Skip to content
CBT Nuggets
DemoBook a Demo

Microsoft Certified: Security Operations Analyst Associate (SC-200)

Advance your cybersecurity analyst career. This Microsoft SC-200 training prepares you for the Security Operations Analyst Associate certification exam. Validate your ability to detect, investigate, and remediate real threats across cloud and on-prem environments. Using SC-200 practice exams, you’ll prepare for real-world incident response, threat hunting, and risk reduction using Microsoft Defender XDR, Microsoft Sentinel, and Security Copilot. You’ll learn to write KQL queries, configure detections, manage playbooks, and automate investigations so you can move from alert triage to confident remediation.

Updated March 2026

18Skills
92Videos
1Practice Exam
15hTotal

Who This Course Is For

This is an intermediate cybersecurity course built for security analysts and engineers with 1-3 years of experience. The Security Operations Analyst Associate is a respected cyber security analyst certification that proves you’re prepared for more senior roles in security operations.

Skills Your Team Will Gain

  • Investigate and remediate incidents using Microsoft Defender XDR
  • Design and manage Microsoft Sentinel workspaces and data ingestion
  • Create KQL queries for threat hunting and custom detections
  • Configure analytics rules and automation playbooks in Microsoft Sentinel
  • Manage exposure and vulnerability risk with Defender tools
  • Use Security Copilot to accelerate investigations and response

Course Curriculum

One skill is free to watch — no signup needed. The other 17 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Intro To Microsoft Defender XDR

Bob SalmansDuration: 46m9 videos

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Intro To Microsoft Defender XDRFree46m · 9 videos
  • Premium skill.Getting Started With Microsoft Defender XDR47m · 12 videos
  • Premium skill.Device Groups and Email Notifications49m · 12 videos
  • Premium skill.Configure Endpoint Settings & Alert Tuning44m · 9 videos
  • Premium skill.Defender Automated Investigation & Response45m · 14 videos
  • Premium skill.Managing Assets and Environments59m · 10 videos
  • Premium skill.Design and configure a MS Sentinel Workspace54m · 12 videos
  • Premium skill.Ingest data sources in MS Sentinel52m · 14 videos
  • Premium skill.Configure Protections & Detections in Defender XDR52m · 12 videos
  • Premium skill.KQL & Custom detections in Defender XDR54m · 13 videos
  • Premium skill.Configure Detections in Sentinel1h · 14 videos
  • Premium skill.Responding To Alerts In Defender Products55m · 16 videos
  • Premium skill.Investigating Defender Alerts & Incidents57m · 10 videos
  • Premium skill.Investigating MS 365 Activities and Sentinel Tools55m · 16 videos
  • Premium skill.Implement and Use Microsoft Security Copilot56m · 16 videos
  • Premium skill.Hunt for threats by using Microsoft Sentinel54m · 14 videos
  • Premium skill.Sentinel workbooks & Hunting Threats in Defender46m · 12 videos
  • Premium skill.Manage SOC Data Collection and Optimization51m · 10 videos
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Certification

Microsoft Certified: Security Operations Analyst Associate (SC-200)

The Microsoft Certified: Security Operations Analyst Associate certification validates the skills and knowledge of security operations analysts to detect and respond to threats, and to configure and use threat detection tools, and who should pursue t...

Exam SC-200Level AssociateDifficulty IntermediateCost $165 USD
Threat managementIncident responseSecurity operationsMicrosoft 365 securityAzure security
Official certification page

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Security teams often inherit Microsoft Defender XDR and Microsoft Sentinel without consistent runbooks for alert tuning, investigation, response, and threat hunting. This SC-200 course gives IT Directors a structured way to align SOC analysts, security engineers, and Microsoft 365 security practitioners around the same Microsoft security operations workflow.

The course is intermediate and works best for teams already supporting Microsoft 365, endpoint security, or SIEM operations. Plan for about 14 hours, 45 minutes per learner across 17 course sections, making it practical for phased enablement rather than a one-time training event. Training Managers can sequence topics from Defender XDR foundations into Sentinel workspace design, data ingestion, KQL, detections, investigations, Security Copilot, and threat hunting.

For change management, Team Leads can assign this course before standardizing detection rules, alert response processes, or Sentinel adoption. CBT Nuggets capabilities such as Playlists and Team Reporting help leaders guide completion and track progress; Practice Exams can support SC-200 certification readiness where exam preparation is part of the team goal.

Team Impact

How this training helps your team succeed

IT teams complete this training to make Microsoft security operations more consistent across Defender XDR and Microsoft Sentinel. The course maps to scenarios SOC teams face when configuring tools, reducing alert noise, investigating incidents, and improving response quality.

  • Standardize Defender XDR operations: Teams learn how device groups, email notifications, endpoint settings, alert tuning, and automated investigation and response fit into day-to-day security operations.
  • Improve Sentinel readiness: Security teams learn how to design a Sentinel workspace, ingest data sources, configure detections, and use workbooks for visibility.
  • Strengthen investigation workflows: Analysts practice the concepts behind responding to alerts, investigating Defender alerts and incidents, and reviewing Microsoft 365 activities with Sentinel tools.
  • Build proactive threat-hunting capability: Teams learn to use KQL, custom detections, Sentinel hunting, Defender hunting, and Microsoft Security Copilot as part of a more mature SOC workflow.

After completion

Capabilities your team walks away with

Knowledge

  • How Microsoft Defender XDR supports security operations across alerts, incidents, assets, endpoint settings, and automated investigation and response.
  • How device groups, email notifications, alert tuning, protections, and detections affect operational consistency.
  • How Microsoft Sentinel workspaces are designed and connected to ingested data sources.
  • How KQL, custom detections, Sentinel detections, workbooks, and hunting tools support investigation and threat discovery.
  • Where Microsoft Security Copilot fits into Microsoft security operations workflows.

Ability

  • Configure core Defender XDR settings that support endpoint security, alert handling, and automated response.
  • Manage security assets and environments in a way that supports SOC visibility.
  • Design and configure a Microsoft Sentinel workspace and connect data sources for analysis.
  • Create and tune detections in Defender XDR and Sentinel using KQL-driven workflows.
  • Respond to and investigate alerts, incidents, Microsoft 365 activities, and threat-hunting findings across Defender and Sentinel.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

If gaps show up, start here

Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)

This Microsoft SC-900 training prepares you to earn your Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) certification. You'll learn the fundamentals of security, compliance, and identity (SCI) within the Microsoft servi...

~22h

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$225one time

No subscription

One year of access to Microsoft SC-200

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Frequently Asked Questions

How long does it take to study for SC-200?

Most people need about 4-8 weeks, depending on experience and familiarity with the underlying tech. If you already work in an SOC or use Microsoft Defender XDR or Sentinel daily, you might be ready in a month with a quick review of this course and its practice exams. On the other hand, someone newer to Microsoft security tools should plan about two months. You'll have time to go through all the videos sequentially, practice KQL queries, build detections, and walk through real incident scenarios. You can cram for the test in a few weeks, but the real-world value of this course is in understanding workflows, so time spent actually using the tools matters more.

What jobs can I get with SC-200?

SC-200 and the Microsoft Certified: Security Operations Analyst Associate cert aligns most directly with Security Operations Analyst, SOC Analyst, Threat Hunter, or Incident Responder roles. It’s also useful for Security Engineers working in Microsoft-centric environments. Organizations that run Microsoft Defender XDR, Sentinel, or Azure security tools need analysts and engineers who actually know how to investigate alerts, build detections, and respond to incidents without constant supervision. It won’t magically land you a senior architect role, but it’s a mid-level step toward security operations jobs and internal promotions.

What is the passing score for the SC-200 exam?

Microsoft exams, including SC-200, are scored on a scale of 1 to 1000, and you need a 700 to pass. The exact number of questions you’ll have to answer correctly isn’t always clear, since some questions count more than others. That’s why a course like this is essential for success. It covers each exam domain: managing a security operations environment, configuring protections and detections, managing incident response, and managing security threats. It also includes practice exams to get confortable with the Microsoft security tools you’ll be tested on, and build your real-world competence.

Is the SC-200 exam difficult?

Yes, SC-200 can be a challenging exam, especially if your experience with Microsoft security tools is mostly theoretical. SC-200 leans heavily on how Defender XDR and Microsoft Sentinel actually behave in a live environment, so you’ll be expected to show you understand how alerts correlate across workloads, how automation rules and playbooks respond, and how to pivot through incidents using KQL. You’ll have access to Microsoft Learn during the exam, but that won’t help much if you’ve never built a hunting query or tuned a noisy detection. If you’ve spent time in Sentinel and Defender investigating real alerts, SC-200 should feel fair. If not, it can be a pretty hard exam.

Is the SC-200 certification worth it?

If you work in a Microsoft-heavy security environment, yes, it’s worth it. The Security Operations Analyst Associate isn’t a theory badge -- it stands for your ability to actually operate Defender XDR and Sentinel in a real SOC workflow. Passing the SC-200 tells employers that you know how alerts correlate across identities, endpoints, email, and cloud workloads, how to write and tune KQL queries, and how to use automation without breaking something. If your company runs Microsoft security tools, this certification signals that you understand how the detection and response pipeline works. If you don’t touch Microsoft security products at all, it’s less relevant. But in the right environment, it carries weight.

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.