Microsoft certification

SC-200: Security operations analyst

Microsoft Security Operations Analyst

Videos
2
Source reviewed
Level
Intermediate
Who this exam is for

As a candidate for this exam, you’re a security operations analyst who reduces organizational risk by performing triage, responding to incidents, hunting for threats, and engineering detections. As a security operations analyst, you monitor, identify, investigate, and respond to threats in multi-cloud and on-premises environments by using Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and Microsoft Defender for Cloud workload protections.

Official scope

Skills measured

Objective names and displayed ranges come from the reviewed Microsoft source. Verify the official guide while planning study.

  1. Manage a security operations environment40–45%
  2. Respond to security incidents35–40%
  3. Perform threat hunting20–25%

Review the official Microsoft skills outline

Learn your way

Study resources

Choose a video, study guide, or available practice resource.

SC-200 video library

Practice videos

2 videos in this group.

  • Practice videos1 h 57 min 13 sec

    SC-200 Practice Exam: 60 Security Operations Analyst Associate questions

    SC-200 practice exam: work through 60 original Microsoft Security Operations Analyst questions covering Microsoft Sentinel, Defender XDR, threat hunting, incident response, KQL, automation, and security operations. This page accompanies “SC-200 Practice Exam: 60 Security Operations Analyst Associate questions.”

    Watch video
  • Practice videos2 h 15 min 5 sec

    SC-200 Practice Exam 2: 60 Security Operations Questions

    SC-200 practice exam: work through 60 original Microsoft Security Operations Analyst questions covering Microsoft Sentinel, Defender XDR, threat hunting, incident response, KQL, automation, and security operations. This page accompanies “SC-200 Practice Exam 2: 60 Security Operations Questions.”

    Watch video