Skip to content
CBT Nuggets

Microsoft Certified: Security Operations Analyst Associate (SC-200)

Advance your cybersecurity analyst career. This Microsoft SC-200 training prepares you for the Security Operations Analyst Associate certification exam. Validate your ability to detect, investigate, and remediate real threats across cloud and on-prem environments. Using SC-200 practice exams, you’ll prepare for real-world incident response, threat hunting, and risk reduction using Microsoft Defender XDR, Microsoft Sentinel, and Security Copilot. You’ll learn to write KQL queries, configure detections, manage playbooks, and automate investigations so you can move from alert triage to confident remediation.

Updated March 2026

17Skills
92Videos
14h 46mTotal
92 videos14h 46m

Who This Course Is For

This is an intermediate cybersecurity course built for security analysts and engineers with 1-3 years of experience. The Security Operations Analyst Associate is a respected cyber security analyst certification that proves you’re prepared for more senior roles in security operations.

Skills Your Team Will Gain

  • Investigate and remediate incidents using Microsoft Defender XDR
  • Design and manage Microsoft Sentinel workspaces and data ingestion
  • Create KQL queries for threat hunting and custom detections
  • Configure analytics rules and automation playbooks in Microsoft Sentinel
  • Manage exposure and vulnerability risk with Defender tools
  • Use Security Copilot to accelerate investigations and response

Course Curriculum

  • Intro To Microsoft Defender XDRFree46m
  • Premium skill.Getting Started With Microsoft Defender XDR47m
  • Premium skill.Device Groups and Email Notifications49m
  • Premium skill.Configure Endpoint Settings & Alert Tuning44m
  • Premium skill.Defender Automated Investigation & Response45m
  • Premium skill.Managing Assets and Environments59m
  • Premium skill.Design and configure a MS Sentinel Workspace54m
  • Premium skill.Ingest data sources in MS Sentinel52m
  • Premium skill.Configure Protections & Detections in Defender XDR52m
  • Premium skill.KQL & Custom detections in Defender XDR54m
  • Premium skill.Configure Detections in Sentinel1h
  • Premium skill.Responding To Alerts In Defender Products55m
  • Premium skill.Investigating Defender Alerts & Incidents57m
  • Premium skill.Investigating MS 365 Activities and Sentinel Tools55m
  • Premium skill.Implement and Use Microsoft Security Copilot56m
  • Premium skill.Hunt for threats by using Microsoft Sentinel54m
  • Premium skill.Sentinel workbooks & Hunting Threats in Defender46m

Certification

Microsoft Certified: Security Operations Analyst Associate (SC-200)

The Microsoft Certified: Security Operations Analyst Associate certification validates the skills and knowledge of security operations analysts to detect and respond to threats, and to configure and use threat detection tools, and who should pursue t...

Exam SC-200Level AssociateDifficulty Intermediate
Threat managementIncident responseSecurity operationsMicrosoft 365 securityAzure security
Official certification page

For IT leaders

What IT leaders need to know before assigning this course

Security teams often inherit Microsoft Defender XDR and Microsoft Sentinel without consistent runbooks for alert tuning, investigation, response, and threat hunting. This SC-200 course gives IT Directors a structured way to align SOC analysts, security engineers, and Microsoft 365 security practitioners around the same Microsoft security operations workflow.

The course is intermediate and works best for teams already supporting Microsoft 365, endpoint security, or SIEM operations. Plan for about 14 hours, 45 minutes per learner across 17 course sections, making it practical for phased enablement rather than a one-time training event. Training Managers can sequence topics from Defender XDR foundations into Sentinel workspace design, data ingestion, KQL, detections, investigations, Security Copilot, and threat hunting.

For change management, Team Leads can assign this course before standardizing detection rules, alert response processes, or Sentinel adoption. CBT Nuggets capabilities such as Playlists and Team Reporting help leaders guide completion and track progress; Practice Exams can support SC-200 certification readiness where exam preparation is part of the team goal.

Team Impact

How this training helps your team succeed

IT teams complete this training to make Microsoft security operations more consistent across Defender XDR and Microsoft Sentinel. The course maps to scenarios SOC teams face when configuring tools, reducing alert noise, investigating incidents, and improving response quality.

  • Standardize Defender XDR operations: Teams learn how device groups, email notifications, endpoint settings, alert tuning, and automated investigation and response fit into day-to-day security operations.
  • Improve Sentinel readiness: Security teams learn how to design a Sentinel workspace, ingest data sources, configure detections, and use workbooks for visibility.
  • Strengthen investigation workflows: Analysts practice the concepts behind responding to alerts, investigating Defender alerts and incidents, and reviewing Microsoft 365 activities with Sentinel tools.
  • Build proactive threat-hunting capability: Teams learn to use KQL, custom detections, Sentinel hunting, Defender hunting, and Microsoft Security Copilot as part of a more mature SOC workflow.

After completion

Knowledge & ability your team will gain

Knowledge

  • How Microsoft Defender XDR supports security operations across alerts, incidents, assets, endpoint settings, and automated investigation and response.
  • How device groups, email notifications, alert tuning, protections, and detections affect operational consistency.
  • How Microsoft Sentinel workspaces are designed and connected to ingested data sources.
  • How KQL, custom detections, Sentinel detections, workbooks, and hunting tools support investigation and threat discovery.
  • Where Microsoft Security Copilot fits into Microsoft security operations workflows.

Ability

  • Configure core Defender XDR settings that support endpoint security, alert handling, and automated response.
  • Manage security assets and environments in a way that supports SOC visibility.
  • Design and configure a Microsoft Sentinel workspace and connect data sources for analysis.
  • Create and tune detections in Defender XDR and Sentinel using KQL-driven workflows.
  • Respond to and investigate alerts, incidents, Microsoft 365 activities, and threat-hunting findings across Defender and Sentinel.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own lesson transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes

Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one? Create an Adept account.

If gaps show up, start here

Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)

This Microsoft SC-900 training prepares you to earn your Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) certification. You'll learn the fundamentals of security, compliance, and identity (SCI) within the Microsoft servi...

~21h 41m

This course is included with every subscription

Get your team access to all 559 courses, virtual labs, and practice exams.

Most Popular

Team

$749per seat / year

5+ learner seats

Get Started

Enterprise

Customannual contracts

Any size

Contact Enterprise Sales

Just need this course?

Single-course enrollment — $399 for 1 year of access to Microsoft SC-200.

Enroll in This Course
Calculate the ROI of training your team

Trusted by 23,000+ organizations

Frequently Asked Questions

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.