What the SC-200 is and who it is for
The SC-200 is Microsoft’s role based certification for security operations analysts. It is the exam for people who sit in a SOC and spend their day triaging alerts, investigating incidents, hunting for threats and building detections. Microsoft describes the goal as reducing organisational risk, and the tooling it expects you to know is its own native security stack: Microsoft Sentinel, Microsoft Defender XDR and Microsoft Defender for Cloud.
It suits analysts who already work in those products and people moving from general IT into a security operations role. It is not a theory exam: if you have never opened Sentinel or written a KQL query, expect most of your preparation to be hands on.
The skills measured were updated on 28 July 2026, and the certification renews annually through a free assessment on Microsoft Learn, so once you have it, keeping it is cheap.
Microsoft SC-200 at a glance
| Item | Detail |
|---|---|
| Exam code | SC-200 |
| Questions | 40 to 60 |
| Time allowed | 100 minutes |
| Passing score | 700 out of 1000 |
| Exam fee | US$165 in the US, priced in local currency elsewhere |
| Where you sit it | Online proctored or at a test centre |
| Certification valid for | One year, renewed free through a Microsoft Learn assessment |
What is on the exam
Manage a security operations environment (40 to 45%). This is the largest domain and it covers the plumbing of a SOC built on Microsoft tools. Expect questions on setting up and tuning a Sentinel workspace, connecting data sources, configuring Defender XDR and Defender for Cloud so the right signals arrive, and writing the analytics rules that turn raw logs into alerts.
Respond to security incidents (35 to 40%). Just over a third of the exam is about what happens once an alert fires. You are tested on investigating incidents across Defender XDR and Sentinel, deciding what the evidence means, taking response actions and automating the routine parts. Scenario questions describe an incident in progress and ask what you do next, so you need to know both the products and the reasoning an analyst applies.
Perform threat hunting (20 to 25%). The smallest domain, but the one that catches the most people out because it leans hardest on KQL. You will be asked to interpret and write queries against Sentinel and Defender data, build hunting queries, and turn what you find into detections. Knowing where the data lives and how to shape a query quickly is the whole point here.
Why people fail it
The most common failure is KQL. It is entirely possible to know Defender XDR inside out and still lose marks on a query you have not seen before, because query questions test whether you can read a few lines of KQL and predict the output, or spot the operator that is wrong. Candidates who skip query practice forget that queries also appear in analytics rule and investigation questions.
The second cause is studying from the old blueprint. Before 28 July 2026 the exam was split product by product: Sentinel, then Defender XDR, then Defender for Cloud. That split is gone. The exam is now organised around what an analyst does, running the environment, responding to incidents and hunting. Material built around “50% Sentinel” is aimed at a blueprint that no longer exists, and it teaches you to think in products when the questions think in tasks.
The third is treating it as a reading exam. Microsoft tests real scenarios: which Defender product applies, how an analytics rule should be configured, what the next investigation step is. Documentation alone does not prepare you for that wording.
A study plan that fits the exam
This is a six week plan weighted to the domains. If you work in Sentinel daily you can compress the first three weeks. Take the free SC-200 practice questions first, so you know the question style and which domain feels weakest.
- Week 1: the SOC environment, part one. Sentinel workspaces, data connectors, log tables and workbooks. Set up a trial tenant if you do not have one at work and connect at least a few data sources yourself.
- Week 2: the SOC environment, part two. Analytics rules, Defender XDR configuration and Defender for Cloud onboarding. Build a scheduled rule from scratch and understand every field on the form.
- Week 3: KQL every day. Spend the whole week on the query language: filtering, summarising, joins, time windows and the common tables. Write queries against real data, then predict the output before you run them.
- Week 4: incident response, part one. Investigate incidents in Defender XDR and Sentinel, follow the evidence across entities, and learn the response actions available in each product.
- Week 5: incident response, part two, plus hunting. Automation and playbooks, then move into hunting queries and turning a hunt into a detection. Start working through the 462 questions in the SC-200 practice pack, reading the explanations for wrong options as carefully as the right ones.
- Week 6: timed runs and gaps. Use the questions only copy for full length runs at 100 minutes with 60 questions. Every question you miss goes back to the product for a hands on repeat, not just a re read.
On exam day
You can sit the SC-200 online with a proctor or at a test centre. Online, clear your desk, test your webcam and internet the day before, and allow time for check in. At a centre you avoid the technical risk but should still arrive early.
You have 100 minutes for between 40 and 60 questions, which is roughly one and a half to two and a half minutes each. Scenario questions read long, so do not spend the first minute re reading the setup: find the question first, then go back for the details that matter. If a KQL question is not resolving, mark it and move on, because a stuck query costs more time than any other question type. The pass mark is 700 out of 1000, and Microsoft scales the score, so do not try to count correct answers in your head.
Frequently asked questions
What happens if I fail the SC-200?
You pay the exam fee again, US$165 in the US, and you have to wait before you can rebook. Microsoft’s retake policy asks you to wait 24 hours after a first fail, then 14 days between each later attempt, so check the current policy on the Microsoft Learn exam page before you schedule. Use the wait to go back to the domain that scored lowest on your score report rather than restudying everything.
Is the practice pack enough on its own?
No, and it is not designed to be. The pack is 462 practice questions with explanations, aligned to the 28 July 2026 blueprint. It shows you the question style, exposes gaps and gives you timed runs. It does not replace hands on time in Sentinel and Defender, and it cannot teach you KQL from nothing. Pair it with a tenant you can experiment in and Microsoft’s own learning paths.
Do I really need KQL for the SC-200?
Yes. Query questions appear across the exam, not only in the hunting domain. If you can read a query and say what it returns, and write a basic filtered, summarised query without help, you are in good shape.
How long does the certification last?
It renews annually, and the renewal is a free assessment on Microsoft Learn rather than a full exam, so the cost after the first pass is only your time.
When you are ready to test yourself against the new blueprint, the SC-200 practice question pack is US$39, refunded if you fail.
