From the course: Microsoft Security Operations Analyst Associate (SC-200) Cert Prep by Microsoft Press

Unlock this course with a free trial

Join today to access over 25,600 courses taught by industry experts.

Investigate and remediate security risks identified by Microsoft Defender for Cloud apps

Investigate and remediate security risks identified by Microsoft Defender for Cloud apps

From the course: Microsoft Security Operations Analyst Associate (SC-200) Cert Prep by Microsoft Press

Investigate and remediate security risks identified by Microsoft Defender for Cloud apps

- [Instructor] Next, we switch back to Microsoft Defender, XDR, and see how to investigate and remediate security risks identified by Microsoft Defender for Cloud Apps. Now in lesson five, we discussed configuring policies for Microsoft Defender for Cloud Apps. Now, after Microsoft Defender for Cloud Apps runs in your cloud environment, you will need a stage of learning and investigating. Before we see how to investigate and remediate security risks, we need to understand the different alerts or what are now called behaviors. Microsoft Defender for Cloud Apps is transitioning security content from alerts to behaviors. Behaviors are attached to multiple attack categories and techniques, and provide a deeper understanding of an event than the raw event data provides. Behavior data lies between raw event data and the alerts generated by an event. While behaviors might be related to security scenarios, but they are not…

Contents