Microsoft Certified: Security Operations Analyst Associate

Microsoft · SC-200 · Associate

Microsoft · Microsoft Security

Microsoft Certified: Security Operations Analyst Associate

SC-200activeAssociate
Official Microsoft source · learn.microsoft.com

SC-200 · ● Active · Associate · Microsoft

This intermediate security certification validates expertise in threat mitigation using Microsoft's XDR and cloud-native security platform. Targets SOC analysts, security operations engineers, and threat hunters with hands-on experience managing security incidents. Requires strong understanding of Microsoft Defender solutions (Endpoint, Office 365, Identity, Cloud Apps), Microsoft Sentinel SIEM/SOAR platform, and cloud security with Microsoft Defender for Cloud. SC-900 foundational knowledge recommended; practical SOC experience highly valued.


Exam facts

FieldValue
Cost$165 USD (regional pricing may vary)
Duration100–120 minutes
Questions40–60 questions (mix of multiple choice, multiple response, and case studies)
Passing700/1000 scaled score
FormatMultiple choice, multiple response, case studies
DeliveryPearson VUE (online or test center)
LanguagesEnglish, Japanese, Spanish, German, French, Portuguese (BR), Korean, Simplified Chinese, Traditional Chinese, Dutch, Arabic
Valid12 months from date of passing (no renewal — retake to maintain)
RenewalPass the exam again or pursue higher-level cert (SC-100)
PrerequisitesSC-900 recommended; hands-on SOC experience required
ReleasedMay 2020
RetiringN/A (active, no retirement date announced)

Vendor source — Microsoft Certified: Security Operations Analyst Associate ↗

Official exam guide — Exam SC-200 study guide ↗

Exam objectives — SC-200 exam details ↗


About

SC-200 is Microsoft's intermediate security certification launched May 2020, targeting security operations professionals (SOC analysts, Tier 2–3 analysts, incident responders) with 1–2+ years of hands-on experience managing security incidents in cloud and hybrid environments. The exam validates ability to detect, investigate, and remediate threats using Microsoft's integrated XDR platform (Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps) and the cloud-native SIEM/SOAR platform (Microsoft Sentinel). Unlike SC-900 (foundational), SC-200 emphasizes practical threat-hunting techniques, incident triage, KQL query writing, workbook development, and automation through Logic Apps playbooks. Popular with organizations adopting Microsoft security solutions and building in-house SOC capabilities. Passing SC-200 unlocks eligibility for SC-100 (Cybersecurity Architect Expert) and other advanced security specializations.


Domain context — Security

Microsoft's comprehensive cloud-native security portfolio protecting identities, applications, data, and infrastructure across hybrid and multi-cloud environments. Spans identity governance, threat detection and response, compliance automation, and data protection — unified under a Zero Trust architecture model.

Read full deep dive — Microsoft Security Ecosystem → | Read full deep dive — Security Domain →


Topics covered

The exam blueprint organizes topics across three weighted domains, as follows:

  • Mitigate threats using Microsoft Defender XDR (30–35%) — Microsoft Defender for Endpoint (device detection and response, threat analytics, advanced hunting), Microsoft Defender for Office 365 (email and collaboration threats, safe links, safe attachments), Microsoft Defender for Identity (identity and authentication threats, lateral movement detection), Microsoft Defender for Cloud Apps (SaaS threat detection, conditional access policies, app governance), Microsoft Defender Experts for Hunting (proactive threat hunting and expert-led incident response)
  • Mitigate threats using Microsoft Defender for Cloud (20–25%) — configure and manage Defender for Cloud, regulatory compliance and security baselines, workload protections (VMs, databases, containers, app service), threat intelligence integration and alerts, security posture management
  • Mitigate threats using Microsoft Sentinel (50–55%) — configure Sentinel workspace and data connectors, create and manage analytics rules (scheduled, near-real-time, machine learning), manage incidents and alerts, threat hunting using Kusto Query Language (KQL), workbooks and dashboards, automation and orchestration (SOAR playbooks with Logic Apps), User and Entity Behavior Analytics (UEBA), watchlists, threat intelligence feeds in Sentinel

Source: Official exam guide ↗


Common skills at Security · Associate

Shared intermediate security skills at associate level — not specific to this cert.

  • Threat detection and incident response workflows
  • Security incident triage and priority assessment
  • Malware and attack pattern recognition
  • Log aggregation and analysis at scale
  • Query language proficiency (KQL, Splunk SPL, or equivalent)
  • Cloud security architecture and shared responsibility models
  • Identity and access control threat vectors
  • Vulnerability assessment and remediation prioritization
  • Security playbook and runbook development
  • Threat hunting and proactive investigation techniques
  • SIEM/SOAR platform administration and tuning
  • Alert fatigue management and fine-tuning

Recommended courses at Security · Associate

ProviderTitleCostURL
Microsoft Learn (Official)Security Operations Analyst (SC-200T00)Free
Microsoft Learn (Official)Mitigate threats with Microsoft Defender learning pathFree
Coursera (Microsoft)Microsoft Defender, Threat Protection, and Azure Security OperationsFree (audit) / $39/mo
PluralsightSC-200: Security Operations Analyst$299/yr subscription
Udemy (various)SC-200 Security Operations Analyst Exam Prep$10–$80
LinkedIn LearningSecurity Operations with Microsoft Defender and Sentinel$25–$40/mo
YouTube (John Savill)SC-200 Security Operations Analyst Study CramFree
A Cloud Guru / AcloudGuruSC-200: Security Operations Analyst$29–$49/mo

Course-selection rule: Microsoft Learn (free, official) is the recommended baseline covering all three domains. Coursera and Pluralsight provide structured video instruction; Udemy options are budget-friendly for targeted review. A Cloud Guru and YouTube creators offer practical, hands-on deep dives with real Sentinel and Defender labs.


Practice exams

ProviderTitleCostURL
MeasureUp (Official Microsoft Partner)SC-200 Security Operations Analyst$99
WhizlabsSC-200 Security Operations Analyst Practice Exams$39–$69
Microsoft Learn (Free)Practice assessments in study guideFree
Tutorials DojoSC-200 Security Operations Analyst Practice ExamsFree (limited) / $12–$20 (full)

Practice exam rule: MeasureUp (official partner) includes 2 full exams with 150+ questions and expert explanations; essential for validating Sentinel and KQL proficiency. Whizlabs offers 2 exams with 100+ unique questions at lower cost. Microsoft Learn's free practice assessments cover all domains — start here before purchasing third-party exams.


Books

TitleAuthorPublisherYearISBNURL
Exam Ref SC-200 Microsoft Security Operations AnalystSander van VugtMicrosoft Press20249780137930204

Book rule: van Vugt's Exam Ref SC-200 is the current official study guide aligned with the 2026 exam blueprint. It covers all three domains with practical examples, hands-on Sentinel labs, KQL query walkthroughs, and review questions. Updated to reflect recent Defender XDR and Sentinel capabilities.


Typical job titles at Security · Associate

Security Operations Analyst · SOC Analyst (Tier 2/3) · Cloud Security Analyst · Threat Hunter · Incident Responder · SIEM Engineer · Analyst (Security Monitoring) · Detection and Response Analyst · Security Engineer (SOC) · Security Consultant (Threat Operations)

(Job titles drawn from current job-board postings that list SC-200 or "Security Operations Analyst" as required or preferred.)


Salary

RegionRangeSource
USD$95k–$145k (SOC Analyst Tier 2–3)Glassdoor ↗ · ZipRecruiter ↗ · Robert Half ↗
ZARR380k–R680k (SOC Analyst mid-level)Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗
GBP£58k–£88k (SOC Analyst Tier 2–3)IT Jobs Watch ↗ · Hays ↗
EUR€66k–€100k (DE/NL/FR mid-level SOC)Indeed ↗ · Glassdoor EU ↗
AUDA$122k–A$178k (SOC Analyst mid-level)Seek ↗ · LinkedIn Jobs ↗

Salary rule: SC-200 is an intermediate credential for hands-on security operations roles requiring 1–2+ years of SOC experience. Salary reflects Tier 2–3 analyst positions managing incident detection, investigation, and remediation. Progression to SC-100 (Cybersecurity Architect Expert) or AZ-500 (Azure Security Engineer Associate) typically increases salary by 20–40%. Figures are 2026 market snapshots and vary by geography, employer size, industry, and prior background.


Skills validated

Cert-specific — what this exam actually tests.

  • Threat detection using Microsoft Defender for Endpoint (EDR, advanced hunting queries)
  • Email and collaboration threat detection (Microsoft Defender for Office 365)
  • Identity-based threat detection (Microsoft Defender for Identity, lateral movement)
  • SaaS threat detection and anomaly detection (Microsoft Defender for Cloud Apps)
  • Microsoft Defender XDR integration and correlation
  • Microsoft Defender Experts for Hunting engagement and escalation
  • Microsoft Sentinel workspace configuration and deployment
  • Connector integration (100+ data sources, syslog, CEF, custom logs)
  • KQL (Kusto Query Language) fundamentals and advanced queries
  • Analytics rule creation (scheduled, near-real-time, machine learning-based)
  • Incident management and triage workflows in Sentinel
  • Alert optimization and tuning to reduce false positives
  • Threat hunting methodologies and hypothesis-driven searches
  • Workbooks and dashboards for visualization and SOC reporting
  • Automation and orchestration with Logic Apps playbooks
  • UEBA (User and Entity Behavior Analytics) configuration
  • Watchlists and threat intelligence feed integration
  • Microsoft Defender for Cloud workload protections and compliance
  • Security posture assessment and remediation guidance
  • Incident response playbooks and containment tactics

Related certifications


Sources


Last verified: 2026-05-02 Parent ecosystem: Microsoft Security Ecosystem Parent domain: Security Domain Vendor overview: Microsoft Overview

Rate this cert
Was this helpful?
Comments ()
0/2000