Certification guide

SC-200

Microsoft Security Operations Analyst: the honest guide

SC-200 is the exam for the person who works incidents in Microsoft's security stack. It covers Defender XDR, Defender for Cloud and Microsoft Sentinel, and it asks what you do with an alert rather than what an alert is.

It is a role-based certification, which in Microsoft's system means it expects you to have done the job. It also means it renews free every year through an online assessment, so the lifetime cost is the one exam fee rather than a recurring bill.

Who Security Operations Analyst is for

A good fit if

  • You work in a security operations role in an organisation running Microsoft 365 and Azure.
  • You already know security concepts and need the Microsoft-specific product knowledge to match.
  • Your team runs Microsoft Sentinel and you want to prove you can write the queries rather than read them.
  • You hold SC-900 and want the role-based certification that follows it.

Probably not, if

  • Your organisation does not run Microsoft security tooling. This exam is product-specific and the knowledge does not transfer to another vendor's stack.
  • You want security fundamentals. SC-900 is the fundamentals exam and it is cheaper, shorter and designed for that.
  • You want to configure Azure infrastructure security. AZ-500 is the engineering exam; this one is operations.

Is Security Operations Analyst worth it?

For an analyst in a Microsoft shop, this is a straightforwardly good certification. The products are the ones on your screen, the free renewal means it costs nothing to keep, and it demonstrates the specific competence the role needs.

Outside a Microsoft environment it is close to worthless, and that is not a criticism of the exam. It is a product certification and its value is entirely tied to whether you use the products.

The KQL requirement makes it more substantial than it looks. Query writing is examinable, which means this certification is harder to pass on portal familiarity alone than most Microsoft role-based exams.

What the exam actually asks you to do

Multiple choice and multiple response, plus drag-and-drop ordering, hot area items where you click a region of a screenshot, and case studies that hold one scenario across several linked questions.

Item formats

  • Multiple choice
  • Multiple response
  • Drag and drop
  • Hot area
  • Case study

The highlighted formats are the ones you cannot answer from memory alone. Microsoft Learn, exam duration and question types

Domain breakdown and official weightings

From the official Microsoft Learn study guides. Manage incident response is the heaviest domain at 32 percent, followed by Manage security threats at 28 percent.

  • Manage a security operations environment22%
  • Configure protections and detections18%
  • Manage incident response32%
  • Manage security threats28%

Where to focus: Incident response and threat management are 60 percent between them. Practising the investigation flow inside a real Defender tenant moves the score faster than reading product docs.

Microsoft Azure: Microsoft Learn study guides

Study plans by experience level

Working in a Microsoft SOC

3 to 4 weeksat 6 hours

  1. 1Week 1: read the skills outline and mark the products you do not touch. Most analysts use two of the four areas daily and have gaps in the others.
  2. 2Week 2: KQL deliberately. Write queries by hand in the free public Log Analytics demo environment rather than reading examples, because this is the part that is hardest to bluff.
  3. 3Week 3: the areas your daily work does not cover, most often Defender for Cloud if you are an endpoint-focused analyst.
  4. 4Week 4: the free Microsoft Learn path as a checklist, then a timed practice sitting.

Security background, new to Microsoft tooling

8 to 10 weeksat 6 hours

  1. 1Weeks 1 to 2: the product map. Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps and Defender for Cloud protect five different things and the exam will offer you all five.
  2. 2Weeks 3 to 5: incident response in Defender XDR, which is 32 percent of the exam and the largest domain. Start a trial tenant and work real incidents through to closure.
  3. 3Weeks 6 to 7: Microsoft Sentinel, including connectors, analytics rules and workbooks. Set a spending cap before connecting anything.
  4. 4Weeks 8 to 9: KQL until you can write a query without a reference open.
  5. 5Week 10: the Microsoft Learn path as revision, then practice questions.

SC-900 passed, no operational experience

12 weeksat 5 to 6 hours

  1. 1Accept that this is a large step up. SC-900 asks what a product is for; SC-200 asks what you do with it at eleven at night.
  2. 2Weeks 1 to 4: work the Microsoft Learn path end to end, in order, without skipping the modules that look familiar.
  3. 3Weeks 5 to 8: a trial tenant with real incidents. Reading about triage does not transfer; doing it does.
  4. 4Weeks 9 to 10: KQL from first principles, then Sentinel analytics rules.
  5. 5Weeks 11 to 12: practice questions and revision of the weakest skill area.

Common mistakes

Underestimating KQL
Query writing is examinable and it is the one part of SC-200 you cannot pass on portal familiarity. Candidates who can navigate every blade and have never written a query by hand lose marks in two of the four skill areas.
Confusing the Defender products
Defender for Endpoint, for Office 365, for Identity, for Cloud Apps and for Cloud are five products protecting five different things, and the exam offers them as four plausible options. Build a one-line map of product to protected asset before anything else.
Studying without a tenant
This exam asks what an action does and where a setting lives. Both are hard to learn from prose and easy to learn from a trial tenant, and trials are free.
Letting a Sentinel lab run up a bill
Sentinel bills on data ingested, so a workspace with chatty connectors left running over a weekend produces a bill much larger than the exam fee. Connect one source, keep it small, and set a spending cap first.
Treating incident response as a small domain
It is 32 percent of the exam, the largest single area, and it is process rather than product knowledge: what you do, in what order, and what each step changes. It rewards practice rather than reading.

What comes after passing

AZ-500 is the natural companion if you want the engineering side of Azure security to go with the operations side, and the two overlap enough that the second is cheaper in study time than the first.

Set a renewal reminder on the day you pass. Role-based certifications last one year and renew free through an online assessment, but if you miss the window it lapses and you sit the full exam again.

In hiring terms this is a credible signal for a Microsoft-focused analyst role and near-invisible outside one. Pair it with a vendor-neutral security certification if you want portability.

The renewal assessment covers what has changed rather than the whole syllabus, which is an efficient way to stay current in a product area that moves quickly.

Costs across the full renewal cycle are on the Security Operations Analyst cost page.

Frequently asked questions

Do I need SC-900 before SC-200?

No, there is no prerequisite. SC-900 is a useful on-ramp if security and Microsoft's product naming are both new to you, but it is a fundamentals exam and the step up to SC-200 is large regardless. Somebody already working in security operations can go straight to SC-200.

How much KQL do I need to know?

Enough to write a query rather than recognise one. Kusto Query Language is examinable and appears across the threat hunting and Sentinel material, and it is the most common reason candidates who know the portals well still fail. Microsoft runs a free public demo environment for practising it.

What is the difference between SC-200 and AZ-500?

SC-200 is security operations: detecting, investigating and responding to threats across Defender and Sentinel. AZ-500 is security engineering: configuring identity, network, compute and data protections in Azure. One runs the response, the other builds the controls, and they overlap around Defender for Cloud.

Does SC-200 expire?

It lasts one year, which is shorter than most certifications, but it renews free through an unproctored online assessment on Microsoft Learn that takes about an hour. The renewal window opens six months before expiry, so the practical cost of keeping it is time rather than money.

Can I pass without access to a real tenant?

It is much harder. The exam asks where settings live and what specific actions change, which is portal knowledge. Microsoft offers free trial tenants for exactly this, and a trial started a few weeks before the exam covers what you need without a licence purchase.

Keep reading

Cheat sheets

Printable reference tables, free.

Compared with

Side by side on cost, difficulty, and which one to take first.

Every guide and cost breakdown, by vendor

Practise Security Operations Analyst for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free Security Operations Analyst questions