Microsoft certification
SC-200: Security operations analyst
Microsoft Security Operations Analyst
Who this exam is for
As a candidate for this exam, you’re a security operations analyst who reduces organizational risk by performing triage, responding to incidents, hunting for threats, and engineering detections. As a security operations analyst, you monitor, identify, investigate, and respond to threats in multi-cloud and on-premises environments by using Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and Microsoft Defender for Cloud workload protections.

Start here
SC-200 Practice Exam: 60 Security Operations Analyst Associate questions
SC-200 practice exam: work through 60 original Microsoft Security Operations Analyst questions covering Microsoft Sentinel, Defender XDR, threat hunting, incident response, KQL, automation, and security operations. This page accompanies “SC-200 Practice Exam: 60 Security Operations Analyst Associate questions.”
Watch this videoOfficial scope
Skills measured
Objective names and displayed ranges come from the reviewed Microsoft source. Verify the official guide while planning study.
- Manage a security operations environment40–45%
- Respond to security incidents35–40%
- Perform threat hunting20–25%
Learn your way
Study resources
Choose a video, study guide, or available practice resource.
- Narrated practice2 public practice videosAvailableOpen resource
- Study guideOfficial Microsoft study guideAvailableOpen resource
SC-200 video library
Practice videos
2 videos in this group.

SC-200 Practice Exam: 60 Security Operations Analyst Associate questions
SC-200 practice exam: work through 60 original Microsoft Security Operations Analyst questions covering Microsoft Sentinel, Defender XDR, threat hunting, incident response, KQL, automation, and security operations. This page accompanies “SC-200 Practice Exam: 60 Security Operations Analyst Associate questions.”
Watch video
SC-200 Practice Exam 2: 60 Security Operations Questions
SC-200 practice exam: work through 60 original Microsoft Security Operations Analyst questions covering Microsoft Sentinel, Defender XDR, threat hunting, incident response, KQL, automation, and security operations. This page accompanies “SC-200 Practice Exam 2: 60 Security Operations Questions.”
Watch video