Free SC-200 Exam Flashcards
Memorize 50 essential terms and definitions for the Microsoft Certified: Security Operations Analyst Associate (SC-200). See the term, recall the definition, then flip to check yourself.
Microsoft Defender XDR
The unified extended detection and response platform at security.microsoft.com that correlates signals across endpoints, email, identity, apps, and cloud into a single incident with a unified investigation experience.
Filter by Topic
Jump to Card
About These SC-200 Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the Microsoft Certified: Security Operations Analyst Associate (SC-200). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Frequently Asked Questions
What is the SC-200 passing score?
SC-200 requires 700 out of 1000 on a scaled scoring system, roughly 70%. The exam typically has 40-60 questions delivered in 100 minutes through Pearson VUE, either online proctored or at a test center.
What changed in the April 16, 2026 SC-200 update?
Microsoft consolidated the exam from five domains to three: Manage a security operations environment (40-45%), Respond to security incidents (35-40%), and Perform threat hunting (20-25%). Sentinel Graph, the Data lake tier, agentic AI investigation with embedded Copilot for Security, KQL jobs, Summary rules, and the Sentinel MCP Server were added.
Is Azure Sentinel still on SC-200?
Yes, now called Microsoft Sentinel after the rebrand. SC-200 covers Sentinel workspaces, data connectors (AMA, CEF/Syslog via AMA, WEF), analytics rules (scheduled, NRT, threat intelligence, ML), automation rules, playbooks, hunting queries, Sentinel Graph, and the new Data lake retention tier.
How much KQL is on SC-200?
KQL appears across all three domains. Expect to read and reason about queries using tables such as DeviceEvents, EmailEvents, IdentityLogonEvents, SecurityAlert, SecurityIncident, and SigninLogs, and operators like where, project, summarize, join, and time functions ago() and bin().
What does SC-200 cost and how is it renewed?
The SC-200 exam fee is $165 USD in the United States; regional pricing varies. Microsoft Learn training is free. The certification is valid for one year and renews free of charge through the renewal assessment on Microsoft Learn.
How is SC-200 different from AZ-500 and SC-100?
SC-200 focuses on operating the Microsoft security stack as a SOC analyst (detection, investigation, response, hunting). AZ-500 focuses on engineering Azure platform security controls. SC-100 is the expert cybersecurity architect exam that builds on top of both.
Explore More Microsoft Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.