Microsoft Certified: Security Operations Analyst Associate Training (SC-200)

Duration: 4 Days
Language: English
Level: Intermediate
The SC-200: Microsoft Security Operations Analyst Associate certification is designed for professionals who detect, investigate, and respond to cybersecurity threats using Microsoft’s security tools. It validates your expertise in managing threat detection, incident response, and implementing proactive measures to secure an organization’s IT infrastructure. This certification is ideal for security analysts, IT professionals, and those in operations-focused security roles.

Prerequisites: There are no mandatory prerequisites for SC-200, but it is recommended that candidates:

• Have hands-on experience with Microsoft security tools such as Microsoft Sentinel, Microsoft Defender for Endpoint, and Microsoft 365 Defender.
• Understand core security principles, threat management, and incident response methodologies.
• Possess familiarity with Azure and Microsoft 365 environments, including basic knowledge of networking and IT fundamentals.
• While SC-900: Microsoft Security, Compliance, and Identity Fundamentals is not required, it can provide a helpful foundation for candidates new to Microsoft security solutions. Practical experience with security operations or tools will also enhance your readiness for the exam.

Read More

• Demos & Labs: You will learn while working with the real environment
• Exam Voucher is included*
• Industry Recognized Certification
• Up to date Microsoft approved material

• Technical labs and discussion board with the instructor available for 6 months.
• For Group/Private sessions, preferred dates may be available and guaranteed to run.

• 20% discount on any two (2) certification courses!
• 30% discount on any three (3) or more certification courses!

Popular Bundle:
1. SC-200 + SC-900 (20% discount)
MS Partner logo dark
March 10, 2025
1800 (USD)

/

2520(CAD)
April 8, 2025
1800 (USD)

/

2520(CAD)
May 20, 2025
1800 (USD)

/

2520(CAD)

Need this training exclusively for your team?

Topics

Skill: Manage a Security Operations Environment

Part 1: Configure Settings in Microsoft Defender XDR

Session 1: Alert and Vulnerability Notifications

  • Configure alert and vulnerability notification rules
  • Manage automated investigation and response capabilities

Session 2: Advanced Features and Attack Disruption

  • Configure Microsoft Defender for Endpoint advanced features

Configure endpoint rules and automatic attack disruption

Part 2: Manage Assets and Environments

Session 3: Device and Resource Management

  • Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint
  • Identify unmanaged devices in Microsoft Defender for Endpoint
  • Discover unprotected resources using Defender for Cloud

Session 4: Risk Mitigation and Exposure Management

  • Identify and remediate devices at risk using Microsoft Defender Vulnerability Management

Mitigate risk using Exposure Management in Microsoft Defender XDR

Skill: Configure Protections and Detections

Part 1: Protections in Microsoft Defender

Session 5: Policy Configuration

  • Configure policies for Microsoft Defender for Cloud Apps
  • Configure policies for Microsoft Defender for Office 365
  • Configure security policies for Microsoft Defender for Endpoints, including attack surface reduction (ASR) rules
  • Configure cloud workload protections in Microsoft Defender for Cloud

Part 2: Detections in Defender XDR and Sentinel

Session 6: Detection Rules and Alerts

  • Configure and manage custom detection rules in Microsoft Defender XDR
  • Manage alerts, including tuning, suppression, and correlation
  • Configure deception rules in Microsoft Defender XDR

Session 7: Analytics and Behavioral Detection

  • Classify and analyze data using entities in Microsoft Sentinel
  • Configure and manage analytics rules
  • Query Microsoft Sentinel data using ASIM parsers

Implement behavioral analytics

Skill: Manage Incident Response

Part 1: Incident Management in Microsoft Defender

Session 8: Responding to Alerts

  • Investigate and remediate threats using Microsoft Defender portals
  • Investigate and remediate ransomware and business email compromise incidents identified by automatic attack disruption
  • Investigate compromised entities identified by Microsoft Purview DLP and insider risk policies

Session 9: Investigating Devices and Activities

  • Investigate device timelines in Microsoft Defender for Endpoint
  • Perform actions on devices, including live response and collecting investigation packages
  • Investigate Microsoft 365 activities using unified audit logs, Content Search, and Graph activity logs

Part 2: Incident Management in Microsoft Sentinel

Session 10: Sentinel Incident Management

  • Investigate and remediate incidents in Microsoft Sentinel
  • Create and configure automation rules and playbooks
  • Run playbooks on on-premises resources

Part 3: Implement and Use Copilot for Security

Session 11: Configuring and Managing Copilot

  • Create and manage promptbooks
  • Manage sources for Copilot for Security, including plugins and files
  • Integrate Copilot for Security by implementing connectors
  • Monitor Copilot for Security capacity and cost

Session 12: Incident Management with Copilot

  • Identify threats and risks using Copilot for Security
  • Investigate incidents and manage permissions using Copilot

Skill: Manage Security Threats

Part 1: Threat Hunting with Microsoft Defender XDR

Session 13: Threat Hunting

  • Hunt for threats using KQL and threat analytics

Create custom hunting queries in KQL

Part 2: Threat Hunting with Microsoft Sentinel

Session 14: Sentinel Threat Management

  • Analyze attack vector coverage using the MITRE ATT&CK matrix
  • Manage and use threat indicators
  • Create and manage hunts and hunting queries
  • Use hunting bookmarks and retrieve archived log data

Part 3: Sentinel Workbooks

Session 15: Workbook Configuration

  • Activate and customize workbook templates
  • Create custom workbooks that include KQL
  • Configure visualizations for insights and investigations

Share:
Facebook
Twitter
LinkedIn

Microsoft Certified: Security Operations Analyst Associate Training (SC-200)

Thank you for your interest! Kindly fill out the form below to secure your seat.

Duration: 4 Days

Session start date:

March 10, 2025

Prices:

$1800 (USD)

/

$2520 (CAD)

+ Applicable taxes

Payment Method

Disclaimer: Please note that MakeCloudWork reserves the right to reschedule training dates to the next available session in the event of insufficient participation or other unforeseen circumstances. We will notify all participants of any changes in advance and provide alternative options where applicable.

Microsoft Certified: Security Operations Analyst Associate Training (SC-200)

Thank you for your interest! Kindly fill out the form below to secure your seat.

Duration: 4 Days

Session start date:

April 8, 2025

Prices:

$1800 (USD)

/

$2520 (CAD)

+ Applicable Taxes

Payment Method

Disclaimer: Please note that MakeCloudWork reserves the right to reschedule training dates to the next available session in the event of insufficient participation or other unforeseen circumstances. We will notify all participants of any changes in advance and provide alternative options where applicable.

Microsoft Certified: Security Operations Analyst Associate Training (SC-200)

Thank you for your interest! Kindly fill out the form below to secure your seat.

Duration: 4 Days

Session start date:

May 20, 2025

Prices:

$1800 (USD)

/

$2520 (CAD)

+ Applicable Taxes

Payment Method

Disclaimer: Please note that MakeCloudWork reserves the right to reschedule training dates to the next available session in the event of insufficient participation or other unforeseen circumstances. We will notify all participants of any changes in advance and provide alternative options where applicable.

Microsoft Certified: Security Operations Analyst Associate Training (SC-200)

Thank you for your interest! Kindly fill out the form below to get started.

Duration: 4 Days
Preferred Time Frame:
makecloudwork email success

Thank you!

We’ve received your inquiry, and one of our cloud experts will be in touch with you shortly. We look forward to helping you advance your cloud skills!

makecloudwork email success

Thank you for your interest in our Cloud Administration Certification Courses

We want to acknowledge that we have successfully received your inquiry and it is important to us. You will receive a follow-up email from our team soon.

makecloudwork email success

Thank you for your interest in our bootcamp!

You have successfully opted in to download our bootcamp course guide. Kindly check your email for the download link.