SC-500 vs SC-200 in 2026: Which Microsoft Security Exam Should You Take?
The SC-500 vs SC-200 choice comes down to one question: do you build security controls, or do you respond when they fire? SC-500 (Cloud and AI Security Engineer Associate) tests whether you can configure and harden identity, networks, storage, compute and AI workloads across Azure and hybrid estates. SC-200 (Security Operations Analyst Associate) tests whether you can detect, investigate and respond to threats in Microsoft Defender XDR and Microsoft Sentinel.
If your day job is configuring Azure resources, take SC-500 first. If it is working an incident queue, take SC-200 first. Most of the comparisons ranking for this search still set SC-200 against AZ-500, which retired on 31 August 2026, so the detail below is taken from the current Microsoft Learn study guides for both exams.
SC-500 vs SC-200 at a glance
| SC-500 | SC-200 | |
|---|---|---|
| Certification | Cloud and AI Security Engineer Associate | Security Operations Analyst Associate |
| Role Microsoft describes | Security engineer protecting cloud and hybrid systems, including AI workloads | Security operations analyst doing triage, incident response, threat hunting and detection engineering |
| Level | Associate (intermediate) | Associate (intermediate) |
| Passing score | 700 | 700 |
| Price | Set by the country or region where you sit it | Set by the country or region where you sit it |
| Formal prerequisites | None | None |
| Free official practice assessment | Not yet available | Available |
| Next outline change | None announced | English exam updated 21 October 2026 (minor change) |
| Counts towards SC-100 expert credential | Yes | Yes |
Exam Tip: Microsoft does not publish a fixed question count for either exam. Any site quoting an exact number is guessing, so plan your timing from the exam sandbox at aka.ms/examdemo instead.
What each exam actually tests
SC-500: build and harden
SC-500 has four domains in the official study guide:
- Manage identity, access and governance (20 to 25%)
- Secure storage, databases and networking (25 to 30%)
- Secure compute (20 to 25%)
- Manage and monitor security posture (20 to 25%)
The objectives are verbs like implement, configure and deploy. You set up Privileged Identity Management and Conditional Access, lock down Key Vault, write Azure Policy definitions, configure NSGs, Azure Firewall and private endpoints, and enable Defender for Cloud workload protection plans. The "Secure compute" domain carries the AI content that gives the certification its name: Microsoft Purview DSPM for Copilot and AI apps, Conditional Access for Microsoft Entra Agent ID, AI Gateway in Azure API Management for Microsoft Foundry, and Defender for AI Services.
Microsoft's audience profile expects practical Azure and hybrid administration, strong familiarity with Entra ID and familiarity with Microsoft 365 administration. Our SC-500 domain breakdown goes through each objective in detail.
SC-200: detect, investigate and respond
SC-200 has three domains in the outline that applies from 21 October 2026:
- Manage a security operations environment (40 to 45%)
- Respond to security incidents (35 to 40%)
- Perform threat hunting (20 to 25%)
Here the verbs are investigate, remediate and hunt. You tune alerts in Defender XDR, configure attack surface reduction rules in Defender for Endpoint, write Sentinel analytics rules, map detection coverage against MITRE ATT&CK, work incidents raised by Defender for Identity, Defender for Cloud Apps and Purview, and write KQL for Advanced Hunting. The current outline also covers hunting through Sentinel Graph, KQL jobs in the Sentinel data lake, and notebooks connected to the Sentinel MCP Server.
KQL is the skill that decides SC-200. Around a quarter of the exam is threat hunting, and a large share of the incident response material assumes you can read a query and say what it returns.
Where the two exams overlap
The overlap is narrower than the shared product names suggest, and it sits almost entirely in Microsoft Sentinel data collection. Both study guides list these objectives in near-identical wording:
- Collecting Windows Security events with data collection rules and Windows Event Forwarding
- Syslog and Common Event Format (CEF) collection
- Creating custom log tables to store ingested data
- Sentinel automation rules and playbooks
- Data retention in Sentinel
- Sentinel roles
The difference is what happens next. SC-500 stops once the data is flowing: its interest is posture, so it moves on to Defender CSPM, compliance against frameworks and Security Copilot configuration. SC-200 starts there, with detection rules, incident investigation and hunting on the data SC-500 taught you to collect.
Defender for Cloud also appears in both, from opposite ends. SC-500 asks you to enable workload protection plans and fix recommendations. SC-200 asks you to investigate the alerts those plans raise.
Exam Tip: If you pass one exam, the Sentinel ingestion objectives are the part of the other you can revise lightly. Everything else is new material, so do not expect the second exam to feel like a retake.
SC-500 vs SC-200 difficulty
Microsoft publishes no pass rates, so any ranking of difficulty is judgement. What the outlines show is that the two exams are hard in different ways.
SC-500 is broad. It spans identity, networking, databases, containers, App Service, Key Vault, Sentinel and a set of AI services that were in preview or brand new when the exam opened. A candidate strong in networking can still be caught out by AKS or Entra Agent ID questions. The AI objectives also change as the products do, and there is not yet an official practice assessment to test yourself against.
SC-200 is deep. It covers fewer products, but expects you to know Defender XDR and Sentinel well enough to pick the right table, the right response action and the right detection type from a scenario. People who have never written KQL find it much harder than people who query logs at work every day.
For a longer readiness check on the newer exam, see Is SC-500 difficult?.
Which should you take first?
Take SC-500 first if:
- You deploy or administer Azure resources and are moving into a security engineering role
- You were preparing for AZ-500 before it retired
- Your organisation is rolling out Copilot, Copilot Studio agents or Microsoft Foundry and someone has to secure them
Take SC-200 first if:
- You work in a SOC, or are applying for SOC analyst roles
- You already use Defender XDR or Sentinel to triage alerts
- You want the exam with a free official practice assessment and a longer track record of training material
If you are new to security and have neither Azure administration nor SOC experience, SC-200 is usually the easier first associate exam, because its product scope is narrower. Build some hands-on Azure time before attempting SC-500.
Taking both, and the path to SC-100
Microsoft updated the Cybersecurity Architect Expert page in September 2026. The certification now requires SC-100 plus one of three associate certifications: Identity and Access Administrator (SC-300), Security Operations Analyst (SC-200), or Cloud and AI Security Engineer (SC-500). Either exam in this comparison makes you eligible for the expert credential, so the SC-100 route should not decide which one you take first.
The pairing matters more for employers. Microsoft's Solutions Partner for Security designation asks partners to have certified people at both the security engineer level (SC-500, or AZ-500 while it remains valid) and SC-200. An engineer who holds both can configure the controls and investigate the alerts they generate, which is also a realistic description of a security role in a smaller team.
If SC-500 is already done and you are deciding what to add, our guide to what comes after SC-500 covers SC-200, SC-300 and SC-100 in that order of decision.
Frequently Asked Questions
Is SC-500 the same as AZ-500?
No. SC-500 replaced AZ-500, which retired on 31 August 2026, but it adds a set of AI security objectives covering Copilot, Copilot Studio agents, Entra Agent ID and Microsoft Foundry. The AZ-500 vs SC-500 comparison sets out what changed.
How much do SC-500 and SC-200 cost?
Microsoft prices both exams by the country or region in which the exam is proctored and does not publish a single global fee. Check the figure for your region when you schedule through your Microsoft Learn profile.
Is SC-200 good for beginners?
SC-200 has no formal prerequisites, but Microsoft expects familiarity with Microsoft 365, Azure, Microsoft security tooling and operating systems. A beginner with some lab time in Defender XDR and Sentinel can pass it. SC-900 is the fundamentals exam if you need a gentler start.
Do SC-500 and SC-200 expire?
Yes. Microsoft associate certifications expire after one year. You renew by passing a free online assessment on Microsoft Learn, with no new exam fee.
Should I study for SC-200 now or wait for the 21 October update?
Microsoft's change log rates the 21 October 2026 SC-200 update as minor, with the data ingestion objectives the section it flags. If your exam falls after that date, study from the new outline. Our SC-200 study plan covers the preparation.
Ready to Start Practising?
Pick the exam that matches your job, then practise on questions written for its current outline. CertCrush has exam-style practice with full explanations for SC-500 and SC-200. Create your free account and start with the one you are booking first.
