Certifications
SC-200 study guide: Security Operations Analyst
Sentinel, Defender XDR and KQL, weighted the way the exam weights them rather than the way training courses order them.
Who this exam is for
SC-200 is aimed at the person who works in the console every day: triaging incidents, tuning detections, hunting, and closing the loop with automation. It is the most directly job-shaped exam in the Microsoft security track, which is also why it is the one people underestimate.
The trap is treating it as a product-features exam. It is not. It is a workflow exam that happens to use Microsoft products, and the questions reward someone who has actually investigated an incident end to end.
The four things that decide whether you pass
KQL you can write, not recognise
The single highest-leverage preparation. You need to be comfortable with where, summarise, join, project and let, and comfortable reading someone else's query and saying what it misses. Recognising KQL is not enough.
Sentinel analytics rules and automation
Scheduled rules, near-real-time rules, automation rules and playbooks, and crucially knowing which one to reach for. A question describing a repetitive triage action is testing whether you reach for an automation rule rather than a playbook.
Defender XDR incident handling
How signals from endpoint, identity, email and cloud apps correlate into a single incident, and what actions are available at each stage.
Data connectors and cost
Which connector to use, what it ingests, and the cost implications of ingesting everything. Cost awareness turns up more than candidates expect.
Where to spend your study time
Our recommended split, weighted toward what people actually fail on rather than the objective sizes.
- KQL and hunting40%
- Sentinel configuration25%
- Defender XDR25%
- Threat intelligence and posture10%
This is a study allocation, not Microsoft's objective weighting.
The most common reason people fail
They studied the products and not the workflow. Someone who can list every Sentinel connector but has never tuned a noisy rule will struggle, because the exam keeps asking what you would do next rather than what a feature is called.
The fix is unglamorous. Spin up a trial workspace, connect two or three real data sources, deliberately create a noisy rule, and then fix it. A weekend of that is worth more than a fortnight of video.
Study resources
What we would actually use. Microsoft Learn is free and comes first for a reason.
Microsoft Learn, the official skills-measured outline
- Best for
- Everyone, before anything paid. It is free and it is the source the exam is written from
- Watch out for
- It teaches the product, not the exam technique. Pair it with scenario practice
MeasureUp practice tests
- Best for
- Exam-realistic question style, as Microsoft's official practice partner
- Watch out for
- The most expensive option, and coverage for brand new exams lags behind release
Tutorials Dojo practice exams
- Best for
- Low cost, detailed answer explanations, good for a final readiness check
- Watch out for
- Stronger on AWS than Microsoft. Check the specific exam is covered before buying
Links above go to the vendor. Where a link is marked as an affiliate link, a purchase may earn this site a commission at no cost to you, and it played no part in the ranking.
The verdict
Worth taking if you work in or want to move into security operations
It maps to real work more directly than any other exam in the track, and the KQL you learn is immediately useful whether or not you pass.
Skip it if you are an architect rather than an operator. SC-100 is the better fit, and it expects SC-200 or equivalent depth as background rather than as a prerequisite.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.