2Security operations (SecOps)
- 2.1Detection and response with XDR and SIEM
Understand the roles of Microsoft Defender XDR (cross-domain detection/response across identity/endpoints/email/SaaS) and Microsoft Sentinel (cloud-native SIEM), an integrated XDR+SIEM detection/response design, and monitoring for hybrid/multicloud.
- 2.2SOAR and incident-response automation
Understand SOAR (orchestration and automated response) with Microsoft Sentinel and Defender XDR, automation rules and playbooks, designing incident response/threat hunting/incident management workflows, and UEBA.
- 2.3Centralized logging/auditing and multi-environment monitoring
Understand centralized logging and auditing including Microsoft Purview Audit, monitoring design supporting hybrid/multicloud, and approaches to log ingestion, retention, and isolation.
- 2.4MITRE ATT&CK and detection coverage
Understand evaluating threat-detection coverage using MITRE ATT&CK matrices (Enterprise, Mobile, ICS) and designing/evaluating incident-response, threat-hunting, and incident-management workflows.

