SC-200: Security Operations Analyst - EN

Last Updated Sep 2025

Course Overview

Investigate, search for, and mitigate threats using Microsoft Sentinel, Microsoft Defender for Cloud, and Microsoft 365 Defender.

Duration - 10 Hours

Level - Intermediate

Style - Self paced

Course Type - Credential Ready

Certification - Yes

Hands on Labs - Yes

Solution Areas - Security

Course Modules

Introduction to Microsoft Defender XDR and Copilot for Security: Threat Mitigation and Operationa...

In this Module you will learn how to protect and manage threats across Microsoft 365 using Microsoft Defender XDR and Entra ID, and gain foundational knowledge of generative AI and Microsoft Security Copilot to enhance security operations. They will also explore hands-on labs to apply real-world security use cases with Defender and Copilot tools.

Mitigate threats using Microsoft Purview & Microsoft Defender for Endpoint

In this module we focus on Microsoft Purview's risk and compliance solutions that assist security operations analysts detect threats to organizations and identify, classify, and protect sensitive data, as well as monitor and report on compliance. This learning path aligns with exam SC-200: Microsoft Security Operations Analyst. Implement the Microsoft Defender for Endpoint platform to detect, investigate, and respond to advanced threats. This learning path aligns with exam SC-200: Microsoft Security Operations Analyst.

Threat Detection and Response with Microsoft Defender for Cloud and Microsoft Sentinel

In this Module you will use Microsoft Defender for Cloud, for Azure, hybrid cloud, and on-premises workload protection and security Write Kusto Query Language (KQL) statements to query log data to perform detections, analysis, and reporting in Microsoft Sentinel. This learning path will focus on the most used operators. Get started with Microsoft Sentinel by properly configuring the Microsoft Sentinel workspace.

Operationalizing Microsoft Sentinel: Log Integration, Threat Detection, Investigation, and Hunting

As part of this module you will cover Connect data at cloud scale across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds to Microsoft Sentinel. This learning path aligns with exam SC-200: Microsoft Security Operations Analyst. Detect previously uncovered threats and rapidly remediate threats with built-in orchestration and automation in Microsoft Sentinel. Proactively hunt for security threats using the Microsoft Sentinel powerful threat hunting tools.

Getting Ready for the Certification: SC-200: Security Operations Analyst

In this exam preparation module, learn effective preparation strategies for the certification exam, including sample questions and study tips.

Practice Test

Take this assessment to validate your skills gathered from the self-paced online learning course completed in this course to mark your completion.

Other courses in this Category

Intermediate

Implement Microsoft Defender for Endpoint

Duration - 12 Hours
Course
Intermediate

Protect cloud, AI Platform and Apps by implementing Defender for Cloud

Duration - 12 Hours
Course
Advanced

Threat Protection and Incident Response with Microsoft Sentinel

Duration - 12 Hours
Course
Beginner

Sales - Modernizing your SecOps with Microsoft Sentinel

Duration - 1.5 Hours
Course