Microsoft
SC-200 practice quiz
The Microsoft SC-200 certifies the Security Operations Analyst: triaging incidents with Microsoft Defender XDR, hunting threats with KQL, building Sentinel analytics rules and automating response with SOAR playbooks. These SC-200-style questions reflect the daily work of a SOC analyst on the Microsoft stack.
Question 1 of 10 · Mitigate threats with Microsoft Sentinel
Page 1 of 52
In KQL, which operator filters rows based on a condition?
Pick an answer, then submit.
Go further with the full SC-200 track
The Microsoft SC-200 certifies the Security Operations Analyst: triaging incidents with Microsoft Defender XDR, hunting threats with KQL, building Sentinel analytics rules and automating response with SOAR playbooks. These SC-200-style questions reflect the daily work of a SOC analyst on the Microsoft stack.
Page 1 of 52 is free right here. Inside PassYour, the same quiz continues page after page - and you also get the full SC-200 course: structured lessons for every exam domain, hundreds of additional exam-style questions with detailed explanations, flashcards, timed mock exams that mirror the real test, plus plenty of extra study resources (cheat sheets, exam-day tips and domain guides).
PassYour is an independent study aid. SC-200 is a trademark of Microsoft; PassYour is not affiliated with or endorsed by Microsoft.