Study guide
Technical reference and lesson notes
Purpose of This Lesson
This lesson introduces Microsoft Defender XDR, Microsoft’s extended detection and response platform for correlating security signals across endpoints, identities, email, SaaS applications, and cloud-connected workloads.
For the SC-200: Microsoft Security Operations Analyst exam, this topic matters because a SOC analyst needs to understand how Microsoft’s security tools work together. The exam often expects you to know which product detects a specific type of threat, how incidents and alerts are correlated, and how Microsoft Defender XDR helps analysts investigate and respond from a unified security operations experience.
The main idea is simple: modern attacks rarely stay in one place. A phishing email may lead to a compromised user identity, which may lead to malicious endpoint activity, suspicious SaaS access, and data exfiltration. Microsoft Defender XDR helps connect those signals so an analyst can understand the full attack story instead of investigating each product in isolation.
Key Concepts
What Is XDR?
XDR stands for Extended Detection and Response.
XDR is a security platform approach that collects and correlates signals across multiple security domains, such as:
- Endpoints
- Identities
- Cloud applications
- SaaS services
- On-premises infrastructure
- Cloud resources
- Data loss prevention signals
- Internet of Things or unmanaged device activity, depending on configuration
The goal of XDR is not just to collect logs. The goal is to help analysts detect, investigate, prioritize, and respond to threats across the environment.
A traditional SIEM is often focused on collecting and querying logs from many sources. XDR goes further by correlating security signals across integrated products and supporting response actions.
For the SC-200 exam, remember this distinction:
- SIEM: Centralizes log collection, correlation, analytics, and investigation.
- XDR: Correlates security signals across security products and supports detection, investigation, and response across connected workloads.
Microsoft’s XDR platform is Microsoft Defender XDR.
Microsoft Defender XDR as a Unified Security Platform
Microsoft Defender XDR brings together multiple Microsoft security products into a unified security operations experience.
Core products commonly associated with Microsoft Defender XDR include:
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Entra ID Protection
- Exchange Online Protection
- Microsoft Defender portal
These products generate signals from different parts of the environment. Microsoft Defender XDR correlates those signals into incidents, alerts, entities, evidence, and automated investigation workflows.
The value is that a SOC analyst does not have to manually piece together every event from separate tools. Microsoft Defender XDR helps show the relationship between users, devices, mailboxes, files, IP addresses, cloud apps, and alerts.
Microsoft Defender XDR vs Traditional Log Collection
The lesson compares XDR with the broader idea of SIEM-style log collection.
A SIEM collects logs from many sources and gives analysts a central place to search, query, alert, and investigate. However, SIEM tools do not always have native response capabilities for every workload they monitor.
Microsoft Defender XDR is different because it is tightly integrated with Microsoft security products. It can correlate signals and support actions such as:
- Investigating an endpoint alert
- Reviewing a compromised mailbox
- Identifying risky user behavior
- Containing a device
- Triggering automated investigation
- Remediating malicious email
- Reviewing identity-based risk
- Hunting across product data
In real environments, XDR and SIEM are often complementary. Microsoft Defender XDR is used for Microsoft security product correlation and response. Microsoft Sentinel is used for broader SIEM/SOAR scenarios, including non-Microsoft data sources, custom analytics, long-term correlation, automation, and centralized security monitoring.
Holistic Security and Signal Correlation
A major theme of the lesson is holistic security.
In a real organization, security data comes from many places:
- Physical devices
- User workstations
- Servers
- Operating systems
- Applications
- Cloud services
- Virtual machines
- Virtual firewalls
- Load balancers
- Microsoft 365 services
- SaaS applications
- Identity providers
- Email systems
- Network infrastructure
Every one of these systems may produce security-relevant events. The challenge for the SOC is that attackers move across these layers.
For example:
- A user receives a phishing email.
- The user clicks a malicious link.
- The attacker captures credentials.
- The attacker signs in from a suspicious location.
- The attacker accesses cloud apps.
- The attacker downloads sensitive files.
- The attacker attempts persistence or lateral movement.
Without correlation, those events may appear as separate alerts. With XDR, those signals can be connected into a single incident timeline.
Microsoft Defender XDR Product Components
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint protects and monitors endpoint devices such as:
- Windows workstations
- Servers
- Mobile devices
- Some network-connected devices, depending on onboarding and licensing
It is used for endpoint detection and response, vulnerability visibility, attack surface reduction, device investigation, and endpoint containment.
Common SOC uses include:
- Investigating suspicious process execution
- Reviewing device timelines
- Isolating a compromised endpoint
- Collecting investigation packages
- Reviewing file, process, registry, and network evidence
- Confirming whether malware executed successfully
For SC-200, associate Defender for Endpoint with endpoint alerts, device evidence, process trees, endpoint isolation, and endpoint investigation.
Microsoft Defender for Office 365
Microsoft Defender for Office 365 focuses on email and collaboration security.
It helps protect against:
- Phishing
- Malware attachments
- Malicious links
- Business email compromise
- Suspicious mailbox activity
- Email-based campaigns
- Threats in Microsoft Teams, SharePoint, and OneDrive, depending on configuration and licensing
It works alongside Exchange Online Protection, which provides baseline email protection for Exchange Online.
For SC-200, associate Defender for Office 365 with phishing investigations, malicious email remediation, Safe Links, Safe Attachments, Explorer, campaign views, and mailbox-related threat response.
Microsoft Defender for Identity
Microsoft Defender for Identity focuses on identity threats, especially those involving on-premises Active Directory.
It helps detect behaviors such as:
- Suspicious authentication activity
- Reconnaissance against Active Directory
- Lateral movement attempts
- Credential theft indicators
- Pass-the-ticket or pass-the-hash style activity
- Domain controller-related attack patterns
For SC-200, associate Defender for Identity with on-premises Active Directory security signals and identity-based attack detection.
Important terminology note:
- Microsoft Entra ID is the current name for Azure Active Directory.
- On-premises Active Directory is still called Active Directory.
- Microsoft Entra ID and Active Directory are related in many hybrid environments, but they are not the same thing.
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps focuses on SaaS and cloud application activity.
It helps with:
- Cloud app discovery
- SaaS application monitoring
- Risky cloud app behavior
- Session control
- OAuth app governance
- Data movement visibility
- Suspicious access patterns
- Integration with Microsoft Defender XDR signals
For SC-200, associate Defender for Cloud Apps with SaaS visibility, cloud application behavior, shadow IT discovery, app governance, and suspicious SaaS access.
Microsoft Entra ID Protection
Microsoft Entra ID Protection detects and helps remediate identity-based risk in Microsoft Entra ID.
It can identify risks such as:
- Risky users
- Risky sign-ins
- Impossible travel
- Anonymous IP address usage
- Leaked credentials
- Suspicious sign-in behavior
It can feed risk into Conditional Access policies or be used by analysts during identity investigations.
For SC-200, associate Microsoft Entra ID Protection with cloud identity risk, risky users, risky sign-ins, and Conditional Access-driven remediation.
Exchange Online Protection
Exchange Online Protection, or EOP, provides baseline protection for Exchange Online.
It helps defend against:
- Spam
- Malware
- Basic phishing
- Mail flow threats
Defender for Office 365 builds on top of this with more advanced investigation, response, and threat protection capabilities.
For exam purposes, do not confuse EOP with Defender for Office 365. EOP is baseline email protection. Defender for Office 365 provides more advanced threat protection and investigation capabilities.
Incidents and Alerts in Microsoft Defender XDR
Microsoft Defender XDR uses alerts and incidents to help analysts prioritize security work.
An alert is a detection from a security product or analytics engine. It usually represents a suspicious or malicious activity.
An incident is a collection of related alerts, evidence, and entities grouped together into a larger investigation.
Example:
- Alert 1: User clicked a malicious link.
- Alert 2: Suspicious sign-in detected.
- Alert 3: Malware executed on endpoint.
- Alert 4: Unusual SaaS file download occurred.
Microsoft Defender XDR may correlate these into one incident so the analyst can investigate the full attack path.
For SC-200, remember:
- Alerts are individual detections.
- Incidents group related alerts.
- Incidents help analysts understand scope, impact, and priority.
- Incidents can include entities such as users, devices, files, IP addresses, mailboxes, and cloud resources.
Incident Prioritization
Microsoft Defender XDR incidents can be prioritized by severity, commonly represented as:
- Low
- Medium
- High
Severity helps analysts determine which incidents need attention first.
In a SOC, prioritization matters because analysts usually have more alerts than time. A high-severity incident involving a compromised identity and endpoint execution should take priority over a low-severity informational alert.
However, severity should not be the only factor. Analysts should also consider:
- Affected user role
- Impacted device criticality
- Whether malware executed
- Whether credentials were compromised
- Whether sensitive data was accessed
- Whether the incident is still active
- Whether the alert is part of a larger campaign
- Whether automated remediation succeeded
Automated Investigation and Response
Microsoft Defender XDR supports automated investigation and response, often abbreviated as AIR.
AIR helps investigate and remediate threats across supported workloads, including:
- Devices
- Email and content
- User identities
Automated response can help reduce manual SOC workload by handling common investigation and remediation steps.
Examples of automated or semi-automated actions may include:
- Investigating suspicious endpoint activity
- Remediating malicious email
- Taking action on compromised mailbox content
- Identifying affected entities
- Recommending remediation steps
- Supporting self-healing for certain affected assets
For SC-200, the exam may ask when automation is appropriate. Automation is useful when the action is supported, repeatable, and safe. However, destructive or broad actions should usually require analyst review, change control, or escalation depending on the environment.
Self-Healing Capabilities
A key benefit of Microsoft Defender XDR is the ability to support self-healing across certain affected resources.
The lesson specifically emphasizes self-healing for:
- Compromised devices
- User identities
- Mailboxes
In practical terms, this means Microsoft Defender XDR may help investigate and remediate the affected asset instead of only generating an alert.
Self-healing does not remove the need for analyst review. A SOC analyst still needs to validate:
- What happened
- Which assets were affected
- Whether the threat was fully contained
- Whether additional remediation is required
- Whether the incident should be escalated
- Whether policies or detections need improvement
Threat Intelligence and Threat Analytics
Microsoft Defender XDR uses Microsoft threat intelligence to help detect and contextualize threats.
Threat intelligence helps answer questions such as:
- Is this IP address associated with known malicious activity?
- Is this file hash known malware?
- Is this behavior associated with a known attack technique?
- Is this activity part of a broader campaign?
- Which users, devices, or applications are repeatedly targeted?
Threat analytics helps analysts understand relevant threats and how they may affect the organization. It can help identify exposure, impacted assets, and recommended actions.
For the SC-200 exam, threat intelligence is important because security operations is not only about responding to alerts. Analysts must understand the context of the threat and use that context to make better triage and response decisions.
Cross-Product Threat Hunting
Microsoft Defender XDR supports cross-product threat hunting.
This means analysts can hunt across data from multiple Defender products instead of investigating endpoint, email, identity, and cloud app data separately.
Cross-product hunting is valuable when an analyst wants to answer questions such as:
- Did any other users receive the same phishing email?
- Did the same IP address sign in to other accounts?
- Did the same file hash appear on other endpoints?
- Did the compromised user access sensitive cloud apps?
- Did the endpoint activity happen before or after the mailbox compromise?
- Are multiple products detecting related behavior?
For SC-200, hunting is proactive. It is used to search for suspicious behavior, indicators of compromise, or attack patterns that may not yet be fully represented by an incident.
Microsoft Security Operations Context
How This Fits Into a SOC Workflow
Microsoft Defender XDR supports the SOC analyst across the full incident lifecycle.
A typical workflow might look like this:
- Alert or incident is generated
- Defender XDR correlates signals from endpoint, email, identity, and cloud app sources.
- Analyst reviews the incident
- The analyst checks severity, status, affected entities, alert timeline, and evidence.
- Analyst identifies the affected entities
- Entities may include users, devices, mailboxes, files, IP addresses, domains, URLs, or cloud applications.
- Analyst determines scope
- The analyst checks whether the activity is isolated or widespread.
- Analyst validates impact
- The analyst determines whether malware executed, credentials were compromised, data was accessed, or persistence was established.
- Analyst performs containment
- Actions may include isolating a device, disabling a user, resetting credentials, removing malicious email, blocking indicators, or escalating to another team.
- Analyst reviews automated investigation
- If automated response ran, the analyst verifies what actions were taken and whether additional remediation is needed.
- Analyst documents findings
- The incident record should include what happened, evidence reviewed, scope, impact, containment steps, remediation, and next actions.
- Analyst improves detection
- The team may tune alerts, create hunting queries, adjust policies, update playbooks, or add additional data sources.
Example SOC Scenario
A user receives a phishing email and clicks a malicious link.
Microsoft Defender for Office 365 may detect the malicious email or URL. Microsoft Entra ID Protection may detect a risky sign-in. Microsoft Defender for Endpoint may detect suspicious process execution on the user’s device. Microsoft Defender for Cloud Apps may detect unusual SaaS activity.
Instead of treating each alert separately, Microsoft Defender XDR can correlate the signals into a single incident. The SOC analyst can then investigate the full chain:
- Email delivery
- User interaction
- Sign-in activity
- Endpoint behavior
- SaaS app access
- Data movement
- Remediation status
This is the main value of XDR: connecting the dots across the attack path.
Exam-Relevant Takeaways
For the SC-200 exam, remember the following:
- Microsoft Defender XDR is Microsoft’s extended detection and response platform.
- XDR focuses on detection, investigation, response, and correlation across multiple security domains.
- Microsoft Defender XDR is not the same thing as Microsoft Sentinel.
- Microsoft Sentinel is Microsoft’s cloud-native SIEM/SOAR platform.
- Defender XDR correlates signals from Microsoft Defender products.
- Incidents group related alerts and evidence.
- Alerts are individual detections.
- Entities are objects involved in an incident, such as users, devices, mailboxes, IP addresses, files, and URLs.
- Defender for Endpoint is used for endpoint investigation and response.
- Defender for Office 365 is used for email and collaboration threat investigation.
- Defender for Identity is used for on-premises Active Directory-related identity threats.
- Microsoft Entra ID Protection is used for cloud identity risk.
- Defender for Cloud Apps is used for SaaS and cloud app activity.
- Automated investigation and response can help reduce manual workload.
- Self-healing does not eliminate the need for analyst validation.
- Threat hunting is proactive investigation across available security data.
- Current terminology matters: Azure AD is now Microsoft Entra ID, but on-premises Active Directory is still Active Directory.
Tool / Feature Decision Guide
| Scenario | Best Microsoft Security Tool or Feature | Why |
|---|---|---|
| Investigate a correlated incident involving endpoint, email, identity, and SaaS activity | Microsoft Defender XDR | Provides unified incident correlation across Microsoft security products |
| Investigate suspicious process execution on a workstation | Microsoft Defender for Endpoint | Endpoint-focused telemetry, device timeline, process evidence, and response actions |
| Investigate phishing email delivery and malicious links | Microsoft Defender for Office 365 | Email and collaboration security investigation |
| Review baseline Exchange Online mail protection | Exchange Online Protection | Provides core spam, malware, and mail flow protection |
| Investigate suspicious activity against on-premises Active Directory | Microsoft Defender for Identity | Detects identity attacks involving domain controllers and Active Directory behavior |
| Investigate risky cloud sign-ins or risky users | Microsoft Entra ID Protection | Focuses on identity risk in Microsoft Entra ID |
| Investigate suspicious SaaS app access or cloud app behavior | Microsoft Defender for Cloud Apps | Provides visibility into cloud apps, SaaS usage, app governance, and data movement |
| Centralize logs from Microsoft and non-Microsoft sources | Microsoft Sentinel | SIEM/SOAR platform for broad log ingestion, analytics, automation, and hunting |
| Group related alerts into one investigation | Incidents | Incidents organize related alerts, evidence, and entities |
| Review an individual detection | Alerts | Alerts represent specific suspicious or malicious activities |
| Search proactively for suspicious behavior | Advanced hunting / hunting queries | Helps analysts query available security data for indicators and attack patterns |
| Reduce repetitive investigation workload | Automated investigation and response | Automates supported investigation and remediation steps |
| Understand current threat campaigns and exposure | Threat analytics | Provides threat context, affected assets, and recommended actions |
KQL Notes
This lesson does not focus on KQL syntax directly, but it does introduce the idea of cross-product threat hunting, which commonly uses KQL in Microsoft Defender XDR advanced hunting and Microsoft Sentinel.
For SC-200, understand the purpose of KQL hunting:
- Search across security data
- Find indicators of compromise
- Identify affected users or devices
- Confirm whether an incident is isolated or widespread
- Support investigation and scoping
Simple Example: Hunting for Activity from a Suspicious IP
DeviceNetworkEvents
| where RemoteIP == "203.0.113.10"
| project Timestamp, DeviceName, InitiatingProcessFileName, RemoteIP, RemoteUrl
| order by Timestamp desc
What This Query Does
| Query Part | Purpose |
|---|---|
DeviceNetworkEvents | Searches endpoint network activity |
where RemoteIP == "203.0.113.10" | Filters results to one suspicious IP address |
project | Selects only the most useful columns for review |
order by Timestamp desc | Shows the newest events first |
How This Helps in an Investigation
If an incident includes a suspicious IP address, an analyst can use hunting to check whether other devices communicated with the same IP. This helps determine scope and whether the incident is isolated.
Exam Reminder
The exam may not require writing complex KQL from memory, but it does expect you to understand when KQL is useful and what common operators do.
Common operators to remember:
| Operator | Purpose |
|---|---|
where | Filters rows |
project | Selects columns |
summarize | Aggregates results |
extend | Creates calculated columns |
join | Combines data from multiple tables |
order by | Sorts results |
take / limit | Returns a limited number of rows |
Common Exam Traps
Confusing Microsoft Defender XDR with Microsoft Sentinel
Microsoft Defender XDR is the XDR platform for Microsoft security products. Microsoft Sentinel is the SIEM/SOAR platform for broader log collection, analytics, automation, and security monitoring.
If the scenario is about correlated Defender incidents across endpoint, email, identity, and cloud apps, think Defender XDR.
If the scenario is about ingesting logs from many sources, building analytics rules, connecting non-Microsoft data sources, or using SIEM/SOAR workflows, think Microsoft Sentinel.
Confusing Alerts with Incidents
An alert is a single detection.
An incident is a grouped investigation that may contain multiple related alerts and entities.
Exam questions may try to trick you by asking whether an analyst should investigate every alert separately. In Defender XDR, the better workflow is usually to start with the incident so you can understand the full correlated attack story.
Using the Wrong Defender Product
Know the workload:
- Endpoint problem: Defender for Endpoint
- Email problem: Defender for Office 365
- On-prem Active Directory identity attack: Defender for Identity
- Cloud identity risk: Microsoft Entra ID Protection
- SaaS/cloud app activity: Defender for Cloud Apps
- Broader SIEM/SOAR: Microsoft Sentinel
Ignoring Current Microsoft Naming
Older training materials, screenshots, and diagrams may use older names.
Common updates:
- Microsoft 365 Defender is now commonly referred to as Microsoft Defender XDR.
- Azure Active Directory is now Microsoft Entra ID.
- Azure AD Identity Protection is now Microsoft Entra ID Protection.
- Cloud App Security is now Microsoft Defender for Cloud Apps.
- On-premises Active Directory is still called Active Directory.
Assuming Automation Means No Analyst Review
Automated investigation and response can reduce workload, but the analyst still needs to validate the result.
For example, if Defender XDR remediates a malicious email or takes action on an endpoint, the analyst should still confirm:
- What happened
- What was affected
- What was remediated
- Whether the user or device is still at risk
- Whether further escalation is required
Treating Severity as the Only Priority Factor
Severity is important, but it is not the only factor.
A medium-severity incident involving a domain admin or executive mailbox may be more urgent than a high-volume low-impact alert affecting a test system.
SOC analysts should consider severity, asset criticality, identity privilege, business impact, and whether the threat is active.
Real-World SOC Analyst Notes
Alert Fatigue
XDR helps reduce alert fatigue by correlating related alerts into incidents. This is valuable because analysts often do not have time to manually reconstruct every event across endpoint, email, identity, and cloud app tools.
However, correlation is not perfect. Analysts still need to validate the incident timeline and evidence.
False Positives
Not every alert is a true compromise.
A SOC analyst should review:
- User behavior
- Device role
- Process lineage
- Email context
- Sign-in location
- Known business activity
- Change records
- Approved administrative tools
- Whether the behavior is expected for that user or system
The goal is not only to close alerts quickly. The goal is to make defensible decisions based on evidence.
Investigation Quality
A good investigation should answer:
- What triggered the alert?
- Which entities were involved?
- What happened first?
- Was the activity successful?
- What was the scope?
- What was the impact?
- What actions were taken automatically?
- What actions still need to be taken manually?
- Does another team need to be involved?
Escalation Paths
Defender XDR may show evidence across multiple domains, but one analyst may not own every remediation step.
Examples:
- Endpoint isolation may involve endpoint engineering.
- User disablement or password reset may involve identity administration.
- Mailbox remediation may involve messaging administrators.
- SaaS app control may involve cloud app owners.
- Firewall or network blocking may involve infrastructure teams.
- Legal or compliance review may be needed for data exposure.
Good SOC work includes knowing when to escalate.
Evidence Preservation
Before taking disruptive action, analysts should preserve enough evidence to explain what happened.
Useful evidence includes:
- Incident ID
- Alert names
- Affected users
- Affected devices
- Timestamps
- File hashes
- IP addresses
- URLs
- Process names
- Email message details
- Automated investigation results
- Response actions taken
This matters for incident documentation, lessons learned, customer communication, and possible compliance reporting.
Automation Safety
Automation is powerful, but it can also create operational risk.
Before enabling broad automation, organizations should consider:
- Which actions are allowed automatically
- Which actions require approval
- Whether VIP users are excluded from certain actions
- Whether business-critical servers require manual review
- Whether automation could interrupt production
- How actions are logged
- How false positives are handled
For example, automatically isolating endpoints may be acceptable for user workstations but risky for production servers.
Tenant-Wide Impact
Some Defender XDR actions can affect many users or devices. Analysts should be careful with broad remediation actions such as:
- Removing email from many mailboxes
- Blocking indicators tenant-wide
- Disabling accounts
- Applying Conditional Access changes
- Isolating devices
- Changing security policies
These actions may require change control or escalation depending on the organization.
Cost and Data Considerations
Microsoft Defender XDR and Microsoft Sentinel are related but different.
Defender XDR is focused on Microsoft security product correlation and response. Sentinel is a SIEM/SOAR platform where cost is often influenced by data ingestion, retention, and connected data sources.
In real environments, the organization should be deliberate about what data goes into Sentinel, how long it is retained, and which analytics rules justify ingestion cost.
Quick Reference Summary
- XDR means Extended Detection and Response.
- Microsoft Defender XDR is Microsoft’s XDR platform.
- XDR correlates signals across endpoints, email, identities, cloud apps, and other security domains.
- Defender XDR helps analysts investigate incidents, alerts, entities, and evidence in one place.
- Alerts are individual detections.
- Incidents group related alerts and evidence.
- Defender for Endpoint handles endpoint security.
- Defender for Office 365 handles email and collaboration threats.
- Defender for Identity handles on-premises Active Directory attack detection.
- Microsoft Entra ID Protection handles cloud identity risk.
- Defender for Cloud Apps handles SaaS and cloud app activity.
- Microsoft Sentinel is the SIEM/SOAR platform, not the same thing as Defender XDR.
- Automated investigation and response can reduce manual SOC workload.
- Self-healing helps remediate affected devices, mailboxes, and identities.
- Analysts still need to validate automated actions and document findings.
- Older materials may use names like Azure AD, Microsoft 365 Defender, or Cloud App Security.
Flashcards
Q: What does XDR stand for?
A: Extended Detection and Response.
Q: What is Microsoft’s XDR platform called?
A: Microsoft Defender XDR.
Q: What is the main purpose of Microsoft Defender XDR?
A: To correlate security signals across Microsoft security products and help analysts detect, investigate, and respond to threats.
Q: What is the difference between an alert and an incident?
A: An alert is an individual detection. An incident groups related alerts, evidence, and entities into a broader investigation.
Q: Which Defender product is used for endpoint investigation and response?
A: Microsoft Defender for Endpoint.
Q: Which Defender product is used for phishing and email threat investigation?
A: Microsoft Defender for Office 365.
Q: Which Defender product is associated with on-premises Active Directory attack detection?
A: Microsoft Defender for Identity.
Q: Which Microsoft product is used for risky users and risky sign-ins?
A: Microsoft Entra ID Protection.
Q: Which Defender product is used for SaaS and cloud application visibility?
A: Microsoft Defender for Cloud Apps.
Q: What is Microsoft Sentinel used for?
A: Microsoft Sentinel is Microsoft’s cloud-native SIEM/SOAR platform for log ingestion, analytics, hunting, automation, and broader security monitoring.
Q: Why is XDR useful in a SOC?
A: It helps analysts connect related activity across multiple security domains instead of investigating isolated alerts separately.
Q: What is automated investigation and response?
A: A capability that automatically investigates and can remediate supported threats across devices, email/content, and identities.
Q: Does self-healing eliminate the need for analyst review?
A: No. Analysts still need to validate scope, impact, remediation, and documentation.
Q: What is the current name for Azure Active Directory?
A: Microsoft Entra ID.
Q: Is on-premises Active Directory now called Microsoft Entra ID?
A: No. On-premises Active Directory is still called Active Directory.
Practice Questions
Question 1:
A SOC analyst receives an incident showing a phishing email, a risky sign-in, suspicious endpoint activity, and unusual SaaS access. The analyst wants to review the correlated attack story in one place.
Which tool should the analyst use first?
A. Microsoft Defender XDR
B. Exchange Admin Center
C. Microsoft Purview compliance portal
D. Microsoft Intune admin center
Correct Answer:
A. Microsoft Defender XDR
Explanation:
Microsoft Defender XDR correlates signals across Microsoft security products, including endpoint, email, identity, and cloud app activity. The analyst should start with the correlated incident view instead of investigating each signal separately.
Question 2:
An analyst needs to investigate suspicious process execution and network connections on a user’s workstation.
Which Microsoft security product is most relevant?
A. Microsoft Defender for Office 365
B. Microsoft Defender for Endpoint
C. Microsoft Defender for Identity
D. Exchange Online Protection
Correct Answer:
B. Microsoft Defender for Endpoint
Explanation:
Microsoft Defender for Endpoint provides endpoint telemetry, device timelines, process evidence, and endpoint response actions.
Question 3:
An organization wants to detect suspicious activity involving on-premises Active Directory, including reconnaissance and credential-based attack behavior against domain controllers.
Which product is most appropriate?
A. Microsoft Defender for Identity
B. Microsoft Defender for Cloud Apps
C. Microsoft Entra ID Protection
D. Microsoft Purview Data Loss Prevention
Correct Answer:
A. Microsoft Defender for Identity
Explanation:
Microsoft Defender for Identity is designed to detect identity-based threats involving on-premises Active Directory.
Question 4:
A security team wants to ingest logs from Microsoft and non-Microsoft systems, create analytics rules, and use SIEM/SOAR workflows.
Which tool best fits this requirement?
A. Microsoft Defender XDR
B. Microsoft Sentinel
C. Microsoft Defender for Office 365
D. Exchange Online Protection
Correct Answer:
B. Microsoft Sentinel
Explanation:
Microsoft Sentinel is Microsoft’s cloud-native SIEM/SOAR platform. Defender XDR is focused on correlated detection and response across Microsoft Defender products.
Question 5:
A Microsoft training diagram refers to Azure AD and Cloud App Security. What should an SC-200 candidate understand about this terminology?
A. Azure AD and Cloud App Security are unrelated to current Microsoft security products.
B. Azure AD is now Microsoft Entra ID, and Cloud App Security is now Microsoft Defender for Cloud Apps.
C. Azure AD is now Active Directory, and Cloud App Security is now Exchange Online Protection.
D. Azure AD was replaced by Microsoft Sentinel.
Correct Answer:
B. Azure AD is now Microsoft Entra ID, and Cloud App Security is now Microsoft Defender for Cloud Apps.
Explanation:
Older Microsoft diagrams and course materials may use older product names. Current terminology matters for the exam and for real-world portal navigation.