Instiq
Chapter 4 · Responding to security incidents·v1.0.0·Updated 6/28/2026·~13 min

What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).

4.2Complex attacks, Security Copilot, and case management

Key points

Understand investigating incidents with agentic AI (embedded Microsoft Security Copilot), investigating complex attacks (multistage, multi-domain, lateral movement), and managing incidents via case management.

Advanced attacks do not fit a single product or alert. Beyond XDR correlation, analysts efficiently track and respond to complex attacks with AI assistance and structured case management.

4.2.1Security Copilot and complex attacks

Embedded Microsoft Security Copilot (agentic AI) accelerates investigation by summarizing incidents, explaining scope, generating KQL, and suggesting responses. For complex attacks involving multistage, multi-domain, lateral movement, the XDR attack story (incident graph) visualizes the chain from intrusion through lateral movement to exfiltration; combined with Copilot summaries, you grasp the whole quickly. The principle: validate AI suggestions before acting (do not take them at face value).

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.