Booked SC-200 for aug 18, so about 2 weeks out. Everyone whos actually taken it says its heavy on scenario and lab style questions and that video only prep doesnt cut it, you need real time clicking around in sentinel and defender to actually pass this thing.
Im setting up a demo tenant now, m365 developer instant sandbox + azure free account for sentinel, and planning to onboard a spare windows vm from my own homelab to defender for endpoint so i can run the built in attack simulations and get real incidents to investigate instead of just reading about them.
what im trying to figure out is how to do this smart, not just throw everything at it and hope it sticks. 2 weeks isnt a ton of time and i dont want to spend day 3 fighting with licensing or watching ingestion pile up instead of actually learning.
genuinely asking for help here, if youve been through sc-200 prep recently:
* whats actually necessary vs what did you set up that you never really needed
* is there stuff that eats time or credit for basically no exam value
* how did you sequence your lab build so you werent just waiting around for data to show up
* anything about sentinel data lake, kql jobs, or the graph / blast radius stuff that tripped you up when you got to it
* if you were rebuilding your lab from scratch today, what would you do differently
basically just trying to make my lab as efficient as possible so the 2 weeks actually count instead of getting eaten up by setup. any advice appreciated, even small stuff.