Scenario library

Practice labs

Build investigation judgment through guided security scenarios. Inspect the evidence, make a decision, and learn from the operational outcome.

4available0In progress0Completed

Knowledge assessment

Exam simulator

Practice with original SC-200 questions balanced across the three exam domains. Review the reasoning behind every answer and use the results to choose what to study next.

Open exam simulator

Performance snapshot

Your investigation progress

A live summary of completed stages and the quality of your decisions across every scenario.

Stages completed0/20
Recommended decisions0%

0 of 0 decisions reviewed

Labs completed0/4

No labs currently in progress

Decision quality

0 decisions reviewed

Complete a stage to start building your decision profile.

01Not started

Respond to security incidents

Investigate a consent-phishing and endpoint compromise

Correlate identity, cloud app, email, and endpoint evidence into one defensible incident response.

Difficulty
Intermediate
Estimated time
30 min
stages
5
Microsoft Defender XDRMicrosoft Entra IDDefender for Cloud AppsDefender for Endpoint
Lab progress0/5
Explore lab
02Not started

Manage a security operations environment

Investigate credential abuse and Azure persistence with Microsoft Sentinel

Correlate sign-in, audit, and Azure activity to validate a privileged cloud compromise and coordinate the response.

Difficulty
Intermediate
Estimated time
35 min
stages
5
Microsoft SentinelMicrosoft Entra IDAzure Activity LogLogic Apps
Lab progress0/5
Explore lab
03Not started

Respond to security incidents

Investigate and contain a ransomware attempt with Defender for Endpoint

Use endpoint evidence to reconstruct execution, find lateral movement, contain affected devices, and recover without destroying forensic value.

Difficulty
Intermediate
Estimated time
35 min
stages
5
Microsoft Defender for EndpointMicrosoft Defender XDRMicrosoft Entra IDAdvanced Hunting
Lab progress0/5
Explore lab
04Not started

Mitigate threats using Microsoft Defender for Cloud

Investigate a compromised cloud workload with Defender for Cloud

Correlate workload alerts and posture findings to contain a compromised VM and remove the attack path that exposed it.

Difficulty
Intermediate
Estimated time
35 min
stages
5
Microsoft Defender for CloudDefender for ServersAzure Resource ManagerMicrosoft Sentinel
Lab progress0/5
Explore lab