← Back to catalogue
Certification preparation

SC-200: investigation and security operations response

SC-200 preparation covering log collection, Sentinel, Defender, incident response, and KQL. Original lessons and cases.

MicrosoftAvailable
MicrosoftSC20010 lessons
Official exam lasts 100 minutes; exact item count unconfirmed. Passing score 700 on the 1–1000 scale, not equivalent to 70%. English update announced for 2026-10-21; July outline recovered from indexed official text and compared with October. Initial practice uses current documentation without executable labs or claimed exhaustive coverage.

Objectives and progression

Ten lessons, 49 questions, and five fictional cases develop decisions about visibility, detection, response, and hunting. Distribution across the three domains: 21/18/10. Internal assessment of 35 decisions in 70 minutes. The July 28, 2026 outline was recovered from indexed official source text and compared with the English update announced for October 21, 2026. The observed change explicitly names Azure activity logs in the ingestion group; all three weight ranges remain unchanged. The path integrates product documentation inspected on October 1, 2026, including the September AIR transition. Initial guided preparation; it does not reproduce every official format or replace practice in a Microsoft environment.

Audience: SOC analysts, L3 support, security engineers, and technical managers coordinating response and RUN handover.

Prerequisites: Microsoft security, Azure, Microsoft 365, Windows/Linux, and log-reading foundations. Basic KQL helps with exercises.

460 estimated study minutes

  • Validate SOC-environment ingestion and permissions.
  • Interpret detection windows, entities, and automation.
  • Coordinate containment, evidence, and recovery with operational context.
  • Use KQL and hunting hypotheses with clear evidence limits.
  • Assess retention, additional collection, and changes in protection capabilities.
  • Distinguish case state, Graph evidence, and cross-service containment effects.
  • Choose KQL jobs, aggregation, graphs, and notebooks for a reproducible investigation.

Modules

  1. SOC collection and permissions
  2. Windows, delays, and entities
  3. Detections and controlled automation
  4. Triage and endpoint response
  5. Identity, content, and handover
  6. KQL for reasoning about events
  7. Hunting, coverage, and continuity
  8. SOC platform: data and protection
  9. Investigating across Microsoft services
  10. Hunting with the lake, graphs, and notebooks

Continue learning

Microsoft Azure

References and version

SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately

What you will explore

0 / 10

Learning is also trying.

Original explained questions, flashcards, and scenarios to apply the concepts.

Practice
This module covers foundations. It is not a complete certification course or a full simulation of the official exam.

Exam domains

Manage a security operations environment—
Respond to security incidents—
Perform threat hunting—