certslothcertsloth
SC-100/Topic 03

Microsoft / Expert

Security operations and compliance

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Collect useful evidence; connect it to response.

Must remember

  • Defender XDR correlates supported signals across security products; Sentinel provides SIEM/SOAR for broader data and workflows. Design source coverage, retention, access and response ownership together.
  • Central logging includes cloud audit, identity, endpoints, applications and supported Purview Audit data. Data quality, time synchronization and ingestion health are prerequisites for detection.
  • Map relevant threat behaviors to MITRE ATT&CK Enterprise/Mobile/ICS coverage. Rule count does not prove coverage; validate telemetry and detection with representative tests.
  • Design triage, hunting, incident management, containment and escalation workflows. Automate reliable enrichment and low-risk actions; use explicit authorization for disruptive response.
  • Translate regulations into control objectives, evidence, owners and review frequency. Purview supports data governance/compliance capabilities; Azure Policy governs supported resource configurations; Defender for Cloud evaluates supported posture/standards.
  • Compliance reports are evidence inputs, not a universal legal conclusion. Include hybrid/multicloud resources and exceptions with documented risk acceptance.

Choose under exam pressure

Requirement Choice and reason
Need correlation across Microsoft endpoints and identities Defender XDR, with required products and telemetry enabled.
Need broad third-party/cloud log correlation and automation Sentinel with designed connectors, analytics and response workflows.

Traps

  • A policy assignment does not prove every resource was remediated.
  • Passing a compliance dashboard check does not cover every process or legal requirement.

Active recall

1. Why monitor ingestion health?

Missing logs can make attacks invisible while alert volumes look reassuringly low.

2. What does ATT&CK mapping help assess?

Detection/control coverage against relevant adversary behaviors.

3. How choose SOAR actions?

Automate repeatable justified steps with scoped identity, error handling and impact controls.

4. What makes compliance evidence useful?

It is current, scoped, attributable and tied to a specific control requirement.

5. Why retain incident ownership?

Automated tools cannot resolve ambiguous responsibility or business recovery decisions.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.