Scenario library
Practice labs
Build investigation judgment through guided security scenarios. Inspect the evidence, make a decision, and learn from the operational outcome.
Knowledge assessment
Exam simulator
Practice with original SC-200 questions balanced across the three exam domains. Review the reasoning behind every answer and use the results to choose what to study next.
Performance snapshot
Your investigation progress
A live summary of completed stages and the quality of your decisions across every scenario.
0 of 0 decisions reviewed
No labs currently in progress
Decision quality
0 decisions reviewedComplete a stage to start building your decision profile.
Respond to security incidents
Investigate a consent-phishing and endpoint compromise
Correlate identity, cloud app, email, and endpoint evidence into one defensible incident response.
- Difficulty
- Intermediate
- Estimated time
- 30 min
- stages
- 5
Manage a security operations environment
Investigate credential abuse and Azure persistence with Microsoft Sentinel
Correlate sign-in, audit, and Azure activity to validate a privileged cloud compromise and coordinate the response.
- Difficulty
- Intermediate
- Estimated time
- 35 min
- stages
- 5
Respond to security incidents
Investigate and contain a ransomware attempt with Defender for Endpoint
Use endpoint evidence to reconstruct execution, find lateral movement, contain affected devices, and recover without destroying forensic value.
- Difficulty
- Intermediate
- Estimated time
- 35 min
- stages
- 5
Mitigate threats using Microsoft Defender for Cloud
Investigate a compromised cloud workload with Defender for Cloud
Correlate workload alerts and posture findings to contain a compromised VM and remove the attack path that exposed it.
- Difficulty
- Intermediate
- Estimated time
- 35 min
- stages
- 5