SC-200 · Hands-on practice

SC-200 Hands-on Labs — practise in a simulated Microsoft Defender portal

Learn it. Practise it. Make it stick.

50 practical tasks. Familiar administration workflows, gradual hints and explanations. Independent simulation — no real tenant, device or cloud resources.

First five tasks are free, repeatable and have no expiry. No credit card required.

SC-200 Hands-on Labs

14.99

All labs for this course. 30 days from payment confirmation.

One-time payment · No automatic renewal.

Purchases are temporarily unavailable. Enjoy your five free tasks.

Best value

SC-200 Practice Exam + Hands-on Labs

29.99

Save €3.99. Exam and all labs each get 60 days.

One-time payment · No automatic renewal.

Purchases are temporarily unavailable. Enjoy your five free tasks.

Your learning path

LAB 01 · FREE

Triage a multi-stage phishing and account takeover incident

Incident response · Defender XDR · 25–30 min

Open lab →

LAB 02 · FREE

Investigate a compromised endpoint and contain it with live response

Incident response · Defender for Endpoint · 25–30 min

Open lab →

LAB 03 · FREE

Hunt a password spray in Advanced hunting and interpret the results

Threat hunting · Advanced hunting · 25–30 min

Open lab →

LAB 04 · FREE

Build a scheduled analytics rule and automate what happens to its incidents

Security operations environment · Microsoft Sentinel · 30–35 min

Open lab →

LAB 05 · FREE

Tune an ASR rule that is blocking a legitimate business process

Security operations environment · Attack surface reduction · 25–30 min

Open lab →

LAB 06 · LOCKED

Classify three Defender for Cloud Apps alerts and act on what the classification means

Respond to security incidents · Microsoft Defender for Cloud Apps · 30–35 min

Included with full SC-200 lab access

LAB 07 · LOCKED

Tune away a noisy internal scanner without suppressing the real detection

Security operations environment · Alert tuning · 30–35 min

Included with full SC-200 lab access

LAB 08 · LOCKED

Ingest an appliance’s text logs: pick the connector, then build the custom table

Security operations environment · Microsoft Sentinel data connectors · 30–35 min

Included with full SC-200 lab access

LAB 09 · LOCKED

Investigate a departing user’s file activity with Microsoft Purview Audit

Respond to security incidents · Microsoft Purview Audit · 30–35 min

Included with full SC-200 lab access

LAB 10 · LOCKED

Read a blast radius graph and pick the containment target that cuts every path

Perform threat hunting · Blast radius and entity relationships · 30–35 min

Included with full SC-200 lab access

LAB 11 · LOCKED

Approve and reject pending actions from two concurrent automated investigations

Respond to security incidents · Automated investigation and response · 30–35 min

Included with full SC-200 lab access

LAB 12 · LOCKED

Respond to a cloud workload compromise without suppressing the detection that found it

Respond to security incidents · Microsoft Defender for Cloud · 35–40 min

Included with full SC-200 lab access

LAB 13 · LOCKED

Turn a hunting query into a custom detection rule that only reaches the right devices

Manage a security operations environment · Custom detections in Microsoft Defender XDR · 35–40 min

Included with full SC-200 lab access

LAB 14 · LOCKED

Scope device groups so full automation never reaches a domain controller

Manage a security operations environment · Device groups, permissions and automation levels · 30–35 min

Included with full SC-200 lab access

LAB 15 · LOCKED

Read a threat analytics report and tell impacted assets apart from exposed ones

Perform threat hunting · Threat analytics in Microsoft Defender XDR · 30–35 min

Included with full SC-200 lab access

LAB 16 · LOCKED

Work the SOC optimization queue: four recommendations, four different right answers

Manage a security operations environment · SOC optimization · 35–40 min

Included with full SC-200 lab access

LAB 17 · LOCKED

Classify nine Defender for Identity alerts and keep the three that are one intrusion together

Respond to security incidents · Microsoft Defender for Identity · 35–40 min

Included with full SC-200 lab access

LAB 18 · LOCKED

Find the one uncovered technique that matters to this threat scenario, and close it with a rule the matrix counts

Manage a security operations environment · MITRE ATT&CK coverage · 35–40 min

Included with full SC-200 lab access

LAB 19 · LOCKED

Build a workbook panel that shows what its title says it shows

Manage a security operations environment · Microsoft Sentinel workbooks · 30–35 min

Included with full SC-200 lab access

LAB 20 · LOCKED

Use Copilot’s incident summary and guided responses — and check the one claim that is wrong

Respond to security incidents · agentic AI and embedded Microsoft Security Copilot · 35–40 min

Included with full SC-200 lab access

LAB 21 · LOCKED

Scope an eDiscovery search so it finds the four items and not the whole tenant

Respond to security incidents · Microsoft Purview eDiscovery · 35–40 min

Included with full SC-200 lab access

LAB 22 · LOCKED

Exclude the two assets that must never be auto-contained, then check what disruption actually did

Manage a security operations environment · Automatic attack disruption · 35–40 min

Included with full SC-200 lab access

LAB 23 · LOCKED

Add four indicators that expire, and refuse the two that would alarm on your own traffic forever

Manage a security operations environment · Threat intelligence in Microsoft Sentinel · 35–40 min

Included with full SC-200 lab access

LAB 24 · LOCKED

Cut the retention bill without losing the investigation, the audit or the detections

Manage a security operations environment · Microsoft Sentinel data retention and tiers · 35–40 min

Included with full SC-200 lab access

LAB 25 · LOCKED

Four apps call Microsoft Graph all day. Find the one that is the intrusion, not the one that is loudest or the one that is failing

Respond to security incidents · Microsoft Graph activity logs · 35–40 min

Included with full SC-200 lab access

LAB 26 · LOCKED

Give six people exactly the Microsoft Sentinel access their job needs, and not one role more

Manage a security operations environment · Microsoft Sentinel roles and permissions · 35–40 min

Included with full SC-200 lab access

LAB 27 · LOCKED

Two Windows connectors, two tables, and three built-in rules that stop matching

Manage a security operations environment · Ingest data sources · 40–45 min

Included with full SC-200 lab access

LAB 28 · LOCKED

Collect every subscription’s activity log without touching a single resource by hand

Manage a security operations environment · Ingest data sources · 40–45 min

Included with full SC-200 lab access

LAB 29 · LOCKED

Nine hundred anomalies a day, and the rule producing them cannot be edited

Manage a security operations environment · Configure protections and detections · 30–35 min

Included with full SC-200 lab access

LAB 30 · LOCKED

Fourteen months of firewall logs, a four-hour hunt, and one job that has to be right

Perform threat hunting · Microsoft Sentinel data lake, KQL jobs and notebooks · 45–50 min

Included with full SC-200 lab access

LAB 31 · LOCKED

Wire a compromised-user playbook to an automation rule so that it actually runs, for the people who are actually allowed to run it

Manage a security operations environment · Configure automation in Microsoft Sentinel · 35–40 min

Included with full SC-200 lab access

LAB 32 · LOCKED

Pick the right rule type for three detection requests, then build the one NRT rule that is actually justified

Manage a security operations environment · Configure protections and detections · 30–35 min

Included with full SC-200 lab access

LAB 33 · LOCKED

Get Syslog and CEF off a mixed estate and into the tables the detections actually query

Manage a security operations environment · Ingest data sources · 40–45 min

Included with full SC-200 lab access

LAB 34 · LOCKED

Set the endpoint advanced features this tenant actually needs, then collect PowerShell from the privileged workstations without collecting everything from everywhere

Manage a security operations environment · Configure settings in Microsoft Defender XDR · 35–40 min

Included with full SC-200 lab access

LAB 35 · LOCKED

Hunt a credential-theft campaign, bookmark the three rows that are evidence, and escalate them into the incident that already exists

Perform threat hunting · Detect threats using Microsoft Sentinel · 40–45 min

Included with full SC-200 lab access

LAB 36 · LOCKED

Work a Microsoft Sentinel incident inside the Defender queue: find the rule alert, fix what it failed to map, finish the tasks, then close it with the classification this portal actually has

Respond to security incidents · Microsoft Sentinel incidents in the Defender portal · 35–40 min

Included with full SC-200 lab access

LAB 37 · LOCKED

Two DLP alerts, one insider risk alert and a built-in tuning rule that is about to make DLP stop being alerts at all

Respond to security incidents · Threats identified by Microsoft Purview · 35–40 min

Included with full SC-200 lab access

LAB 38 · LOCKED

Seven hops, two forests and one jump host that is not the attacker: find the hop that crossed the trust and contain it when the portal refuses twice

Respond to security incidents · Lateral movement across domains · 40–45 min

Included with full SC-200 lab access

LAB 39 · LOCKED

A TI Map rule that has never alerted, for a reason nobody on the team guessed — then build one that matches

Manage a security operations environment · Configure protections and detections · 35–40 min

Included with full SC-200 lab access

LAB 40 · LOCKED

The ticket says "turn Fusion on". In this workspace you cannot, and the two notification rules you build instead are where the damage gets done

Manage a security operations environment · Configure protections and detections · 35–40 min

Included with full SC-200 lab access

LAB 41 · LOCKED

Work five endpoint rules change requests without blocking the payroll vendor, the recruiters or the engineers who need the tool you are blocking

Manage a security operations environment · Configure settings in Microsoft Defender XDR · 35–40 min

Included with full SC-200 lab access

LAB 42 · LOCKED

Summarise 1.1 TB a day of Auxiliary firewall logs into a table a detection can actually run on, without aggregating away the three fields the detection needs

Perform threat hunting · Hunt for threats using Microsoft Sentinel · 35–40 min

Included with full SC-200 lab access

LAB 43 · LOCKED

Follow a phishing message into a process launch with a join, and prove which of three recipients actually ran it

Threat hunting · Advanced hunting · 40–45 min

Included with full SC-200 lab access

LAB 44 · LOCKED

Three hosts look like the pivot, one of them is busier than the real one, and the account you need has no UPN in the table that saw it

Threat hunting · Advanced hunting · 40–45 min

Included with full SC-200 lab access

LAB 45 · LOCKED

Four risky users, three of whom are not compromised, and two legacy policies that stop working in eight days

Respond to security incidents · Microsoft Entra ID Protection · 45–50 min

Included with full SC-200 lab access

LAB 46 · LOCKED

Four messages in Explorer: remediate one, report two in opposite directions, and leave the two the service already handled alone

Respond to security incidents · Microsoft Defender for Office 365 · 45–50 min

Included with full SC-200 lab access

LAB 47 · LOCKED

Two watchlists, one SearchKey that quietly matches the whole finance department, and a rule that references a watchlist by a name it does not have

Manage a security operations environment · Microsoft Sentinel · 45–50 min

Included with full SC-200 lab access

LAB 48 · LOCKED

Seven months of archived firewall logs, two questions about them, and a restore that keeps billing until somebody remembers it

Manage a security operations environment · Microsoft Sentinel · 45–50 min

Included with full SC-200 lab access

LAB 49 · LOCKED

Build a tier-1 triage role for one region, and find out that the scope everyone reaches for is not in the role wizard

Manage a security operations environment · Microsoft Defender XDR · 45–50 min

Included with full SC-200 lab access

LAB 50 · LOCKED

Two business units worked the same campaign without knowing it, a third incident only looks like it, and the case has a status nobody else moves

Respond to security incidents · Microsoft Defender XDR · 45–50 min

Included with full SC-200 lab access

SC-200 hands-on labs — questions

Does SC-200 have labs, and can I practise them without a tenant?
Yes. ExamIT Lab gives you 50 guided SC-200 labs in a simulated Microsoft Defender portal. Nothing is deployed to a real Microsoft tenant, subscription or device, so there is nothing to set up, nothing to pay Microsoft for, and nothing you can break.
Are the SC-200 labs free?
The first 5 labs in the learning order are free, repeatable and never expire — no credit card and no sign-up required to start. The full course of 50 labs is a one-time purchase with no subscription.
What does a SC-200 lab look like?
Each lab opens a realistic simulation of Microsoft Defender XDR, Microsoft Sentinel, Defender for Endpoint/Identity/Cloud Apps and Microsoft Purview — incident triage, threat hunting and detection engineering. You get a task brief, a guided or independent mode, progressive hints and a "Check configuration" button that grades the actual end state you left behind — not just the buttons you clicked.
Do the labs cover the current SC-200 exam outline?
The labs are mapped to the objectives in Microsoft's current SC-200 study guide, and we re-audit the mapping when Microsoft updates the skills measured. Combine them with the SC-200 practice test on ExamIT Lab for full coverage.
How is this different from a Microsoft Learn sandbox or a trial tenant?
A trial tenant gives you a blank environment and no feedback. These labs give you a pre-built scenario with fictional users, devices and policies, a clear goal, and automatic checking of your result — so you practise the exact administration workflows the SC-200 exam expects, in minutes, not hours of setup.

Access is per course. Sign in for account progress. After paid access expires, your saved progress is retained and the first five tasks remain free.