Microsoft / Security and identity

Investigate security incidents

Learn logs, basic query skills and incident response before advanced threat hunting.

Target: SC-200Self-paced study route

Optional foundation

Check your starting knowledge

Use SC-900 to review the basics. You do not need to take this foundation exam to follow our route. If you already know the material, move on.

Core learning · SC-200

Learn the role, one area at a time

Work through the official guide and its learning resources. Use these three study blocks to organize your notes; the official skills outline remains your complete coverage checklist.

  1. 1.Configure security operations and protections
  2. 2.Investigate and respond to incidents
  3. 3.Hunt threats using security data
Open the official SC-200 study guide ↗

Hands-on consolidation

Put it into practice

Write an incident timeline from synthetic sign-in and endpoint events. Record evidence, containment decisions and follow-up detections.

Ready to move on when…

You can distinguish an alert from a confirmed incident and justify the response.

Use a dedicated lab and synthetic data, never an employer's production environment. Check licensing and costs before provisioning; budget alerts do not stop spending. Remove resources when finished.

Review & exam planning

Find gaps with our SC-200 test

Try the test, explain each missed answer and return to the corresponding learning topic. Repeat the practical task where needed. A practice score is feedback, not proof of certification readiness.

Before booking, check the official page for current exam availability, any retirement or beta notice, and the credential's full requirements. This guide does not track completion or award a certificate.

Where these skills can lead

Choose a direction that fits your goal—not every path below.