certslothcertsloth
SC-200/Topic 01

Microsoft / Associate

SOC Platform, Roles and Retention

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Collect with a purpose; keep it where the investigation can use it.

Must remember

Microsoft Defender XDR correlates signals across supported endpoint, identity, email and application products. Microsoft Sentinel adds SIEM/SOAR capabilities across Microsoft and third-party sources. A unified portal experience does not erase underlying connector, workspace, licensing or role requirements.

Separate reading, investigating, configuration and automation permissions. Sentinel Reader inspects; Responder handles incidents; Contributor configures Sentinel resources within its scope. Playbook execution also needs the relevant Logic Apps/identity permissions. A user who can see an incident may still lack authority to isolate a device or run a playbook.

Choose table tier and retention by detection latency, investigation frequency, query capability and cost. Analytics, data-lake and XDR data surfaces are not interchangeable hot stores. Verify which rule/query types can use a tier before moving required detection data. Retention governs how long evidence remains; collection gaps cannot be repaired by increasing retention afterward.

Workbooks visualize query results and operational metrics. Track connector health, ingestion delay, rule failures, incident backlog and response time. SOC optimization recommendations can reveal coverage/cost opportunities, but validate their relevance before changing collection or detections. A quiet dashboard can indicate a broken pipeline rather than a quiet attacker.

Set notifications for the right audience and urgency. Incident, automated-action and threat-analytics notifications answer different questions. Record ownership, escalation and retention decisions so an on-call analyst can act without broadening permissions during an incident.

Choose under exam pressure

Requirement Choice and reason
Analyst must manage incidents without editing every rule Scoped responder permissions.
Long history needed for occasional hunting Evaluate data-lake retention/query trade-offs.
Show ingestion delays and incident trends A workbook over reliable operational data.

Traps

  • Portal consolidation does not grant all response permissions.
  • No alerts is not proof of no malicious activity.

Active recall

1. Sentinel versus Defender XDR?

Cross-source SIEM/SOAR versus correlated detection/response across supported Defender signals, with integrated experiences.

2. Why separate response from configuration roles?

To let analysts act while limiting accidental or malicious rule/platform changes.

3. Why choose table tier carefully?

Query, detection, retention and cost characteristics differ.

4. What can a workbook reveal?

Trends and operational evidence, including unhealthy collection.

5. Why monitor connector health?

Missing telemetry can make detection appear falsely clean.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.