Instiq
Chapter 4 · Manage and monitor security posture·v1.1.0·Updated 6/11/2026·~16 min

What's changed: Added per-section figures (cert-figure-retrofit). New SC-500 Chapter 4 (Domain 4 "Manage and monitor posture": Defender for Cloud = CSPM(recommendations/Secure Score/attack paths/regulatory compliance)-CWP plans-multicloud(AWS/GCP)-Defender Vulnerability Management-EASM; Microsoft Sentinel = workspaces/roles/content hub/data connectors/Syslog-CEF/Windows events(DCR-WEF)/custom tables/automation rules-playbooks/data retention/Purview Audit in Defender XDR; Microsoft Security Copilot = workspaces/permissions-roles/plugins/Microsoft-Security Store agents)

4.2Event collection and automated response with Microsoft Sentinel

Key points

Learn Microsoft Sentinel, the cloud-native SIEM/SOAR: workspaces and roles, content hub, data connectors, Syslog/CEF and Windows Security events (data collection rules, WEF), custom log tables, automation rules and playbooks, data retention, and querying Purview Audit in Defender XDR.

The center of "monitoring" posture is Microsoft Sentinel. It provides SIEM (Security Information and Event Management—aggregate and correlate logs to detect threats) and SOAR (Security Orchestration, Automation, and Response—automate post-detection response) cloud-natively. Its foundation is a Log Analytics workspace, where logs from many sources are collected and analyzed with KQL.

4.2.1Workspaces, roles, content hub, and data connectors

Enable Sentinel on a Log Analytics workspace. Assign access with least privilege via Sentinel roles (Reader/Responder/Contributor, etc.). From the content hub, install per-product solutions (bundles of connectors + analytics rules + workbooks + playbooks). Ingest logs via data connectors that connect Azure resources, Microsoft 365, and various cloud/on-prem sources.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.