All certifications / SC-200 / Cheat sheet
SC-200 SC-200 cheat sheet
Domain 1: Manage a security operations environment (41%)
Exam tips
- To silence one known-benign alert while keeping protection, pick alert tuning scoped narrowly. To limit which devices an analyst can see, pick a device group with Entra group access, not a tenant-wide Entra role.
- Expect questions on the order of ASR rollout (audit before block) and on the dependency between custom IP or URL indicators and network protection. Tamper protection is the answer whenever someone with admin rights tries to switch off Defender.
- If an option says foundational CSPM will produce threat alerts, it is wrong. Threat alerts need a Defender workload plan; attack path analysis needs the paid Defender CSPM plan.
- Know the server list for MDI sensors: all domain controllers plus AD FS, AD CS and Entra Connect. For MDO, time-of-click checking means Safe Links; sandbox detonation means Safe Attachments.
- Responder versus Contributor is a favorite question: managing incidents only means Responder; editing rules, watchlists or workbooks means Contributor. Automation Contributor is granted to Sentinel, not to a user.
- When a scenario says 'keep verbose logs cheaply for years but still detect on aggregates', the answer combines a low-cost tier with a summary rule. Standard analytics rules need data in the analytics tier.
- Map formats to tables: Windows events to SecurityEvent, Syslog to Syslog, CEF to CommonSecurityLog, custom API data to a _CL table. Filtering and transformation happen in the DCR.
- Words like 'within about a minute' point to NRT. 'Multistage attack across products' points to Fusion (or Defender XDR correlation in the unified portal). 'Too many incidents for the same user' points to alert grouping.
- If a question says the rule cannot be saved, check for missing required columns. If it asks how to see which ATT&CK techniques lack detections, choose the MITRE ATT&CK coverage view or SOC optimization coverage recommendations.
- Choose an automation rule for in-Sentinel changes (owner, status, severity, tags, tasks). Choose a playbook when the scenario mentions an external system, enrichment API, email, Teams or ticketing. Automation rules are often what runs the playbook.
Key terms
- Alert tuning rule
- A rule, formerly called a suppression rule, that hides or auto-resolves alerts matching chosen conditions without changing protection.
- Unified RBAC
- Defender XDR's role-based access control model, where custom roles combine permission groups and are assigned per data source.
- Device group
- A ranked set of devices, defined by matching rules, that controls access, automation level and scope for other settings.
- Device group rank
- The order that decides which group a device joins when it matches several; the highest-ranked match wins.
- Incident notification rule
- A setting that emails chosen recipients when incidents matching filters such as severity or source are created or updated.
- Automation level
- The per-device-group setting that decides whether automated investigation remediates on its own or waits for approval.
- Onboarding package
- The script or configuration downloaded from the Defender portal that connects a device to your tenant through a chosen deployment method.
- Tamper protection
- A setting that prevents local changes to Defender security settings, even by administrators or malware with admin rights.
- ASR rule modes
- Audit logs only, Warn blocks but allows a user bypass, and Block enforces the rule.
- Indicator
- A custom allow, audit, warn or block entry for a file hash, IP address, URL, domain or certificate.
- Network protection
- An operating-system-wide filter that blocks connections to malicious domains and IPs and enforces custom IP and URL indicators outside Edge.
- Device discovery
- The feature that uses onboarded devices to find unmanaged devices on the network, in basic (passive) or standard (active) mode.
- Foundational CSPM
- The free Defender for Cloud tier that provides secure score, recommendations and asset inventory.
- Defender CSPM
- The paid posture plan that adds attack path analysis, cloud security explorer, agentless scanning and governance.
- Cloud workload protection
- The paid Defender plans (Servers, Storage, Databases and others) that detect threats and raise security alerts.
- Multicloud connector
- The Defender for Cloud connection to an AWS account or GCP project, created with a CloudFormation template or a GCP script.
- Azure Arc
- The service that projects non-Azure servers into Azure so extensions and Defender plans can be applied to them.
- Defender for Endpoint integration
- The Defender for Servers feature that deploys and licenses the Defender for Endpoint sensor on protected servers.
- Defender for Identity sensor
- Software installed on domain controllers and AD FS, AD CS and Entra Connect servers that collects identity traffic and events for detection.
- Directory Service account
- The account, ideally a gMSA, that Defender for Identity uses to query Active Directory.
- Group managed service account (gMSA)
- An AD account whose password is managed and rotated automatically by domain controllers, suited to services.
- Safe Links
- An MDO feature that checks URLs when they are clicked in email, Teams and Office apps.
- Safe Attachments
- An MDO feature that detonates attachments in a sandbox to find unknown malware before or during delivery.
- Dynamic Delivery
- A Safe Attachments action that delivers the email body immediately and adds the attachment after sandbox scanning.
- Preset security policies
- Microsoft-maintained Standard and Strict policy bundles that take precedence over custom policies.
- Log Analytics workspace
- The Azure Monitor data store that Sentinel is enabled on and where all its tables live.
- Microsoft Sentinel Reader
- The role that allows viewing data, incidents and content without changing anything.
- Microsoft Sentinel Responder
- The role that allows viewing data and managing incidents but not creating or editing content.
- Microsoft Sentinel Contributor
- The role that adds creating and editing content such as analytics rules, workbooks and watchlists.
- Microsoft Sentinel Automation Contributor
- A role granted to the Sentinel service on a resource group so automation rules can run playbooks there.
- Unified security operations platform
- Sentinel and Defender XDR working together in the Microsoft Defender portal with one incident queue.
- Primary workspace
- The Sentinel workspace designated in the Defender portal whose alerts are correlated with Defender XDR data.
- Analytics tier
- The interactive, higher-cost storage tier that supports analytics rules, workbooks and fast hunting queries.
- Sentinel data lake tier
- Low-cost long-term storage for high-volume data, queried with KQL jobs, exploration queries or notebooks.
- Table plan
- The per-table setting (Analytics, Basic or Auxiliary) that trades ingestion cost against query features.
- Summary rule
- A scheduled KQL query that aggregates detailed data and writes the results into an analytics-tier table.
- SOC optimization
- A page of recommendations on data value, detection coverage and peer-based data sources.
- Ingestion-time transformation
- A KQL statement in a DCR that filters or reshapes data before it is stored, reducing cost.
- Content hub
- Sentinel's catalog of solutions that package connectors, rules, workbooks, parsers and playbooks.
- Azure Monitor Agent (AMA)
- The current agent for Windows and Linux that collects data according to data collection rules.
- Data collection rule (DCR)
- A configuration that defines sources, an optional ingestion-time transformation and the destination table.
- Common Event Format (CEF)
- A structured, key-value log format carried over Syslog that lands in the CommonSecurityLog table.
- Linux log forwarder
- A Linux machine running a Syslog daemon and AMA that receives logs from devices and sends them to the workspace.
- Logs Ingestion API
- A REST API for sending custom data into a workspace table through a DCR.
- Scheduled rule
- A KQL-based analytics rule that runs on a set frequency over a set lookback and alerts when a threshold is met.
- NRT rule
- A near-real-time rule that runs about every minute for urgent detections.
- Microsoft security rule
- A rule that creates Sentinel incidents from alerts raised by other Microsoft security products.
- Anomaly rule
- A built-in machine learning rule whose parameters, but not logic, can be tuned in a duplicate.
- Fusion
- Sentinel's machine-learning correlation that combines alerts and anomalies into multistage attack incidents.
- Entity mapping
- Mapping query columns to entity types such as Account, Host and IP so alerts carry structured evidence.
- Alert grouping
- Settings that decide which alerts are combined into one incident and for how long.
- Custom detection rule
- A scheduled advanced hunting query in Defender XDR that creates alerts and can trigger automated response actions.
- Required columns
- Identifier columns, such as Timestamp, DeviceId and ReportId, that a custom detection query must return.
- Impacted entity
- The device, user or mailbox column the rule marks as affected and targets for actions.
- MITRE ATT&CK
- A public framework of adversary tactics and techniques used to label detections and measure coverage.
- Tactic
- In MITRE ATT&CK, the adversary's goal at a stage of an attack, such as credential access or persistence.
- Technique
- In MITRE ATT&CK, the method used to achieve a tactic, identified by an ID such as T1003.
- Automation rule
- A built-in Sentinel rule that acts on incidents or alerts when they are created or updated, including running playbooks.
- Playbook
- An Azure Logic Apps workflow triggered by a Sentinel incident, alert or entity for enrichment or response.
- Incident task
- A checklist item inside an incident that standardizes and tracks investigation steps.
- Watchlist
- A reference list, queried with _GetWatchlist(), used to enrich or filter rules and hunts.
- Workbook
- An interactive KQL-driven dashboard for visualization and reporting.
- UEBA
- User and entity behavior analytics, which baselines normal activity and highlights anomalies on entity pages.
- STIX/TAXII
- A standard format (STIX) and transport protocol (TAXII) for sharing threat intelligence indicators.
Domain 2: Respond to security incidents (37%)
Exam tips
- An authorized penetration test or red-team exercise is informational expected activity with a security testing determination (benign positive in Sentinel), not a false positive. False positive means the detection logic or data was wrong.
- Isolation versus restrict app execution is a classic pair: active spread or command-and-control means isolate; user must keep working and the tool is unsigned means restrict app execution. A tenant-wide block is a file indicator, not quarantine on one device.
- If remediation 'did not happen', check the Pending tab: the device group's automation level probably required approval. Attack disruption is automatic and high-confidence; it does not wait for approval.
- Threat Explorer is Plan 2; Real-time detections is Plan 1. The remediation you take from Threat Explorer shows up in the Action center. Soft delete is recoverable; hard delete is not.
- KRBTGT is reset twice because AD accepts tickets signed with the current or the previous password. DCSync is recognized by replication requests coming from a machine that is not a domain controller.
- Password reset plus revoke sessions is the usual correct answer for token theft. Confirm compromised raises risk to high and trains the model; dismiss only clears risk.
- Resetting a password does not remove a malicious OAuth grant. The answer is to revoke consent or ban the app, then restrict user consent.
- Questions asking 'who did what, when' in Microsoft 365 point to a Purview Audit search. 'Which emails did the attacker read' points to the MailItemsAccessed audit event.
- Run a Logic App on one alert now: Trigger automated response on the Take action tab. Run it every time automatically: workflow automation. Stop expected alerts: suppression rule.
- If entities are missing from the investigation graph, the fix is entity mapping in the analytics rule. For an authorized test, close as benign positive; false positive means the rule or data was wrong.
- Map the need to the feature: 'explain this obfuscated command' is script analysis, 'what should I do next' is guided response, 'brief the next shift' is the incident summary or incident report.
Key terms
- Incident
- A group of correlated alerts and evidence that represents one attack or related activity.
- Alert correlation
- Automatic grouping of alerts into incidents based on shared entities and timing.
- Attack story
- The incident view that shows the alert timeline, an incident graph and alert details.
- Merge incidents
- Combining incidents that represent the same attack so their alerts sit in one incident.
- Classification
- The resolution verdict: true positive, informational expected activity or false positive.
- Determination
- The detailed reason under a classification, such as phishing, security testing or not malicious.
- Isolate device
- Disconnects a device from the network except for the Defender service connection.
- Restrict app execution
- Allows only Microsoft-signed code to run on a device while it stays connected.
- Investigation package
- A zip of forensic data (processes, connections, autoruns, logs) collected remotely from a device.
- Live response
- A remote shell session into a device for collecting files and running approved scripts.
- Stop and quarantine file
- An action that kills a file's processes and quarantines it on the devices where it was seen.
- Device timeline
- A chronological view of a device's process, network, file, logon and registry events with alerts marked.
- Action center
- The Defender portal page listing pending and completed remediation actions across Defender XDR.
- Automated investigation and response (AIR)
- Defender's automatic investigation of alerts that produces verdicts and proposed remediation actions.
- Automation level
- A device group setting that decides whether remediation runs automatically or waits for approval.
- Automatic attack disruption
- High-confidence automatic containment of compromised devices and users during an active attack.
- Contain device
- An attack disruption action that stops other onboarded devices from communicating with a compromised device.
- Contain user
- An attack disruption action that stops a compromised account from being used to move laterally.
- Threat Explorer
- An MDO Plan 2 tool for searching, analyzing and remediating email across the tenant.
- Real-time detections
- The simpler MDO Plan 1 email search tool, with fewer remediation actions than Threat Explorer.
- Soft delete
- Removing a message from the mailbox into Recoverable Items, where it can still be restored.
- Submissions
- The Defender portal page for user-reported messages and admin submissions of email, files and URLs to Microsoft.
- Zero-hour auto purge (ZAP)
- Automatic removal of already delivered messages later found to be malicious.
- Tenant Allow/Block List
- A tenant-wide list of allow and block entries for senders, URLs and files.
- DCSync
- An attack that impersonates a domain controller to request password data via directory replication.
- KRBTGT account
- The AD account whose key signs every Kerberos ticket-granting ticket in the domain.
- Golden Ticket
- A forged Kerberos TGT created with the stolen KRBTGT hash, granting access as any user.
- Pass-the-hash
- Authenticating with a stolen NTLM hash instead of the password.
- Lateral movement path
- A chain of sessions and admin rights that lets an attacker move from a low-value account to a sensitive one.
- LAPS
- Local Administrator Password Solution, which gives each device a unique, rotated local admin password.
- Sign-in risk
- The likelihood that a specific sign-in was not performed by the legitimate user.
- User risk
- The likelihood that the account itself is compromised, such as from leaked credentials.
- Confirm user compromised
- An analyst action that sets user risk to high, triggers policies and feeds back to the risk model.
- Revoke sessions
- Invalidating a user's refresh tokens and session cookies so all sessions must re-authenticate.
- MFA fatigue
- An attack that floods a user with push approval prompts hoping they approve one.
- Number matching
- An MFA push setting that requires typing a displayed number, defeating blind approvals in MFA fatigue attacks.
- Cloud access security broker (CASB)
- A service that gives visibility and control over the use of cloud apps; Defender for Cloud Apps is Microsoft's.
- Impossible travel
- An anomaly alert for sign-ins from distant locations within a time that makes physical travel impossible.
- OAuth app consent
- Permission a user or admin grants an app to access data on their behalf.
- Consent phishing
- Tricking users into granting a malicious app OAuth permissions, bypassing password controls.
- Ban app
- A Defender for Cloud Apps action that revokes an OAuth app's permissions and blocks new consent.
- Admin consent workflow
- An Entra ID feature that lets users request admin approval for apps they are not allowed to consent to.
- Data loss prevention (DLP)
- Purview policies that detect and control sharing of sensitive information across services and endpoints.
- Insider risk management
- Purview capability that detects risky user activity such as data theft by departing employees.
- Pseudonymization
- Showing an alias instead of a user's real name in insider risk alerts until identity reveal is authorized.
- Unified audit log
- Purview Audit's record of user and admin activities across Microsoft 365 services.
- Audit (Premium)
- The Purview Audit tier that adds longer retention, custom retention policies and extra high-value events.
- MailItemsAccessed
- A mailbox audit event, now available in Audit (Standard) as well as Premium, that shows which mailbox items were accessed.
- Security alert
- A Defender for Cloud detection of a threat against a protected workload, raised by a paid Defender plan.
- Take action tab
- The alert tab with sections to inspect context, mitigate, prevent recurrence, trigger automation and suppress similar alerts.
- Workflow automation
- A Defender for Cloud feature that runs a Logic App automatically when alerts or recommendations match conditions.
- Suppression rule
- A rule that hides or dismisses expected alerts matching conditions, with an optional expiration.
- Continuous export
- Streaming Defender for Cloud alerts and recommendations to Event Hubs or a Log Analytics workspace.
- Dismiss
- An alert status change that hides the alert without remediating anything.
- Investigation graph
- A visual map of an incident's entities where exploration queries add related entities and alerts.
- Entity page
- A page that shows an entity's alerts, activity timeline, related entities and UEBA insights.
- Investigation priority
- A UEBA score in BehaviorAnalytics that ranks how unusual an activity is, to guide triage.
- Playbook Operator
- A Sentinel role that allows listing and running playbooks manually.
- Benign positive
- A Sentinel classification for activity that was correctly detected but expected, such as an approved test.
- Incident task
- A checklist item in an incident, added manually or by automation, that tracks investigation steps.
- Security Copilot
- Microsoft's generative AI assistant for security operations, embedded in the Defender portal.
- Incident summary
- A Copilot-generated narrative of an incident's timeline, entities, attack stages and status.
- Guided response
- Copilot's recommended triage, containment, investigation and remediation actions for an incident.
- Script analysis
- A Copilot feature that decodes and explains suspicious scripts and command lines found in evidence.
- Incident report
- A Copilot-generated document of an incident's timeline, findings and actions taken.
- Security compute unit (SCU)
- The unit of capacity an organization provisions to run Security Copilot.
Domain 3: Perform threat hunting (22%)
Exam tips
- Know the difference between project (keep only listed columns) and extend (add columns, keep all), and between take (unsorted sample) and top (sorted and limited). Remember Timestamp in Defender tables and TimeGenerated in Sentinel tables.
- The exam likes asking which join kind finds records without a match (leftanti) and why has is preferred over contains (performance on whole terms). Remember the default join kind is innerunique.
- Match question wording to tables: process and command line means DeviceProcessEvents; connection or remote IP means DeviceNetworkEvents; on-premises Kerberos or NTLM logons means IdentityLogonEvents; mailbox rules in Exchange Online usually means CloudAppEvents.
- If a scenario says the rule can't be saved or alerts lack entities, the query is missing required or entity columns. Generated KQL is a starting point that the analyst must validate.
- Save evidence from a hunt: bookmark. Watch for new matches without writing a rule: livestream. Python, machine learning or complex enrichment: notebook with MSTICPy.
- Look for these clues: 'find records matching X from last year' means search job; 'investigate everything in that week with full KQL' means restore; 'query the data lake on a schedule and send results to the analytics tier' means KQL job.
- One query across many vendors for the same event type means ASIM. Use the _Im_ filtering parsers with parameters for performance; _ASim_ parsers take no parameters.
- TAXII is the transport and STIX the format. Written reports on actors with exposure and mitigation status in your tenant means threat analytics; matching indicators against logs means TI map analytics rules.
- When a question asks what an attacker could reach from a compromised identity or device, the answer is blast radius or an attack path view; when it asks which events match a condition, it is a KQL query.
Key terms
- where
- An operator that keeps only rows matching a condition.
- project
- An operator that keeps, orders and optionally renames only the listed columns.
- extend
- An operator that adds calculated columns while keeping the existing ones.
- summarize
- An operator that groups rows and computes aggregates such as count() or dcount().
- bin()
- A function that rounds values, usually timestamps, into fixed-size buckets for grouping.
- ago()
- A function that returns a time relative to now, such as ago(1d) for one day ago.
- render
- An operator that draws the query results as a chart, such as a timechart.
- has vs contains
- has matches whole indexed terms quickly; contains matches any substring and is slower.
- has_any
- An operator that checks whether a text column contains any term from a list.
- let
- A statement that names a value, list or query for reuse later in the query.
- leftanti join
- A join that returns left-side rows with no match on the right.
- union
- An operator that stacks rows from several tables into one result.
- mv-expand
- An operator that turns each element of an array into its own row.
- make-series
- An operator that builds regular time series for analysis with functions such as series_decompose_anomalies().
- DeviceProcessEvents
- The table of process creation events, including command lines and parent process details.
- DeviceNetworkEvents
- The table of network connections from devices, with remote IP, port, URL and initiating process.
- NetworkMessageId
- The email identifier that links EmailEvents with EmailUrlInfo, EmailAttachmentInfo and related tables.
- IdentityLogonEvents
- Authentication events from Defender for Identity (on-premises AD) and Microsoft Entra ID.
- CloudAppEvents
- Activity from cloud apps such as Exchange Online and SharePoint, with details in RawEventData.
- AlertEvidence
- One row per entity attached to an alert, joined to AlertInfo on AlertId.
- Hypothesis-driven hunting
- Hunting that starts from a specific idea about attacker behavior and tests it with queries.
- Detection-ready query
- A query that returns specific events with required identifier and entity columns and acceptable noise.
- arg_max()
- An aggregation that returns the row with the maximum value of a column, keeping other columns.
- Noise testing
- Running a candidate detection over its full lookback to measure how often it would fire before saving it.
- Natural-language to KQL
- Security Copilot's ability to generate a KQL query from a plain-language request.
- Detection rules page
- The Defender portal page where custom detections are listed, edited, run and monitored.
- Threat hunting
- Proactively searching for attackers who have evaded existing detections, usually starting from a hypothesis.
- Hunting query
- A saved KQL query for proactive searching, often mapped to MITRE ATT&CK, that does not create alerts.
- Hunt
- A Sentinel object that organizes a hunting project with a hypothesis, queries, status and findings.
- Bookmark
- Saved query results with notes, tags and entities that can be added to or create an incident.
- Livestream
- A session that runs a hunting query continuously on new data and notifies you of matches.
- MSTICPy
- An open-source Python library for security investigations in notebooks, with data queries, enrichment and visualization.
- Long-term retention
- Low-cost storage of data beyond interactive retention, not directly usable by analytics rules.
- Search job
- An asynchronous search of long-term data whose matching records are written to a _SRCH table.
- Restore
- Bringing a time range of long-term data back to the analytics tier in a _RST table for full querying.
- KQL job
- A one-time or scheduled KQL query over the Sentinel data lake that writes results to an analytics-tier table.
- Data lake exploration
- Interactive KQL querying of data held in the Sentinel data lake tier.
- Results table
- The analytics-tier table created by a search job, restore or KQL job, which can be queried with normal KQL.
- ASIM
- The Advanced Security Information Model, which normalizes events from different sources into common schemas.
- ASIM schema
- A standard set of column names and values for one event type, such as network session or DNS.
- Source-specific parser
- An ASIM function that normalizes data from one product into a schema.
- Unifying parser
- An ASIM function that combines all source-specific parsers for a schema into one normalized result.
- Filtering parser
- An _Im_ parser that accepts parameters such as time and IP filters to improve performance.
- Query-time normalization
- Converting vendor data to a common schema when the query runs, rather than when data is ingested.
- Indicator of compromise (IoC)
- An observable such as an IP, domain, URL or hash associated with malicious activity.
- STIX
- Structured Threat Information Expression, a standard format for describing threat intelligence.
- TAXII
- Trusted Automated Exchange of Intelligence Information, a protocol for sharing STIX data between servers and clients.
- TI map rule
- A threat intelligence matching analytics rule that alerts when indicators appear in logs.
- Threat analytics
- Defender portal reports on active threats, showing related incidents, impacted assets and mitigation status.
- Exposure and mitigations
- The threat analytics section showing whether your devices have the patches and settings that defend against a threat.
- Graph
- A data model of nodes (entities) and edges (relationships) used to analyze connections.
- Node and edge
- A node is an entity such as a user or device; an edge is a relationship between two nodes, such as member of.
- Sentinel graph
- A relationship model of identities, devices, resources and activity built on Sentinel data lake and Microsoft security data.
- Hunting graph
- A visual, interactive exploration of entity relationships during a hunt in the Defender portal.
- Blast radius
- The set of assets an attacker could reach from a compromised user or device, shown as paths to critical targets.
- Attack path
- A chain of relationships and weaknesses that could lead an attacker from an entry point to a critical asset.
Study SC-200 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SC-200 study planLessons, quizzes, exam simulations and hands-on labs.