SC-200 is about to get a minor update, just some minor wording and terminology changes. Back in June additional items were added to the exam including device groups, device discovery, attack surface reduction, unified audit log, Content Search, Defender for DevOps, an expansion of UEBA topics and working with archived log data in Sentinel. There are more, but I just wanted to hihglight that the changes are found in all three sections of the exam topics.

This is one my favorite exams to recommend for someone who wants to get into Microsoft cybersecurity technologies and exams, due to some of the Defender and Sentinel skills you need to pass the exam. If you’ve already passed MS-500 (recently retired) and AZ-500, this is an excellent choice as your next exam, because there will be some overlap in the technologies, but expect this exam to go much deeper into understanding the Defender family of technologies, and it also goes deeper into Sentinel than you will have seen on previous exams. You will definitely need to spend some time with Kusto and Log Analytics, not just for the Microsoft Sentinel portion of the exam, but Microsoft 365 Defender and Microsoft Defender for Cloud as well.

Mitigate threats using Microsoft 365 Defender (25-30%)

Mitigate threats to the productivity environment by using Microsoft 365 Defender 

Mitigate endpoint threats by using Microsoft Defender for Endpoint

Mitigate identity threats

Manage extended detection and response (XDR) in Microsoft 365 Defender

Investigate threats by using audit features in Microsoft 365 Defender and Microsoft Purview

Mitigate threats using Microsoft Defender for Cloud (15-20%)

Implement and maintain cloud security posture management

Configure environment settings in Defender for Cloud

Respond to alerts and incidents in Microsoft Defender for Cloud

Mitigate threats using Microsoft Sentinel (50-55%)

Design and configure an Microsoft Sentinel workspace

Plan and Implement the use of data connectors for ingestion of data sources in Microsoft Sentinel

Manage Microsoft Sentinel analytics rules

Perform data classification and normalization

Configure Security Orchestration Automation and Response (SOAR) in Microsoft Sentinel

Manage Microsoft Sentinel Incidents

Use Microsoft Sentinel workbooks to analyze and interpret data

Hunt for threats using Microsoft Sentinel

Manage threats by using entity behavior analytics