Memory hook: Collect useful evidence; connect it to response.
Must remember
- Defender XDR correlates supported signals across security products; Sentinel provides SIEM/SOAR for broader data and workflows. Design source coverage, retention, access and response ownership together.
- Central logging includes cloud audit, identity, endpoints, applications and supported Purview Audit data. Data quality, time synchronization and ingestion health are prerequisites for detection.
- Map relevant threat behaviors to MITRE ATT&CK Enterprise/Mobile/ICS coverage. Rule count does not prove coverage; validate telemetry and detection with representative tests.
- Design triage, hunting, incident management, containment and escalation workflows. Automate reliable enrichment and low-risk actions; use explicit authorization for disruptive response.
- Translate regulations into control objectives, evidence, owners and review frequency. Purview supports data governance/compliance capabilities; Azure Policy governs supported resource configurations; Defender for Cloud evaluates supported posture/standards.
- Compliance reports are evidence inputs, not a universal legal conclusion. Include hybrid/multicloud resources and exceptions with documented risk acceptance.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Need correlation across Microsoft endpoints and identities | Defender XDR, with required products and telemetry enabled. |
| Need broad third-party/cloud log correlation and automation | Sentinel with designed connectors, analytics and response workflows. |
Traps
- A policy assignment does not prove every resource was remediated.
- Passing a compliance dashboard check does not cover every process or legal requirement.
Active recall
1. Why monitor ingestion health?
Missing logs can make attacks invisible while alert volumes look reassuringly low.
2. What does ATT&CK mapping help assess?
Detection/control coverage against relevant adversary behaviors.
3. How choose SOAR actions?
Automate repeatable justified steps with scoped identity, error handling and impact controls.
4. What makes compliance evidence useful?
It is current, scoped, attributable and tied to a specific control requirement.
5. Why retain incident ownership?
Automated tools cannot resolve ambiguous responsibility or business recovery decisions.