SC-200 · ● Active · Associate · Microsoft
This intermediate security certification validates expertise in threat mitigation using Microsoft's XDR and cloud-native security platform. Targets SOC analysts, security operations engineers, and threat hunters with hands-on experience managing security incidents. Requires strong understanding of Microsoft Defender solutions (Endpoint, Office 365, Identity, Cloud Apps), Microsoft Sentinel SIEM/SOAR platform, and cloud security with Microsoft Defender for Cloud. SC-900 foundational knowledge recommended; practical SOC experience highly valued.
Exam facts
| Field | Value |
|---|---|
| Cost | $165 USD (regional pricing may vary) |
| Duration | 100–120 minutes |
| Questions | 40–60 questions (mix of multiple choice, multiple response, and case studies) |
| Passing | 700/1000 scaled score |
| Format | Multiple choice, multiple response, case studies |
| Delivery | Pearson VUE (online or test center) |
| Languages | English, Japanese, Spanish, German, French, Portuguese (BR), Korean, Simplified Chinese, Traditional Chinese, Dutch, Arabic |
| Valid | 12 months from date of passing (no renewal — retake to maintain) |
| Renewal | Pass the exam again or pursue higher-level cert (SC-100) |
| Prerequisites | SC-900 recommended; hands-on SOC experience required |
| Released | May 2020 |
| Retiring | N/A (active, no retirement date announced) |
Vendor source — Microsoft Certified: Security Operations Analyst Associate ↗
Official exam guide — Exam SC-200 study guide ↗
Exam objectives — SC-200 exam details ↗
About
SC-200 is Microsoft's intermediate security certification launched May 2020, targeting security operations professionals (SOC analysts, Tier 2–3 analysts, incident responders) with 1–2+ years of hands-on experience managing security incidents in cloud and hybrid environments. The exam validates ability to detect, investigate, and remediate threats using Microsoft's integrated XDR platform (Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps) and the cloud-native SIEM/SOAR platform (Microsoft Sentinel). Unlike SC-900 (foundational), SC-200 emphasizes practical threat-hunting techniques, incident triage, KQL query writing, workbook development, and automation through Logic Apps playbooks. Popular with organizations adopting Microsoft security solutions and building in-house SOC capabilities. Passing SC-200 unlocks eligibility for SC-100 (Cybersecurity Architect Expert) and other advanced security specializations.
Domain context — Security
Microsoft's comprehensive cloud-native security portfolio protecting identities, applications, data, and infrastructure across hybrid and multi-cloud environments. Spans identity governance, threat detection and response, compliance automation, and data protection — unified under a Zero Trust architecture model.
Read full deep dive — Microsoft Security Ecosystem → | Read full deep dive — Security Domain →
Topics covered
The exam blueprint organizes topics across three weighted domains, as follows:
- Mitigate threats using Microsoft Defender XDR (30–35%) — Microsoft Defender for Endpoint (device detection and response, threat analytics, advanced hunting), Microsoft Defender for Office 365 (email and collaboration threats, safe links, safe attachments), Microsoft Defender for Identity (identity and authentication threats, lateral movement detection), Microsoft Defender for Cloud Apps (SaaS threat detection, conditional access policies, app governance), Microsoft Defender Experts for Hunting (proactive threat hunting and expert-led incident response)
- Mitigate threats using Microsoft Defender for Cloud (20–25%) — configure and manage Defender for Cloud, regulatory compliance and security baselines, workload protections (VMs, databases, containers, app service), threat intelligence integration and alerts, security posture management
- Mitigate threats using Microsoft Sentinel (50–55%) — configure Sentinel workspace and data connectors, create and manage analytics rules (scheduled, near-real-time, machine learning), manage incidents and alerts, threat hunting using Kusto Query Language (KQL), workbooks and dashboards, automation and orchestration (SOAR playbooks with Logic Apps), User and Entity Behavior Analytics (UEBA), watchlists, threat intelligence feeds in Sentinel
Source: Official exam guide ↗
Common skills at Security · Associate
Shared intermediate security skills at associate level — not specific to this cert.
- Threat detection and incident response workflows
- Security incident triage and priority assessment
- Malware and attack pattern recognition
- Log aggregation and analysis at scale
- Query language proficiency (KQL, Splunk SPL, or equivalent)
- Cloud security architecture and shared responsibility models
- Identity and access control threat vectors
- Vulnerability assessment and remediation prioritization
- Security playbook and runbook development
- Threat hunting and proactive investigation techniques
- SIEM/SOAR platform administration and tuning
- Alert fatigue management and fine-tuning
Recommended courses at Security · Associate
| Provider | Title | Cost | URL |
|---|---|---|---|
| Microsoft Learn (Official) | Security Operations Analyst (SC-200T00) | Free | ↗ |
| Microsoft Learn (Official) | Mitigate threats with Microsoft Defender learning path | Free | ↗ |
| Coursera (Microsoft) | Microsoft Defender, Threat Protection, and Azure Security Operations | Free (audit) / $39/mo | ↗ |
| Pluralsight | SC-200: Security Operations Analyst | $299/yr subscription | ↗ |
| Udemy (various) | SC-200 Security Operations Analyst Exam Prep | $10–$80 | ↗ |
| LinkedIn Learning | Security Operations with Microsoft Defender and Sentinel | $25–$40/mo | ↗ |
| YouTube (John Savill) | SC-200 Security Operations Analyst Study Cram | Free | ↗ |
| A Cloud Guru / AcloudGuru | SC-200: Security Operations Analyst | $29–$49/mo | ↗ |
Course-selection rule: Microsoft Learn (free, official) is the recommended baseline covering all three domains. Coursera and Pluralsight provide structured video instruction; Udemy options are budget-friendly for targeted review. A Cloud Guru and YouTube creators offer practical, hands-on deep dives with real Sentinel and Defender labs.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| MeasureUp (Official Microsoft Partner) | SC-200 Security Operations Analyst | $99 | ↗ |
| Whizlabs | SC-200 Security Operations Analyst Practice Exams | $39–$69 | ↗ |
| Microsoft Learn (Free) | Practice assessments in study guide | Free | ↗ |
| Tutorials Dojo | SC-200 Security Operations Analyst Practice Exams | Free (limited) / $12–$20 (full) | ↗ |
Practice exam rule: MeasureUp (official partner) includes 2 full exams with 150+ questions and expert explanations; essential for validating Sentinel and KQL proficiency. Whizlabs offers 2 exams with 100+ unique questions at lower cost. Microsoft Learn's free practice assessments cover all domains — start here before purchasing third-party exams.
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Exam Ref SC-200 Microsoft Security Operations Analyst | Sander van Vugt | Microsoft Press | 2024 | 9780137930204 | ↗ |
Book rule: van Vugt's Exam Ref SC-200 is the current official study guide aligned with the 2026 exam blueprint. It covers all three domains with practical examples, hands-on Sentinel labs, KQL query walkthroughs, and review questions. Updated to reflect recent Defender XDR and Sentinel capabilities.
Typical job titles at Security · Associate
Security Operations Analyst · SOC Analyst (Tier 2/3) · Cloud Security Analyst · Threat Hunter · Incident Responder · SIEM Engineer · Analyst (Security Monitoring) · Detection and Response Analyst · Security Engineer (SOC) · Security Consultant (Threat Operations)
(Job titles drawn from current job-board postings that list SC-200 or "Security Operations Analyst" as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $95k–$145k (SOC Analyst Tier 2–3) | Glassdoor ↗ · ZipRecruiter ↗ · Robert Half ↗ |
| ZAR | R380k–R680k (SOC Analyst mid-level) | Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗ |
| GBP | £58k–£88k (SOC Analyst Tier 2–3) | IT Jobs Watch ↗ · Hays ↗ |
| EUR | €66k–€100k (DE/NL/FR mid-level SOC) | Indeed ↗ · Glassdoor EU ↗ |
| AUD | A$122k–A$178k (SOC Analyst mid-level) | Seek ↗ · LinkedIn Jobs ↗ |
Salary rule: SC-200 is an intermediate credential for hands-on security operations roles requiring 1–2+ years of SOC experience. Salary reflects Tier 2–3 analyst positions managing incident detection, investigation, and remediation. Progression to SC-100 (Cybersecurity Architect Expert) or AZ-500 (Azure Security Engineer Associate) typically increases salary by 20–40%. Figures are 2026 market snapshots and vary by geography, employer size, industry, and prior background.
Skills validated
Cert-specific — what this exam actually tests.
- Threat detection using Microsoft Defender for Endpoint (EDR, advanced hunting queries)
- Email and collaboration threat detection (Microsoft Defender for Office 365)
- Identity-based threat detection (Microsoft Defender for Identity, lateral movement)
- SaaS threat detection and anomaly detection (Microsoft Defender for Cloud Apps)
- Microsoft Defender XDR integration and correlation
- Microsoft Defender Experts for Hunting engagement and escalation
- Microsoft Sentinel workspace configuration and deployment
- Connector integration (100+ data sources, syslog, CEF, custom logs)
- KQL (Kusto Query Language) fundamentals and advanced queries
- Analytics rule creation (scheduled, near-real-time, machine learning-based)
- Incident management and triage workflows in Sentinel
- Alert optimization and tuning to reduce false positives
- Threat hunting methodologies and hypothesis-driven searches
- Workbooks and dashboards for visualization and SOC reporting
- Automation and orchestration with Logic Apps playbooks
- UEBA (User and Entity Behavior Analytics) configuration
- Watchlists and threat intelligence feed integration
- Microsoft Defender for Cloud workload protections and compliance
- Security posture assessment and remediation guidance
- Incident response playbooks and containment tactics
Related certifications
- Stacks with: Microsoft AZ-500 (Azure Security Engineer Associate) ↗ — infrastructure security to complement SOC operations
- Prerequisite for: SC-100 (Cybersecurity Architect Expert) ↗
- Built on: SC-900 (Security, Compliance, and Identity Fundamentals) ↗
- Replaces: N/A (not a replacement; newer advanced certs available above)
- Related domain certs: SC-300 (Identity and Access Administrator Associate) ↗
- Vendor overview: Microsoft Vendor Overview ↗
Sources
- Microsoft Certified: Security Operations Analyst Associate (official page)
- Exam SC-200 study guide
- Exam SC-200 details and registration
- Microsoft Learn – SC-200T00-A course
- Microsoft Learn – Security Operations Analyst learning path
- Exam Ref SC-200 book (Microsoft Press Store)
- Microsoft Defender XDR documentation
- Microsoft Sentinel documentation
- Microsoft Defender for Cloud documentation
- MeasureUp SC-200 practice exams
- Whizlabs SC-200 practice exams
- Coursera – Microsoft Defender, Threat Protection, and Azure Security Operations
- Pluralsight – SC-200: Security Operations Analyst
- LinkedIn Learning – Security Operations with Microsoft Sentinel
- John Savill's YouTube – SC-200 Study Cram
- A Cloud Guru – SC-200: Security Operations Analyst
- Microsoft Security overview
- Microsoft Certification roadmap – Security
Last verified: 2026-05-02 Parent ecosystem: Microsoft Security Ecosystem Parent domain: Security Domain Vendor overview: Microsoft Overview