PassYour
Try for freeSign in

SC-200 Study Plan: Sentinel and Defender XDR in 6 Weeks

A 6-week SC-200 study plan covering Microsoft Sentinel, Defender XDR and KQL hunting - with labs, practice questions and mock exams.

SC-200 preparation · 7 min read · updated 2026-09-04

SC-200 rewards candidates who practise in the products, not just read about them. Six weeks with a lab tenant, KQL every week and question drills is a proven route to the Security Operations Analyst certification.

Weeks 1-2: Microsoft Defender XDR

Set up a trial tenant and onboard devices. Learn the Defender for Endpoint, Office 365, Identity and Cloud Apps consoles, incident correlation across them and the advanced hunting experience.

Write one advanced hunting query per day from week one - KQL is a language, and languages are not crammed in the last week.

Weeks 3-4: Microsoft Sentinel

Deploy Sentinel, connect data sources, and master its core objects: analytics rules, incidents, playbooks (Logic Apps), workbooks, hunting queries and UEBA. Sentinel carries the largest share of the exam.

Create every rule type once at least: scheduled, fusion, ML anomalies and NRT. The exam asks you to choose the right rule for a detection goal.

Weeks 5-6: Reduce risk, KQL depth and full mocks

Cover governance and risk reduction: secure score, regulatory compliance, threat modelling conversations and how an analyst communicates exposure to management.

Finish with practice questions and two timed mock exams, then redo every failed question inside the product - seeing the real blade cements the answer.

Frequently asked questions

How many questions are on the SC-200 exam?
SC-200 typically presents 40 to 60 questions in 100 minutes, with case studies, hands-on-like lab items and multiple choice. The passing score is 700 on a scale of 1000.
Do I need Azure experience before SC-200?
There is no formal prerequisite, but you should be comfortable in the Azure portal and with Microsoft 365 security concepts. Without that baseline, add one or two weeks of portal familiarisation before starting the plan.
Is SC-200 worth it for a SOC analyst?
Yes - Microsoft Sentinel and Defender XDR dominate Microsoft-centric SOCs, and the certification proves production skills: writing KQL, tuning analytics rules and automating response. It pairs naturally with Security+ or CySA+ on the defensive track.

Keep reading for SC-200

PassYour is an independent study aid and is not affiliated with, endorsed by or sponsored by ISC2, CompTIA or Microsoft.

SC-200 Study Plan: Sentinel and Defender XDR in 6 Weeks | PassYour CISSP