SC-200: investigation and security operations response
SC-200 preparation covering log collection, Sentinel, Defender, incident response, and KQL. Original lessons and cases.
Objectives and progression
Ten lessons, 49 questions, and five fictional cases develop decisions about visibility, detection, response, and hunting. Distribution across the three domains: 21/18/10. Internal assessment of 35 decisions in 70 minutes. The July 28, 2026 outline was recovered from indexed official source text and compared with the English update announced for October 21, 2026. The observed change explicitly names Azure activity logs in the ingestion group; all three weight ranges remain unchanged. The path integrates product documentation inspected on October 1, 2026, including the September AIR transition. Initial guided preparation; it does not reproduce every official format or replace practice in a Microsoft environment.
Audience: SOC analysts, L3 support, security engineers, and technical managers coordinating response and RUN handover.
Prerequisites: Microsoft security, Azure, Microsoft 365, Windows/Linux, and log-reading foundations. Basic KQL helps with exercises.
460 estimated study minutes
- Validate SOC-environment ingestion and permissions.
- Interpret detection windows, entities, and automation.
- Coordinate containment, evidence, and recovery with operational context.
- Use KQL and hunting hypotheses with clear evidence limits.
- Assess retention, additional collection, and changes in protection capabilities.
- Distinguish case state, Graph evidence, and cross-service containment effects.
- Choose KQL jobs, aggregation, graphs, and notebooks for a reproducible investigation.
Modules
- SOC collection and permissions
- Windows, delays, and entities
- Detections and controlled automation
- Triage and endpoint response
- Identity, content, and handover
- KQL for reasoning about events
- Hunting, coverage, and continuity
- SOC platform: data and protection
- Investigating across Microsoft services
- Hunting with the lake, graphs, and notebooks
Continue learning
- SC-900 — Security, Compliance and Identity Fundamentals
- CompTIA Security+
- Production Support L3
- Monitoring and Observability
References and version
SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately
- SC-200 certification · 2026-09-30
- SC-200 study guide · 2026-10-01
- Microsoft exam scoring · 2026-09-30
- Scheduled analytics rules · 2026-09-30
- Ingestion delay · 2026-09-30
- Automation rules · 2026-09-30
- Response playbooks · 2026-09-30
- Custom detections · 2026-09-30
- Advanced hunting KQL · 2026-09-30
- CEF and Syslog via AMA · 2026-09-30
- Sentinel roles · 2026-09-30
- Data connector health · 2026-09-30
- Device response actions · 2026-09-30
- Live response · 2026-09-30
- Investigate incident cases · 2026-09-30
- Legacy incident investigation · 2026-09-30
- Emergency access revocation · 2026-09-30
- Copilot application card · 2026-09-30
- KQL join · 2026-09-30
- KQL summarize · 2026-09-30
- Threat hunting · 2026-09-30
- Hunting bookmarks · 2026-09-30
- MITRE coverage in Sentinel · 2026-09-30
- Purview Audit · 2026-09-30
- Purview eDiscovery · 2026-09-30
- Defender XDR · 2026-09-30
- Identity Protection · 2026-09-30
- Microsoft Sentinel overview · 2026-09-30
- Sentinel data tiers and retention · 2026-10-01
- Defender device groups · 2026-10-01
- Automation levels and AIR transition · 2026-10-01
- Configure automatic attack disruption · 2026-10-01
- Defender advanced features · 2026-10-01
- Deploy ASR rules · 2026-10-01
- Custom endpoint data collection rules · 2026-10-01
- Windows connectors through AMA · 2026-10-01
- Onboard Microsoft Sentinel · 2026-10-01
- Custom application logs through AMA · 2026-10-01
- SOC optimization · 2026-10-01
- Near-real-time analytics rules · 2026-10-01
- Threat indicators in analytics rules · 2026-10-01
- Customizable machine learning anomalies · 2026-10-01
- Alert notification rules · 2026-10-01
- Manage incident cases · 2026-10-01
- Remediate delivered malicious email · 2026-10-01
- Investigate Purview DLP alerts · 2026-10-01
- Manage Defender for Cloud alerts · 2026-10-01
- Govern connected cloud apps · 2026-10-01
- Microsoft Graph activity logs · 2026-10-01
- Compare lake KQL jobs, summary rules and search jobs · 2026-10-01
- Microsoft Sentinel Graph · 2026-10-01
- Run notebooks on the Sentinel data lake · 2026-10-01
- Sentinel MCP data exploration · 2026-10-01
- AI-assisted graph authoring · 2026-10-01
What you will explore
0 / 10SOC collection and permissions
Confirm data arrival and each identity’s required access.
Windows, delays, and entities
Design detections that respect time, aggregation, and context.
Detections and controlled automation
Keep rules, permissions, and actions aligned with operations.
Triage and endpoint response
Decide containment and evidence collection with service context.
Identity, content, and handover
Distinguish evidence sources and communicate certainty.
KQL for reasoning about events
Interpret filters, projections, aggregation, and table relationships.
Hunting, coverage, and continuity
Turn hypotheses into reproducible investigations useful to RUN.
SOC platform: data and protection
Connect collection, retention, policies, and response capabilities before a change.
Investigating across Microsoft services
Connect identity, email, applications, and resources in an investigation with verifiable actions.
Hunting with the lake, graphs, and notebooks
Choose search mechanisms and validate results with scope, cost, and provenance.