Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
09Mitigate threats using Microsoft Purview4 modules · 42 units · DLP alerts, insider risk, Audit, eDiscovery, Defender XDR, and investigation workflows0/42 units complete
Learning path 09 · Mitigate threats using Microsoft Purview

4 modules · 42 units · DLP alerts, insider risk, Audit, eDiscovery, Defender XDR, and investigation workflows

0%

Study focus

Data risk response

Investigate DLP and insider-risk alerts, correlate evidence, remediate activity, and manage cases.

Evidence discovery

Search, validate, retain, and export evidence with Microsoft Purview Audit and eDiscovery.

4 modules · 42 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

01

Module 1

Investigate and respond to Microsoft Purview Data Loss Prevention alerts

Focus: DLP alert generation, lifecycle, Purview and Defender investigations, remediation, ownership, and policy tuning.
0/11
01 / 11Introduction

DLP alerts can become noise without consistent triage. A reliable process confirms what triggered the alert, reviews user and content context, correlates related security evidence, records decisions, responds proportionately, and feeds false-positive findings back into policy design.

Official lessonDLP investigation objectives
02 / 11Understand data loss prevention (DLP) alerts

An alert is generated when activity matches a DLP rule condition, either in one event or through aggregated events. It signals policy criteria, not confirmed malicious intent.

PortalBest use
Microsoft PurviewPolicy, rule, matched content, event, and compliance context; policy tuning.
Microsoft Defender XDRCorrelate DLP with endpoint, identity, cloud app, email, and incident evidence.
Official lessonAlert meaning and portal roles
03 / 11Understand the DLP alert lifecycle
TriggerActivity matches policy logic.
TriageValidate severity, user, content, and event.
InvestigateCorrelate activities and incidents.
ResolveRemediate, document, close, and tune.

Assign ownership early, preserve evidence, update status as work progresses, and use consistent dispositions so queue metrics remain meaningful.

Official lessonAlert handling lifecycle
04 / 11Configure DLP policies to generate alerts

Alert behavior is controlled by rule conditions, locations, users or groups, sensitive information thresholds, action severity, and aggregation settings. Choose alerting that reflects risk and operational capacity rather than alerting on every match.

Use test mode, incident reports, policy tips, overrides, and scoped exceptions to validate behavior before broad enforcement.

Official lessonAlert-generation controls
05 / 11Investigate DLP alerts in Microsoft Purview

Review the alert summary, policy and rule, severity, status, owner, matched events, user, location, sensitive information types, content metadata, and related activity. Activity explorer helps place the event in a broader pattern.

Determine whether the match is legitimate business use, accidental exposure, policy misclassification, or potentially malicious behavior before acting.

Official lessonPurview alert investigation
06 / 11Investigate DLP alerts in Microsoft Defender XDR

Open the DLP alert or related incident in Defender XDR to correlate it with alerts, devices, identities, cloud applications, files, and timelines. Use the incident graph, evidence, entities, advanced hunting, and action center to determine whether data activity is part of a broader attack.

Official lessonCross-domain XDR investigation
07 / 11Investigate DLP alerts with Security Copilot and AI agents

Security Copilot can summarize alerts, interpret matched activity, highlight related evidence, and suggest investigation steps. AI agents can assist with repeated triage tasks.

Analyst responsibility: validate generated conclusions against source evidence, preserve least privilege and data boundaries, and retain human approval for consequential response.
Official lessonAI-assisted DLP triage
08 / 11Respond to DLP alerts

Response may include contacting the user or manager, removing access, deleting or quarantining content, containing a device, escalating to insider risk or legal teams, updating incident status, and documenting evidence and rationale.

If a benign pattern repeatedly triggers, adjust policy scope, thresholds, classifiers, exceptions, or alert aggregation—without weakening protection for the real risk scenario.

Official lessonRemediation and policy feedback
09 / 11Exercise - Investigate a DLP alert and related incident

Use Purview to review the DLP rule, matched event, sensitive data, and user context; then pivot to Defender XDR to inspect the incident and related evidence. Assign ownership, record findings, choose response, and close with a defensible disposition.

Official exercisePurview-to-Defender investigation
10 / 11Module assessment

Review alert generation and aggregation, lifecycle states, Purview versus Defender XDR roles, matched-event evidence, Copilot validation, response options, ownership, closure, and policy tuning.

Official assessmentDLP alert knowledge check
11 / 11Summary

Strong DLP operations combine policy context in Purview, cross-domain correlation in Defender XDR, proportionate response, complete documentation, and continuous tuning.

Official lessonModule summary
End of learning pathMitigate threats using Microsoft Purview