Certification guideSC-200

Microsoft Security Operations Analyst: the honest guide

Everything Microsoft Azure publishes about SC-200, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.

This guide page is built from the registry, not written yet.

Everything below comes from SC-200’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.

Practise SC-200 questions in the meantime

What the exam actually asks you to do

Multiple choice and multiple response, plus drag-and-drop ordering, hot area items where you click a region of a screenshot, and case studies that hold one scenario across several linked questions.

  • Multiple choice
  • Multiple response
  • Drag and drop
  • Hot area
  • Case study

The highlighted formats are the ones you cannot answer from memory alone. Microsoft Learn, exam duration and question types

Domain breakdown and official weightings

From the official Microsoft Learn study guides. Manage incident response is the heaviest domain at 32 percent, followed by Manage security threats at 28 percent.

  • Manage a security operations environment22%
  • Configure protections and detections18%
  • Manage incident response32%
  • Manage security threats28%

Where to focus: Incident response and threat management are 60 percent between them. Practicing the investigation flow inside a real Defender tenant moves the score faster than reading product docs.

Official SC-200 exam objectives ↗

What comes after passing

SC-200 is valid for 1 year. Free online renewal assessment on Microsoft Learn each year.

Costs across the full renewal cycle are on the SC-200 cost page.

Frequently asked questions

How much KQL does SC-200 need?

Enough to read a hunting query and say what it returns, and enough to spot the one clause that makes a query miss the thing it is looking for. You are not asked to write long queries from a blank page, but you cannot avoid the language.

Which products does SC-200 cover?

Microsoft Sentinel and the Defender XDR family: Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, and Defender for Cloud. Incident response across those products is the heaviest domain at 32%.

Do I need SC-900 first?

It is not required. SC-900 is a vocabulary exam and SC-200 assumes you already have the vocabulary, so people who work in a Microsoft security stack usually skip straight to SC-200.

How long does SC-200 stay valid?

One year, renewed free through an online assessment on Microsoft Learn. The assessment is unproctored, open book, and takes under an hour.

Keep reading

Every guide and cost breakdown, by vendor

Practise SC-200 for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free SC-200 questions