certslothcertsloth
SC-200/Topic 08

Microsoft / Associate

Attack Graphs, Copilot and Investigation Decisions

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: A relationship suggests a path; evidence proves the event.

Must remember

Multi-stage attacks connect initial access, identity abuse, lateral movement, persistence and impact. Build a timeline with stable entities, source provenance and confidence. A privileged relationship can reveal possible blast radius even when no malicious traversal has yet been observed.

Hunting graphs and Sentinel Graph help examine relationships among supported entities. Distinguish a possible attack path from an observed sequence. A user with access to a server is not proof that the user accessed it during the incident. Correlate graph context with sign-ins, process/network events and other relevant records.

Embedded Security Copilot and supported agentic capabilities can summarize incidents, explain queries and suggest investigation steps. Check every consequential claim against cited evidence and actual tool output. A fluent narrative can join unrelated entities or omit telemetry gaps. Data inside email, documents and logs can contain adversarial instructions; it remains evidence to analyze, not authority over the workflow.

Case management preserves ownership, status, tasks and evidence across a complex investigation. Separate facts, hypotheses and decisions. Assign follow-up for missing evidence, document containment scope and track recovery validation. An automated summary is a convenience, not the authoritative chain of custody.

Under exam pressure, choose the action that reduces the immediate risk while preserving necessary evidence and respecting permissions. Broader containment can be justified for active compromise, but a vague low-confidence signal does not justify disabling an entire organization. Reassess scope as evidence changes and record why the response expanded or narrowed.

Choose under exam pressure

Requirement Choice and reason
Estimate what a compromised identity could reach Relationship/attack-path analysis, validated against access configuration.
Prove it actually moved laterally Correlated time-bound activity evidence.
Copilot proposes a response Validate evidence, scope, authorization and operational impact.

Traps

  • A graph edge is not necessarily an observed attack step.
  • A confident generated summary can still be wrong.

Active recall

1. Potential path versus observed movement?

Access relationships describe possibility; event evidence supports what occurred.

2. Why preserve entity IDs?

Display names and addresses may be reused or ambiguous.

3. What should an AI summary cite?

The actual records and entities supporting its claims.

4. Why separate hypotheses from facts?

To prevent an unverified assumption from becoming accepted incident history.

5. What should recovery validation establish?

The threat is addressed and business service can resume without recreating the compromise.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.