Microsoft · 考试 SC-200

围绕考试实际考察的判断力设计的 SC-200 练习题。

Practice the workflows used to investigate, hunt, and respond across Microsoft Sentinel, Defender XDR, and cloud security operations.

无需绑卡即可开始 · 一次性付款 · 永久访问
内容审核于 2026年9月

还不确定 SC-200 适不适合你?

先做免费的 10 题诊断——无需注册,即时评分并按领域给出详细分析,让你在做决定之前先了解自己的水平。

免费 10 题诊断

限时模拟考试

一次完整的限时模拟,包含 SC-200 道练习题,提交前不显示任何反馈——最接近真实考试的体验。

开始限时模拟
为你的下一次尝试而设计

有目标的备考。

Microsoft security operations analysts who work with Sentinel, Defender XDR, cloud workloads, incidents, and KQL-driven threat hunting.

CertSprint 结合了针对性练习、详细解析、基于表现的任务和分领域的准备度评估,让每次练习都清楚告诉你接下来该学什么。

完整题库

超越 20 道题的预览版,进入围绕当前考纲的技能与场景组织的完整题库。

有启发性的解析

了解为什么正确答案符合证据,以及为什么其他选项不成立,从而培养判断力而不是死记硬背。

PBQ 与应用场景题

练习排序、匹配、排查和配置类任务,让知识在考试压力下也能真正用得上。

按领域评估准备度

正确率会映射到各考试领域,揭示薄弱环节,把考试日期变成切实可行的每日练习目标。

你将练习的内容

专注于 SC-200 的覆盖范围。

整个体验围绕相关的判断与故障排查设计,而不是零散的知识点。

  • Microsoft Sentinel investigations
  • Defender XDR alerts and incidents
  • KQL-based threat hunting and response
示例题目

考察的是推理,而不是措辞。

Worked example

A Microsoft Sentinel incident contains alerts from several users and endpoints. Which feature should an analyst use to visualize the relationships between the entities?

AInvestigation graph最佳答案
BData connector
CAnalytics rule template
DWatchlist import

完整访问权限包含每道已作答题目后的清晰解析,包括为什么其他选项不够合适。

Why this is the best answer

A relationship graph helps connect the users, devices, alerts, and other entities involved in an incident. Use those connections to decide which evidence to inspect next, then confirm the sequence in the underlying records. The graph name and available investigation experience depend on whether you are working in the Azure or Defender portal.

Why the other options fit less well

Data connectors ingest telemetry. Analytics rules detect activity, and watchlists supply reference data. Those functions support investigation but do not replace the incident relationship view requested here.

Microsoft: investigate incidents and their relationships
考试是如何进行的

准确了解考试当天的情况。

Microsoft SC-200(SC-200)官方考试形式 — 预约前请到官方网站确认最新价格和政策,因为这些可能会变化。

形式1 exam
题目数量Typically 40–60 questions (Microsoft varies the exact count per delivery)
时长100 minutes for the assessment; appointment time also includes administrative steps
及格分数700 out of 1000
题型Multiple choice, multiple answer, drag-and-drop/build-list items, and case studies with several linked questions
考试方式Pearson VUE test center or online proctored
重考政策Wait 24 hours after the first failed attempt and 14 days between subsequent attempts. Maximum five attempts within 12 months of the first. Retake fees apply.
学习计划

一份按真实题库权重分配的 6 周计划。

每周的时长与该领域实际拥有的 SC-200 练习题数量成正比,而不是通用模板。可在仪表盘中跟踪真实进度。

  1. 1

    Manage a security operations environment

    25% of the full question bank — the single largest block this week.

    约每天 17 题
  2. 2

    Configure protections and detections + Manage incident response

    Smaller domains grouped together to keep every week substantive.

    约每天 24 题
  3. 3

    Perform threat hunting

    22% of the full question bank — the single largest block this week.

    约每天 14 题
  4. 4

    Respond to security incidents

    16% of the full question bank — the single largest block this week.

    约每天 11 题
  5. 5

    Cumulative review

    Mixed practice across every domain, prioritizing whichever ones your readiness tracker shows below 80% accuracy — not a fixed list, but whatever the data says is weakest this week.

  6. 6

    Timed mock exam

    Simulate the real exam: one sitting, the real question count and time limit, no pausing. Re-drill any domain that comes in under 80%.

用数据说话

在考试日发现之前,先找到你的薄弱领域。

免费试做 20 道 SC-200 题目。准备好后再解锁完整练习空间。

免费开始 SC-200

Go deeper on SC-200

有依据地练习

理解答案背后的判断。

先分析情境,找出关键证据,再对照解析检查自己的推理。根据各领域的得分决定下一次复习重点。练习正确率只能提示学习进度,不能预测正式考试成绩,也不等同于官方分数。

Microsoft当前的考试大纲有三个技能领域:管理安全运营环境、响应事件和威胁搜寻。CertSprint 的部分练习类别仍沿用更细的历史分类。