certslothcertsloth
SC-200/Topic 03

Microsoft / Associate

Detection Engineering, Tuning and Automation

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: A query finds evidence; a detection makes it actionable.

Must remember

Start with a threat hypothesis and required telemetry. Scheduled Sentinel analytics rules run a query on a configured cadence/lookback; near-real-time rules have their own supported constraints. Thresholds, entity mapping, grouping and suppression decide how query results become alerts and incidents. A rule that runs successfully can still miss events arriving outside its effective window.

Defender custom detections use supported advanced-hunting tables and required identifying fields. Preserve the identifiers and timestamps needed to create useful alerts or response actions. Map detections to MITRE ATT&CK techniques to expose coverage gaps; a colored matrix is not evidence that each technique is reliably detected.

Tune with labeled examples. Narrow exclusions to known expected behavior, measure false positives and keep a way to detect abuse of the exception. Threat-intelligence matches and anomaly/ML signals need context and validation. Suppressing a noisy alert globally can hide a real attack using the same pattern.

Sentinel automation rules react to supported incident/alert conditions and can update fields, assign work or invoke playbooks. Playbooks run Logic Apps workflows and need authorized identities for their connectors/actions. Distinguish a rule's trigger from the playbook's trigger and test error/retry paths. A repeated event should not repeatedly disable a legitimate account without control.

Automated investigation and response and automatic attack disruption can contain activity across supported Defender signals. Configure prerequisites, scope and approval/automation levels deliberately. Keep evidence, record actions and verify recovery. Automation speed is useful only when the detection, permissions and rollback are trustworthy.

Choose under exam pressure

Requirement Choice and reason
Recurring query becomes an incident Analytics rule with entities, thresholds and grouping.
Route and enrich a new incident Automation rule and an appropriately triggered playbook.
Evaluate detection coverage Map validated detections to ATT&CK and inspect telemetry gaps.

Traps

  • Rule success is not proof of detection effectiveness.
  • A broad suppression can remove evidence of real abuse.

Active recall

1. Why overlap a lookback appropriately?

To tolerate ingestion delay while controlling duplicate alerts.

2. Why map entities?

To connect evidence to accounts, hosts, addresses and investigation context.

3. Automation rule versus playbook?

Incident/alert handling logic versus the workflow that performs integrated actions.

4. Why make response idempotent?

Retries and repeated events should not cause uncontrolled duplicate effects.

5. What validates an ATT&CK coverage claim?

Representative evidence and successful detection tests, not merely a tag.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.