← SC-200 overviewSecurity Operations Analyst / STUDY TOOLS
Exam coverage map
This path targets the published October 21, 2026 update. That is later than this October 10 review; compare your booking outline for an earlier sitting. Microsoft portal layouts, data-lake features and licensing can change, so study the decision and evidence path as well as the current UI.
Published objectives
| Objective |
Revision topic |
| 1A · Automation and endpoint controls |
03 Detection Engineering, Tuning and Automation, 04 Endpoint Controls and Investigation |
| 1B · Sentinel platform configuration |
01 SOC Platform, Roles and Retention |
| 1C · Security data ingestion |
02 Connectors, AMA and Collection Boundaries |
| 1D · Detection engineering |
03 Detection Engineering, Tuning and Automation |
| 2A · Cross-domain incident response |
05 Cross-Domain Incidents and Microsoft 365 Evidence, 08 Attack Graphs, Copilot and Investigation Decisions |
| 2B · Endpoint investigation and response |
04 Endpoint Controls and Investigation, 05 Cross-Domain Incidents and Microsoft 365 Evidence |
| 2C · Microsoft 365 investigation |
05 Cross-Domain Incidents and Microsoft 365 Evidence |
| 3A · Defender hunting and graph analysis |
06 KQL Hunting and Evidence Quality, 08 Attack Graphs, Copilot and Investigation Decisions |
| 3B · Sentinel hunting and data lake jobs |
06 KQL Hunting and Evidence Quality, 07 Data Lake Jobs, Summaries and Notebooks, 08 Attack Graphs, Copilot and Investigation Decisions |