From the course: Microsoft Security Operations Analyst Associate (SC-200) Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 25,600 courses taught by industry experts.
Investigate and remediate security risks identified by Microsoft Defender for Cloud apps
From the course: Microsoft Security Operations Analyst Associate (SC-200) Cert Prep by Microsoft Press
Investigate and remediate security risks identified by Microsoft Defender for Cloud apps
- [Instructor] Next, we switch back to Microsoft Defender, XDR, and see how to investigate and remediate security risks identified by Microsoft Defender for Cloud Apps. Now in lesson five, we discussed configuring policies for Microsoft Defender for Cloud Apps. Now, after Microsoft Defender for Cloud Apps runs in your cloud environment, you will need a stage of learning and investigating. Before we see how to investigate and remediate security risks, we need to understand the different alerts or what are now called behaviors. Microsoft Defender for Cloud Apps is transitioning security content from alerts to behaviors. Behaviors are attached to multiple attack categories and techniques, and provide a deeper understanding of an event than the raw event data provides. Behavior data lies between raw event data and the alerts generated by an event. While behaviors might be related to security scenarios, but they are not…
Contents
-
-
-
-
-
-
-
-
-
-
(Locked)
Learning objectives1m 46s
-
(Locked)
Investigate and remediate threats to Microsoft Teams, SharePoint Online, and OneDrive5m 34s
-
(Locked)
Investigate and remediate threats in email using Microsoft Defender for Office6m 8s
-
(Locked)
Investigate and remediate ransomware and business email compromise incidents identified by automatic attack disruption4m 39s
-
(Locked)
Investigate and remediate compromised entities identified by Microsoft Purview data loss prevention (DLP) policies5m 1s
-
(Locked)
Investigate and remediate threats identified by Microsoft Purview insider risk policies10m 1s
-
(Locked)
Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud7m 59s
-
(Locked)
Investigate and remediate security risks identified by Microsoft Defender for Cloud apps5m 3s
-
(Locked)
Investigate and remediate compromised identities in Microsoft Entra ID3m 48s
-
(Locked)
Investigate and remediate security alerts from Microsoft Defender for Identity5m 4s
-
(Locked)
Manage actions and submissions in the Microsoft Defender portal8m 34s
-
(Locked)
-
-
-
-
-
-
-
-