What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).
4.1Investigating and remediating incidents in Defender XDR
Understand investigating and remediating alerts/incidents/compromised entities identified by Defender for Office 365, Microsoft Purview, Defender for Cloud workload protections, Defender for Cloud Apps, Microsoft Entra ID, Defender for Identity, and Microsoft Sentinel in Microsoft Defender XDR.
The Microsoft Defender XDR portal aggregates alerts from each workload into a single incident. Analysts understand "which product sees what" and investigate/remediate with the right tool.
4.1.1Each product’s coverage
The responsible product depends on where the threat originates: phishing/BEC in email/collaboration = Defender for Office 365; SaaS app risk = Defender for Cloud Apps; threats to cloud workloads (VMs/containers/storage) = Defender for Cloud workload protections; cloud identity compromise (risky sign-ins) = Microsoft Entra ID (ID Protection); attacks on on-prem AD (lateral movement, Pass-the-Hash) = Defender for Identity; data/compliance-origin (insider, etc.) = Microsoft Purview; and org-wide aggregation/correlation = Microsoft Sentinel. Analysts investigate each alert within an incident using the tool matching its origin.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

