Technology8 min read

SC-200 2026: Microsoft SOC Workflow Study Guide

A current SC-200 guide for security operations analysts: the 2026 Microsoft skills outline, July 28 2026 update, price, languages, Sentinel, Defender XDR, incident response, KQL, and threat hunting.

Ran Chen, EA, CFP®May 4, 2026

Key Facts

  • SC-200 earns the Microsoft Certified: Security Operations Analyst Associate credential for Microsoft security operations analysts.
  • The SC-200 exam fee is about 165 USD, with the exact price set by the country or region where it is proctored.
  • The Microsoft SC-200 exam gives candidates 100 minutes and typically contains roughly 40 to 60 questions.
  • Microsoft requires a scaled score of 700 out of 1000 or greater to pass the SC-200 exam.
  • The Security Operations Analyst Associate credential renews every 12 months through a free Microsoft Learn online assessment.
  • SC-200 weights Manage a security operations environment at 40-45% of the official Microsoft exam outline.
  • SC-200 weights Respond to security incidents at 35-40% of the official Microsoft Learn skills-measured exam outline.
  • SC-200 weights Perform threat hunting, including KQL, at 20-25% of the official Microsoft Learn exam outline.
  • Microsoft will update the English SC-200 exam on July 28, 2026, keeping the same three groups and percentage weights.
  • SC-200 is offered in ten languages, including English, Japanese, Korean, French, German, Spanish, and Italian.

📺 Watch the Video

SC-200 Changed: Study The 2026 SOC Workflow, Not Last Year's Domain Map

Microsoft SC-200 is the exam for the Microsoft Certified: Security Operations Analyst Associate credential. In 2026, the best SC-200 prep starts with one fact many older guides miss: the current Microsoft Learn study guide lists three functional groups, not the older four-domain outline. The weights are Manage a security operations environment at 40-45%, Respond to security incidents at 35-40%, and Perform threat hunting at 20-25%. Microsoft is rolling a scheduled update to the English exam on July 28, 2026 that keeps these same three groups and the same percentage ranges, while refreshing the underlying objectives toward agentic AI and embedded Microsoft Security Copilot, Sentinel Graph, KQL jobs in the data lake, summary rule tables, and the Sentinel MCP Server. Localized languages update roughly eight weeks later.

That change matters. SC-200 is no longer best approached as a loose tour of Sentinel, Defender, and KQL. It is a workflow exam: configure the SOC environment, respond to incidents across Microsoft security products, then hunt for threats using Defender XDR, Microsoft Sentinel, KQL, Sentinel Graph, notebooks, and related data lake capabilities.

free SC-200 practice questionsPractice questions with detailed explanations

The 2026 Microsoft Exam Frame

Item2026 detail
CredentialMicrosoft Certified: Security Operations Analyst Associate
ExamSC-200: Microsoft Security Operations Analyst
Exam length100 minutes
QuestionsAbout 40-60 items (Microsoft does not publish an exact count)
Passing score700 out of 1000 (scaled)
PriceAbout 165 USD, varies by country or region
RenewalEvery 12 months, free Microsoft Learn renewal assessment
ProviderPearson VUE, test center or online proctored
LanguagesEnglish, Japanese, Korean, French, German, Spanish, Italian, Portuguese (Brazil), Chinese (Simplified), Chinese (Traditional)
Skills outlineThree groups; scheduled English update July 28, 2026
DomainsSOC environment 40-45%, incident response 35-40%, threat hunting 20-25%
Official pageMicrosoft SC-200 certification page

Microsoft says candidates reduce organizational risk by triaging, responding to incidents, hunting threats, and engineering detections. The exam expects familiarity with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Defender for Cloud workload protections, KQL, Sentinel Graph, AI agents, and Copilots.

On logistics: the SC-200 fee is about 165 USD, though the price is set by the country or region where you are proctored, so it differs in GBP, EUR, INR, and other currencies. Microsoft does not publish a fixed question count, but candidates typically report roughly 40 to 60 items, including multiple-choice, drag-and-drop, and case-study formats. The exam is offered in ten languages: English, Japanese, Korean, French, German, Spanish, Italian, Portuguese (Brazil), Chinese (Simplified), and Chinese (Traditional). If the exam is not offered in your preferred language, you can request an extra 30 minutes. There is no formal prerequisite, but Microsoft recommends prior hands-on security operations experience.

Domain 1: Manage A Security Operations Environment

This is now the largest domain at 40-45%. Treat it as the foundation of the exam. You need to know how a SOC environment is configured before you can answer response or hunting questions reliably.

Focus on automation for Microsoft Defender XDR and Microsoft Sentinel, alert notifications, tuning and suppression, automated investigation and response, automatic attack disruption, Sentinel automation rules, and playbooks. Then study the Sentinel platform: roles, retention, workbooks, data tiers, SOC optimization, data connectors, Windows Security Events through AMA, data collection rules, Syslog, CEF, Azure activity logs, threat indicators, custom log tables, analytics rules, near-real-time rules, machine learning rules, anomalies, and MITRE ATT&CK coverage.

The trap is thinking this domain is only administration. It is administration that changes detection quality. If you cannot explain how data is ingested, retained, normalized, alerted, and automated, you will struggle with scenario questions.

Domain 2: Respond To Security Incidents

Incident response is 35-40% of the exam and is the most realistic part of SC-200. You need to know where to investigate, which portal or product owns the signal, and which response action is appropriate.

Expect questions involving Microsoft Defender XDR incidents, Defender for Office 365, Microsoft Purview investigations, Defender for Cloud workload protections, Defender for Cloud Apps, Microsoft Entra ID, Defender for Identity, Microsoft Sentinel, Defender for Endpoint device timelines, live response, investigation packages, evidence and entity investigation, case management, Audit, Content Search, Microsoft Graph activity logs, complex multi-stage attacks, lateral movement, and embedded Copilot for Security.

Do not memorize response actions in isolation. Build an incident worksheet: alert source, affected entity, evidence source, containment action, remediation action, automation option, and documentation step.

Domain 3: Perform Threat Hunting

Threat hunting is 20-25%, but it can feel larger because KQL shows up across operations and response. You should be comfortable choosing the right table, writing and interpreting KQL, creating Advanced Hunting queries, using threat analytics, creating hunting graphs, analyzing entity relationships in Sentinel Graph, creating and monitoring Sentinel hunting queries, and using notebooks where appropriate.

The best prep is short daily KQL practice. Do not save KQL for the last week. Work with process, network, identity, email, cloud, and device examples until you can recognize which table and field would answer a question.

Six Weeks Through Sentinel, Defender, And KQL

SC-200 practice questionsPractice questions with detailed explanations

Week 2: Configure the SOC environment. Study Defender XDR settings, Sentinel roles, connectors, AMA data collection rules, CEF/Syslog ingestion, retention, workbooks, automation rules, playbooks, analytics rules, custom detections, and MITRE mapping.

Week 3: Practice incident response workflows. Work through Defender XDR, Sentinel, Entra ID, Purview, Defender for Endpoint, Defender for Cloud Apps, Defender for Cloud, and case management scenarios. For every miss, identify whether the gap was tool selection, evidence interpretation, or response action.

Week 4: Drill KQL and hunting. Write small queries daily. Practice identifying tables, filtering events, projecting fields, joining where needed, summarizing counts, and explaining why a query finds a threat pattern.

study guidePractice questions with detailed explanations

Week 6: Final review. Target high accuracy on SOC environment questions because it is the largest domain. Rehearse incident triage checklists and KQL table selection. Review Microsoft Learn updates one last time before scheduling.

What Older SC-200 Guides Miss

Many pages still emphasize older domain names and smaller percentages. That can misallocate your study time. If a guide tells you incident response is 25-30% or separates configure protections and detections into its own 15-20% domain, compare it against Microsoft's current study guide before relying on it.

The current outline makes environment configuration nearly half the exam. The scheduled July 28, 2026 English update keeps the same three groups and weights, but it also explicitly adds newer operational language around agentic AI, embedded Security Copilot, Sentinel Graph, KQL jobs in the data lake, summary rule tables, and Sentinel MCP Server references. You do not need to become an expert in every feature, but you do need to recognize where each feature belongs in a SOC workflow.

SOC Analyst Readiness Check

You are ready when you can describe the SC-200 domains from memory, explain how Sentinel ingests and retains data, choose the right Defender or Sentinel response action, interpret a device timeline, distinguish Audit from Content Search, write basic KQL without panic, map detections to MITRE ATT&CK, and explain how automation rules and playbooks differ.

If your practice misses cluster around KQL, schedule later. If they cluster around product boundaries, make a one-page map of Defender XDR, Sentinel, Purview, Entra ID, Defender for Cloud, and Defender for Cloud Apps.

2026 Lab Checklist

The current SC-200 outline is practical. Build labs around the workflows Microsoft names, not around product tours. In Defender XDR, practice incident queues, alert tuning, automated investigation concepts, action center review, threat analytics, and role-based access. In Sentinel, practice connecting data, analytics rules, incidents, workbooks, automation rules, playbooks, watchlists, content hub solutions, and KQL queries.

For hunting, write KQL daily. You should be comfortable filtering, projecting, summarizing, joining, parsing, using time windows, and turning a query into an investigation path. The current outline and the July 28, 2026 update also name Sentinel Graph, notebooks, data lake jobs, agentic AI, and Copilots, so candidates using older courses need to check whether those workflows are covered.

A good readiness test is whether you can explain the SOC lifecycle from telemetry collection to incident triage, investigation, response, automation, hunting, and leadership reporting without switching study guides.

Microsoft Pages To Check Before Scheduling

SC-200 practice questionsPractice questions with detailed explanations
Test Your Knowledge
Question 1 of 3

Which SC-200 domain has the largest current 2026 weight?

A
Configure protections and detections
B
Manage a security operations environment
C
Perform threat hunting
D
Manage identity governance
Learn More with AI

10 free AI interactions per day

SC-200Microsoft Security Operations AnalystMicrosoft SentinelMicrosoft Defender XDRKQLthreat huntingincident responseMicrosoft certification

Related Articles

Stay Updated

Get free exam tips and study guides delivered to your inbox.

Free exam tips & study guides. Unsubscribe anytime.