Microsoft / Associate / SC-200
Security Operations Analyst
Collect useful evidence, engineer detections, investigate incidents and turn hunting into reliable response.
This path targets the published October 21, 2026 update. That is later than this October 10 review; compare your booking outline for an earlier sitting. Microsoft portal layouts, data-lake features and licensing can change, so study the decision and evidence path as well as the current UI.
THE REVISION PATH
Your topics, in order.
Read. Recall. Explain the alternative.
SOC Platform, Roles and Retention
Collect with a purpose; keep it where the investigation can use it.
Connectors, AMA and Collection Boundaries
An installed agent is only the start of an evidence pipeline.
Detection Engineering, Tuning and Automation
A query finds evidence; a detection makes it actionable.
Endpoint Controls and Investigation
Contain the device while preserving the story.
Cross-Domain Incidents and Microsoft 365 Evidence
Follow the identity across email, devices, apps and cloud.
KQL Hunting and Evidence Quality
Filter early, preserve identifiers, test the hypothesis.
Data Lake Jobs, Summaries and Notebooks
Scan history deliberately; keep summaries tied to raw evidence.
Attack Graphs, Copilot and Investigation Decisions
A relationship suggests a path; evidence proves the event.
How this guide is organised
Original revision notes arranged around practical decisions. The linked official objectives define the mapped scope; primary technical documentation supports the explanations. Read, recall without looking, then explain why another option would fail.
- Official exam guide ↗ Scope authority
Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.