GregLab | Exam Prep

Respond to security incidents

Cross-Product Incident Response

Core

Correlate mail, data, workload, SaaS, identity, and Sentinel evidence into one defensible attack story, then contain the assets that the evidence shows are compromised.

Aligned to SC-200 skills measured as of July 28, 2026; product behavior verified September 18, 2026.

Why this matters

A single campaign can start in email, steal an identity, spread to endpoints, and reach cloud resources. Local cleanup in one portal may remove the first artifact while leaving sessions, persistence, or downstream access active.

Must Know

  • Defender for Office 365 evidence identifies campaign messages, recipients, delivery, clicks, and remediation status.
  • Purview alerts describe sensitive-data and user activity; correlate them with identity and endpoint evidence before attributing cause.
  • Defender for Cloud workload alerts pivot through the affected cloud resource and its process, network, and identity context.
  • Defender for Cloud Apps investigations center on app, user, session, and activity evidence; Microsoft Entra risk signals strengthen identity decisions.
  • Defender for Identity exposes directory reconnaissance, credential theft, and lateral movement relationships.
  • Security Copilot can organize evidence and propose pivots, but analysts must validate its claims against source records.
  • Use Sentinel incident entities, timelines, ownership, status, and tasks to correlate complex attacks and maintain a durable case across handoffs.
  • Case management preserves owner, status, tasks, findings, evidence, actions, and handoff context.

Compare and Distinguish

  • An alert is evidence from a detection; an incident correlates alerts and entities into an investigation; a case preserves coordinated handling context.
  • Containment limits ongoing harm; remediation removes or reverses malicious changes; recovery returns assets to trusted operation.
  • AI-generated summaries accelerate triage but remain hypotheses until validated against the underlying evidence.

Scenario examples

  • Scenario: Email, identity, and endpoint alerts describe one campaign. Think: investigate the correlated incident and contain across affected domains.
  • Scenario: Embedded Security Copilot proposes a root cause. Think: verify cited entities, timestamps, and actions before remediation.
  • Scenario: A handoff crosses shifts. Think: preserve ownership, status, evidence, tasks, and rationale in case management.

Exam traps

  • Blocking a sender does not retract delivered mail or remediate a clicked account.
  • A valid credential does not make a risky sign-in legitimate.
  • A shared IP or product-generated correlation is a lead whose relationship and timing still need review.
  • An AI summary is not an action record and cannot prove isolation or exfiltration.

Key takeaways

  • Follow shared entities and timestamps across product boundaries.
  • Contain confirmed identity, device, session, and workload paths, then verify eradication before recovery.
  • Keep the incident record current enough for another team to continue without guessing.
How it works
  • Defender XDR correlates supported alert and entity evidence into an incident attack story.
  • Responders pivot into the source product for detailed activity and return action outcomes to the incident record.
Objects and administrative surfaces
  • Unified incident queue and attack story in the Microsoft Defender portal.
  • Microsoft Sentinel incident entities, timeline, tasks, comments, owner, and status.
  • Source-product evidence for email, identity, endpoint, app, Purview, and cloud-workload remediation.
When to use it
  • Use product-specific evidence to investigate the stage it observes, then correlate across the incident.
  • Use Security Copilot to accelerate summaries and pivots when every material claim can still be checked against source telemetry.
Security and governance implications
  • Preserve sensitive-data, identity, device, and workload evidence under the case access policy.
  • Record justification and outcome for broad identity or workload containment.
Troubleshooting signals
  • When alerts appear unrelated, compare canonical entity IDs, timestamps, IPs, sessions, and process ancestry.
  • When an automated action and an AI summary disagree, rely on the action record and primary event evidence.
More detail
  • Defender for Office 365 evidence identifies campaign messages, recipients, delivery, clicks, and remediation status.
  • Purview alerts describe sensitive-data and user activity; correlate them with identity and endpoint evidence before attributing cause.
  • Defender for Cloud workload alerts pivot through the affected cloud resource and its process, network, and identity context.
  • Defender for Cloud Apps investigations center on app, user, session, and activity evidence; Microsoft Entra risk signals strengthen identity decisions.
  • Defender for Identity exposes directory reconnaissance, credential theft, and lateral movement relationships.
  • Security Copilot can organize evidence and propose pivots, but analysts must validate its claims against source records.
  • Use Sentinel incident entities, timelines, ownership, status, and tasks to correlate complex attacks and maintain a durable case across handoffs.
  • Case management preserves owner, status, tasks, findings, evidence, actions, and handoff context.

Ready for the quiz?

  • What evidence distinguishes a delivered phishing message from a compromised recipient?
  • How do you bound a cloud-workload response to the affected resource?
  • Which case fields prevent duplicate work during a shift handoff?

Related objectives

  • D2.1.S1 — Investigate and remediate threats by using Microsoft Defender for Office 365, including automatic attack disruption
  • D2.1.S2 — Investigate and remediate threats or compromised entities identified by Microsoft Purview
  • D2.1.S3 — Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud workload protections
  • D2.1.S4 — Investigate and remediate security risks identified by Microsoft Defender for Cloud Apps
  • D2.1.S5 — Investigate and remediate compromised identities that are identified by Microsoft Entra ID
  • D2.1.S6 — Investigate and remediate security alerts from Microsoft Defender for Identity
  • D2.1.S7 — Investigate and remediate alerts and incidents identified by Microsoft Sentinel
  • D2.1.S8 — Investigate incidents by using agentic AI, including embedded Microsoft Security Copilot
  • D2.1.S9 — Investigate complex attacks, such as multi-stage, multi-domain, and lateral movement
  • D2.1.S10 — Manage security incidents by using case management

Learn more

Free Microsoft Certified: Security Operations Analyst Associate prep

Build focused SC-200 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-200 at a glance

Level
Intermediate / Associate
Duration
100 minutes
Questions
No fixed live question count published
Formats
No guaranteed question-type mix
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-200. This lane contains multiple-choice and multiple-response exam-style practice. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Intermediate Associate-level security-operations complexity rather than a Microsoft-published question rating.

Reference

SC-200 topics and reference map

Study links

SC-200 resources