Memory hook: Collect the right evidence, correlate it, then authorise every response action.
Must remember
- Sentinel uses supported workspaces, data connectors, analytics content and incident workflows. Assign appropriate Sentinel/workspace roles. Content Hub solutions supply supported connectors/rules/workbooks; installing content is not the same as configuring data collection.
- Syslog/CEF, Windows Security events and WEF require the correct collection pipeline, agent/forwarder and data collection rules. Custom logs need appropriate tables/schema and ingestion configuration. Verify arrival, parsing, timestamps and retention before relying on detections.
- Analytics rules correlate events into alerts/incidents under their configuration. Automation rules coordinate incident handling; playbooks use Logic Apps for response. Scope managed identities and target permissions, add approvals where needed and make actions idempotent.
- Define retention for relevant data stores based on investigation and cost needs. A missing event may reflect connector permissions, DCR configuration, network, parser or retention failure. Query Purview Audit through supported Defender XDR capabilities for the relevant audit scenario.
- Security Copilot workspaces, roles, plugins and supported agents control who can use which capabilities. Enable only needed plugins and review their data/action access. Microsoft and Security Store agents need the same ownership, evaluation and permission discipline as other automation.
- Treat generated investigation summaries as assistance that requires evidence validation. Preserve source links, analyst decisions and response audit. A confidently worded recommendation is not authorisation to isolate a business-critical service without the defined response process.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| No Windows events appear in Sentinel | Inspect collection rules, forwarding/agent, connector and workspace arrival. |
| Repeated incident needs a standard response | Automation rule plus a scoped, tested playbook. |
| Copilot must use one external capability | Enable the specific plugin with reviewed permissions. |
Traps
- Content installation does not prove telemetry is flowing.
- A playbook can have broader permissions than its trigger author.
- AI-generated incident analysis can contain unsupported conclusions.
Active recall
1. What distinguishes an automation rule from a playbook?
The rule controls incident automation logic; the playbook executes a workflow of actions.
2. Why check timestamps and parsing?
Bad normalisation can break correlation or make events appear outside the queried window.
3. What should a response workflow preserve?
Evidence, action identity, inputs/results, approvals and a recovery path.
4. Why scope Copilot plugins?
They extend accessible data/tools and therefore the potential exposure or action surface.
5. How should a generated incident conclusion be validated?
Against the underlying telemetry and established investigation/response procedure.