SC-200Free Study Guide

Microsoft Security Operations Analyst SC-200The Complete Beginner's Guide

Complete SC-200 study guide — threat mitigation using Microsoft Sentinel, Defender XDR, and cloud security.

101 chapters
~42 hours total read
Free — no signup required

How to use this guide

This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.

① Read a chapter② Answer practice questions③ Review missed answers④ Repeat
Study Chapters

101 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.

Start Chapter 1
Practice Questions

Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.

Go to practice test
Glossary

Every SC-200term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.

Browse glossary
Exam Overview

Exam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.

View exam guide

Mitigate Threats Using Microsoft Defender XDR (25–30%)

33 chapters

Domain overview
1

Microsoft Defender for Endpoint

Objective 1.1 · Defender XDR

25m
2

Microsoft Defender for Identity

Objective 1.2 · Defender XDR

25m
3

Microsoft Defender for Office 365

Objective 1.3 · Defender XDR

25m
4

Microsoft Defender for Cloud Apps

Objective 1.4 · Defender XDR

25m
17

Defender for Endpoint Alert Triage

Objective 1.1 · Defender XDR

25m
18

Advanced Hunting with KQL in Defender

Objective 1.1 · Defender XDR

25m
19

Defender for Endpoint Live Response

Objective 1.1 · Defender XDR

25m
20

Defender for Identity Attack Detections

Objective 1.2 · Defender XDR

25m
46

Defender XDR Incident Correlation

Objective 1.1 · Defender XDR

25m
47

Defender for Endpoint ASR Rules

Objective 1.1 · Defender XDR

25m
48

Defender for Endpoint Network Protection

Objective 1.1 · Defender XDR

25m
49

Defender for Endpoint Device Inventory

Objective 1.1 · Defender XDR

25m
50

Defender for Endpoint Onboarding Methods

Objective 1.1 · Defender XDR

25m
51

Automated Investigation and Response (AIR) in MDE

Objective 1.1 · Defender XDR

25m
52

Defender for Identity Alert Categories

Objective 1.2 · Defender XDR

25m
53

Domain Controller and Active Directory Monitoring

Objective 1.2 · Defender XDR

25m
54

Defender for Office 365 Policy Configuration

Objective 1.3 · Defender XDR

25m
55

Safe Attachments and ZAP in Defender

Objective 1.3 · Defender XDR

25m
56

Defender for Cloud Apps Policies

Objective 1.4 · Defender XDR

25m
57

Shadow IT Discovery with MCAS

Objective 1.4 · Defender XDR

25m
58

Conditional Access App Control in MCAS

Objective 1.4 · Defender XDR

25m
72

SOC Incident Triage and Escalation

Objective 1.1 · Defender XDR

25m
73

Live Response and Remote Forensics

Objective 1.1 · Defender XDR

25m
75

Custom Detection Rules in Defender XDR

Objective 1.1 · Defender XDR

25m
76

Entra ID Risk Policies and Sign-In Risk

Objective 1.4 · Defender XDR

25m
81

Device Timeline Analysis in MDE

Objective 1.1 · Defender XDR

25m
82

User Risk Investigation in Entra ID Protection

Objective 1.4 · Defender XDR

25m
86

Microsoft Copilot for Security

Objective 1.1 · Defender XDR

25m
92

Defender for Endpoint Security Baselines

Objective 1.1 · Defender XDR

25m
93

Defender for Endpoint Web Content Filtering

Objective 1.1 · Defender XDR

25m
97

Defender XDR Security Graph and Investigations

Objective 1.1 · Defender XDR

25m
99

Microsoft Copilot for Security

Objective 1.1 · Defender XDR

25m
101

Defender XDR Automatic Attack Disruption

Objective 1.1 · Defender XDR

25m

Mitigate Threats Using Microsoft Sentinel (50–55%)

44 chapters

Domain overview
5

Microsoft Sentinel Workspace Setup

Objective 2.1 · Sentinel

25m
6

KQL for Security Analysts

Objective 2.2 · Sentinel

25m
7

Sentinel Analytics Rules

Objective 2.3 · Sentinel

25m
8

Sentinel Incident Management

Objective 2.4 · Sentinel

25m
9

Sentinel Playbooks and Automation

Objective 2.5 · Sentinel

25m
10

Threat Hunting in Sentinel

Objective 2.6 · Sentinel

25m
13

User and Entity Behaviour Analytics in Sentinel

Objective 2.2 · Sentinel

25m
14

Microsoft Sentinel Workbooks

Objective 2.1 · Sentinel

25m
15

Sentinel Watchlists

Objective 2.2 · Sentinel

25m
16

Automation Rules vs Playbooks in Sentinel

Objective 2.5 · Sentinel

25m
26

Threat Intelligence in Microsoft Sentinel

Objective 2.2 · Sentinel

25m
27

Fusion ML Detection Rules in Sentinel

Objective 2.3 · Sentinel

25m
28

Sentinel Data Connectors

Objective 2.1 · Sentinel

25m
29

Advanced KQL: Joins, Summarize, and Aggregations

Objective 2.2 · Sentinel

25m
30

KQL Time Functions and Temporal Analysis

Objective 2.2 · Sentinel

25m
31

Sentinel Entity Mapping and Investigation Graph

Objective 2.4 · Sentinel

25m
32

Sentinel Notebooks with Jupyter

Objective 2.2 · Sentinel

25m
33

Threat Intelligence Indicators in Sentinel

Objective 2.2 · Sentinel

25m
34

Mapping Sentinel Rules to MITRE ATT&CK

Objective 2.3 · Sentinel

25m
35

Scheduled Analytics Rules vs NRT Rules

Objective 2.3 · Sentinel

25m
36

Multi-Workspace Sentinel Architecture

Objective 2.1 · Sentinel

25m
37

Sentinel Workspace Design Considerations

Objective 2.1 · Sentinel

25m
38

Sentinel Health and Auditing

Objective 2.1 · Sentinel

25m
39

M365 Defender Data Connectors

Objective 2.1 · Sentinel

25m
40

Azure Activity and Entra ID Connectors

Objective 2.1 · Sentinel

25m
41

CEF and Syslog Connector Configuration

Objective 2.1 · Sentinel

25m
42

Logic Apps Playbooks for Sentinel Automation

Objective 2.5 · Sentinel

25m
43

Alert Enrichment with Automation Rules

Objective 2.5 · Sentinel

25m
44

Sentinel Cost Management and Data Retention

Objective 2.1 · Sentinel

25m
45

Custom Sentinel Data Connectors

Objective 2.1 · Sentinel

25m
71

Sentinel and Defender XDR Bi-Directional Sync

Objective 2.1 · Sentinel

25m
74

Threat Hunting Query Library

Objective 2.6 · Sentinel

25m
77

SOAR Workflows with Sentinel

Objective 2.5 · Sentinel

25m
78

Sentinel Data Export and Archiving

Objective 2.1 · Sentinel

25m
79

Sentinel Basic Logs vs Analytics Logs

Objective 2.1 · Sentinel

25m
80

Sentinel Summary Rules for Large Data

Objective 2.2 · Sentinel

25m
85

AI and ML Threat Detection in Microsoft Security

Objective 2.3 · Sentinel

25m
87

Sentinel Customer-Managed Keys (CMK)

Objective 2.1 · Sentinel

25m
88

Sentinel Private Link and Data Privacy

Objective 2.1 · Sentinel

25m
89

Sentinel Near-Real-Time (NRT) Analytics Rules

Objective 2.3 · Sentinel

25m
90

Sentinel Entity Behaviour Scoring

Objective 2.2 · Sentinel

25m
91

Sentinel Fusion ML Detection Scenarios

Objective 2.3 · Sentinel

25m
96

Sentinel Data Tiering: Hot, Cold, Archive

Objective 2.1 · Sentinel

25m
98

Sentinel Content Hub and Solutions

Objective 2.1 · Sentinel

25m

Mitigate Threats Using Defender for Cloud (20–25%)

24 chapters

Domain overview
11

Microsoft Defender for Cloud

Objective 3.1 · Cloud Security

25m
12

Cloud Security Posture Management

Objective 3.2 · Cloud Security

25m
21

Microsoft Defender for Storage

Objective 3.1 · Cloud Security

25m
22

Microsoft Defender for Key Vault

Objective 3.1 · Cloud Security

25m
23

Microsoft Secure Score Improvements

Objective 3.2 · Cloud Security

25m
24

Defender CSPM and Attack Paths

Objective 3.2 · Cloud Security

25m
25

Regulatory Compliance Assessment

Objective 3.2 · Cloud Security

25m
59

Defender for Cloud Plans and Coverage

Objective 3.1 · Cloud Security

25m
60

Defender for Cloud Agents and Extensions

Objective 3.1 · Cloud Security

25m
61

Defender for Cloud Multi-Cloud (AWS, GCP)

Objective 3.1 · Cloud Security

25m
62

Defender for Servers Plans

Objective 3.1 · Cloud Security

25m
63

Just-In-Time VM Access

Objective 3.1 · Cloud Security

25m
64

File Integrity Monitoring in Defender

Objective 3.1 · Cloud Security

25m
65

Adaptive Network Hardening

Objective 3.1 · Cloud Security

25m
66

Secure Score: Controls and Recommendations

Objective 3.2 · Cloud Security

25m
67

Security Policy Initiatives

Objective 3.2 · Cloud Security

25m
68

Governance Rules and Risk Owners

Objective 3.2 · Cloud Security

25m
69

Container Security and Kubernetes Threat Detection

Objective 3.2 · Cloud Security

25m
70

Defender for APIs Threat Detection

Objective 3.1 · Cloud Security

25m
83

NIST Cybersecurity Framework for SC-200

Objective 3.2 · Cloud Security

25m
84

Zero Trust Implementation with Microsoft Security

Objective 3.2 · Cloud Security

25m
94

Defender CSPM Attack Path Simulation

Objective 3.2 · Cloud Security

25m
95

Azure Arc-Connected Machines in Defender

Objective 3.1 · Cloud Security

25m
100

Cloud Security Architecture Review

Objective 3.2 · Cloud Security

25m

Ready to test your knowledge?

Free SC-200 practice questions with full explanations. Test what you learn chapter by chapter.

SC-200 Practice Questions