SC-200

Microsoft Security Operations Analyst practice questions

Original questions written from the published exam objectives, never recalled exam content, with an explanation that teaches the concept behind every answer. Why that matters.

Exam code
SC-200
Cost
$165 USD
Questions
40 to 60
Duration
100 minutes
Passing score
700 (scale 1000)
Format
Multiple choice, drag-and-drop, hot area, and case studies

The SC-200 exam costs $165. Fail it and the retake is another $165. Practicing until you are ready is the cheapest part of this. Full cost breakdown.

Exam domains and official weightings

From the official Microsoft Learn study guides. Put your study time where the weight is.

4domains
  • Manage a security operations environment22%
  • Configure protections and detections18%
  • Manage incident response32%
  • Manage security threats28%
  • Manage a security operations environment22%
  • Configure protections and detections18%
  • Manage incident response32%
  • Manage security threats28%

Where to focus: Incident response and threat management are 60 percent between them. Practicing the investigation flow inside a real Defender tenant moves the score faster than reading product docs.

Try 5 free sample questions

No account needed. Every question includes our three-tier explanation: the concept, why the answer follows, and why each wrong option is wrong.

Sample question 1 of 5

Manage incident responseModerate

Microsoft Sentinel is raising a separate incident for every alert produced by one analytics rule during a password spray, flooding the queue. Which change consolidates them?

Sample question 2 of 5

Manage security threatsHard

This hunting query is meant to find accounts with repeated failed sign-ins followed by a success, but it returns nothing.

SigninLogs
| where TimeGenerated > ago(1d)
| where ResultType == 0 and ResultType != 0
| summarize count() by UserPrincipalName

What is wrong with it?

Sample question 3 of 5

Configure protections and detectionsModerate

A device in Defender for Endpoint is confirmed compromised. You need to stop it reaching other systems while keeping the ability to investigate it from the portal. Which action fits?

Sample question 4 of 5

Manage a security operations environmentModerate

Sentinel ingestion costs have doubled after onboarding verbose firewall logs that are needed for quarterly audits but almost never queried during investigations. What is the appropriate change?

Sample question 5 of 5

Manage security threatsModerate

You want every high severity Sentinel incident involving a specific tag to automatically disable the affected account and post to a Teams channel. Which combination does this?

Full SC-200 question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What the exam actually asks you to do

Multiple choice and multiple response, plus drag-and-drop ordering, hot area items where you click a region of a screenshot, and case studies that hold one scenario across several linked questions.

  • Multiple choice
  • Multiple response
  • Drag and drop
  • Hot area
  • Case study

The highlighted formats are the ones you cannot answer from memory alone. Microsoft Learn, exam duration and question types

An honest study plan

  1. 1. Read the official objectives first

    Download the official objectives from Microsoft Azure and skim every line. The exam can only test what’s listed there, it’s the contract.

  2. 2. Weight your study toward Manage incident response and Manage security threats

    Together the top two domains are 60% of the exam. Practice them until your accuracy is consistently above 80%.

  3. 3. Drill weak domains, then take a mock exam

    Use Domain Drill on your weakest areas, then a full timed mock at real length (40 to 60 questions, 100 minutes). Book the real exam when you’re consistently passing mocks, not before.

Official free resources

Study from the source. These are Microsoft Azure’s own materials:

Official SC-200 exam page & objectives ↗

Where SC-200 fits

Related certifications

Frequently asked questions

How much KQL does SC-200 need?

Enough to read a hunting query and say what it returns, and enough to spot the one clause that makes a query miss the thing it is looking for. You are not asked to write long queries from a blank page, but you cannot avoid the language.

Which products does SC-200 cover?

Microsoft Sentinel and the Defender XDR family: Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, and Defender for Cloud. Incident response across those products is the heaviest domain at 32%.

Do I need SC-900 first?

It is not required. SC-900 is a vocabulary exam and SC-200 assumes you already have the vocabulary, so people who work in a Microsoft security stack usually skip straight to SC-200.

How long does SC-200 stay valid?

One year, renewed free through an online assessment on Microsoft Learn. The assessment is unproctored, open book, and takes under an hour.

Ready to practice for SC-200?

Play the free samples now. The full question bank is in progress, and you can join the waitlist on any sample question.

Start practicing free
SC-200 pass coming soon

Payment is not switched on yet. Everything free stays free either way, and explanations are never behind a payment.

$29 buys the SC-200 bank for good, including everything added to it later. Right now that is 5 sample questions, so buy it to back the work rather than for what is there today. Or go Pro for every certification.