Instiq
Chapter 2 · Security operations (SecOps)·v1.0.0·Updated 6/28/2026·~13 min

What's changed: Created SC-100 Chapter 2 (Domain 2 first-half "Security operations": Defender XDR/Sentinel (SIEM)/XDR+SIEM integration/Defender for Endpoint, Identity, Office 365, Cloud Apps; SOAR/automation rules/playbooks (Logic Apps)/threat hunting (KQL)/UEBA; centralized logging/Microsoft Purview Audit (Standard, Premium)/multicloud monitoring/retention and isolation; MITRE ATT&CK (Enterprise/Mobile/ICS)/detection coverage/incident-response workflows).

2.3Centralized logging/auditing and multi-environment monitoring

Key points

Understand centralized logging and auditing including Microsoft Purview Audit, monitoring design supporting hybrid/multicloud, and approaches to log ingestion, retention, and isolation.

Detection, response, investigation, and compliance all rest on "trustworthy logs." Architects design what is recorded, where, for how long, and in a form no one can tamper with.

2.3.1Microsoft Purview Audit

Microsoft Purview Audit centrally records audit logs of user/admin activity across Microsoft 365/Entra. Audit (Standard) provides baseline logging; Audit (Premium) provides longer retention (extended by default) and high-value events crucial to breach investigation (e.g., access to mail items = MailItemsAccessed). Architects design the right Purview Audit tier and retention for "after an incident, trace how far back and what happened."

2.3.2Hybrid/multicloud monitoring

Monitoring extends beyond Microsoft. Microsoft Sentinel data connectors ingest AWS (CloudTrail/GuardDuty), GCP, and on-prem logs for org-wide correlation. Infrastructure configuration risk is evaluated across clouds by Microsoft Defender for Cloud, while threats are detected by Defender XDR/Sentinel. Architects organize design decisions for "log retention (cost vs investigation needs)," "tamper-resistant storage isolated from production," and "retention required by regulation."

Exam point

Cues: "M365/Entra activity audit, high-value events for investigations, long retention" = Purview Audit (Premium). "Collect and correlate AWS/GCP/on-prem too" = Sentinel connectors. "Evaluate cloud configuration posture across clouds" = Defender for Cloud.

Warning

Watch the mix-ups: (1) Purview Audit (activity audit logs) and Sentinel (SIEM correlation/detection) are complementary—different roles. (2) Design logs for tamper-resistance, isolation, and retention—not just collection. (3) Balance compliance retention requirements with investigative practicality (cost).

Diagram of Purview Audit (M365/Entra activity audit; Premium for long retention/high-value events), multicloud monitoring via Sentinel connectors, and tamper-resistance/isolation/regulatory-retention design.
Keep trustworthy logs

2.3.3Section summary

  • Purview Audit = M365/Entra activity audit; Premium adds long retention + high-value investigation events
  • Multicloud monitoring = Sentinel connectors aggregate AWS/GCP/on-prem; Defender for Cloud evaluates configuration posture
  • Design logs for tamper-resistance, isolation from production, and regulatory retention

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To trace high-value events like mail-item access (MailItemsAccessed) over a long period for breach investigation, which is best?

Q2. To correlate AWS CloudTrail and on-prem firewall logs together with Microsoft 365 signals, which is best?

Q3. To evaluate cloud infrastructure configuration risk (posture) including AWS/GCP, which is best?

Q4. Which is the most important consideration in centralized logging design?

Q5. Which correctly states the relationship between Purview Audit and Microsoft Sentinel?

Check your understandingPractice questions for Chapter 2: Security operations (SecOps)