-
Book Overview & Buying
-
Table Of Contents
Microsoft Security Operations Analyst Exam Ref SC-200 Guide - Second Edition
By :
This chapter covered how automation is configured across Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Sentinel, and related response workflows. You looked at email notifications, alert tuning, suppression, and correlation, and how these settings affect what analysts receive, investigate, and act on.
You also covered advanced features, rule settings, custom data collection, security policies, and ASR rules in Microsoft Defender for Endpoint. These controls define which endpoint capabilities are available, how telemetry is collected, and how preventive controls are applied to devices.
The chapter then moved into automated response. You reviewed AIR, automatic attack disruption, device groups, permissions, automation levels, Microsoft Sentinel automation rules, and playbooks. Together, these mechanisms show how automated handling, response execution, and cross-system coordination are configured without losing analyst oversight.
Throughout this book, you have...