Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
07Create detections and perform investigations using Microsoft Sentinel8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management0/56 units complete
Learning path 07 · Create detections and perform investigations using Microsoft Sentinel

8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management

0%

Study focus

Detection and response

Build analytics rules, automate triage, run playbooks, and manage security incidents.

Analytics and content

Apply UEBA, ASIM, KQL, workbooks, Content Hub solutions, and repository-based deployment.

8 modules · 56 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

04

Module 4

Security incident management in Microsoft Sentinel

Focus: incident structure, evidence, entities, ownership, status, severity, tasks, and resolution.
0/7
01 / 07Introduction

An incident groups related alerts, evidence, and entities into a case. Analysts triage priority, establish scope, document findings, respond, and close with an accurate classification.

Official moduleIncident objectives
02 / 07Exercise - Set up the Azure environment

Deploy the lab, connect Azure Activity, retain the environment, and validate actual log arrival before relying on the investigation workflow.

Official exercisePrepare the investigation lab
03 / 07Understand incidents

Analytics alerts become incidents when creation is enabled. Related alerts can be grouped by entities, tactics, timing, or rule settings. Severity, status, owner, tags, source, and timestamps support triage.

Exam takeaway: an alert is a detection signal; an incident is the analyst case containing one or more alerts.
Official lessonAlerts and incidents
04 / 07Incident evidence and entities

Evidence includes events, queries, timelines, comments, tasks, bookmarks, and entities. Entity mapping creates pivots such as account, host, IP, URL, file, process, and resource. Use the investigation graph and entity pages to follow relationships and establish an attack path.

Official lessonEvidence and graph pivots
05 / 07Incident management
  1. Assign ownership and validate severity.
  2. Set New, Active, or Closed status.
  3. Use tags, comments, and tasks for handoff.
  4. Investigate alerts, entities, timelines, and similar incidents.
  5. Run response actions and close with reason and classification.

Accurate closure classification improves metrics and tuning.

Official lessonTriage through closure
06 / 07Exercise - Investigate an incident

Generate suspicious activity, locate the incident, assign and activate it, examine alerts and entities, pivot through logs, record findings, and resolve it with the correct classification.

Official exerciseEnd-to-end investigation
07 / 07Summary

A disciplined workflow preserves evidence, makes decisions auditable, accelerates response, and feeds quality improvements back into detections.

Official moduleSummary and assessment
End of learning pathCreate detections and perform investigations using Microsoft Sentinel