1. Home
  2. Microsoft
  3. SC-200 Exam

SC-200 Microsoft Security Operations Analyst Exam Topics and Questions

Let's Practice Free Microsoft SC-200 Questions Aligned with Official Exam Topics

Follows Microsoft's official outline Updated 18 Sep, 2026 3 Topics
Reviewed by Daniel Young, Microsoft SC-200 Certified Professional
Topic Content
Configure automation for Microsoft Defender XDR and Microsoft Sentinel by setting up email notifications for incidents, actions, and threat analytics, configuring alert notifications with tuning, suppression, and correlation capabilities, and enabling advanced features and rule settings in Microsoft Defender for Endpoint. Implement custom data collection, security policies including attack surface reduction rules, and automated investigation and response capabilities while managing device groups, permissions, and automation levels. Create and configure automation rules and playbooks in Microsoft Sentinel to streamline security operations... See More
Sample Questions for Topic 1 : Manage a security operations environment
Q1

You have a Microsoft 365 E5 subscription.

You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode.

All Windows devices are on boarded to Microsoft Defender for Endpoint.

You need to ensure that the devices are protected from malicious artifacts that were undetected by the third-party antivirus product.

Solution: You enable Live Response.

Does this meet the goal?

Topic Content
Respond to security incidents by managing alerts and incidents across Microsoft Defender XDR, including investigating and remediating threats identified by Microsoft Defender for Office 365, Microsoft Purview, Microsoft Defender for Cloud workload protections, Microsoft Defender for Cloud Apps, Microsoft Entra ID, and Microsoft Defender for Identity. Utilize Microsoft Sentinel for incident investigation and leverage agentic AI with embedded Microsoft Security Copilot to analyze complex attacks involving multi-stage, multi-domain, and lateral movement scenarios while implementing case management for security incident tracking.... See More
Sample Questions for Topic 2 : Respond to security incidents
Q2

You create a custom analytics rule to detect threats in Azure Sentinel.

You discover that the rule fails intermittently.

What are two possible causes of the failures? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Topic Content
Perform Threat Hunting Using Microsoft Security Tools Threat hunting involves proactively detecting and investigating security threats across your organizations infrastructure. Using Microsoft Defender XDR, you will learn to identify the appropriate data tables for KQL queries, leverage Kusto Query Language to identify threats, and create advanced hunting queries to uncover suspicious activities. You will interpret threat analytics within Microsoft Defender XDR, develop hunting graphs that visualize blast radius and attack scope, and analyze relationships between entities using Sentinel Graph to understand... See More

Ready to Start Practicing?

Access all questions and start your exam preparation journey

Upgrade to Full SC-200 Exam Questions 🚀
Exams Made Simple. Success Made Possible.