Instiq
Chapter 4 · Responding to security incidents·v1.0.0·Updated 8/6/2026·~15 min

What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).

4.1Investigating and remediating incidents in Defender XDR

Key points

Understand investigating and remediating alerts/incidents/compromised entities identified by Defender for Office 365, Microsoft Purview, Defender for Cloud workload protections, Defender for Cloud Apps, Microsoft Entra ID, Defender for Identity, and Microsoft Sentinel in Microsoft Defender XDR.

The Microsoft Defender XDR portal aggregates alerts from each workload into a single incident. Analysts understand "which product sees what" and investigate/remediate with the right tool.

4.1.1Each product’s coverage

The responsible product depends on where the threat originates: phishing/BEC in email/collaboration = Defender for Office 365; SaaS app risk = Defender for Cloud Apps; threats to cloud workloads (VMs/containers/storage) = Defender for Cloud workload protections; cloud identity compromise (risky sign-ins) = Microsoft Entra ID (ID Protection); attacks on on-prem AD (lateral movement, Pass-the-Hash) = Defender for Identity; data/compliance-origin (insider, etc.) = Microsoft Purview; and org-wide aggregation/correlation = Microsoft Sentinel. Analysts investigate each alert within an incident using the tool matching its origin.

Exam point

Cues: email/collab = Defender for Office 365; SaaS = Defender for Cloud Apps; cloud workloads = Defender for Cloud; cloud identity compromise = Entra ID (ID Protection); on-prem AD attacks = Defender for Identity; data/insider = Purview; org-wide aggregation/correlation = Sentinel. XDR bundles these into one incident.

Warning

Watch the mix-ups: (1) Defender for Identity (on-prem AD) vs Entra ID Protection (cloud identity). (2) Defender for Cloud (cloud-workload threats/posture) vs Defender for Cloud Apps (SaaS CASB) are different. (3) An incident bundles alerts from multiple products—view the whole at the incident level, not per alert.

Diagram of choosing the product by threat origin: email:Defender for Office 365 / SaaS:Cloud Apps / workloads:Defender for Cloud / cloud ID:Entra ID / on-prem AD:Defender for Identity / data:Purview, with Sentinel for org-wide aggregation.
Choose product by origin

4.1.2Section summary

  • Choose the product by origin: email:O365 / SaaS:Cloud Apps / workloads:Defender for Cloud / cloud ID:Entra ID / on-prem AD:Defender for Identity / data:Purview / aggregation:Sentinel
  • XDR aggregates each product’s alerts into one incident—respond at the incident level
  • Distinguish Defender for Identity (on-prem AD) from Entra ID Protection (cloud ID), and Defender for Cloud (workloads) from Cloud Apps (SaaS)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to investigate alerts about lateral movement and Pass-the-Hash on on-prem Active Directory. Which product?

Q2. You want to investigate/remediate an email phishing/BEC incident. Which product?

Q3. You want to investigate threat alerts on cloud workloads (Azure VMs, containers, storage). Which product?

Q4. Which correctly distinguishes Defender for Cloud from Defender for Cloud Apps?

Q5. You want to investigate/remediate compromised cloud identities (risky sign-ins) in Entra ID. Which product?

Check your understandingPractice questions for Chapter 4: Responding to security incidents

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.