Microsoft SC-200 — The Analyst's Exam, From the Log Up
The SOC analyst's certification, taught from the log up: the query language from nothing on data shaped like real tickets, what a detection rule, incident and entity are made of, and the four scenario shapes the exam keeps reusing — with every query actually run and every error real. An independent course, not affiliated with or endorsed by Microsoft.
- trending_upIntermediate
- schedule6h 57m
- menu_book12 堂課程
- publicEnglish
- workspace_premiumBasic
課程簡介
This exam assumes your hands have been on the product, and most people preparing for it have never had a tenant to touch. So this segment is built backwards from that problem. The layer that is fully testable and completely free — the query language and the shapes of the objects — happens to be the layer the questions are actually written against, because the exam's authors face the same annual product renames you do. Learn the shapes and the renames become cosmetic. Learn the click paths and every rename resets you to zero. Module 1 reads the published blueprint as four stable verbs and maps the product estate as three surfaces on one pipeline. Module 2 is the one nobody else writes properly: the query language from nothing, taught on 53 rows of sign-in data shaped like the tickets you triaged in segment C2 — a service account, all successes, an overnight walk across six machines. Every output you see was produced by really running the query, and every error message is real, including the ones we make you cause on purpose. You will learn to distrust the zero-row answer that looks like reassurance, watch a flat daily chart certify an attack as normal, and catch an inner join silently dropping a third of your evidence. Module 3 promotes a query into a detection and fills in the seven-field anatomy card: frequency and lookback as independent dials, thresholds as claims about normal, entities as the join keys of correlation, and the window-boundary blind spot you find in your own output, with arithmetic. Module 4 splits automation into the rule that edits paperwork and the workflow that acts on the world, then works the four scenario shapes the exam keeps reusing — detect it, tune it, hunt it, hand it off — end to end, finishing with a hunt that includes its own negative control. The judgement about what patterns mean stays in C2, the governance argument about what machines may decide stays in R3, and how to sit the exam stays in R2. This segment owns the product surface and the language. This is an independent course. It is not affiliated with, endorsed by, sponsored by or approved by Microsoft, and it reproduces no Microsoft courseware or question material. The only exam-authored facts used are from the public study guide, which lesson 1.1 sends you to read on the live page. Every scenario, dataset, query and question here was written for this course.
課程大綱 · 4 個單元
lock隨存取權限解鎖- 01 The Exam, and the Stack It Assumes3 堂課程·1h 29m
The exam is written against shapes, not click paths, because its authors face the same annual renames you do. This module builds the vocabulary the other three spend. Nothing here needs a tenant, and…
- 02 The Query Language From Nothing3 堂課程·1h 45m
Every output and every error message in this module is pasted from a real run against the printed dataset — type along and yours should match. The judgement about what the patterns mean stays in C2;…
- 03 A Detection Is a Query on a Clock3 堂課程·1h 36m
Every judgement in this module arrives with a number attached. The rule anatomy card built in 3.1 is filled, stressed and inked across all three lessons — it is the artefact, and the exam's scenario…
- 04 Automation, and the Four Shapes3 堂課程·2h 7m
The automation line is drawn in R3; this module wires it. The tuning lab's discipline — name what the noise is before choosing a fix — and the hunting lab's negative control are the two habits that…
常見問題
- 我將在 Microsoft SC-200 — The Analyst's Exam, From the Log Up 中學到什麼?
- The SOC analyst's certification, taught from the log up: the query language from nothing on data shaped like real tickets, what a detection rule, incident and entity are made of, and the four scenario shapes the exam keeps reusing — with every query actually run and every error real. An independent
- 我需要事先具備經驗嗎?
- 建議在開始 Microsoft SC-200 — The Analyst's Exam, From the Log Up 前具備一些先備知識。
- Microsoft SC-200 — The Analyst's Exam, From the Log Up 需要多長時間?
- Microsoft SC-200 — The Analyst's Exam, From the Log Up 包含 4 個單元和 12 堂課程。你可以按自己的進度學習。
- 我如何取得存取權限?
- Microsoft SC-200 — The Analyst's Exam, From the Log Up 包含在任何付費訂閱方案中。