Manage incident response

Respond to alerts and incidents across Microsoft Defender portal, investigate Microsoft 365 activities, respond to incidents in Microsoft Sentinel, and implement Security Copilot.

Covers responding to alerts and incidents in the Microsoft Defender portal including investigating threats from Defender for Office 365, ransomware and business email compromise incidents, compromised entities from DLP policies, insider risk policies, Defender for Cloud workload protections, Defender for Cloud Apps, Microsoft Entra ID, and Defender for Identity. Includes responding to Defender for Endpoint alerts through device timelines, live response, investigation packages, and evidence investigation. Also covers investigating Microsoft 365 activities through unified audit log, Content Search, and Microsoft Graph activity logs. Encompasses responding to incidents in Microsoft Sentinel with automation rules, playbooks, and on-premises resource playbooks. Includes implementing and using Microsoft Security Copilot for promptbooks, source management, connectors, permissions, cost monitoring, and incident investigation.
5 minutes 5 Questions

Incident response management is a critical component of the Microsoft Security Operations Analyst Associate role, focusing on effectively handling security incidents from detection through resolution. In Microsoft Sentinel and Microsoft Defender XDR, analysts must understand the complete incident l…

Concepts covered: Investigate and remediate threats with Defender for Office 365, Investigate ransomware and BEC incidents from attack disruption, Investigate compromised entities from Purview DLP policies, Investigate threats from Purview insider risk policies, Investigate alerts from Defender for Cloud workload protections, Investigate security risks from Defender for Cloud Apps, Investigate compromised identities from Microsoft Entra ID, Investigate security alerts from Defender for Identity, Investigate device timelines in Defender for Endpoint, Perform live response and collect investigation packages, Perform evidence and entity investigation, Investigate threats using the unified audit log, Investigate threats using Content Search, Investigate threats using Microsoft Graph activity logs, Investigate and remediate incidents in Microsoft Sentinel, Create and configure automation rules in Sentinel, Create and configure Microsoft Sentinel playbooks, Run playbooks on on-premises resources, Create and use Security Copilot promptbooks, Manage Security Copilot sources, plugins, and files, Integrate Security Copilot with connectors, Manage permissions and roles in Security Copilot, Monitor Security Copilot capacity and cost, Identify threats and risks using Security Copilot, Investigate incidents using Security Copilot

Test mode:
More Manage incident response questions
1000 questions (total)