arrow_backกลับไปที่บันทึกภาคสนาม
CERTIFICATIONS เผยแพร่แล้ว 7 Aug 2026

SC-200: สอบของนักวิเคราะห์ผ่านฟังก์ชันบันทึก

สิ่งที่ SC-200 ทดสอบจริง ๆ วิธีการแมปไปยัง Defender และ Sentinel workflows และวิธีการเตรียมตัวเหมือนนักวิเคราะห์ SOC ที่ทำงานจริง

SC-200 (Microsoft Security Operations Analyst) ได้รับการรับรองว่าคุณสามารถเรียกใช้ security operations workflow ภายในสแต็ก Microsoft: ตรวจจับ สืบสวน ตอบสนอง และค้นหาโดยใช้ Microsoft Sentinel, Microsoft Defender XDR และชุด Defender สำหรับ cloud, identity, endpoint และ Office 365 ไม่ใช่สอบทฤษฎีเกี่ยวกับแนวคิด security ในเชิงนามธรรม มันสร้างขึ้นโดยอ้อมวงของ Tier 1/Tier 2 analyst ที่ทำงานภายใน Defender และ Sentinel consoles

สิ่งที่สอบครอบคลุมจริง ๆ

แบบพิมพ์สอบแบ่งออกเป็นสามส่วน: บรรเทาภัยคุกคามด้วย Defender XDR บรรเทาภัยคุกคามด้วย Sentinel และการกำหนดค่าการป้องกัน/การตรวจจับในทั่วทั้ง Defender ecosystem ในทางปฏิบัติ หมายความว่าคุณต้องมีความรู้ในการใช้งาน:

  • Microsoft Defender for Endpoint — device onboarding, attack surface reduction rules, automated investigation and remediation (AIR) และการอ่าน process trees ในมุมมอง incident
  • Microsoft Defender for Identity — การทำความเข้าใจ lateral movement paths, Pass-the-Hash/Pass-the-Ticket alerts และวิธีการที่มันเชื่อมสัมพันธ์กับ on-prem AD signals
  • Microsoft Defender for Cloud Apps — OAuth app governance, anomaly detection policies และ session control basics
  • Microsoft Sentinel — data connectors, KQL-based analytics rules, workbooks, playbooks (Logic Apps) และ incident investigation graph
  • Microsoft Defender for Cloud — regulatory compliance dashboards และ workload protection alerts สำหรับ VMs, storage และ containers

KQL ไม่ใช่ตัวเลือก

ถ้าคุณไม่สามารถเขียน Kusto Query Language ได้อย่างสบายใจ คุณจะประสบปัญหากับส่วนที่มีความหมายของสอบนี้ และสำคัญกว่านั้น กับงานจริง คุณควรจะเขียนคิวรีแบบนี้ได้จากความจำ ไม่ใช่แค่รู้จักเท่านั้น:

DeviceProcessEvents
| where FileName =~ "powershell.exe"
| where ProcessCommandLine has_any ("-enc", "-EncodedCommand", "IEX")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
| order by Timestamp desc

คาดหวังคำถาม scenario ที่คุณได้รับส่วนของคิวรี KQL และถูกขอให้แก้ไขข้อผิดพลาด syntax หรือคาดการณ์ผลลัพธ์ ฝึกฝน summarize, join, mv-expand และ time-window functions เช่น bin() — analytics rules ของ Sentinel ขึ้นอยู่กับสิ่งเหล่านี้อย่างมาก

การอ่าน incident เหมือนนักวิเคราะห์ ไม่ใช่ผู้ทำสอบ

คำถาม SC-200 จำนวนมากเสนอ Sentinel incident พร้อม correlated alerts หลายชุด และขอให้คุณระบุ entity, MITRE ATT&CK technique หรือขั้นตอน investigative ที่ถูกต้อง สิ่งนี้สะท้อนการแยกประเภทจริง: คุณกำลังหมุนระหว่าง alert timeline, entity page (user, host, IP) และ related incidents เพื่อสร้างเรื่องราว ใช้เวลาในพื้นที่ทำงาน Sentinel trial โดยคลิกผ่าน incidents จริงแทนที่จะเพียงแค่จดจำชื่อ alert — สอบให้รางวัล pattern recognition ที่สร้างขึ้นจากการทำซ้ำแบบ hands-on

Automation และ playbooks ปรากฏมากกว่าที่คนคาดหวัง

ผู้สมัครมักเตรียมตัวน้อยเกินไปสำหรับส่วน Logic Apps / playbook คุณควรรู้วิธีการที่ playbook ทริกเกอร์ off a Sentinel incident วิธีการส่ง incident entities (เช่น user หรือ IP) เข้าสู่ automated action เช่น disabling an account via Azure AD หรือ isolating a device via Defender for Endpoint และความแตกต่างระหว่าง automation rules และ playbooks — automation rules จัดการกับ routing/tagging/assignment logic, playbooks ดำเนินการขั้นตอน remediation จริง

เส้นทางการศึกษาในทางปฏิบัติ

  1. สปินอัป Azure subscription ฟรีและปรับใช้ Sentinel workspace พร้อม data connector อย่างน้อยหนึ่งตัว (Azure AD sign-in logs ใจดีให้เปิดใช้งาน)
  2. ทำผ่าน Microsoft Learn SC-200 learning path — มันฟรีและแมปไปยัง exam objectives โดยตรง
  3. สร้าง analytics rules ห้า หกตัวจากศูนย์โดยใช้ KQL ไม่ใช่ templates เพื่อให้คุณเข้าใจ query logic ข้างใต้
  4. ใช้ Microsoft's official practice assessment (ผ่าน Pearson VUE/MeasureUp) เมื่อคุณรู้สึกพร้อม — มันเข้าใกล้ actual question style มากกว่า third-party dumps ส่วนใหญ่
  5. ทบทวน MITRE ATT&CK tactic names เย็นชา คำถามมักขอให้คุณจัดประเภท observed behavior เข้าสู่ tactic (Initial Access, Persistence, Lateral Movement ฯลฯ) แทนที่จะตั้งชื่อ tactic อย่างชัดเจน

ใครที่ certification นี้ช่วยจริง ๆ

SC-200 เป็นสัญญาณที่แข็งแกร่งสำหรับ SOC analyst, security engineer หรือ incident responder roles ในองค์กรที่มุ่งมั่นกับสแต็ก security ของ Microsoft — ซึ่ง เมื่อพิจารณาจาก Defender และ Sentinel's market presence คือชิ้นส่วนใหญ่ของ enterprise environments ไม่ได้สอนคุณ general SOC theory วิธี GCIH หรือ Security+ อาจทำ แต่มันพิสูจน์ว่าคุณสามารถดำเนินการ tools ที่ SOC โฟกัส Microsoft จริง ๆ ทำงานบน

ถ้า detection engineering และ KQL จับความสนใจของคุณที่นี่ Korra Studio มี segments ที่เกี่ยวข้องในการสร้าง Sentinel analytics rules และใน MITRE ATT&CK mapping ที่คุ้มค่าที่จะตรวจสอบต่อไป

เขียนด้วยความช่วยเหลือของ AI ตรวจสอบและเผยแพร่โดย Michal Pilch (CISSP), Korra Studio

พร้อมที่จะไปต่อหรือไม่

นี่คือบันทึกหนึ่งจากฐานความรู้ของ Korra Studio — แพลตฟอร์มจับคู่หัวข้อแต่ละหัวข้อกับการฝึกสอนแบบ 1-to-1

เริ่มใช้งานฟรีarrow_forward