No matching guide sections
Change the search or section filter.
Study Guide preview
Unlock Pro for every SC-200 flashcard-note lesson.
Preview the beginning of Section 1. Pro includes the complete Study Guide by section, plus Course Notes, guided course access, and Pro downloads.
Unlock with Pro
Opens the SC-200 Practice Test purchase options.
Section 1
Configure Defender XDR notifications, tuning, suppression, and correlation
Preview
Preview: Manage a security operations environment
Preview includes- 4 of 5 lesson topics
- 1 overview segment
- 3 core concepts
- 2 exam tips
Lesson Topics
- Configure Incident Notification Rules
- Utilize Threat Analytics Notifications
- Implement Alert Tuning
- Manage Correlated Incident Routing
Overview
This objective covers configuring Defender XDR notifications to ensure the right teams receive timely alerts based on defined criteria.
Core Concepts
- Incident notification rules trigger alerts based on severity and device-group scope.
- Threat analytics notification rules alert on threat intelligence report updates.
- Alert tuning allows for scoped conditions to handle known benign activity without deleting historical incidents.
Exam Tips
- Carefully consider the scope of each notification rule. Narrowly defined rules ensure relevant information reaches the correct teams.
- Understand the difference between alerting and suppression. Suppression hides detections, while tuning changes the handling of matching detections.
Section 1 continues in Pro.Unlock Pro to read the full Configure Defender XDR notifications, tuning, suppression, and correlation lesson plus every remaining SC-200 Study Guide section.
Unlock with Pro
Section 2
Investigate and manage Microsoft Defender XDR incidents and complex attacks
Pro
Investigate and manage Microsoft Defender XDR incidents and complex attacks unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 3
Select tables and apply KQL operators for threat hunting
Pro
Select tables and apply KQL operators for threat hunting unlocks with Pro.Unlock Pro to read the full 7 topics flashcard-note study guide for this section.
Unlock with Pro
Section 4
Configure Microsoft Defender for Endpoint advanced features, rules, collection, and security policies
Pro
Configure Microsoft Defender for Endpoint advanced features, rules, collection, and security policies unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 5
Investigate Defender for Office 365 and Microsoft Purview threats
Pro
Investigate Defender for Office 365 and Microsoft Purview threats unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 6
Manage automated investigation, response, and automatic attack disruption
Pro
Manage automated investigation, response, and automatic attack disruption unlocks with Pro.Unlock Pro to read the full 4 topics flashcard-note study guide for this section.
Unlock with Pro
Section 7
Create Advanced Hunting queries and interpret threat analytics
Pro
Create Advanced Hunting queries and interpret threat analytics unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 8
Investigate Defender for Cloud workload and Defender for Cloud Apps alerts
Pro
Investigate Defender for Cloud workload and Defender for Cloud Apps alerts unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 9
Create and configure Microsoft Sentinel automation rules
Pro
Create and configure Microsoft Sentinel automation rules unlocks with Pro.Unlock Pro to read the full 4 topics flashcard-note study guide for this section.
Unlock with Pro
Section 10
Investigate compromised identities with Entra ID Protection and Defender for Identity
Pro
Investigate compromised identities with Entra ID Protection and Defender for Identity unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 11
Create and configure Microsoft Sentinel playbooks
Pro
Create and configure Microsoft Sentinel playbooks unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 12
Create hunting graphs and analyze entity relationships with Sentinel Graph
Pro
Create hunting graphs and analyze entity relationships with Sentinel Graph unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 13
Investigate and manage incidents in Microsoft Sentinel
Pro
Investigate and manage incidents in Microsoft Sentinel unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 14
Configure Microsoft Sentinel roles and data retention tiers
Pro
Configure Microsoft Sentinel roles and data retention tiers unlocks with Pro.Unlock Pro to read the full 4 topics flashcard-note study guide for this section.
Unlock with Pro
Section 15
Investigate device timelines and perform Defender for Endpoint device actions
Pro
Investigate device timelines and perform Defender for Endpoint device actions unlocks with Pro.Unlock Pro to read the full 7 topics flashcard-note study guide for this section.
Unlock with Pro
Section 16
Create workbooks and optimize the Microsoft Sentinel platform
Pro
Create workbooks and optimize the Microsoft Sentinel platform unlocks with Pro.Unlock Pro to read the full 4 topics flashcard-note study guide for this section.
Unlock with Pro
Section 17
Create Sentinel hunting queries and KQL jobs in the data lake
Pro
Create Sentinel hunting queries and KQL jobs in the data lake unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 18
Perform endpoint evidence investigation and respond to disrupted attacks
Pro
Perform endpoint evidence investigation and respond to disrupted attacks unlocks with Pro.Unlock Pro to read the full 3 topics flashcard-note study guide for this section.
Unlock with Pro
Section 19
Collect Windows Security events with AMA, DCRs, and Windows Event Forwarding
Pro
Collect Windows Security events with AMA, DCRs, and Windows Event Forwarding unlocks with Pro.Unlock Pro to read the full 4 topics flashcard-note study guide for this section.
Unlock with Pro
Section 20
Investigate Microsoft 365 activity with Purview Audit, eDiscovery, and Graph activity logs
Pro
Investigate Microsoft 365 activity with Purview Audit, eDiscovery, and Graph activity logs unlocks with Pro.Unlock Pro to read the full 4 topics flashcard-note study guide for this section.
Unlock with Pro
Section 21
Collect Syslog and CEF data through Azure Monitor Agent
Pro
Collect Syslog and CEF data through Azure Monitor Agent unlocks with Pro.Unlock Pro to read the full 4 topics flashcard-note study guide for this section.
Unlock with Pro
Section 22
Use summary rules and notebooks for Sentinel threat hunting
Pro
Use summary rules and notebooks for Sentinel threat hunting unlocks with Pro.Unlock Pro to read the full 4 topics flashcard-note study guide for this section.
Unlock with Pro
Section 23
Ingest Azure activity, diagnostic, threat indicator, and custom log data
Pro
Ingest Azure activity, diagnostic, threat indicator, and custom log data unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 24
Create and manage custom detections in Microsoft Defender XDR
Pro
Create and manage custom detections in Microsoft Defender XDR unlocks with Pro.Unlock Pro to read the full 5 topics flashcard-note study guide for this section.
Unlock with Pro
Section 25
Configure Sentinel analytics rules, anomalies, and MITRE ATT&CK coverage
Pro
Configure Sentinel analytics rules, anomalies, and MITRE ATT&CK coverage unlocks with Pro.Unlock Pro to read the full 7 topics flashcard-note study guide for this section.
Unlock with Pro