StudyToCert

All certifications / SC-200 / Cheat sheet

SC-200 SC-200 cheat sheet

Every exam tip and key term from the free SC-200 lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Manage a security operations environment (41%)

Exam tips

Key terms

Alert tuning rule
A rule, formerly called a suppression rule, that hides or auto-resolves alerts matching chosen conditions without changing protection.
Unified RBAC
Defender XDR's role-based access control model, where custom roles combine permission groups and are assigned per data source.
Device group
A ranked set of devices, defined by matching rules, that controls access, automation level and scope for other settings.
Device group rank
The order that decides which group a device joins when it matches several; the highest-ranked match wins.
Incident notification rule
A setting that emails chosen recipients when incidents matching filters such as severity or source are created or updated.
Automation level
The per-device-group setting that decides whether automated investigation remediates on its own or waits for approval.
Onboarding package
The script or configuration downloaded from the Defender portal that connects a device to your tenant through a chosen deployment method.
Tamper protection
A setting that prevents local changes to Defender security settings, even by administrators or malware with admin rights.
ASR rule modes
Audit logs only, Warn blocks but allows a user bypass, and Block enforces the rule.
Indicator
A custom allow, audit, warn or block entry for a file hash, IP address, URL, domain or certificate.
Network protection
An operating-system-wide filter that blocks connections to malicious domains and IPs and enforces custom IP and URL indicators outside Edge.
Device discovery
The feature that uses onboarded devices to find unmanaged devices on the network, in basic (passive) or standard (active) mode.
Foundational CSPM
The free Defender for Cloud tier that provides secure score, recommendations and asset inventory.
Defender CSPM
The paid posture plan that adds attack path analysis, cloud security explorer, agentless scanning and governance.
Cloud workload protection
The paid Defender plans (Servers, Storage, Databases and others) that detect threats and raise security alerts.
Multicloud connector
The Defender for Cloud connection to an AWS account or GCP project, created with a CloudFormation template or a GCP script.
Azure Arc
The service that projects non-Azure servers into Azure so extensions and Defender plans can be applied to them.
Defender for Endpoint integration
The Defender for Servers feature that deploys and licenses the Defender for Endpoint sensor on protected servers.
Defender for Identity sensor
Software installed on domain controllers and AD FS, AD CS and Entra Connect servers that collects identity traffic and events for detection.
Directory Service account
The account, ideally a gMSA, that Defender for Identity uses to query Active Directory.
Group managed service account (gMSA)
An AD account whose password is managed and rotated automatically by domain controllers, suited to services.
Safe Links
An MDO feature that checks URLs when they are clicked in email, Teams and Office apps.
Safe Attachments
An MDO feature that detonates attachments in a sandbox to find unknown malware before or during delivery.
Dynamic Delivery
A Safe Attachments action that delivers the email body immediately and adds the attachment after sandbox scanning.
Preset security policies
Microsoft-maintained Standard and Strict policy bundles that take precedence over custom policies.
Log Analytics workspace
The Azure Monitor data store that Sentinel is enabled on and where all its tables live.
Microsoft Sentinel Reader
The role that allows viewing data, incidents and content without changing anything.
Microsoft Sentinel Responder
The role that allows viewing data and managing incidents but not creating or editing content.
Microsoft Sentinel Contributor
The role that adds creating and editing content such as analytics rules, workbooks and watchlists.
Microsoft Sentinel Automation Contributor
A role granted to the Sentinel service on a resource group so automation rules can run playbooks there.
Unified security operations platform
Sentinel and Defender XDR working together in the Microsoft Defender portal with one incident queue.
Primary workspace
The Sentinel workspace designated in the Defender portal whose alerts are correlated with Defender XDR data.
Analytics tier
The interactive, higher-cost storage tier that supports analytics rules, workbooks and fast hunting queries.
Sentinel data lake tier
Low-cost long-term storage for high-volume data, queried with KQL jobs, exploration queries or notebooks.
Table plan
The per-table setting (Analytics, Basic or Auxiliary) that trades ingestion cost against query features.
Summary rule
A scheduled KQL query that aggregates detailed data and writes the results into an analytics-tier table.
SOC optimization
A page of recommendations on data value, detection coverage and peer-based data sources.
Ingestion-time transformation
A KQL statement in a DCR that filters or reshapes data before it is stored, reducing cost.
Content hub
Sentinel's catalog of solutions that package connectors, rules, workbooks, parsers and playbooks.
Azure Monitor Agent (AMA)
The current agent for Windows and Linux that collects data according to data collection rules.
Data collection rule (DCR)
A configuration that defines sources, an optional ingestion-time transformation and the destination table.
Common Event Format (CEF)
A structured, key-value log format carried over Syslog that lands in the CommonSecurityLog table.
Linux log forwarder
A Linux machine running a Syslog daemon and AMA that receives logs from devices and sends them to the workspace.
Logs Ingestion API
A REST API for sending custom data into a workspace table through a DCR.
Scheduled rule
A KQL-based analytics rule that runs on a set frequency over a set lookback and alerts when a threshold is met.
NRT rule
A near-real-time rule that runs about every minute for urgent detections.
Microsoft security rule
A rule that creates Sentinel incidents from alerts raised by other Microsoft security products.
Anomaly rule
A built-in machine learning rule whose parameters, but not logic, can be tuned in a duplicate.
Fusion
Sentinel's machine-learning correlation that combines alerts and anomalies into multistage attack incidents.
Entity mapping
Mapping query columns to entity types such as Account, Host and IP so alerts carry structured evidence.
Alert grouping
Settings that decide which alerts are combined into one incident and for how long.
Custom detection rule
A scheduled advanced hunting query in Defender XDR that creates alerts and can trigger automated response actions.
Required columns
Identifier columns, such as Timestamp, DeviceId and ReportId, that a custom detection query must return.
Impacted entity
The device, user or mailbox column the rule marks as affected and targets for actions.
MITRE ATT&CK
A public framework of adversary tactics and techniques used to label detections and measure coverage.
Tactic
In MITRE ATT&CK, the adversary's goal at a stage of an attack, such as credential access or persistence.
Technique
In MITRE ATT&CK, the method used to achieve a tactic, identified by an ID such as T1003.
Automation rule
A built-in Sentinel rule that acts on incidents or alerts when they are created or updated, including running playbooks.
Playbook
An Azure Logic Apps workflow triggered by a Sentinel incident, alert or entity for enrichment or response.
Incident task
A checklist item inside an incident that standardizes and tracks investigation steps.
Watchlist
A reference list, queried with _GetWatchlist(), used to enrich or filter rules and hunts.
Workbook
An interactive KQL-driven dashboard for visualization and reporting.
UEBA
User and entity behavior analytics, which baselines normal activity and highlights anomalies on entity pages.
STIX/TAXII
A standard format (STIX) and transport protocol (TAXII) for sharing threat intelligence indicators.

Domain 2: Respond to security incidents (37%)

Exam tips

Key terms

Incident
A group of correlated alerts and evidence that represents one attack or related activity.
Alert correlation
Automatic grouping of alerts into incidents based on shared entities and timing.
Attack story
The incident view that shows the alert timeline, an incident graph and alert details.
Merge incidents
Combining incidents that represent the same attack so their alerts sit in one incident.
Classification
The resolution verdict: true positive, informational expected activity or false positive.
Determination
The detailed reason under a classification, such as phishing, security testing or not malicious.
Isolate device
Disconnects a device from the network except for the Defender service connection.
Restrict app execution
Allows only Microsoft-signed code to run on a device while it stays connected.
Investigation package
A zip of forensic data (processes, connections, autoruns, logs) collected remotely from a device.
Live response
A remote shell session into a device for collecting files and running approved scripts.
Stop and quarantine file
An action that kills a file's processes and quarantines it on the devices where it was seen.
Device timeline
A chronological view of a device's process, network, file, logon and registry events with alerts marked.
Action center
The Defender portal page listing pending and completed remediation actions across Defender XDR.
Automated investigation and response (AIR)
Defender's automatic investigation of alerts that produces verdicts and proposed remediation actions.
Automation level
A device group setting that decides whether remediation runs automatically or waits for approval.
Automatic attack disruption
High-confidence automatic containment of compromised devices and users during an active attack.
Contain device
An attack disruption action that stops other onboarded devices from communicating with a compromised device.
Contain user
An attack disruption action that stops a compromised account from being used to move laterally.
Threat Explorer
An MDO Plan 2 tool for searching, analyzing and remediating email across the tenant.
Real-time detections
The simpler MDO Plan 1 email search tool, with fewer remediation actions than Threat Explorer.
Soft delete
Removing a message from the mailbox into Recoverable Items, where it can still be restored.
Submissions
The Defender portal page for user-reported messages and admin submissions of email, files and URLs to Microsoft.
Zero-hour auto purge (ZAP)
Automatic removal of already delivered messages later found to be malicious.
Tenant Allow/Block List
A tenant-wide list of allow and block entries for senders, URLs and files.
DCSync
An attack that impersonates a domain controller to request password data via directory replication.
KRBTGT account
The AD account whose key signs every Kerberos ticket-granting ticket in the domain.
Golden Ticket
A forged Kerberos TGT created with the stolen KRBTGT hash, granting access as any user.
Pass-the-hash
Authenticating with a stolen NTLM hash instead of the password.
Lateral movement path
A chain of sessions and admin rights that lets an attacker move from a low-value account to a sensitive one.
LAPS
Local Administrator Password Solution, which gives each device a unique, rotated local admin password.
Sign-in risk
The likelihood that a specific sign-in was not performed by the legitimate user.
User risk
The likelihood that the account itself is compromised, such as from leaked credentials.
Confirm user compromised
An analyst action that sets user risk to high, triggers policies and feeds back to the risk model.
Revoke sessions
Invalidating a user's refresh tokens and session cookies so all sessions must re-authenticate.
MFA fatigue
An attack that floods a user with push approval prompts hoping they approve one.
Number matching
An MFA push setting that requires typing a displayed number, defeating blind approvals in MFA fatigue attacks.
Cloud access security broker (CASB)
A service that gives visibility and control over the use of cloud apps; Defender for Cloud Apps is Microsoft's.
Impossible travel
An anomaly alert for sign-ins from distant locations within a time that makes physical travel impossible.
OAuth app consent
Permission a user or admin grants an app to access data on their behalf.
Consent phishing
Tricking users into granting a malicious app OAuth permissions, bypassing password controls.
Ban app
A Defender for Cloud Apps action that revokes an OAuth app's permissions and blocks new consent.
Admin consent workflow
An Entra ID feature that lets users request admin approval for apps they are not allowed to consent to.
Data loss prevention (DLP)
Purview policies that detect and control sharing of sensitive information across services and endpoints.
Insider risk management
Purview capability that detects risky user activity such as data theft by departing employees.
Pseudonymization
Showing an alias instead of a user's real name in insider risk alerts until identity reveal is authorized.
Unified audit log
Purview Audit's record of user and admin activities across Microsoft 365 services.
Audit (Premium)
The Purview Audit tier that adds longer retention, custom retention policies and extra high-value events.
MailItemsAccessed
A mailbox audit event, now available in Audit (Standard) as well as Premium, that shows which mailbox items were accessed.
Security alert
A Defender for Cloud detection of a threat against a protected workload, raised by a paid Defender plan.
Take action tab
The alert tab with sections to inspect context, mitigate, prevent recurrence, trigger automation and suppress similar alerts.
Workflow automation
A Defender for Cloud feature that runs a Logic App automatically when alerts or recommendations match conditions.
Suppression rule
A rule that hides or dismisses expected alerts matching conditions, with an optional expiration.
Continuous export
Streaming Defender for Cloud alerts and recommendations to Event Hubs or a Log Analytics workspace.
Dismiss
An alert status change that hides the alert without remediating anything.
Investigation graph
A visual map of an incident's entities where exploration queries add related entities and alerts.
Entity page
A page that shows an entity's alerts, activity timeline, related entities and UEBA insights.
Investigation priority
A UEBA score in BehaviorAnalytics that ranks how unusual an activity is, to guide triage.
Playbook Operator
A Sentinel role that allows listing and running playbooks manually.
Benign positive
A Sentinel classification for activity that was correctly detected but expected, such as an approved test.
Incident task
A checklist item in an incident, added manually or by automation, that tracks investigation steps.
Security Copilot
Microsoft's generative AI assistant for security operations, embedded in the Defender portal.
Incident summary
A Copilot-generated narrative of an incident's timeline, entities, attack stages and status.
Guided response
Copilot's recommended triage, containment, investigation and remediation actions for an incident.
Script analysis
A Copilot feature that decodes and explains suspicious scripts and command lines found in evidence.
Incident report
A Copilot-generated document of an incident's timeline, findings and actions taken.
Security compute unit (SCU)
The unit of capacity an organization provisions to run Security Copilot.

Domain 3: Perform threat hunting (22%)

Exam tips

Key terms

where
An operator that keeps only rows matching a condition.
project
An operator that keeps, orders and optionally renames only the listed columns.
extend
An operator that adds calculated columns while keeping the existing ones.
summarize
An operator that groups rows and computes aggregates such as count() or dcount().
bin()
A function that rounds values, usually timestamps, into fixed-size buckets for grouping.
ago()
A function that returns a time relative to now, such as ago(1d) for one day ago.
render
An operator that draws the query results as a chart, such as a timechart.
has vs contains
has matches whole indexed terms quickly; contains matches any substring and is slower.
has_any
An operator that checks whether a text column contains any term from a list.
let
A statement that names a value, list or query for reuse later in the query.
leftanti join
A join that returns left-side rows with no match on the right.
union
An operator that stacks rows from several tables into one result.
mv-expand
An operator that turns each element of an array into its own row.
make-series
An operator that builds regular time series for analysis with functions such as series_decompose_anomalies().
DeviceProcessEvents
The table of process creation events, including command lines and parent process details.
DeviceNetworkEvents
The table of network connections from devices, with remote IP, port, URL and initiating process.
NetworkMessageId
The email identifier that links EmailEvents with EmailUrlInfo, EmailAttachmentInfo and related tables.
IdentityLogonEvents
Authentication events from Defender for Identity (on-premises AD) and Microsoft Entra ID.
CloudAppEvents
Activity from cloud apps such as Exchange Online and SharePoint, with details in RawEventData.
AlertEvidence
One row per entity attached to an alert, joined to AlertInfo on AlertId.
Hypothesis-driven hunting
Hunting that starts from a specific idea about attacker behavior and tests it with queries.
Detection-ready query
A query that returns specific events with required identifier and entity columns and acceptable noise.
arg_max()
An aggregation that returns the row with the maximum value of a column, keeping other columns.
Noise testing
Running a candidate detection over its full lookback to measure how often it would fire before saving it.
Natural-language to KQL
Security Copilot's ability to generate a KQL query from a plain-language request.
Detection rules page
The Defender portal page where custom detections are listed, edited, run and monitored.
Threat hunting
Proactively searching for attackers who have evaded existing detections, usually starting from a hypothesis.
Hunting query
A saved KQL query for proactive searching, often mapped to MITRE ATT&CK, that does not create alerts.
Hunt
A Sentinel object that organizes a hunting project with a hypothesis, queries, status and findings.
Bookmark
Saved query results with notes, tags and entities that can be added to or create an incident.
Livestream
A session that runs a hunting query continuously on new data and notifies you of matches.
MSTICPy
An open-source Python library for security investigations in notebooks, with data queries, enrichment and visualization.
Long-term retention
Low-cost storage of data beyond interactive retention, not directly usable by analytics rules.
Search job
An asynchronous search of long-term data whose matching records are written to a _SRCH table.
Restore
Bringing a time range of long-term data back to the analytics tier in a _RST table for full querying.
KQL job
A one-time or scheduled KQL query over the Sentinel data lake that writes results to an analytics-tier table.
Data lake exploration
Interactive KQL querying of data held in the Sentinel data lake tier.
Results table
The analytics-tier table created by a search job, restore or KQL job, which can be queried with normal KQL.
ASIM
The Advanced Security Information Model, which normalizes events from different sources into common schemas.
ASIM schema
A standard set of column names and values for one event type, such as network session or DNS.
Source-specific parser
An ASIM function that normalizes data from one product into a schema.
Unifying parser
An ASIM function that combines all source-specific parsers for a schema into one normalized result.
Filtering parser
An _Im_ parser that accepts parameters such as time and IP filters to improve performance.
Query-time normalization
Converting vendor data to a common schema when the query runs, rather than when data is ingested.
Indicator of compromise (IoC)
An observable such as an IP, domain, URL or hash associated with malicious activity.
STIX
Structured Threat Information Expression, a standard format for describing threat intelligence.
TAXII
Trusted Automated Exchange of Intelligence Information, a protocol for sharing STIX data between servers and clients.
TI map rule
A threat intelligence matching analytics rule that alerts when indicators appear in logs.
Threat analytics
Defender portal reports on active threats, showing related incidents, impacted assets and mitigation status.
Exposure and mitigations
The threat analytics section showing whether your devices have the patches and settings that defend against a threat.
Graph
A data model of nodes (entities) and edges (relationships) used to analyze connections.
Node and edge
A node is an entity such as a user or device; an edge is a relationship between two nodes, such as member of.
Sentinel graph
A relationship model of identities, devices, resources and activity built on Sentinel data lake and Microsoft security data.
Hunting graph
A visual, interactive exploration of entity relationships during a hunt in the Defender portal.
Blast radius
The set of assets an attacker could reach from a compromised user or device, shown as paths to critical targets.
Attack path
A chain of relationships and weaknesses that could lead an attacker from an entry point to a critical asset.
Study SC-200 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SC-200 study plan