Microsoft Security Operations Analyst Associate (SC-200) Cert Prep by Microsoft Press
8h 46mIntermediate2026-07-24
Authors

Microsoft Press
Microsoft
Course details
Prepare to pass the SC-200 Microsoft Security Operations Analyst certification exam and step into a role focused on reducing organizational risk through threat detection, incident response, and proactive hunting. Learn how to configure automation across Microsoft Defender XDR and Microsoft Sentinel, ingest and analyze security data, and build custom detections that surface real threats. Investigate and remediate incidents across the full Microsoft security stack—Defender for Endpoint, Office 365, Purview, Cloud, Cloud Apps, Entra ID, and Defender for Identity—including AI-assisted investigations with embedded Security Copilot. Explore proactive threat hunting with Kusto Query Language (KQL), advanced hunting queries, Sentinel Graph, and notebooks connected to the Sentinel MCP server. After completing this course, you'll have the knowledge you need to operate confidently as a security operations analyst and sit for exam SC-200.
Learning objectives
Manage a security operations environment in Microsoft Defender XDR and Microsoft Sentinel.
Configure protections and detections across Microsoft's security platforms.
Manage incident response across identity, endpoint, cloud, and Microsoft 365 workloads.
Manage security threats through proactive hunting with KQL, Sentinel Graph, and notebooks.
Learning objectives
Manage a security operations environment in Microsoft Defender XDR and Microsoft Sentinel.
Configure protections and detections across Microsoft's security platforms.
Manage incident response across identity, endpoint, cloud, and Microsoft 365 workloads.
Manage security threats through proactive hunting with KQL, Sentinel Graph, and notebooks.
Concepts
Introduction
- Exam SC-200 Microsoft Security Operations Analyst - Introduction
Configure Automation for Microsoft Defender XDR and Microsoft Sentinel
- Learning Objectives
- Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analysis
- Configure alert notifications in Microsoft Defender XDR, including tuning, suppression, and correlation
- Configure Microsoft Defender for Endpoint advanced features
- Configure rule settings in Microsoft Defender for Endpoint
- Configure custom datasets in Microsoft Defender for Endpoint
- Configure Microsoft Defender for Endpoint security policies, including ASR rules
- Manage automated review and response capabilities in Microsoft Defender XDR
- Configure automated attack mitigation in Microsoft Defender XDR
- Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint
- Create and configure automation rules in Microsoft Sentinel
- Create and configure Microsoft Sentinel guides
Configure Microsoft Sentinel SIEM and Platform
- Learning Objectives
- Identify Microsoft Sentinel roles
- Manage data retention for XDR and Microsoft Sentinel tables, including analytics, data lakes, and XDR layers
- Create and configure Microsoft Sentinel workbooks
- Optimize the Microsoft Sentinel platform, including SOC optimization recommendations
Ingest data into Microsoft Sentinel SIEM and Platform
- Learning Objectives
- Select data connectors based on data source needs, including Windows logs and security events
- Configure Windows Security Event Collection using Windows Security Events through AMA, including data collection rules
- Plan and configure Windows Security Event Collection using WEF
- Plan and configure Syslog through AMA and CEF through AMA connectors
- A collection Configure Azure Activities using Azure Policy and Resource Troubleshooting Settings
- Import threat markers into Microsoft Sentinel
- Create custom logging tables in the workspace to store the received data
Configure Detections in Defender XDR and Sentinel
- Learning Objectives
- Create custom detection rules using Advanced Hunting in Microsoft Defender XDR
- Manage custom detection rules in Microsoft Defender XDR
- Configure and manage analysis rules in Microsoft Sentinel SIEM, including scheduled, NRT, threat intelligence, and machine learning
- Analyze attack vector coverage using the MITRE ATT&CK matrix
- Configure anomalies in Microsoft Sentinel
Respond to alerts and incidents in Microsoft Defender XDR
- Learning Objectives
- Investigate and remediate threats using Microsoft Defender for Office 365, including automated attack disruption
- Threats or Review and remediate compromised entities identified by Microsoft Purview.
- Review and remediate alerts and incidents identified by Microsoft Defender for Cloud Workload Protection
- Review and remediate security risks identified by Microsoft Defender for Cloud Apps
- Review and remediate compromised identities identified by Microsoft Entra ID.
- Review and remediate Microsoft Defender for Identity security alerts
- Review and remediate alerts and incidents detected by Microsoft Sentinel
- Investigate incidents using agent-based AI, including Copilot Embedded Security
- Investigate complex attacks such as multi-step, multi-domain, and lateral movement
- Manage security incidents using case management
Respond to alerts and incidents in Microsoft Defender for Endpoint
- Learning objectives
- Review device timeline
- Take actions on the device including live response and collect investigation packages
- Perform evidence and entity review
- Review and remediate incidents detected with automated attack disruption
Review Microsoft 365 activities for threat detection
- Learning objectives
- Investigate threats using Audit from Microsoft Purview
- Investigate threats using Content Search in Microsoft Purview
- Identify threats using Review Microsoft Graph activity reports
Identify threats using Microsoft Defender XDR
- Learning Objectives
- Identify the appropriate table to use in a KQL query
- Identify threats using KQL
- Create an Advanced Hunting expression
- Interpret threat analysis in Microsoft Defender XDR
- Create hunting graphs, including blast radius
- Analyze relationships between entities using Sentinel Graph
Identify threats using the Microsoft Sentinel Platform
- Learning Objectives
- Create and monitor hunting queries
- Create and manage KQL jobs in the data lake
- Create and manage summary rule tables for queries
- Search for threats using notebooks, including connecting to the Sentinel MCP server
Summary
- Microsoft Security SC-200 Exam