Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
02Microsoft Defender for Endpoint9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management0/60 units complete
Learning path 02 · Microsoft Defender for Endpoint

9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management

0%

Study focus

Endpoint readiness

Deploy, onboard, configure, and harden devices with Microsoft Defender for Endpoint.

Investigation and response

Investigate devices and evidence, take response actions, automate remediation, and tune detections.

9 modules · 60 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

04

Module 4

Perform device investigations in Microsoft Defender for Endpoint

Focus: device inventory, device page evidence, behavioral blocking, and device discovery.
0/7
01 / 07Introduction

Device investigations pivot from an alert or incident into endpoint context: identity, health, exposure, alerts, behavioral timeline, software, vulnerabilities, and response actions.

Official moduleInvestigation objectives
02 / 07Use the device inventory list

The device inventory supports risk-based triage. Risk level reflects active alert severity and status; exposure level reflects the cumulative impact of pending security recommendations. Health states include active, inactive, and misconfigured, with communication and sensor issues called out separately.

Use filters and CSV export to validate onboarding, identify nonreporting endpoints, and prioritize high-risk or highly exposed devices.

Official lessonInventory, risk, exposure, and health
03 / 07Investigate the device

The device page exposes Overview, Alerts, Timeline, Security recommendations, Software inventory, Discovered vulnerabilities, and Missing KBs. The timeline is the primary chronological evidence view and can be searched, filtered, exported, or flagged to build a clean breach sequence.

  • Pivot from a timeline event to related entities.
  • Use Hunt for related events to open a prebuilt advanced hunting query.
  • Review logged-on users, active alerts, software, recommendations, and vulnerability context.
  • Choose response actions only after establishing scope and business impact.
Official lessonDevice page and timeline
04 / 07Use behavioral blocking

Behavioral blocking and containment use endpoint telemetry, cloud analytics, threat intelligence, and EDR context to stop suspicious behavior even when the exact file is not known as malware. Examples include blocking credential theft, persistence, process injection, malicious scripts, and observed attack chains.

Exam takeaway: post-breach behavioral blocking is part of EDR protection and can operate alongside antivirus to contain behavior after an attack begins.
Official lessonBehavioral blocking and containment
05 / 07Detect devices with device discovery

Device discovery finds unmanaged devices by observing network activity from onboarded endpoints. Standard discovery is the recommended mode. Discovered devices should be assessed, classified, and onboarded or otherwise controlled to reduce blind spots.

Official lessonUnmanaged device discovery
06 / 07Module assessment

Distinguish device risk from exposure, identify the correct device-page tab for chronological evidence, and understand how discovery identifies unmanaged assets.

Official assessmentDevice investigation knowledge check
07 / 07Summary and resources

A strong device investigation connects alert context to the device timeline, users, software, vulnerabilities, and other entities before selecting containment or remediation.

Official moduleSummary and resources
End of learning pathMicrosoft Defender for Endpoint