AzureAssociate

Microsoft Certified: Security Operations Analyst Associate

SC-200

Mitigate threats using Microsoft Sentinel, Microsoft Defender XDR and Defender for Cloud.

Duration
100 min
Exam questions
40–60
Passing score
700 / 1000
Exam fee
$165
Question formats:Multiple choiceMultiple responseYes / NoYes / No statementsDrag and dropHot areacase study
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions
Pro
Case study: Korrindale Energy
6 questions · 10 min
Pro
Case study: Marravel Insurance
6 questions · 10 min

Domain papers 540 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min
Pro
Mixed paper 4
25 questions · 60 min
Pro
Mixed paper 5
25 questions · 60 min
Pro
Mixed paper 6
25 questions · 60 min
Pro
Mixed paper 7
25 questions · 60 min
Pro
Mixed paper 8
25 questions · 60 min
Pro
Mixed paper 9
25 questions · 60 min
Pro
Mixed paper 10
14 questions · 34 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
50 questions · 100 min
Mock exam 2
50 questions · 100 min
Mock exam 3
50 questions · 100 min

Try a sample question

All 10 sample questions →
Question 1Manage a security operations environment

Relecloud connects Microsoft Defender XDR to Microsoft Sentinel. An automation rule whose only condition is that the analytics rule name contains the word phishing tags and assigns incidents correctly for incidents that Microsoft Sentinel creates, but never runs for the phishing incidents that arrive from Microsoft Defender XDR. Why?

  1. A.

    Incidents synchronized from Microsoft Defender XDR are not created by a Microsoft Sentinel analytics rule, so the condition never matches

  2. B.

    The Microsoft Defender XDR connector synchronizes incidents only once every 24 hours, so the automation rule expires before those incidents reach the workspace

  3. C.

    Automation rules cannot act on incidents that were created in Microsoft Defender XDR, so a playbook triggered by the Microsoft Defender XDR connector is required instead

  4. D.

    Automation rules that contain an Assign owner action are skipped for incidents whose owner field was already populated by the originating security product

Show answer

Answer: A

An incident that came from Microsoft Defender XDR has no Microsoft Sentinel analytics rule name, so a condition written on that property can never be satisfied.

  • A. Synchronized Defender XDR incidents have no Sentinel analytics rule name, so that condition can never match.
  • B. Incident synchronization is near real time, not a daily batch.
  • C. Automation rules do apply to synchronized Defender XDR incidents; the limitation is invented.
  • D. No skip behaviour exists for incidents that already have an owner; the action would simply overwrite it.

What's on the exam

3 domains · 9 task statements, straight from the official exam guide (as of October 21, 2026).

  1. 1.1Configure automation for Microsoft Defender XDR and Microsoft Sentinel
    • Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics
    • Configure alert notifications in Microsoft Defender XDR, including tuning, suppression, and correlation
    • Configure Microsoft Defender for Endpoint advanced features
    • Configure rules settings in Microsoft Defender for Endpoint
    • Configure custom data collection in Microsoft Defender for Endpoint
    • Configure security policies for Microsoft Defender for Endpoint, including attack surface reduction (ASR) rules
    • Manage automated investigation and response capabilities in Microsoft Defender XDR
    • Configure automatic attack disruption in Microsoft Defender XDR
    • Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint
    • Create and configure automation rules in Microsoft Sentinel
    • Create and configure Microsoft Sentinel playbooks
  2. 1.2Configure the Microsoft Sentinel SIEM and platform
    • Specify Microsoft Sentinel roles
    • Manage data retention for XDR and Microsoft Sentinel tables, including Analytics, Data lake, and XDR tiers
    • Create and configure Microsoft Sentinel workbooks
    • Optimize the Microsoft Sentinel platform, including SOC optimization recommendations
  3. 1.3Ingest data into the Microsoft Sentinel SIEM and platform
    • Select data connectors based on data source requirements, including Windows logs and security events
    • Configure collection of Windows Security events by using Windows Security Events via AMA, including data collection rules
    • Plan and configure collection of Windows Security events by using Windows Event Forwarding (WEF)
    • Plan and configure Syslog via AMA and Common Event Format (CEF) via AMA connectors
    • Configure collection of Azure activity logs by using Azure Policy and resource diagnostic settings
    • Ingest threat indicators into Microsoft Sentinel
    • Create custom log tables in the workspace to store ingested data
  4. 1.4Configure detections
    • Create custom detection rules by using Advanced Hunting in Microsoft Defender XDR
    • Manage custom detection rules in Microsoft Defender XDR
    • Configure and manage analytics rules in Microsoft Sentinel SIEM, including scheduled, near-real time (NRT), threat intelligence, and machine learning
    • Analyze attack vector coverage by using the MITRE ATT&CK matrix
    • Configure anomalies in Microsoft Sentinel

Outline reproduced from the vendor's public exam guide for study reference.Official guide

SC-200 practice — frequently asked questions

Are these real SC-200 exam questions?

No. Every question on CertifyCloudx is original, written by us against Microsoft Azure's publicly available SC-200 exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Microsoft Azure.

How many SC-200 practice questions are there?

540 practice questions, including 3 full-length timed mock exams and 48 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current SC-200 exam guide?

The questions are written against the SC-200 exam guide dated October 21, 2026, and we revise them when Microsoft Azure updates the guide.

What question formats are covered?

The same formats the real SC-200 uses: Multiple choice, Multiple response, Yes / No, Yes / No statements, Drag and drop, Hot area, case study. Each is rendered and graded the way the exam does it.

How long is the SC-200 exam and how many questions does it have?

According to Microsoft Azure's published exam details: 40–60 questions, 100 minutes, passing score 700 / 1000. Our mock exams use the same time limit, with a question count in the middle of that range. Always confirm current details with Microsoft Azure before booking.

Can I practise SC-200 for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.