Memory hook: Collect → detect → correlate → contain → prove recovery.
Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.
Scope/version: This path targets the published October 21, 2026 update. That is later than this October 10 review; compare your booking outline for an earlier sitting. Microsoft portal layouts, data-lake features and licensing can change, so study the decision and evidence path as well as the current UI.
Must remember by domain
| Domain | Rapid revision |
|---|---|
| Environment/access | Defender XDR correlates supported product signals; Sentinel supplies SIEM/SOAR over broader sources. Sentinel Reader reads, Responder handles incidents, Contributor configures within scope; endpoint actions/playbooks require additional appropriate permissions. Device groups and automation levels constrain response. Tier/retention choices must still support required detections and investigations. |
| Collection | Source audit settings generate evidence; connector/forwarder/AMA gathers it; DCR defines supported selection/routing; table/schema stores it. WEF centralizes Windows events; Syslog/CEF commonly use Linux forwarders. Activity Log concerns control-plane operations; resource diagnostics concern selected services. Test known records, timestamps, duplicates and latency. |
| Detection/automation | Scheduled rules use cadence/lookback; NRT has supported limits. Thresholds, entity mapping, grouping and suppression affect incidents. Defender custom detections require correct timestamp/entity identifiers. ATT&CK mapping identifies intended coverage, not proof of detection. Automation rules coordinate handling; Logic Apps playbooks execute scoped actions. ASR audit observes, block enforces. |
| Incident response | Validate signal → scope entities/time → preserve evidence → contain proportionately → eradicate persistence → recover → learn. Device timeline, investigation packages and Live Response answer different needs. Isolation limits connectivity; a package collects evidence; scanning investigates malware. Verify sensor/onboarding health before concluding no activity exists. |
| Cross-domain evidence | Correlate endpoint process trees, sign-ins, email delivery/clicks, identity changes, OAuth grants and cloud activity. Purview Audit records supported actions; eDiscovery content search locates content; Graph activity logs illuminate supported API calls. Password reset alone may leave malicious app consent, sessions or mailbox persistence. |
| Hunting | Start with a hypothesis and required table. Filter time early, preserve identifiers, join on reliable entity/time keys and summarize at the intended grain. Defender hunting graphs/Sentinel Graph show supported relationships and potential blast radius; potential access is not proof of observed movement. Threat intelligence needs context/expiry. |
| Data lake/assistance | KQL jobs and summary rules produce reusable analyses with freshness/grain tradeoffs; they do not replace raw forensic evidence. Notebooks/MCP extend supported investigation under scoped access. Security Copilot may summarize and suggest, but validate claims, source evidence and action authority. Track case ownership and unresolved evidence gaps. |
Traps and diagnostic order
No event: source generation → sensor/forwarder → connector permissions → DCR/filter → table/parser/time → retention/query. No incident: query window → schema/identifiers → rule threshold/grouping → suppression. Do not disable broad protections because of one false positive; narrow an exception using evidence. A graph edge or indicator match is a lead, not a conviction.
Last-pass self-check
1. A connector is installed: is collection proven?
No. Verify an expected source event arriving correctly in its destination table.
2. Why can a scheduled rule miss a real event?
Ingestion delay or incorrect timestamps/lookback can put it outside the evaluated window.
3. Isolation versus investigation package?
Containment versus evidence collection; choose deliberately and preserve needed access.
4. How can a KQL join inflate counts?
Nonunique keys can create many-to-many row multiplication; validate grain and deduplicate appropriately.
5. What must accompany an automated containment action?
Reliable evidence, authorized scope, audit trail and a tested recovery/escalation path.
Sources
- Official exam scope and version
- azure · sentinel · overview
- azure · sentinel · roles
- azure · sentinel · datalake · sentinel-lake-overview
- azure · sentinel · monitor-your-data
- azure · sentinel · connect-windows-security-events
- azure · sentinel · connect-cef-syslog-ama
- azure · azure-monitor · data-collection · data-collection-rule-overview
- azure · azure-monitor · essentials · diagnostic-settings
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · SOC Platform, Roles and Retention
Memory hook: Collect with a purpose; keep it where the investigation can use it.
Must remember
Microsoft Defender XDR correlates signals across supported endpoint, identity, email and application products. Microsoft Sentinel adds SIEM/SOAR capabilities across Microsoft and third-party sources. A unified portal experience does not erase underlying connector, workspace, licensing or role requirements.
Separate reading, investigating, configuration and automation permissions. Sentinel Reader inspects; Responder handles incidents; Contributor configures Sentinel resources within its scope. Playbook execution also needs the relevant Logic Apps/identity permissions. A user who can see an incident may still lack authority to isolate a device or run a playbook.
Choose table tier and retention by detection latency, investigation frequency, query capability and cost. Analytics, data-lake and XDR data surfaces are not interchangeable hot stores. Verify which rule/query types can use a tier before moving required detection data. Retention governs how long evidence remains; collection gaps cannot be repaired by increasing retention afterward.
Workbooks visualize query results and operational metrics. Track connector health, ingestion delay, rule failures, incident backlog and response time. SOC optimization recommendations can reveal coverage/cost opportunities, but validate their relevance before changing collection or detections. A quiet dashboard can indicate a broken pipeline rather than a quiet attacker.
Set notifications for the right audience and urgency. Incident, automated-action and threat-analytics notifications answer different questions. Record ownership, escalation and retention decisions so an on-call analyst can act without broadening permissions during an incident.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Analyst must manage incidents without editing every rule | Scoped responder permissions. |
| Long history needed for occasional hunting | Evaluate data-lake retention/query trade-offs. |
| Show ingestion delays and incident trends | A workbook over reliable operational data. |
Traps
- Portal consolidation does not grant all response permissions.
- No alerts is not proof of no malicious activity.
02 · Connectors, AMA and Collection Boundaries
Memory hook: An installed agent is only the start of an evidence pipeline.
Must remember
Choose the connector for the actual source and required event types. Azure Monitor Agent (AMA) uses data collection rules (DCRs) to define supported collection/routing. Associate the rule with the intended machines and verify destination tables, permissions, network access and event arrival. An agent service running locally does not prove useful records reached Sentinel.
Windows Security Events via AMA collects selected security events. Windows Event Forwarding can centralize events on collectors before ingestion; size and monitor the collector and distinguish original event source from collection host. Audit policy determines which events are generated in the first place.
Syslog via AMA collects supported Linux/appliance syslog. Common Event Format (CEF) adds a structured event representation, commonly relayed through a Linux collector. Configure the sender, transport, listener, parser and DCR consistently. Check facility/severity filters and timestamp handling; an incorrect filter can silently discard the needed evidence.
Azure Activity records control-plane operations. Resource diagnostic settings collect supported service logs/metrics, a separate surface from the subscription activity log. Azure Policy can deploy consistent diagnostic configuration at scale, but remediation and identity permissions still need validation.
Custom tables need a planned schema, timestamps and supported ingestion/transformation path. Threat-intelligence indicators require source trust, validity periods and matching logic; an indicator is not a verdict on every matching event. Check ingestion latency and duplicates, use known test records, and retain sufficient source detail to investigate normalization errors.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Windows security event selection and destination | AMA plus an associated DCR and appropriate audit policy. |
| Appliance emits CEF | Configure its supported CEF collector/connector path. |
| Collect service-specific resource logs consistently | Diagnostic settings, with Policy where suitable. |
Traps
- Azure Activity is not every resource data-plane event.
- WEF collection does not create events that audit policy never generated.
03 · Detection Engineering, Tuning and Automation
Memory hook: A query finds evidence; a detection makes it actionable.
Must remember
Start with a threat hypothesis and required telemetry. Scheduled Sentinel analytics rules run a query on a configured cadence/lookback; near-real-time rules have their own supported constraints. Thresholds, entity mapping, grouping and suppression decide how query results become alerts and incidents. A rule that runs successfully can still miss events arriving outside its effective window.
Defender custom detections use supported advanced-hunting tables and required identifying fields. Preserve the identifiers and timestamps needed to create useful alerts or response actions. Map detections to MITRE ATT&CK techniques to expose coverage gaps; a colored matrix is not evidence that each technique is reliably detected.
Tune with labeled examples. Narrow exclusions to known expected behavior, measure false positives and keep a way to detect abuse of the exception. Threat-intelligence matches and anomaly/ML signals need context and validation. Suppressing a noisy alert globally can hide a real attack using the same pattern.
Sentinel automation rules react to supported incident/alert conditions and can update fields, assign work or invoke playbooks. Playbooks run Logic Apps workflows and need authorized identities for their connectors/actions. Distinguish a rule's trigger from the playbook's trigger and test error/retry paths. A repeated event should not repeatedly disable a legitimate account without control.
Automated investigation and response and automatic attack disruption can contain activity across supported Defender signals. Configure prerequisites, scope and approval/automation levels deliberately. Keep evidence, record actions and verify recovery. Automation speed is useful only when the detection, permissions and rollback are trustworthy.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Recurring query becomes an incident | Analytics rule with entities, thresholds and grouping. |
| Route and enrich a new incident | Automation rule and an appropriately triggered playbook. |
| Evaluate detection coverage | Map validated detections to ATT&CK and inspect telemetry gaps. |
Traps
- Rule success is not proof of detection effectiveness.
- A broad suppression can remove evidence of real abuse.
04 · Endpoint Controls and Investigation
Memory hook: Contain the device while preserving the story.
Must remember
Onboard supported devices and verify sensor health, connectivity and data availability. Device groups scope access and automation behavior. Advanced features, rules and indicators change endpoint behavior; confirm licensing, platform support and conflicts with other management channels before assuming one setting applies everywhere.
Attack surface reduction (ASR) rules prevent risky behaviors. Audit mode observes impact; block mode enforces; exclusions should be narrow and justified. An ASR policy is a preventive control, while an investigation timeline is evidence about what happened. Use staged rollout and measured impact for legitimate applications.
Investigate the device timeline, process tree, command line, network activity, file hashes, user context and related alerts. Parent/child processes and timing can distinguish an ordinary administrative tool from suspicious use. A hash match is one indicator, not a complete explanation of execution or intent.
Response options include supported isolation, antivirus scans, investigation packages and live response. Isolation changes connectivity; collecting a package preserves useful artifacts. Live response is powerful and must use authorized commands and role permissions. Capture enough evidence before destructive remediation, while prioritizing urgent containment where necessary.
Follow automated investigations through pending actions, approvals and completion. Validate that persistence and related identities are addressed before reconnecting a device. Closing the alert is workflow bookkeeping, not proof of eradication. Document scope, evidence, action times and reasons so the incident can be reconstructed.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Understand suspicious execution sequence | Device timeline and process/entity evidence. |
| Assess an ASR rule before broad enforcement | Audit/staged rollout with measured impact. |
| Limit a compromised device’s communication | Authorized supported isolation, with evidence and recovery planning. |
Traps
- A closed alert does not certify a clean endpoint.
- Blocking a file alone may leave the compromised identity or persistence mechanism active.
05 · Cross-Domain Incidents and Microsoft 365 Evidence
Memory hook: Follow the identity across email, devices, apps and cloud.
Must remember
Triage severity, confidence, affected assets and business impact. An incident groups related alerts; investigate its attack story and entities rather than treating every alert as unrelated. Assign an owner, track hypotheses, preserve evidence and record decisions in incident/case management.
Defender for Office 365 provides email/collaboration threat evidence and remediation capabilities. Trace message delivery, clicks and related sign-ins before deciding the scope. Defender for Identity adds on-premises identity signals; Entra sign-in/risk evidence adds cloud identity context. Password reset, session revocation and device containment solve different parts of account compromise.
Defender for Cloud Apps helps investigate application activity and risky sessions; Defender for Cloud workload protections surface threats affecting protected cloud resources. Purview alerts can indicate risky data handling. Correlate the same user, device, app and time window across sources, then validate that similarly named entities really are the same identity.
Purview Audit records supported activities for investigation. eDiscovery Content search finds relevant content under its permissions and scope; it is not the same as querying activity logs. Microsoft Graph activity logs describe Graph API request activity when configured. Use the correct evidence source for the question and preserve timestamps/time zones.
Contain first when impact demands it, then eradicate and recover under the incident plan. Track lateral movement, persistence and exfiltration, not just initial access. Confirm actions succeeded and measure residual risk. Escalate legal, privacy and business decisions to the appropriate owners; an analyst should not invent a notification deadline from technical evidence alone.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Who accessed or changed an item? | Relevant audit/activity evidence. |
| Find communications/content in scope | Authorized eDiscovery search. |
| Compromised user remains active after password reset | Investigate sessions/tokens and other persistence; apply appropriate revocation/containment. |
Traps
- Content search and activity audit answer different questions.
- Matching a display name is weaker than matching stable entity identifiers.
06 · KQL Hunting and Evidence Quality
Memory hook: Filter early, preserve identifiers, test the hypothesis.
Must remember
Choose the table whose schema represents the activity: device processes, network connections, sign-ins and email events are different evidence. Inspect sample rows and available columns before writing joins. Limit time and project needed fields early to control cost and result volume.
where filters, project selects/computes columns, extend adds columns and summarize aggregates. bin groups values into intervals. has uses term semantics while contains searches substrings; case-sensitive variants and exact comparisons can matter for correctness and speed. Parse structured dynamic fields deliberately and validate null/type behavior.
Join on stable keys and appropriate time relationships. A many-to-many join can multiply evidence and create misleading counts. Use distinct identifiers or an explicit deduplication strategy where justified, preserving the raw evidence for review. Union combines compatible results; it does not correlate them by identity.
A hunt starts with a falsifiable hypothesis, relevant telemetry and an expected pattern. Record the query, time range, evidence and confidence. A result is a lead; absence can mean no activity, missing data or an inadequate query. Save useful queries, monitor them and promote repeatable high-value logic into detections after testing.
Use Defender threat analytics for context about campaigns and mitigations, then check applicability to your environment. Advanced hunting queries and Sentinel queries may use different schemas despite both being KQL. Preserve required fields when converting a hunt to a custom detection; a summarized chart may omit identifiers needed for an actionable alert.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Find a whole command-line term | Consider has with the intended token semantics. |
| Correlate account activity across sources | Join validated stable identifiers and time windows. |
| Repeated useful hunt should alert automatically | Test and convert it into an appropriate detection rule. |
Traps
- No query results cannot prove absence when collection is incomplete.
- Aggregating away entity IDs can make a detection unusable.
07 · Data Lake Jobs, Summaries and Notebooks
Memory hook: Scan history deliberately; keep summaries tied to raw evidence.
Must remember
Data-lake hunting separates long-term evidence exploration from the latency needs of operational detections. A KQL job can query supported data-lake data and materialize useful results according to its configured destination and schedule. Check permissions, time range, query limits and expected processing cost before launching a broad historical scan.
Summary rules create preaggregated tables for repeated analysis. Choose bins, dimensions and retained identifiers around the questions analysts must answer. A daily count is fast to query but cannot reconstruct every original process event. Keep a route from suspicious summaries back to raw data.
Search jobs retrieve relevant historical records through their supported search mechanism; they are different from a continuously running near-real-time detection. Distinguish the selected table/tier and query feature instead of assuming every interactive query supports the same retention range.
Notebooks combine code, data access, visualization and analytical workflows. They can support enrichment and complex hunting, but require dependency, identity, data handling and output review. Reproducibility needs saved code, parameter/time-range records and controlled environments; a screenshot alone is weak evidence.
Microsoft Sentinel's MCP support exposes supported capabilities to authorized AI clients. It does not give a model unrestricted permission or make its reasoning reliable. Scope the identity and tools, inspect retrieved evidence, and require appropriate human control over consequential response. Treat log content as untrusted data, including text that looks like an instruction to an agent.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Repeat a costly historical aggregation | A scheduled summary/job with appropriate retained detail. |
| Explore complex evidence with code and visualizations | A governed notebook. |
| AI client needs Sentinel context | Supported MCP access with scoped identity and verified evidence. |
Traps
- A summary table may omit the raw evidence needed to prove an event.
- An AI tool connection does not make log text trustworthy instructions.
08 · Attack Graphs, Copilot and Investigation Decisions
Memory hook: A relationship suggests a path; evidence proves the event.
Must remember
Multi-stage attacks connect initial access, identity abuse, lateral movement, persistence and impact. Build a timeline with stable entities, source provenance and confidence. A privileged relationship can reveal possible blast radius even when no malicious traversal has yet been observed.
Hunting graphs and Sentinel Graph help examine relationships among supported entities. Distinguish a possible attack path from an observed sequence. A user with access to a server is not proof that the user accessed it during the incident. Correlate graph context with sign-ins, process/network events and other relevant records.
Embedded Security Copilot and supported agentic capabilities can summarize incidents, explain queries and suggest investigation steps. Check every consequential claim against cited evidence and actual tool output. A fluent narrative can join unrelated entities or omit telemetry gaps. Data inside email, documents and logs can contain adversarial instructions; it remains evidence to analyze, not authority over the workflow.
Case management preserves ownership, status, tasks and evidence across a complex investigation. Separate facts, hypotheses and decisions. Assign follow-up for missing evidence, document containment scope and track recovery validation. An automated summary is a convenience, not the authoritative chain of custody.
Under exam pressure, choose the action that reduces the immediate risk while preserving necessary evidence and respecting permissions. Broader containment can be justified for active compromise, but a vague low-confidence signal does not justify disabling an entire organization. Reassess scope as evidence changes and record why the response expanded or narrowed.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Estimate what a compromised identity could reach | Relationship/attack-path analysis, validated against access configuration. |
| Prove it actually moved laterally | Correlated time-bound activity evidence. |
| Copilot proposes a response | Validate evidence, scope, authorization and operational impact. |
Traps
- A graph edge is not necessarily an observed attack step.
- A confident generated summary can still be wrong.