Skip to content

MicrosoftSC-200

SC-200 Practice Exam — Microsoft Security Operations Analyst

SC-200 tests whether you can run a security operations team on Microsoft's tools: set up Microsoft Sentinel and Defender XDR so the right data arrives and the right detections fire, investigate and respond to incidents across Defender for Endpoint, Office 365, Identity and Cloud Apps, and hunt for threats with KQL. Practise across all three official skill areas with full 50-question papers and a score breakdown per skill area.

SC-200 exam at a glance

Questions per paper
50
Time limit
100 minutes
Passing score
700 / 1000
Question format
Multiple choice, multiple response, drag and drop, hot area and case studies
Certification valid for
One year; renew free online
ReadyForCert access
60 days · $8.99 AUD
Free sample
20 questions

Study, practise, review

Study by topic

Work through the complete question bank by official exam domain, save questions, and revisit incorrect answers.

Timed exams

Take 50-question simulations with a 100-minute timer and saved progress.

Exam reports

Review your score, every answer, and your performance across each exam domain.

What the SC-200 exam covers

  1. Manage a security operations environment

    Automation and notifications in Defender XDR and Defender for Endpoint, attack surface reduction and automated response, Microsoft Sentinel roles, retention, workbooks and data connectors, and custom detections and analytics rules.

    40–45%
  2. Respond to security incidents

    Investigating and remediating alerts from Defender for Office 365, Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Cloud, Entra ID and Microsoft Sentinel, live response, and Purview Audit and eDiscovery searches.

    35–40%
  3. Perform threat hunting

    Choosing the right tables and writing KQL, advanced hunting in Defender XDR, hunting queries, search jobs and notebooks in Microsoft Sentinel, and threat analytics.

    20–25%

A sample SC-200 question

One question written for this page, in the same style as the questions in the bank.

Perform threat hunting

You need to find every device on which a file with a specific SHA-256 hash was created or modified in the last seven days by using advanced hunting in Microsoft Defender XDR. Which table should you query?

  • ADeviceFileEventsCorrect answer
  • BIdentityLogonEvents
  • CEmailEvents
  • DCloudAppEvents

About the SC-200 exam

How many questions are on the SC-200 exam and how long is it?

Microsoft does not publish a fixed question count, but most of its certification exams contain 40 to 60 questions, and SC-200 gives you 100 minutes to answer them. ReadyForCert papers use 50 questions on the same 100-minute clock.

What score do I need to pass SC-200?

700 on a scale of 1 to 1,000. The score is scaled rather than a raw percentage of questions answered correctly, so it does not map exactly onto “70% of questions right”.

Do I need to know KQL for SC-200?

Yes. Threat hunting is about a fifth of the exam, and many other questions show a query and ask what it returns or how to finish it. You do not need to write long queries from memory, but you should be able to read one and pick the right table, operator or join.

Are these the real SC-200 exam questions?

No. These are practice questions written against the current Microsoft study guide. Real exam content is covered by Microsoft's exam agreement, and the bank is refreshed regularly.

Same format, same price, same free quiz.

© 2026 ReadyForCert ReadyForCert is an independent practice service. AWS, Google Cloud, Microsoft and other certification names belong to their respective owners, and none of them sponsor or endorse this service.