SC-200 – Security Operations Analyst Associate
SC-200 validates the day-to-day skills of a security operations analyst: managing a security operations environment, configuring and using Microsoft Defender XDR for threat protection, and configuring and operating Microsoft Sentinel for detection, investigation, and incident response. This simulator reproduces the scenario-heavy style of the real exam with per-domain scoring.
Ready to sit the mock exam?
The timer starts as soon as you begin. You can flag questions, move freely between them, and review everything before submitting. No sign-in required — sign in afterwards to save the result to your history.
Start SC-200 examSkills measured
Manage a Security Operations Environment
20%Configuring settings, roles, and automation across Microsoft's security tooling.
Configure Protections and Detections Using Microsoft Defender XDR
25%Defender for Endpoint, Office 365, Identity, and Cloud Apps configuration and alerts.
Configure Protections and Detections Using Microsoft Sentinel
30%Data connectors, analytics rules, workbooks, and detection tuning in Sentinel.
Manage Incident Response
25%Investigating, triaging, and responding to incidents across the Microsoft security stack.