Instiq
Chapter 2 · Security operations (SecOps)·v1.0.0·Updated 6/28/2026·~13 min

What's changed: Created SC-100 Chapter 2 (Domain 2 first-half "Security operations": Defender XDR/Sentinel (SIEM)/XDR+SIEM integration/Defender for Endpoint, Identity, Office 365, Cloud Apps; SOAR/automation rules/playbooks (Logic Apps)/threat hunting (KQL)/UEBA; centralized logging/Microsoft Purview Audit (Standard, Premium)/multicloud monitoring/retention and isolation; MITRE ATT&CK (Enterprise/Mobile/ICS)/detection coverage/incident-response workflows).

2.4MITRE ATT&CK and detection coverage

Key points

Understand evaluating threat-detection coverage using MITRE ATT&CK matrices (Enterprise, Mobile, ICS) and designing/evaluating incident-response, threat-hunting, and incident-management workflows.

To show "is our detection sufficient" with a common language rather than opinion, use the industry-standard MITRE ATT&CK. Architects map detection coverage to ATT&CK tactics/techniques, visualize gaps, and close them by priority.

2.4.1Evaluating coverage with ATT&CK

MITRE ATT&CK is a knowledge base organizing adversary tactics (goals: initial access, persistence, lateral movement, exfiltration, etc.) and techniques (how). Choose the Enterprise (IT), Mobile, or ICS (industrial control systems) matrix to match the environment. Microsoft Sentinel maps analytics rules to ATT&CK techniques and visualizes detection coverage on the matrix. Architects evaluate "which tactic stages have thin detection" and reinforce rules or data sources.

2.4.2Designing incident-response workflows

Beyond detection, design the full workflow: incident response (detect→triage→contain→eradicate→recover→lessons learned), threat hunting, and incident management. Architects define roles and procedures (who/when/what), the boundary between automation (SOAR) and human judgment, and continuous detection improvement based on ATT&CK. This makes the SOC reproducible and avoids dependence on individuals.

Exam point

Cues: "evaluate detection completeness in a common language and visualize gaps" = MITRE ATT&CK (Sentinel mapping). Pick by environment: IT = Enterprise, industrial control = ICS, mobile = Mobile. "Define response procedures, roles, automation boundary" = incident-response workflow design.

Warning

Watch the mix-ups: (1) ATT&CK is a "detection-evaluation framework," not a detection product itself. (2) Do not apply only the Enterprise matrix to ICS/OT (use the ICS matrix + Defender for IoT). (3) Workflow design separates automation (SOAR) from human judgment—neither fully automatic nor fully manual.

Diagram of MITRE ATT&CK (Enterprise/Mobile/ICS) as a common tactics/techniques language, Sentinel mapping analytics rules to visualize coverage, and incident-response workflows (roles/procedures/automation boundary).
Visualize and close gaps

2.4.3Section summary

  • MITRE ATT&CK = evaluate detection coverage in a common tactics/techniques language; pick Enterprise/Mobile/ICS by environment
  • Sentinel maps analytics rules to ATT&CK, visualizing thin stages to reinforce
  • Design incident-response/hunting/management workflows with roles, procedures, and the automation boundary

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To evaluate detection-rule completeness against industry-standard tactics/techniques and visualize coverage gaps, which is best?

Q2. When evaluating threat-detection coverage for an industrial control (OT/ICS) environment, which is most appropriate?

Q3. To avoid SOC dependence on individuals and make operations reproducible, what should be designed?

Q4. Which correctly characterizes MITRE ATT&CK?

Q5. The ATT&CK matrix shows thin detection at the "lateral movement" stage. What is the architect’s best next step?

Check your understandingPractice questions for Chapter 2: Security operations (SecOps)