Course curriculum
Microsoft SC-200 Security Operations Analyst
Study guides for the Microsoft SC-200 Security Operations Analyst certification.
Curriculum
Modules and lessons
Module 01
Microsoft Sentinel
- 01Create and Manage Microsoft Sentinel Hunts – SC-200 Study GuideLearn how to create and manage Microsoft Sentinel hunts, use live streams and bookmarks, track hunt status, evaluate hypotheses, and prepare for SC-200 scenarios.Open lesson →
- 02Manage and Use Microsoft Sentinel Threat Indicators – SC-200 Study GuideLearn how to manage Microsoft Sentinel threat indicators, CTI objects, relationships, Content Hub solutions, IOC metadata, and SOC investigation decisions for the SC-200 exam.Open lesson →
- 03Microsoft Sentinel SIEM and SOAR Fundamentals – SC-200 Study GuidePurpose of This Lesson This lesson introduces Microsoft Sentinel as Microsoft’s cloud-native security information and event management and security orchestration, automation, and response platform. For the SC-200 Microsoft Security Operations Analyst exam, Sentinel is one of the most important products to understand because it sits at the center of many SOC workflows. A Microsoft Security […]Open lesson →
- 04Planning and Creating a Microsoft Sentinel Workspace – SC-200 Study GuidePurpose of This Lesson This lesson explains the foundational setup required before Microsoft Sentinel can be used as a cloud-native SIEM and SOAR platform. The main focus is planning and creating the Log Analytics workspace that Microsoft Sentinel depends on. For the SC-200 exam, this is important because Microsoft Sentinel does not operate in isolation. […]Open lesson →
- 05Microsoft Sentinel Roles, Permissions, Log Storage, and Retention – SC-200 Study GuidePurpose of This Lesson This lesson focuses on two foundational Microsoft Sentinel administration topics: role-based access control and log storage/retention. For the SC-200 exam, you need to understand more than how to investigate alerts. You also need to know how Microsoft Sentinel is secured, who can perform specific SOC actions, where Sentinel data is stored, […]Open lesson →
- 06Microsoft Sentinel Workbooks and Custom Dashboards – SC-200 Study GuidePurpose of This Lesson This lesson explains how Microsoft Sentinel workbooks are used to visualize security data, review trends, and build interactive dashboards for SOC monitoring. For the SC-200 exam, you need to understand that workbooks are not detection rules, incidents, or automated response tools. They are primarily used for visual analysis, reporting, dashboarding, and […]Open lesson →
- 07Microsoft Sentinel Data Connectors and Content Hub – SC-200 Study GuidePurpose of This Lesson This lesson explains how Microsoft Sentinel receives security data from Microsoft services, cloud platforms, on-premises systems, third-party products, and custom applications. For the SC-200 exam, this topic matters because Microsoft Sentinel is only useful when it has the right data sources connected. A Security Operations Analyst must understand how data connectors […]Open lesson →
- 08Microsoft Sentinel Data Connectors, Azure Monitor Agent, Syslog, and CEF – SC-200 Study GuidePurpose of This Lesson This lesson explains how Microsoft Sentinel collects data from Microsoft services, Azure resources, Windows and Linux systems, and third-party security appliances. For the SC-200 exam, this matters because Microsoft Sentinel is only useful when it has the right data sources connected. A Security Operations Analyst must understand how logs are ingested, […]Open lesson →
- 09Microsoft Sentinel Syslog, CEF, and Windows Event Collection – SC-200 Study GuidePurpose of This Lesson This lesson explains how Microsoft Sentinel ingests security event data from different operating systems, appliances, and log sources using common logging formats and data connectors. For the SC-200 exam, this topic matters because a Microsoft Security Operations Analyst must understand how data gets into Microsoft Sentinel before it can be used […]Open lesson →
- 10Microsoft Sentinel Entities and Entity Mapping – SC-200 Study GuidePurpose of This Lesson Microsoft Sentinel entities are one of the core concepts that help transform raw security logs into meaningful investigation context. In a SOC, it is not enough to know that an alert fired. An analyst needs to understand which user, device, IP address, URL, file, or cloud resource was involved. Entities allow […]Open lesson →
- 11Microsoft Sentinel Analytics Rules – SC-200 Study GuidePurpose of This Lesson Microsoft Sentinel analytics rules are used to detect suspicious activity, anomalies, known attack patterns, and indicators of compromise across connected data sources. For the SC-200 exam, this topic is important because analytics rules are one of the main ways Microsoft Sentinel turns raw security data into actionable alerts and incidents. A […]Open lesson →
- 12Microsoft Sentinel ASIM Normalization and Parsers – SC-200 Study GuidePurpose of This Lesson This lesson explains ASIM, the Advanced Security Information Model, in Microsoft Sentinel. ASIM matters because Microsoft Sentinel collects security data from many different sources: Microsoft products, on-premises servers, Linux systems, DNS platforms, firewalls, cloud services, endpoint tools, and custom applications. Each source may use different table names, field names, and event […]Open lesson →
- 13Microsoft Sentinel UEBA and Behavioral Analytics – SC-200 Study GuidePurpose of This Lesson This lesson explains how to implement User and Entity Behavior Analytics, commonly called UEBA, in Microsoft Sentinel. UEBA helps Microsoft Sentinel detect suspicious activity that may not match a simple rule-based detection. Instead of only looking for obvious indicators like repeated failed sign-ins, known malware, or specific attack signatures, UEBA builds […]Open lesson →
- 14Investigate and Remediate Microsoft Sentinel Incidents – SC-200 Study GuideLearn how to investigate, manage, classify, and remediate Microsoft Sentinel incidents in the Defender portal for the SC-200 exam.Open lesson →
- 15Microsoft Sentinel Automation Rules and Playbooks – SC-200 Study GuideLearn how Microsoft Sentinel automation rules and Logic Apps playbooks support incident triage, enrichment, integrations, remediation, and SC-200 scenario decisions.Open lesson →
- 16Create and Configure Microsoft Sentinel Automation Rules – SC-200 Study GuideLearn how to configure Microsoft Sentinel automation rules, including triggers, conditions, actions, execution order, expiration, and SC-200 exam scenarios.Open lesson →
- 17Create and Configure Microsoft Sentinel Playbooks – SC-200 Study GuideLearn how Microsoft Sentinel playbooks use Azure Logic Apps, managed identities, triggers, templates, connectors, and permissions for SC-200 incident response.Open lesson →
- 18Run Sentinel Playbooks on On-Premises Resources – SC-200 Study GuideLearn how Microsoft Sentinel playbooks use Azure Automation and Hybrid Runbook Workers to execute secure on-premises response actions for the SC-200 exam.Open lesson →
- 19Configure Anomaly Detection Analytics Rules – SC-200 Study GuideLearn how Microsoft Sentinel anomaly analytics, UEBA signals, NRT rules, KQL thresholds, and failed-logon detection support SC-200 exam decisions and SOC investigations.Open lesson →
- 20Customizing Microsoft Sentinel Hunting Queries with KQL – SC-200 Study GuideLearn how to use Microsoft Sentinel GitHub hunting queries in Defender Advanced Hunting, customize KQL time ranges, and avoid SC-200 investigation traps.Open lesson →
Module 02
Microsoft Defender XDR
- 01Microsoft Defender XDR Overview – SC-200 Study GuidePurpose of This Lesson This lesson introduces Microsoft Defender XDR, Microsoft’s extended detection and response platform for correlating security signals across endpoints, identities, email, SaaS applications, and cloud-connected workloads. For the SC-200: Microsoft Security Operations Analyst exam, this topic matters because a SOC analyst needs to understand how Microsoft’s security tools work together. The exam […]Open lesson →
- 02Microsoft Defender XDR and Microsoft Purview Portals – SC-200 Study GuidePurpose of This Lesson This lesson introduces two major Microsoft security and compliance portals that appear throughout the SC-200 exam: For a Microsoft Security Operations Analyst, these portals are important because security operations rarely exist in isolation. Threat detection, incident response, identity protection, endpoint security, email security, cloud app discovery, compliance policies, data protection, and […]Open lesson →
- 03Microsoft Defender XDR Actions and Submissions – SC-200 Study GuidePurpose of This Lesson This lesson explains how the Actions and Submissions area in Microsoft Defender XDR supports security operations workflows. This is important for the SC-200 exam because Microsoft Security Operations Analysts need to understand how suspicious files, emails, Teams messages, URLs, and user-reported content can be submitted for analysis and how resulting actions […]Open lesson →
- 04Microsoft Secure Score in Microsoft Defender – SC-200 Study GuidePurpose of This Lesson This lesson introduces Microsoft Secure Score inside Microsoft Defender and explains how it helps organizations improve their overall security posture. For the SC-200 Microsoft Security Operations Analyst exam, Secure Score is important because it connects directly to posture management, risk reduction, and proactive security operations. While many SOC tasks focus on […]Open lesson →
- 05Microsoft Defender Threat Analytics and Custom Alert Policies – SC-200 Study GuidePurpose of This Lesson This lesson focuses on two important Microsoft Defender capabilities for security operations analysts: For the SC-200 exam, this topic matters because a Microsoft Security Operations Analyst must know how to monitor active threats, determine whether the organization is affected, review recommended actions, and configure alerting so important activity is surfaced quickly. […]Open lesson →
- 06Investigating Defender XDR Incidents with Security Copilot – SC-200 Study GuideLearn how to use Security Copilot with Microsoft Defender XDR incident IDs to summarize incidents, investigate alerts, and make SC-200 response decisions.Open lesson →
- 07Investigate Microsoft Defender XDR Incident Timelines – SC-200 Study GuideLearn how to investigate Microsoft Defender XDR incidents using attack stories, entity details, file hashes, evidence and response, and scope validation for SC-200.Open lesson →
Module 03
Microsoft Security Copilot
- 01Microsoft Security Copilot: Incident Response, KQL, and SOC Use Cases – SC-200 Study GuideLearn how Microsoft Security Copilot supports SC-200 incident response, KQL hunting, threat triage, posture management, and safe analyst decision-making.Open lesson →
- 02Security Copilot Security Compute Units (SCUs) – SC-200 Study GuideLearn Security Copilot SCU capacity models, Azure billing, overage limits, hourly charges, monitoring, and SC-200 exam traps.Open lesson →
- 03Setting Up Sample Alerts for Security Copilot – SC-200 Study GuideLearn how to create Defender for Cloud sample alerts for Security Copilot practice, including subscriptions, resource scope, limitations, and SC-200 exam traps.Open lesson →
- 04Microsoft Security Copilot SCU Capacity and Billing Warning – SC-200 Study GuideLearn SC-200 exam essentials for Security Copilot SCU capacity, workspace prerequisites, hourly billing behavior, deletion, and lab cost control.Open lesson →
- 05Allocating SCUs for Security Copilot – SC-200 Study GuideLearn how to provision, configure, govern, and delete Security Compute Units for Microsoft Security Copilot with SC-200 exam tips and SOC cost-control guidance.Open lesson →
- 06How to Delete Security Copilot SCUs and Avoid Ongoing Azure Costs – SC-200 Study GuideLearn how to safely clean up Microsoft Security Copilot SCUs, delete temporary Azure resource groups, avoid ongoing charges, and apply SC-200 exam decision-making.Open lesson →
Module 04
Microsoft Defender for Endpoint
- 01Microsoft Defender for Endpoint Core Capabilities – SC-200 Study GuidePurpose of This Lesson This lesson introduces Microsoft Defender for Endpoint, one of the core Microsoft security platforms covered in the SC-200 exam. Defender for Endpoint is important because it gives security operations analysts visibility into endpoint activity, endpoint threats, vulnerabilities, attack surface risks, and response actions. For the SC-200 exam, you need to understand […]Open lesson →
- 02Microsoft Defender for Endpoint Settings, Device Groups, Indicators, and Detection Tests – SC-200 Study GuidePurpose of This Lesson This lesson introduces the major configuration areas inside Microsoft Defender for Endpoint as managed from the Microsoft Defender portal. The focus is not on mastering every setting individually, but on understanding where endpoint security settings live, what they control, and how they support security operations. For the SC-200: Microsoft Security Operations […]Open lesson →
- 03Microsoft Defender for Endpoint Onboarding with Intune and Local Script – SC-200 Study GuidePurpose of This Lesson This lesson explains how to onboard Windows devices into Microsoft Defender for Endpoint and why onboarding matters for Microsoft security operations. For the SC-200 exam, this topic is important because a Security Operations Analyst needs to understand how endpoint telemetry gets into the Microsoft Defender portal. If a device is not […]Open lesson →
- 04Microsoft Defender for Endpoint Settings, Device Groups, Indicators, and Detection Tests – SC-200 Study GuidePurpose of This Lesson This lesson introduces the major configuration areas inside Microsoft Defender for Endpoint as managed from the Microsoft Defender portal. The focus is not on mastering every setting individually, but on understanding where endpoint security settings live, what they control, and how they support security operations. For the SC-200: Microsoft Security Operations […]Open lesson →
- 05Microsoft Defender for Endpoint Device Discovery and Unmanaged Devices – SC-200 Study GuidePurpose of This Lesson This lesson explains how Microsoft Defender for Endpoint can identify unmanaged devices on a network using Device Discovery. For the SC-200 exam, this matters because a Microsoft Security Operations Analyst is responsible for understanding where security visibility exists — and where it does not. A device that is connected to the […]Open lesson →
- 06Microsoft Defender for Endpoint Attack Surface Reduction Rules – SC-200 Study GuidePurpose of This Lesson Attack Surface Reduction, commonly called ASR, is a Microsoft Defender for Endpoint capability used to reduce the number of ways an attacker can compromise a Windows device. For the SC-200 exam, this topic matters because Security Operations Analysts need to understand how endpoint prevention controls affect detection, investigation, alert triage, ransomware […]Open lesson →
- 07How to Trigger Microsoft Defender for Endpoint Test Incidents – SC-200 Study GuideLearn how to safely trigger Microsoft Defender for Endpoint test activity, validate ASR and scripting detections, handle telemetry delays, and investigate alerts for the SC-200 exam.Open lesson →
Module 05
Microsoft Defender for Office 365
- 01Microsoft Defender for Office 365 Attack Simulation Training – SC-200 Study GuidePurpose of This Lesson This lesson focuses on Attack Simulation Training in the Microsoft Defender portal. This feature allows security teams to run safe phishing simulations against users, measure who interacts with simulated phishing messages, and assign training based on user behavior. For the SC-200 Microsoft Security Operations Analyst exam, this topic matters because it […]Open lesson →
- 02Microsoft Defender for Office 365 Threat Policies and Email Protection – SC-200 Study GuidePurpose of This Lesson This lesson explains how Microsoft Defender for Office 365 and Exchange Online Protection protect users from phishing, spam, malware, malicious attachments, and dangerous URLs. For the SC-200 exam, the important skill is not memorizing the exact location of every portal menu. Microsoft frequently changes portal navigation and feature labels. Instead, focus […]Open lesson →
- 03Microsoft Defender for Office 365 Threat Explorer and Email Investigation – SC-200 Study GuidePurpose of This Lesson Microsoft Defender for Office 365 provides security analysts with tools for investigating suspicious email, phishing attempts, malicious attachments, unsafe links, and coordinated email campaigns. A central investigation tool is Explorer, commonly called Threat Explorer. It allows analysts to search email activity, examine delivery outcomes, inspect senders and recipients, review authentication results, […]Open lesson →
Module 06
Microsoft Defender for Cloud Apps
- 01Discover and Manage Cloud Applications with Defender for Cloud Apps – SC-200 Study GuideStudy Microsoft Defender for Cloud Apps for SC-200: Cloud Discovery, app connectors, session controls, shadow IT, policies, remediation, and SOC decision-making.Open lesson →
- 02Microsoft Defender for Cloud Apps Policies and Investigation – SC-200 Study GuideStudy Microsoft Defender for Cloud Apps policy types, cloud discovery, file-sharing controls, activity-log investigation, and SC-200 exam decisions.Open lesson →
Module 07
Microsoft Purview
- 01Microsoft Purview Data Loss Prevention Design and Workload Protecof This LessonMicrosoft Purview Data Loss Prevention, commonly called DLP, helps organizations identify sensitive information, monitor how it is used, and prevent it from being shared through unauthorized channels. For a Microsoft Security Operations Analyst, DLP is relevant because suspected data loss may represent: The analyst must understand where DLP policies are configured, which workloads they protect, […]Open lesson →
- 02Microsoft Purview DLP Roles and Permissions – SC-200 Study GuidePurpose of This Lesson Microsoft Purview Data Loss Prevention relies on role-based access control to determine who can create policies, review reports, investigate alerts, and access sensitive content. For the SC-200 exam, the important skill is not simply memorizing administrator titles. You must understand: These decisions directly affect how a security operations team separates policy […]Open lesson →
- 03Microsoft Purview Data Loss Prevention Policy Configuration – SC-200 Study GuidePurpose of This Lesson This lesson explains how to create and configure a Data Loss Prevention policy in Microsoft Purview. The policy is designed to identify sensitive information, notify users and administrators, generate alerts, and optionally restrict how protected content is shared or used. For the SC-200 exam, the main objective is not simply memorizing […]Open lesson →
- 04Microsoft Purview DLP Policy Priority and Rule Precedence – SC-200 Study GuidePurpose of This Lesson This lesson explains how Microsoft Purview Data Loss Prevention determines which policy or rule takes precedence when multiple DLP controls apply to the same content or user activity. The two central concepts are: These concepts matter for the SC-200 exam because a Security Operations Analyst must understand why a DLP event […]Open lesson →
- 05Microsoft Purview DLP Policy Priority and Rule Precedence – SC-200 Study GuidePurpose of This Lesson This lesson explains how Microsoft Purview Data Loss Prevention handles precedence when multiple DLP policies or rules could apply to the same activity. There are two separate concepts to understand: The most important distinction is that Microsoft Purview DLP treats a lower policy priority number as a higher priority. A policy […]Open lesson →
- 06Microsoft Purview Insider Risk Management Planning and Investigation – SC-200 Study GuidePurpose of This Lesson Microsoft Purview Insider Risk Management helps organizations identify, investigate, and respond to risky activities performed by people inside the organization. Insider risk does not always involve a malicious employee. It can also result from mistakes, poor security awareness, excessive permissions, careless data handling, or users attempting to complete legitimate work through […]Open lesson →
- 07Microsoft Purview Unified Audit Log Licensing and Requirements – SC-200 Study GuideUnderstand Microsoft Purview unified audit log licensing, Standard versus Premium capabilities, retention, APIs, and SC-200 investigation decisions.Open lesson →
- 08Microsoft Purview Audit Search and Permissions – SC-200 Study GuideLearn how to use Microsoft Purview Audit for Microsoft 365 threat investigation, filtering, event analysis, permissions, evidence export, and SC-200 exam decisions.Open lesson →
- 09Microsoft Purview Content Search and eDiscovery – SC-200 Study GuideLearn how to use Microsoft Purview Content Search and eDiscovery for SC-200 investigations, evidence preservation, indexing limits, search scope, and result analysis.Open lesson →
Module 08
KQL and Threat Hunting
- 01Threat Hunting with Microsoft Graph Activity Logs – SC-200 Study GuideLearn how to configure Microsoft Graph activity logs with Microsoft Entra diagnostic settings, Log Analytics, KQL, and SOC investigation workflows for the SC-200 exam.Open lesson →
- 02KQL for Microsoft Security Investigations and Threat Hunting – SC-200 Study GuideLearn how KQL supports Defender XDR, Microsoft Sentinel, Purview audit analysis, threat hunting, analytics rules, and SC-200 incident investigations.Open lesson →
- 03Practicing KQL in Microsoft’s Demo Environment – SC-200 Study GuidePractice Microsoft KQL with the demo environment, AI-assisted query drafting, schema validation, and SC-200 SOC investigation guidance.Open lesson →
- 04Searching for Information with Basic KQL Syntax – SC-200 Study GuideLearn foundational KQL for SC-200: tables, time ranges, search versus where, Boolean logic, Windows logon events, and SOC investigation techniques.Open lesson →
- 05Summarizing KQL Results and Filtering Time Ranges – SC-200 Study GuideLearn SC-200 KQL techniques for time filtering, summarize, count, dcount, top, extend, and efficient Microsoft security investigations.Open lesson →
- 06Using KQL to Filter, Shape, and Calculate Security Data – SC-200 Study GuideLearn SC-200 KQL techniques for filtering, projecting, sorting, limiting, and calculating Microsoft security event data for SOC investigations.Open lesson →
- 07KQL Variables, Union, and Join for Security Investigations – SC-200 Study GuideLearn how SC-200 exam candidates use KQL let variables, union, and inner joins to reuse filters, combine security events, and correlate SOC investigation data.Open lesson →
- 08Microsoft Defender Advanced Hunting and KQL – SC-200 Study GuideLearn Microsoft Defender Advanced Hunting and KQL for SC-200, including tables, filters, time ranges, sorting, variables, threat investigation, and common exam traps.Open lesson →