Study by topic
Work through the complete question bank by official exam domain, save questions, and revisit incorrect answers.

MicrosoftSC-200
SC-200 tests whether you can run a security operations team on Microsoft's tools: set up Microsoft Sentinel and Defender XDR so the right data arrives and the right detections fire, investigate and respond to incidents across Defender for Endpoint, Office 365, Identity and Cloud Apps, and hunt for threats with KQL. Practise across all three official skill areas with full 50-question papers and a score breakdown per skill area.
Work through the complete question bank by official exam domain, save questions, and revisit incorrect answers.
Take 50-question simulations with a 100-minute timer and saved progress.
Review your score, every answer, and your performance across each exam domain.
Automation and notifications in Defender XDR and Defender for Endpoint, attack surface reduction and automated response, Microsoft Sentinel roles, retention, workbooks and data connectors, and custom detections and analytics rules.
Investigating and remediating alerts from Defender for Office 365, Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Cloud, Entra ID and Microsoft Sentinel, live response, and Purview Audit and eDiscovery searches.
Choosing the right tables and writing KQL, advanced hunting in Defender XDR, hunting queries, search jobs and notebooks in Microsoft Sentinel, and threat analytics.
One question written for this page, in the same style as the questions in the bank.
Perform threat hunting
You need to find every device on which a file with a specific SHA-256 hash was created or modified in the last seven days by using advanced hunting in Microsoft Defender XDR. Which table should you query?
Microsoft does not publish a fixed question count, but most of its certification exams contain 40 to 60 questions, and SC-200 gives you 100 minutes to answer them. ReadyForCert papers use 50 questions on the same 100-minute clock.
700 on a scale of 1 to 1,000. The score is scaled rather than a raw percentage of questions answered correctly, so it does not map exactly onto “70% of questions right”.
Yes. Threat hunting is about a fifth of the exam, and many other questions show a query and ask what it returns or how to finish it. You do not need to write long queries from memory, but you should be able to read one and pick the right table, operator or join.
No. These are practice questions written against the current Microsoft study guide. Real exam content is covered by Microsoft's exam agreement, and the bank is refreshed regularly.
Same format, same price, same free quiz.