Microsoft SC-200 Exam Prep
Security operations across Defender XDR, Sentinel, and Purview, the way SC-200 tests it.
Tuition
$199
Beginner
Level
3
Modules
12
Lessons
3
Graded quizzes
8 hours
Estimated time
What you will be able to do
- Configure and manage a Microsoft Defender XDR and Sentinel operations environment
- Triage and manage incidents in the unified queue
- Respond to endpoint threats with Microsoft Defender for Endpoint
- Respond to identity, email, and cloud app threats
- Investigate Microsoft 365 activity with Purview Audit and eDiscovery
- Hunt threats with KQL and manage Sentinel analytics
- Pass a timed practice exam against the current SC-200 outline
What is inside
3 modules, 12 lessons. Each module ends in a graded quiz.
- 01
Building and Managing the Security Operations Environment
Covers the Microsoft Security Operations Analyst (SC-200) domain "Manage a security operations environment", the single heaviest area of the exam at 40 to 45 percent of scored content. You will configure Microsoft Defender XDR automation and Microsoft Sentinel workspace settings, connect and normalize data sources, and engineer the detections that turn that data into incidents. Every lesson pairs the exact portal setting with the reasoning the exam expects when it asks for the BEST or MOST cost effective approach.
4 lessons · 15 quiz questions
- 02
Responding to Incidents Across Endpoint, Identity, Email, and Cloud
Covers the Microsoft Security Operations Analyst (SC-200) domain "Respond to security incidents", the second heaviest area of the exam at 35 to 40 percent of scored content. You will triage and manage incidents in the unified Microsoft Defender portal queue, respond on devices with Microsoft Defender for Endpoint, and remediate compromises across identity, email, cloud applications, cloud workloads, and Microsoft Purview data signals. Every lesson drills the decision the exam actually tests: which response action, taken in which product, and in which order.
4 lessons · 15 quiz questions
- 03
Proactive Threat Hunting with KQL
Covers the SC-200 exam domain Perform threat hunting, which carries 20 to 25 percent of the scored content. You will learn to pick the right table, write and tune Kusto Query Language (KQL) queries, hunt across Microsoft Defender XDR and the Microsoft Sentinel platform, and scale investigations with graph queries, data lake jobs, summary rules, and notebooks. Every lesson teaches the decision the exam actually asks you to make: which tool, which table, which operator, and which artifact to produce next.
4 lessons · 15 quiz questions