Microsoft Security Operations Analyst practice questions
Original questions written from the published exam objectives, never recalled exam content, with an explanation that teaches the concept behind every answer. Why that matters.
- Exam code
- SC-200
- Cost
- $165 USD
- Questions
- 40 to 60
- Duration
- 100 minutes
- Passing score
- 700 (scale 1000)
- Format
- Multiple choice, drag-and-drop, hot area, and case studies
The SC-200 exam costs $165. Fail it and the retake is another $165. Practicing until you are ready is the cheapest part of this. Full cost breakdown.
Exam domains and official weightings
From the official Microsoft Learn study guides. Put your study time where the weight is.
- Manage a security operations environment22%
- Configure protections and detections18%
- Manage incident response32%
- Manage security threats28%
- Manage a security operations environment22%
- Configure protections and detections18%
- Manage incident response32%
- Manage security threats28%
Where to focus: Incident response and threat management are 60 percent between them. Practicing the investigation flow inside a real Defender tenant moves the score faster than reading product docs.
Try 5 free sample questions
No account needed. Every question includes our three-tier explanation: the concept, why the answer follows, and why each wrong option is wrong.
Sample question 1 of 5
Microsoft Sentinel is raising a separate incident for every alert produced by one analytics rule during a password spray, flooding the queue. Which change consolidates them?
Sample question 2 of 5
This hunting query is meant to find accounts with repeated failed sign-ins followed by a success, but it returns nothing.
SigninLogs
| where TimeGenerated > ago(1d)
| where ResultType == 0 and ResultType != 0
| summarize count() by UserPrincipalNameWhat is wrong with it?
Sample question 3 of 5
A device in Defender for Endpoint is confirmed compromised. You need to stop it reaching other systems while keeping the ability to investigate it from the portal. Which action fits?
Sample question 4 of 5
Sentinel ingestion costs have doubled after onboarding verbose firewall logs that are needed for quarterly audits but almost never queried during investigations. What is the appropriate change?
Sample question 5 of 5
You want every high severity Sentinel incident involving a specific tag to automatically disable the affected account and post to a Teams channel. Which combination does this?
Full SC-200 question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
What the exam actually asks you to do
Multiple choice and multiple response, plus drag-and-drop ordering, hot area items where you click a region of a screenshot, and case studies that hold one scenario across several linked questions.
- Multiple choice
- Multiple response
- Drag and drop
- Hot area
- Case study
The highlighted formats are the ones you cannot answer from memory alone. Microsoft Learn, exam duration and question types ↗
An honest study plan
1. Read the official objectives first
Download the official objectives from Microsoft Azure and skim every line. The exam can only test what’s listed there, it’s the contract.
2. Weight your study toward Manage incident response and Manage security threats
Together the top two domains are 60% of the exam. Practice them until your accuracy is consistently above 80%.
3. Drill weak domains, then take a mock exam
Use Domain Drill on your weakest areas, then a full timed mock at real length (40 to 60 questions, 100 minutes). Book the real exam when you’re consistently passing mocks, not before.
Official free resources
Study from the source. These are Microsoft Azure’s own materials:
Official SC-200 exam page & objectives ↗Where SC-200 fits
Related certifications
Microsoft Security, Compliance, and Identity Fundamentals
4 domains
Try free sample questionsMicrosoft Azure Security Engineer
4 domains · 5 practice questions
Try free sample questionsMicrosoft Azure Fundamentals
3 domains
Try free sample questionsMicrosoft Azure Administrator
5 domains
Try free sample questionsFrequently asked questions
How much KQL does SC-200 need?
Enough to read a hunting query and say what it returns, and enough to spot the one clause that makes a query miss the thing it is looking for. You are not asked to write long queries from a blank page, but you cannot avoid the language.
Which products does SC-200 cover?
Microsoft Sentinel and the Defender XDR family: Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, and Defender for Cloud. Incident response across those products is the heaviest domain at 32%.
Do I need SC-900 first?
It is not required. SC-900 is a vocabulary exam and SC-200 assumes you already have the vocabulary, so people who work in a Microsoft security stack usually skip straight to SC-200.
How long does SC-200 stay valid?
One year, renewed free through an online assessment on Microsoft Learn. The assessment is unproctored, open book, and takes under an hour.
Ready to practice for SC-200?
Play the free samples now. The full question bank is in progress, and you can join the waitlist on any sample question.
Payment is not switched on yet. Everything free stays free either way, and explanations are never behind a payment.
$29 buys the SC-200 bank for good, including everything added to it later. Right now that is 5 sample questions, so buy it to back the work rather than for what is there today. Or go Pro for every certification.