4Responding to security incidents
- 4.1Investigating and remediating incidents in Defender XDR
Understand investigating and remediating alerts/incidents/compromised entities identified by Defender for Office 365, Microsoft Purview, Defender for Cloud workload protections, Defender for Cloud Apps, Microsoft Entra ID, Defender for Identity, and Microsoft Sentinel in Microsoft Defender XDR.
- 4.2Complex attacks, Security Copilot, and case management
Understand investigating incidents with agentic AI (embedded Microsoft Security Copilot), investigating complex attacks (multistage, multi-domain, lateral movement), and managing incidents via case management.
- 4.3Device response in Defender for Endpoint
Understand investigating device timelines, performing device actions (live response, collecting investigation packages), evidence/entity investigation, and responding to incidents identified by automatic attack disruption in Microsoft Defender for Endpoint.
- 4.4Investigating Microsoft 365 activities
Understand investigating threats from Microsoft 365 activities using Microsoft Purview Audit, Content search in Microsoft Purview eDiscovery, and Microsoft Graph activity logs.

