Microsoft · Exam SC-200

SC-200 practice questions built around the decisions the exam tests.

Practice the workflows used to investigate, hunt, and respond across Microsoft Sentinel, Defender XDR, and cloud security operations.

No card to start · one-time payment · permanent access
Content reviewed September 2026

Not sure SC-200 is the right fit yet?

Take the free 10-question diagnostic first — no signup, instant score and domain breakdown, so you know where you stand before you commit.

Free 10-question diagnostic

Timed exam simulation

A full-length, timed sitting of SC-200 practice questions with no feedback until you submit — the closest thing to sitting the real exam.

Start the timed simulation
Designed for your next attempt

Preparation with a purpose.

Microsoft security operations analysts who work with Sentinel, Defender XDR, cloud workloads, incidents, and KQL-driven threat hunting.

CertSprint combines targeted practice, explanations, performance-based tasks, and domain-level readiness so each session tells you what to study next.

Complete practice bank

Move beyond the 20-question preview into the full exam-focused bank, organized around the skills and scenarios represented by the current blueprint.

Explanations that teach

See why the right answer fits the evidence and why the distractors fail, so you build judgment instead of memorizing answer patterns.

PBQs and applied scenarios

Practice ordering, matching, investigation, and configuration-style tasks designed to make knowledge usable under exam pressure.

Readiness by domain

Accuracy is mapped to exam areas, exposing weak domains and turning an exam date into a realistic daily practice target.

What you will practice

Coverage that stays focused on SC-200.

The experience is designed around relevant decisions and troubleshooting, not disconnected trivia.

  • Microsoft Sentinel investigations
  • Defender XDR alerts and incidents
  • KQL-based threat hunting and response
Sample question

Test the reasoning, not the wording.

Worked example

A Microsoft Sentinel incident contains alerts from several users and endpoints. Which feature should an analyst use to visualize the relationships between the entities?

AInvestigation graphBest answer
BData connector
CAnalytics rule template
DWatchlist import

Full access includes a clear explanation after every answered question, including why the remaining options are less appropriate.

Why this is the best answer

A relationship graph helps connect the users, devices, alerts, and other entities involved in an incident. Use those connections to decide which evidence to inspect next, then confirm the sequence in the underlying records. The graph name and available investigation experience depend on whether you are working in the Azure or Defender portal.

Why the other options fit less well

Data connectors ingest telemetry. Analytics rules detect activity, and watchlists supply reference data. Those functions support investigation but do not replace the incident relationship view requested here.

Microsoft: investigate incidents and their relationships
How the exam works

Know exactly what exam day looks like.

Official format for Microsoft SC-200 (SC-200) — confirm current pricing and policy on the vendor's site before you book, since those can change.

Format1 exam
QuestionsTypically 40–60 questions (Microsoft varies the exact count per delivery)
Duration100 minutes for the assessment; appointment time also includes administrative steps
Passing score700 out of 1000
Question typesMultiple choice, multiple answer, drag-and-drop/build-list items, and case studies with several linked questions
DeliveryPearson VUE test center or online proctored
Retake policyWait 24 hours after the first failed attempt and 14 days between subsequent attempts. Maximum five attempts within 12 months of the first. Retake fees apply.
Study plan

A 6-week plan weighted to the real question bank.

Every week's length is proportional to how many SC-200 practice questions that domain actually has — not a generic template. Track real progress against it from your dashboard.

  1. 1

    Manage a security operations environment

    25% of the full question bank — the single largest block this week.

    ~17 questions/day
  2. 2

    Configure protections and detections + Manage incident response

    Smaller domains grouped together to keep every week substantive.

    ~24 questions/day
  3. 3

    Perform threat hunting

    22% of the full question bank — the single largest block this week.

    ~14 questions/day
  4. 4

    Respond to security incidents

    16% of the full question bank — the single largest block this week.

    ~11 questions/day
  5. 5

    Cumulative review

    Mixed practice across every domain, prioritizing whichever ones your readiness tracker shows below 80% accuracy — not a fixed list, but whatever the data says is weakest this week.

  6. 6

    Timed mock exam

    Simulate the real exam: one sitting, the real question count and time limit, no pausing. Re-drill any domain that comes in under 80%.

Start with evidence

Find your weak domains before exam day finds them.

Try 20 SC-200 questions free. Unlock the complete workspace only when you are ready.

Start SC-200 free

Go deeper on SC-200

Practice with perspective

Learn the decision behind the answer.

Work through the scenario, identify the evidence that matters, then compare your reasoning with the explanation. Use domain scores to choose your next study session. A practice percentage is a learning signal, not a prediction or an official exam score.

The current Microsoft outline has three skill areas: managing the security operations environment, responding to incidents, and threat hunting. Some existing CertSprint practice categories use a more detailed historical grouping.