Associate SC-200
Azure security operations cert for SOC analysts using Microsoft Sentinel, Microsoft Defender XDR, and Defender for Cloud to investigate and respond to threats.
The Microsoft Security Operations Analyst Associate (SC-200) validates the skills required to investigate, respond to, and hunt for threats using Microsoft security platforms. It targets security operations center (SOC) analysts, threat hunters, and incident responders working in organizations that use the Microsoft security stack.
The exam covers three main areas: Mitigate Threats Using Microsoft Defender XDR (25–30%), Mitigate Threats Using Defender for Cloud (15–20%), and Mitigate Threats Using Microsoft Sentinel (50–55%). You must demonstrate proficiency in Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, Microsoft Sentinel (workspace setup, analytics rules, automation with SOAR playbooks, hunting queries with KQL), and Defender for Cloud recommendations.
The SC-200 is one of the most practical and in-demand Azure security certifications for hands-on security roles. It focuses on detection and response rather than engineering, making it complementary to AZ-500 (security engineering) and SC-300 (identity management). KQL (Kusto Query Language) proficiency is critical for success on this exam.
SOC analysts, threat hunters, incident responders, and security engineers working with Microsoft Sentinel and Microsoft Defender.
Prerequisites: AZ-900 and SC-900 (Security Fundamentals) recommended. Familiarity with Microsoft security products and basic KQL knowledge.