What's changed: Created SC-200 Chapter 4 (Domain 2: Defender XDR incident investigation/remediation (coverage of Defender for Office 365/Purview/Defender for Cloud workload protections/Defender for Cloud Apps/Entra ID Protection/Defender for Identity/Sentinel); complex attacks (multistage/multi-domain/lateral movement)/attack story (incident graph)/embedded Microsoft Security Copilot (agentic AI)/case management; Defender for Endpoint response (device timeline/live response/investigation package collection/evidence-entity investigation/automatic attack disruption); M365 investigation (Purview Audit/Purview eDiscovery Content search/Microsoft Graph activity logs)).
4.2Complex attacks, Security Copilot, and case management
Understand investigating incidents with agentic AI (embedded Microsoft Security Copilot), investigating complex attacks (multistage, multi-domain, lateral movement), and managing incidents via case management.
Advanced attacks do not fit a single product or alert. Beyond XDR correlation, analysts efficiently track and respond to complex attacks with AI assistance and structured case management.
4.2.1Security Copilot and complex attacks
Embedded Microsoft Security Copilot (agentic AI) accelerates investigation by summarizing incidents, explaining scope, generating KQL, and suggesting responses. For complex attacks involving multistage, multi-domain, lateral movement, the XDR attack story (incident graph) visualizes the chain from intrusion through lateral movement to exfiltration; combined with Copilot summaries, you grasp the whole quickly. The principle: validate AI suggestions before acting (do not take them at face value).
4.2.2Case management
Case management manages incidents as a SOC workflow—assigning owners, tracking status/priority, consolidating evidence and notes, and recording actions (audit trail) in one place. It runs investigations spanning multiple incidents, handovers, and compliance reporting consistently without depending on individuals.
Cues: "accelerate investigation with incident summary/KQL generation/recommended response" = embedded Security Copilot (validate suggestions). "visualize the intrusion→lateral movement→exfiltration chain" = attack story (incident graph). "centralize owner/status/evidence/records" = case management.
Watch the mix-ups: (1) Security Copilot (AI-assisted investigation) vs AIR (automated investigation/remediation)—Copilot assists, AIR auto-remediates. (2) Validate AI suggestions before acting. (3) Case management (SOC workflow) differs from the incident itself (a bundle of threats).
4.2.3Section summary
- Embedded Security Copilot summarizes/generates KQL/suggests responses—accelerating investigation (validate suggestions)
- Visualize complex attacks via the attack story (incident graph): intrusion→lateral movement→exfiltration
- Case management centralizes owner/status/evidence/records, avoiding dependence on individuals
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to accelerate investigation with incident summaries, KQL generation, and recommended responses. Which is best?
Q2. You want to manage owner assignment, status/priority, evidence/notes, and action records in one place as a SOC workflow. Which is best?
Q3. For a multistage, multi-domain attack, you want to visualize the chain from intrusion through lateral movement to exfiltration. Which is best?
Q4. Which correctly distinguishes Security Copilot from AIR (automated investigation and response)?
Q5. What is the best principle when handling Security Copilot suggestions?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

