The following labs were completed as hands-on preparation for the SC-200: Microsoft Security Operations Analyst exam. Labs were performed across two environments: an employer-provided Azure subscription (resources provisioned and deleted immediately after each lab to control cost) and a personal, paid Microsoft 365 E5 test tenant. Lab instructions sourced from the MicrosoftLearning GitHub repository and Microsoft Learn interactive exercises.
- Lab 1 – Microsoft Defender XDRE5 TenantExplore the Defender XDR portal, apply preset security policies, and configure the workspace.
- Lab 2 – Microsoft Security CopilotE5 TenantExplore Security Copilot and use it to investigate and respond to endpoint threats.
- Lab 3 – Microsoft Purview: Audit, DLP, eDiscovery & Insider RiskE5 TenantExplore Purview Audit, investigate DLP alerts, run eDiscovery searches, and investigate insider risk alerts.
- Lab 4 – Microsoft Defender for EndpointAzure + E5 TenantDeploy and configure Defender for Endpoint, onboard devices, mitigate simulated attacks, and harden endpoints.
- Lab 5 – Kusto Query Language (KQL)AzureWrite KQL queries against Sentinel log data, build visualizations, and work with multi-table statements.
- Lab 6 – Microsoft Sentinel: Deployment & Data ConnectorsAzureDeploy Sentinel into Microsoft Defender and connect data from Defender for Cloud, Windows, Linux, and XDR.
- Lab 7 – Microsoft Sentinel: Analytics Rules, Detections & ASIMAzureCreate scheduled query rules, simulate attacks, build detections, and implement ASIM parsers.
- Lab 8 – Microsoft Sentinel: Incidents, Playbooks & InvestigationAzureInvestigate incidents, create Logic Apps playbooks for automated response, and manage Sentinel content.
- Lab 9 – Microsoft Sentinel: Threat Hunting, Workbooks & NotebooksAzurePerform proactive threat hunting with KQL, build Sentinel workbooks, and use Jupyter notebooks for investigation.
← Back to Labs