SC-200 Glossary: Key Terms for the Security Operations Analyst
A plain-English SC-200 glossary - AMA, ASIM, KQL, MDI, MDO, NRT rules, UEBA, XDR and the Sentinel terms the exam leans on.
SC-200 glossary · 9 min read · updated 2026-09-05
SC-200 is product-heavy, and the products carry their own vocabulary. These are the terms the exam leans on, in plain English, grouped by the part of the stack they belong to.
Microsoft Sentinel essentials
Workspace - the Log Analytics container holding Sentinel data; architecture and cost questions start here. AMA - Azure Monitoring Agent, the current data collection agent replacing the legacy MMA, deployed via DCR (Data Collection Rules). ASIM - Advanced Security Information Model, Microsoft's normalisation schema so queries work across similar sources. Retention and tiers - how long data stays (interactive vs archive) and what it costs.
Analytics rules - scheduled, NRT (near-real-time), fusion and ML anomaly: know which fits which detection goal. Automation rules vs playbooks - simple incident-time logic vs Logic Apps workflows. UEBA - user and entity behaviour analytics, building behaviour profiles from ingested signals. Watchlists - small reference tables for fast lookups; Livestream - running a query interactively against a stream.
Defender XDR suite
XDR - extended detection and response: correlated incidents across products in one queue. MDE - Defender for Endpoint, the EDR covering process, network and exploit signals on devices. MDO - Defender for Office 365, Safe Links and Safe Attachments plus Threat Explorer. MDI - Defender for Identity, domain-controller signals catching Kerberoasting, pass-the-hash and reconnaissance. MDC - Defender for Cloud for Azure resource posture.
TVM - Threat and Vulnerability Management, the exposure management engine inside MDE. ASR - attack surface reduction rules. AIR - automated investigation and response. Advanced hunting - the KQL interface across the XDR tables (Device*, Email*, Identity*, CloudAppEvents).
Response and hunting vocabulary
Incident vs alert - an alert is one detection; an incident is the correlated case built from many. Triage - deciding priority and next action. Containment actions the exam names: device isolation, user containment, app execution restriction, investigation package collection. Blast radius - everything an identity or device touched; advanced hunting answers it by pivoting tables.
KQL - Kusto Query Language, the pipeline query language of both Sentinel Log Analytics and Defender advanced hunting. Pivot - moving between related entities across tables. False positive tuning - adjusting rules so analysts keep trusting the queue, a theme the exam rewards over raw detection volume.
Frequently asked questions
- How much product terminology is on the SC-200 exam?
- A lot: the exam is written in product terms, and questions often hinge on knowing which console, rule type or agent a capability belongs to. This glossary plus hands-on time in a trial tenant covers the vocabulary efficiently.
- What is the difference between Sentinel and Defender XDR?
- Defender XDR correlates Microsoft 365 and endpoint security signals in one incident queue; Sentinel is the cloud-native SIEM/SOAR that ingests nearly any source at scale. The SC-200 covers operating both, and the unified portal increasingly connects them.
- Where can I drill SC-200 terms with real questions?
- The PassYour SC-200 track includes 179 questions with explanations mapped to the three objective areas and 24 lessons with flashcards, plus a free 10-question quiz to start with no account.
Keep reading for SC-200
PassYour is an independent study aid and is not affiliated with, endorsed by or sponsored by ISC2, CompTIA or Microsoft.
