All certifications / SC-200 / Lessons
SC-200 SC-200 lessons
Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Manage a security operations environment
- Defender XDR settings: incident and alert email notifications, alert tuning (suppression) rules, portal RBAC and device groups
- Defender for Endpoint configuration: onboarding, device groups, tamper protection, attack surface reduction rules (audit, warn, block), indicators and network protection, device discovery
- Defender for Cloud: foundational CSPM vs paid workload protection plans (Servers, Storage, Databases), connecting AWS and GCP accounts, Defender for Endpoint integration for servers
- Defender for Identity sensors on domain controllers and AD FS/AD CS servers; Defender for Office 365 Safe Links and Safe Attachments
- Sentinel workspace design: Log Analytics workspace, Sentinel roles (Reader, Responder, Contributor, Automation Contributor), onboarding to the Defender portal
- Data retention and cost: analytics tier vs Sentinel data lake tier, table plans, summary rules, SOC optimization recommendations
- Data connectors and Content hub solutions; Windows Security Events and CEF/Syslog through the Azure Monitor Agent and data collection rules (DCRs); the Logs Ingestion API for custom sources
- Analytics rules: scheduled, near-real-time (NRT), Microsoft incident creation, anomaly and Fusion; entity mapping, alert grouping, custom details
- Custom detection rules in Defender XDR advanced hunting; MITRE ATT&CK coverage of your rules
- Automation: automation rules vs Logic Apps playbooks, triggers, incident tasks; watchlists, workbooks, UEBA and threat intelligence connectors
Domain 2: Respond to security incidents
- Defender portal incident queue: triage, assignment, attack story, alert correlation, linking alerts and merging incidents, classification and determination
- Defender for Endpoint response: isolate device, restrict app execution, run antivirus scan, collect investigation package, live response, stop and quarantine file, file indicators, device timeline
- Action center: pending and completed remediation actions; automatic attack disruption of compromised users and devices
- Defender for Office 365: Threat Explorer, removing delivered phishing, user-reported messages and Submissions
- Defender for Identity alerts: DCSync, Golden Ticket, pass-the-hash; lateral movement paths; KRBTGT reset
- Microsoft Entra ID Protection: risky users and sign-ins, confirm user compromised, revoking sessions; MFA fatigue response
- Defender for Cloud Apps: impossible travel and other anomaly alerts, OAuth app risk and revoking app consent
- Microsoft Purview: DLP and insider risk alerts in the Defender portal; Purview Audit (unified audit log) searches
- Defender for Cloud security alerts: alert details, the Take action tab, triggering automation
- Sentinel incidents: investigation graph, entity pages and UEBA insights, running playbooks on demand, incident tasks, closing with the right classification
- Microsoft Security Copilot embedded in the Defender portal: incident summaries, guided response, script analysis
Domain 3: Perform threat hunting
- KQL basics: where, project, extend, summarize, count, bin, ago(), order by, take, render
- KQL for hunting: has vs contains, in and has_any, let statements and dynamic lists, join kinds, union, parse_json and mv-expand, make-series with anomaly functions
- Advanced hunting schema: DeviceProcessEvents, DeviceNetworkEvents, DeviceLogonEvents, EmailEvents, EmailUrlInfo, IdentityLogonEvents, CloudAppEvents, AlertInfo and AlertEvidence
- Turning a hunting query into a custom detection rule; Security Copilot help with writing KQL
- Sentinel hunting: hunting queries, hunts, bookmarks, livestream, notebooks with MSTICPy
- Long-term data: search jobs, restore, Sentinel data lake KQL jobs
- Normalized hunting with ASIM parsers across vendors
- Threat intelligence: TI indicators, TAXII feeds, threat analytics reports in Defender XDR
- Graph-based hunting: Sentinel graph and hunting graphs with blast radius