manage custom detection rules
Configure and manage configure and manage custom detection rules
Manage alerts, including tuning, suppression, and correlation
Configure and manage manage alerts, including tuning, suppression, and correlation
Configure deception rules in Microsoft Defender XDR
Configure and manage configure deception rules in microsoft defender xdr
Classify and analyze data by using entities
Configure and manage classify and analyze data by using entities
Configure and manage analytics rules
Configure and manage configure and manage analytics rules
Query Microsoft Sentinel data by using ASIM parsers
Configure and manage query microsoft sentinel data by using asim parsers
Implement behavioral analytics
Configure and manage implement behavioral analytics
Investigate and remediate threats by using Microsoft Defender for
Configure and manage investigate and remediate threats by using microsoft defender for
Investigate and remediate ransomware and business email compromise
Configure and manage investigate and remediate ransomware and business email compromise
Investigate and remediate compromised entities identified by Microsoft
Configure and manage investigate and remediate compromised entities identified by microsoft
Investigate and remediate threats identified by Microsoft Purview
Configure and manage investigate and remediate threats identified by microsoft purview
Investigate and remediate alerts and incidents identified by Microsoft
Configure and manage investigate and remediate alerts and incidents identified by microsoft
Investigate and remediate security risks identified by Microsoft
Configure and manage investigate and remediate security risks identified by microsoft
Investigate and remediate compromised identities that are identified
Configure and manage investigate and remediate compromised identities that are identified
Investigate and remediate security alerts from Microsoft Defender for
Configure and manage investigate and remediate security alerts from microsoft defender for
Investigate device timelines
Configure and manage investigate device timelines
Perform actions on the device, including live response and collecting
Configure and manage perform actions on the device, including live response and collecting
Perform evidence and entity investigation
Configure and manage perform evidence and entity investigation
Investigate threats by using the unified audit log
Configure and manage investigate threats by using the unified audit log
Investigate threats by using Content Search
Configure and manage investigate threats by using content search
Investigate threats by using Microsoft Graph activity logs
Configure and manage investigate threats by using microsoft graph activity logs
Investigate and remediate incidents in Microsoft Sentinel
Configure and manage investigate and remediate incidents in microsoft sentinel
Create and configure automation rules
Configure and manage create and configure automation rules
Create and configure Microsoft Sentinel playbooks
Configure and manage create and configure microsoft sentinel playbooks
Run playbooks on on-premises resources
Configure and manage run playbooks on on-premises resources
Create and use promptbooks
Configure and manage create and use promptbooks
Manage sources for Security Copilot, including plugins and files
Configure and manage manage sources for security copilot, including plugins and files
Integrate Security Copilot by implementing connectors
Configure and manage integrate security copilot by implementing connectors
Manage permissions and roles in Security Copilot
Configure and manage manage permissions and roles in security copilot
Monitor Security Copilot capacity and cost
Configure and manage monitor security copilot capacity and cost
Identify threats and risks by using Security Copilot
Configure and manage identify threats and risks by using security copilot
Investigate incidents by using Security Copilot
Configure and manage investigate incidents by using security copilot
Identify threats by using Kusto Query Language (KQL)
Configure and manage identify threats by using kusto query language (kql)
Interpret threat analytics in the Microsoft Defender portal
Configure and manage interpret threat analytics in the microsoft defender portal
Create custom hunting queries by using KQL
Configure and manage create custom hunting queries by using kql
Analyze attack vector coverage by using the MITRE ATT&CK matrix
Configure and manage analyze attack vector coverage by using the mitre att&ck matrix
Manage and use threat indicators
Configure and manage manage and use threat indicators
Create and manage hunts
Configure and manage create and manage hunts
Create and monitor hunting queries
Configure and manage create and monitor hunting queries
Use hunting bookmarks for data investigations
Configure and manage use hunting bookmarks for data investigations
Retrieve and manage archived log data
Configure and manage retrieve and manage archived log data
Create and manage search jobs
Configure and manage create and manage search jobs
Activate and customize workbook templates
Configure and manage activate and customize workbook templates
Create custom workbooks that include KQL
Configure and manage create custom workbooks that include kql
Configure visualizations
Configure and manage configure visualizations
Manage security threats
Configure alert and vulnerability notification rules
Configure and manage configure alert and vulnerability notification rules
Configure Microsoft Defender for Endpoint advanced features
Configure and manage configure microsoft defender for endpoint advanced features
Configure endpoint rules settings
Configure and manage configure endpoint rules settings
Manage automated investigation and response capabilities in Microsoft
Configure and manage manage automated investigation and response capabilities in microsoft
Configure automatic attack disruption in Microsoft Defender XDR
Configure and manage configure automatic attack disruption in microsoft defender xdr
Configure and manage device groups, permissions, and automation levels
Configure and manage configure and manage device groups, permissions, and automation levels
Identify unmanaged devices in Microsoft Defender for Endpoint
Configure and manage identify unmanaged devices in microsoft defender for endpoint
Discover unprotected resources by using Defender for Cloud
Configure and manage discover unprotected resources by using defender for cloud
Identify and remediate devices at risk by using Microsoft Defender
Configure and manage identify and remediate devices at risk by using microsoft defender
Mitigate risk by using Exposure Management in Microsoft Defender XDR
Configure and manage mitigate risk by using exposure management in microsoft defender xdr
Plan a Microsoft Sentinel workspace
Configure and manage plan a microsoft sentinel workspace
Configure Microsoft Sentinel roles
Configure and manage configure microsoft sentinel roles
Specify Azure RBAC roles for Microsoft Sentinel configuration
Configure and manage specify azure rbac roles for microsoft sentinel configuration
Design and configure Microsoft Sentinel data storage, including log
Configure and manage design and configure microsoft sentinel data storage, including log
Identify data sources to be ingested for Microsoft Sentinel
Configure and manage identify data sources to be ingested for microsoft sentinel
Implement and use Content hub solutions
Configure and manage implement and use content hub solutions
Configure and use Microsoft connectors for Azure resources, including
Configure and manage configure and use microsoft connectors for azure resources, including
Plan and configure Syslog and Common Event Format (CEF) event
Configure and manage plan and configure syslog and common event format (cef) event
Plan and configure collection of Windows Security events by using data
Configure and manage plan and configure collection of windows security events by using data
Create custom log tables in the workspace to store ingested data
Configure and manage create custom log tables in the workspace to store ingested data
Monitor and optimize data ingestion
Configure and manage monitor and optimize data ingestion
Configure policies for Microsoft Defender for Cloud Apps
Configure and manage configure policies for microsoft defender for cloud apps
Configure policies for Microsoft Defender for Office 365
Configure and manage configure policies for microsoft defender for office 365
Configure security policies for Microsoft Defender for Endpoints,
Configure and manage configure security policies for microsoft defender for endpoints,
Configure cloud workload protections in Microsoft Defender for Cloud
Configure and manage configure cloud workload protections in microsoft defender for cloud
Configure and manage custom detection rules
Configure and manage configure and manage custom detection rules
Manage alerts, including tuning, suppression, and correlation
Configure and manage manage alerts, including tuning, suppression, and correlation
Configure deception rules in Microsoft Defender XDR
Configure and manage configure deception rules in microsoft defender xdr
Classify and analyze data by using entities
Configure and manage classify and analyze data by using entities
Configure and manage analytics rules
Configure and manage configure and manage analytics rules
Query Microsoft Sentinel data by using ASIM parsers
Configure and manage query microsoft sentinel data by using asim parsers
Implement behavioral analytics
Configure and manage implement behavioral analytics
Investigate and remediate threats by using Microsoft Defender for
Configure and manage investigate and remediate threats by using microsoft defender for
Investigate and remediate ransomware and business email compromise
Configure and manage investigate and remediate ransomware and business email compromise
Investigate and remediate compromised entities identified by Microsoft
Configure and manage investigate and remediate compromised entities identified by microsoft
Investigate and remediate threats identified by Microsoft Purview
Configure and manage investigate and remediate threats identified by microsoft purview
Investigate and remediate alerts and incidents identified by Microsoft
Configure and manage investigate and remediate alerts and incidents identified by microsoft
Investigate and remediate security risks identified by Microsoft
Configure and manage investigate and remediate security risks identified by microsoft
Investigate and remediate compromised identities that are identified
Configure and manage investigate and remediate compromised identities that are identified
Investigate and remediate security alerts from Microsoft Defender for
Configure and manage investigate and remediate security alerts from microsoft defender for
Investigate device timelines
Configure and manage investigate device timelines
Perform actions on the device, including live response and collecting
Configure and manage perform actions on the device, including live response and collecting
Perform evidence and entity investigation
Configure and manage perform evidence and entity investigation
Investigate threats by using the unified audit log
Configure and manage investigate threats by using the unified audit log
Investigate threats by using Content Search
Configure and manage investigate threats by using content search
Investigate threats by using Microsoft Graph activity logs
Configure and manage investigate threats by using microsoft graph activity logs
Investigate and remediate incidents in Microsoft Sentinel
Configure and manage investigate and remediate incidents in microsoft sentinel
Create and configure automation rules
Configure and manage create and configure automation rules
Create and configure Microsoft Sentinel playbooks
Configure and manage create and configure microsoft sentinel playbooks
Run playbooks on on-premises resources
Configure and manage run playbooks on on-premises resources
Create and use promptbooks
Configure and manage create and use promptbooks
Manage sources for Security Copilot, including plugins and files
Configure and manage manage sources for security copilot, including plugins and files
Integrate Security Copilot by implementing connectors
Configure and manage integrate security copilot by implementing connectors
Manage permissions and roles in Security Copilot
Configure and manage manage permissions and roles in security copilot
Monitor Security Copilot capacity and cost
Configure and manage monitor security copilot capacity and cost
Identify threats and risks by using Security Copilot
Configure and manage identify threats and risks by using security copilot
Investigate incidents by using Security Copilot
Configure and manage investigate incidents by using security copilot
Identify threats by using Kusto Query Language (KQL)
Configure and manage identify threats by using kusto query language (kql)
Interpret threat analytics in the Microsoft Defender portal
Configure and manage interpret threat analytics in the microsoft defender portal
Create custom hunting queries by using KQL
Configure and manage create custom hunting queries by using kql
Analyze attack vector coverage by using the MITRE ATT&CK matrix
Configure and manage analyze attack vector coverage by using the mitre att&ck matrix
Manage and use threat indicators
Configure and manage manage and use threat indicators
Create and manage hunts
Configure and manage create and manage hunts
Create and monitor hunting queries
Configure and manage create and monitor hunting queries
Use hunting bookmarks for data investigations
Configure and manage use hunting bookmarks for data investigations
Retrieve and manage archived log data
Configure and manage retrieve and manage archived log data
Create and manage search jobs
Configure and manage create and manage search jobs
Activate and customize workbook templates
Configure and manage activate and customize workbook templates
Create custom workbooks that include KQL
Configure and manage create custom workbooks that include kql
Configure visualizations
Configure and manage configure visualizations
How to study for this exam?
The most effective way to prepare for SC-200 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
What's changed on this exam?
- ACTIVE
- Last content update: 2024-07-15
Who should take this exam?
- Experience with Microsoft 365 security
- Knowledge of Microsoft Sentinel and KQL
- Understanding of threat detection and response
- Familiarity with security operations concepts