Free knowledge base

Microsoft Security Operations Analyst — key terms, tricks & tips

Everything from the course in one searchable place: 546 entries. Use it to review before a practice test or look up a word you forgot.

546 results · showing first 300, refine your search

Key term

Scaled Score

A score adjusted for question difficulty, not a raw percentage.

Getting Started: Understanding the SC-200 Exam

Key term

Case Study

An exam question type presenting a scenario with multiple related questions.

Getting Started: Understanding the SC-200 Exam

Key term

Lab Question

Interactive exam questions requiring tasks in a simulated environment.

Getting Started: Understanding the SC-200 Exam

Key term

Certification Path

The sequence of exams or certifications leading to a specific credential.

Getting Started: Understanding the SC-200 Exam

Key term

Renewal Assessment

A free online assessment to extend certification validity annually.

Getting Started: Understanding the SC-200 Exam

Key term

Microsoft Learn

Microsoft's official platform for free online learning and documentation.

Getting Started: Understanding the SC-200 Exam

Memory trick

SC-200 Exam Structure, Scoring, and Certification Path

To remember the passing score: 'Seven Hundred' for 'SC-200' – both start with 'S' sounds and have a clear, round number.

Getting Started: Understanding the SC-200 Exam

Exam tip

SC-200 Exam Structure, Scoring, and Certification Path

The SC-200 exam requires a passing score of 700 out of 1000. Certifications are valid for one year and renewed via a free online assessment. Memorize these exact numbers and rules.

Getting Started: Understanding the SC-200 Exam

Common mistake

SC-200 Exam Structure, Scoring, and Certification Path

Mistaking the scaled score for a simple percentage, leading to misjudgment of preparation needs.

Getting Started: Understanding the SC-200 Exam

Common mistake

SC-200 Exam Structure, Scoring, and Certification Path

Neglecting hands-on lab practice, which is critical for performance-based questions.

Getting Started: Understanding the SC-200 Exam

Common mistake

SC-200 Exam Structure, Scoring, and Certification Path

Forgetting to renew the certification annually, causing it to expire and requiring re-taking the full exam.

Getting Started: Understanding the SC-200 Exam

Key term

SecOps

Security Operations: practices for protecting info systems.

Getting Started: Understanding the SC-200 Exam

Key term

SIEM

Security Information and Event Management: centralizes security data.

Getting Started: Understanding the SC-200 Exam

Key term

SOAR

Security Orchestration, Automation, and Response: automates incident handling.

Getting Started: Understanding the SC-200 Exam

Key term

XDR

Extended Detection and Response: unified security across multiple domains.

Getting Started: Understanding the SC-200 Exam

Key term

Threat Intelligence

Information about current and emerging cyber threats.

Getting Started: Understanding the SC-200 Exam

Key term

Incident Response

Process of handling security breaches from detection to recovery.

Getting Started: Understanding the SC-200 Exam

Key term

Vulnerability Management

Identifying, assessing, and remediating security weaknesses.

Getting Started: Understanding the SC-200 Exam

Memory trick

Key Concepts of Security Operations and Microsoft Security

CIA: Confidentiality, Integrity, Availability – the three pillars of information security. Think of a 'CIA agent' protecting secrets (confidentiality), ensuring truth (integrity), and always being there when needed (availability).

Getting Started: Understanding the SC-200 Exam

Exam tip

Key Concepts of Security Operations and Microsoft Security

The SC-200 exam frequently tests your understanding of the core functions of SecOps and how specific Microsoft security products (like Sentinel, Defender, and Azure AD) map to these functions. Memorize the purpose of SIEM, SOAR, and XDR.

Getting Started: Understanding the SC-200 Exam

Common mistake

Key Concepts of Security Operations and Microsoft Security

Confusing SecOps with DevOps; while they collaborate, SecOps focuses purely on security.

Getting Started: Understanding the SC-200 Exam

Common mistake

Key Concepts of Security Operations and Microsoft Security

Believing security is a one-time setup; it's a continuous, evolving process.

Getting Started: Understanding the SC-200 Exam

Common mistake

Key Concepts of Security Operations and Microsoft Security

Underestimating the importance of human factors, like security awareness training, in overall security posture.

Getting Started: Understanding the SC-200 Exam

Key term

Defender XDR

Unified pre- and post-breach enterprise defense suite.

Microsoft Defender XDR Core Management

Key term

Defender for Endpoint

Security solution for devices and servers.

Microsoft Defender XDR Core Management

Key term

Defender for Identity

Protects user identities and hybrid environments.

Microsoft Defender XDR Core Management

Key term

Defender for Office 365

Secures email, documents, and collaboration tools.

Microsoft Defender XDR Core Management

Key term

Defender for Cloud Apps

Cloud Access Security Broker (CASB) for cloud apps.

Microsoft Defender XDR Core Management

Key term

Advanced Hunting

Proactive threat searching using Kusto Query Language.

Microsoft Defender XDR Core Management

Key term

Kusto Query Language (KQL)

Powerful query language for data exploration.

Microsoft Defender XDR Core Management

Memory trick

Overview of Microsoft Defender XDR capabilities

Remember 'E.I.O.C.' for the core Defender components: Endpoint, Identity, Office 365, Cloud Apps. It's like a farm of security!

Microsoft Defender XDR Core Management

Exam tip

Overview of Microsoft Defender XDR capabilities

The SC-200 exam frequently tests your understanding of which specific Defender component addresses which security domain (e.g., 'Endpoint' for devices, 'Identity' for users, 'Office 365' for email, 'Cloud Apps' for SaaS). Memorize these associations.

Microsoft Defender XDR Core Management

Common mistake

Overview of Microsoft Defender XDR capabilities

Confusing Defender XDR with individual Defender products; XDR is the unified suite.

Microsoft Defender XDR Core Management

Common mistake

Overview of Microsoft Defender XDR capabilities

Underestimating the importance of advanced hunting for proactive threat detection.

Microsoft Defender XDR Core Management

Common mistake

Overview of Microsoft Defender XDR capabilities

Failing to recognize that Defender XDR automatically correlates alerts into incidents, simplifying investigations.

Microsoft Defender XDR Core Management

Key term

Attack Surface Reduction (ASR)

Rules that prevent common attack vectors by blocking suspicious behaviors.

Microsoft Defender XDR Core Management

Key term

Endpoint Detection and Response (EDR)

Capabilities for monitoring, detecting, and responding to endpoint threats.

Microsoft Defender XDR Core Management

Key term

Safe Attachments

A Defender for Office 365 feature that sandboxes email attachments.

Microsoft Defender XDR Core Management

Key term

Safe Links

A Defender for Office 365 feature that rewrites and scans URLs in emails.

Microsoft Defender XDR Core Management

Key term

Spoof Intelligence

A Defender for Office 365 feature to identify and block spoofed senders.

Microsoft Defender XDR Core Management

Key term

Device Isolation

A Defender for Endpoint action to disconnect a compromised device.

Microsoft Defender XDR Core Management

Key term

Role-Based Access Control (RBAC)

A method of restricting system access based on user roles.

Microsoft Defender XDR Core Management

Memory trick

Configuring and Managing Defender XDR Settings

To remember the key Defender XDR components for settings, think 'E.I.O.': Endpoints, Identity, Office 365. Each letter points to a major area of configuration!

Microsoft Defender XDR Core Management

Exam tip

Configuring and Managing Defender XDR Settings

For the SC-200 exam, memorize the primary Defender XDR component associated with each major setting category: Endpoints for device security, Identity for user accounts, and Office 365 for email/collaboration. Keywords like 'Attack surface reduction' or 'Safe Links' should immediately map to their respective Defender services.

Microsoft Defender XDR Core Management

Common mistake

Configuring and Managing Defender XDR Settings

Overlooking the impact of settings on user experience, leading to excessive false positives or blocked legitimate actions.

Microsoft Defender XDR Core Management

Common mistake

Configuring and Managing Defender XDR Settings

Failing to regularly review and update security settings, leaving the organization vulnerable to new threats.

Microsoft Defender XDR Core Management

Common mistake

Configuring and Managing Defender XDR Settings

Granting overly broad administrative permissions, violating the principle of least privilege and increasing risk.

Microsoft Defender XDR Core Management

Key term

Incident

A correlated collection of related alerts that form a potential attack.

Microsoft Defender XDR Core Management

Key term

Alert

A detection of a suspicious or malicious activity by a Defender XDR component.

Microsoft Defender XDR Core Management

Key term

Incident graph

A visual representation of the attack chain, showing connected entities.

Microsoft Defender XDR Core Management

Key term

Response actions

Predefined actions taken on entities to contain or remediate threats.

Microsoft Defender XDR Core Management

Key term

Entity

Any asset involved in an incident, such as a device, user, or mailbox.

Microsoft Defender XDR Core Management

Key term

Severity

A rating indicating the potential impact and urgency of an incident.

Microsoft Defender XDR Core Management

Key term

Incident queue

The list of active and resolved incidents in the Defender XDR portal.

Microsoft Defender XDR Core Management

Memory trick

Using the Defender XDR portal for incident response

To remember the incident response steps: D-C-P-I-R-R (Detect, Correlate, Prioritize, Investigate, Respond, Resolve). It's like 'Doctor's CPR' for your security!

Microsoft Defender XDR Core Management

Exam tip

Using the Defender XDR portal for incident response

The exam frequently tests your ability to differentiate between an 'alert' and an 'incident' and to identify the appropriate response actions for various scenarios (e.g., isolating a device, blocking a file). Be familiar with the incident lifecycle states.

Microsoft Defender XDR Core Management

Common mistake

Using the Defender XDR portal for incident response

Failing to prioritize incidents, leading to critical threats being overlooked.

Microsoft Defender XDR Core Management

Common mistake

Using the Defender XDR portal for incident response

Not fully investigating all associated alerts and entities before resolving an incident.

Microsoft Defender XDR Core Management

Common mistake

Using the Defender XDR portal for incident response

Taking response actions without understanding their full impact on business operations.

Microsoft Defender XDR Core Management

Key term

Custom Detection Rule

Automated alert generated from an advanced hunting query.

Microsoft Defender XDR Core Management

Key term

Indicator of Compromise (IOC)

Evidence of a security breach or attack.

Microsoft Defender XDR Core Management

Key term

DeviceProcessEvents

KQL table containing process creation and termination events.

Microsoft Defender XDR Core Management

Key term

Pipe Operator (|)

Used in KQL to chain multiple operators together.

Microsoft Defender XDR Core Management

Memory trick

Advanced Hunting and Custom Detection Rules

KQL: 'K'eep 'Q'uerying 'L'og data to find the bad guys!

Microsoft Defender XDR Core Management

Exam tip

Advanced Hunting and Custom Detection Rules

The exam often tests your understanding of KQL operators. Memorize common ones like 'where', 'project', 'summarize', and 'join', and know their basic function. Pay attention to scenarios where you'd use advanced hunting versus built-in alerts.

Microsoft Defender XDR Core Management

Common mistake

Advanced Hunting and Custom Detection Rules

Not validating advanced hunting queries before creating custom detection rules, leading to false positives.

Microsoft Defender XDR Core Management

Common mistake

Advanced Hunting and Custom Detection Rules

Overlooking the performance impact of complex KQL queries, which can slow down hunting or rule execution.

Microsoft Defender XDR Core Management

Common mistake

Advanced Hunting and Custom Detection Rules

Failing to regularly review and refine custom detection rules, resulting in outdated or noisy alerts.

Microsoft Defender XDR Core Management

Key term

Onboarding

Connecting an endpoint to Defender for Endpoint service.

Endpoint Protection with Defender for Endpoint

Key term

Telemetry

Security data reported by the endpoint agent.

Endpoint Protection with Defender for Endpoint

Key term

Microsoft Intune

Cloud-based MDM for managing devices and apps.

Endpoint Protection with Defender for Endpoint

Key term

Group Policy (GPO)

Windows infrastructure for managing user/computer settings.

Endpoint Protection with Defender for Endpoint

Key term

MECM

Microsoft Endpoint Configuration Manager for large-scale deployments.

Endpoint Protection with Defender for Endpoint

Key term

Device Inventory

List of all onboarded devices in the Defender portal.

Endpoint Protection with Defender for Endpoint

Key term

Detection Test

Simulated threat to verify sensor functionality.

Endpoint Protection with Defender for Endpoint

Memory trick

Onboarding Devices to Defender for Endpoint

To ONBOARD, remember 'O-N-B-O-A-R-D': O-perating systems, N-etwork, B-asic agent, O-rganizational tools, A-utomate, R-eview, D-etect.

Endpoint Protection with Defender for Endpoint

Exam tip

Onboarding Devices to Defender for Endpoint

Memorize the common onboarding methods for Windows (GPO, Intune, MECM, local script) and understand that Intune is primary for mobile devices. The exam often asks about the 'how' for different OS types.

Endpoint Protection with Defender for Endpoint

Common mistake

Onboarding Devices to Defender for Endpoint

Forgetting to check network connectivity or proxy settings, leading to devices failing to report.

Endpoint Protection with Defender for Endpoint

Common mistake

Onboarding Devices to Defender for Endpoint

Not verifying the onboarding status in the Defender portal after deployment, assuming success.

Endpoint Protection with Defender for Endpoint

Common mistake

Onboarding Devices to Defender for Endpoint

Using an outdated onboarding package or script, which can cause compatibility issues.

Endpoint Protection with Defender for Endpoint

Key term

Audit Mode

ASR rule setting that logs events without blocking.

Endpoint Protection with Defender for Endpoint

Key term

Block Mode

ASR rule setting that actively prevents malicious actions.

Endpoint Protection with Defender for Endpoint

Key term

Security Settings Management

Centralized configuration of security policies.

Endpoint Protection with Defender for Endpoint

Key term

False Positive

Legitimate activity incorrectly identified as malicious.

Endpoint Protection with Defender for Endpoint

Key term

Defense-in-Depth

Layered security approach.

Endpoint Protection with Defender for Endpoint

Memory trick

Managing Security Settings and Attack Surface Reduction

ASR: Always Secure Rules. Remember to Audit before you Set to Block!

Endpoint Protection with Defender for Endpoint

Exam tip

Managing Security Settings and Attack Surface Reduction

Memorize specific examples of ASR rules and their purpose. The exam often asks about which rule would prevent a certain type of attack, or how to implement ASR rules in a phased approach (audit then block).

Endpoint Protection with Defender for Endpoint

Common mistake

Managing Security Settings and Attack Surface Reduction

Deploying ASR rules directly in 'Block' mode without prior testing, leading to legitimate applications being blocked and user frustration.

Endpoint Protection with Defender for Endpoint

Common mistake

Managing Security Settings and Attack Surface Reduction

Not regularly monitoring ASR rule alerts and reports, missing opportunities to fine-tune rules or identify new threats.

Endpoint Protection with Defender for Endpoint

Common mistake

Managing Security Settings and Attack Surface Reduction

Overlooking the integration of security settings management with other tools like Intune, resulting in inconsistent policies or inefficient deployment.

Endpoint Protection with Defender for Endpoint

Key term

Automated Investigation

Automated processes to examine alerts, gather evidence, and resolve threats.

Endpoint Protection with Defender for Endpoint

Key term

Device Timeline

A chronological view of all events and activities on a specific device.

Endpoint Protection with Defender for Endpoint

Key term

Isolate Device

A response action to disconnect a compromised device from the network.

Endpoint Protection with Defender for Endpoint

Key term

Containment

Actions taken to stop the spread of a security incident.

Endpoint Protection with Defender for Endpoint

Key term

Eradication

The process of removing the threat from affected systems.

Endpoint Protection with Defender for Endpoint

Memory trick

Investigating Alerts and Responding to Incidents

To remember the incident response stages: 'DICE-R-P': Detection, Investigation, Containment, Eradication, Recovery, Post-incident Review.

Endpoint Protection with Defender for Endpoint

Exam tip

Investigating Alerts and Responding to Incidents

The exam frequently tests your understanding of the incident response lifecycle stages and the specific response actions available in Defender for Endpoint, such as 'isolate device' or 'stop and quarantine file.' Be prepared to identify the correct action for a given scenario.

Endpoint Protection with Defender for Endpoint

Common mistake

Investigating Alerts and Responding to Incidents

Failing to prioritize incidents based on severity, leading to critical threats being overlooked.

Endpoint Protection with Defender for Endpoint

Common mistake

Investigating Alerts and Responding to Incidents

Jumping directly to remediation without fully investigating the scope of an incident, potentially leaving parts of the threat active.

Endpoint Protection with Defender for Endpoint

Common mistake

Investigating Alerts and Responding to Incidents

Not documenting investigation steps and response actions, hindering collaboration and post-incident review.

Endpoint Protection with Defender for Endpoint

Key term

Exposure Score

Dynamic metric reflecting an organization's security posture and risk.

Endpoint Protection with Defender for Endpoint

Key term

Security Recommendations

Actionable steps to remediate identified vulnerabilities and misconfigurations.

Endpoint Protection with Defender for Endpoint

Key term

Threat Analytics

Reports from Microsoft on emerging threats, impact, and mitigation.

Endpoint Protection with Defender for Endpoint

Key term

Software Inventory

Comprehensive list of installed applications on managed devices.

Endpoint Protection with Defender for Endpoint

Key term

Weaknesses

Specific identified vulnerabilities in software or system configurations.

Endpoint Protection with Defender for Endpoint

Key term

Remediation

The process of fixing or mitigating identified security vulnerabilities.

Endpoint Protection with Defender for Endpoint

Memory trick

Vulnerability Management and Threat Analytics

VMT: Vulnerabilities, Mitigation, Threats. Remember these three pillars for endpoint protection!

Endpoint Protection with Defender for Endpoint

Exam tip

Vulnerability Management and Threat Analytics

For the SC-200 exam, be prepared to describe the purpose of Defender Vulnerability Management and Threat Analytics. Know that the Exposure Score is a key metric for prioritization and that Security Recommendations provide actionable steps. Understand the difference between identifying a vulnerability and remediating it.

Endpoint Protection with Defender for Endpoint

Common mistake

Vulnerability Management and Threat Analytics

Ignoring the Exposure Score and prioritizing low-impact vulnerabilities.

Endpoint Protection with Defender for Endpoint

Common mistake

Vulnerability Management and Threat Analytics

Failing to regularly review Threat Analytics reports for new threats.

Endpoint Protection with Defender for Endpoint

Common mistake

Vulnerability Management and Threat Analytics

Not integrating remediation efforts with existing IT management tools like Intune.

Endpoint Protection with Defender for Endpoint

Key term

Anti-Malware Policy

Configuration to detect and block malicious software in email.

Securing Email and Collaboration with Defender for O365

Key term

Anti-Spam Policy

Configuration to filter and manage unsolicited bulk email.

Securing Email and Collaboration with Defender for O365

Key term

Anti-Phishing Policy

Configuration to detect and prevent social engineering attacks.

Securing Email and Collaboration with Defender for O365

Key term

Zero-hour Auto Purge (ZAP)

Automatically removes malicious email after delivery.

Securing Email and Collaboration with Defender for O365

Key term

Impersonation Protection

Detects emails that mimic trusted senders or domains.

Securing Email and Collaboration with Defender for O365

Key term

Spam Confidence Level (SCL)

Numerical rating indicating likelihood of an email being spam.

Securing Email and Collaboration with Defender for O365

Key term

Policy Priority

Determines the order in which policies are applied.

Securing Email and Collaboration with Defender for O365

Memory trick

Configuring anti-phishing, anti-spam, anti-malware

MAP: Malware for Attachments, Anti-spam for Phishing, Phishing for Impersonation. (Wait, that's not right!) Think: 'Malware stops Attachments, Spam stops Junk, Phishing stops Impersonation.'

Securing Email and Collaboration with Defender for O365

Exam tip

Configuring anti-phishing, anti-spam, anti-malware

The exam often tests your understanding of which policy type addresses specific threats. Memorize that anti-malware handles attachments, anti-spam handles junk mail, and anti-phishing handles impersonation and credential theft. Also, know that a lower priority number means higher priority.

Securing Email and Collaboration with Defender for O365

Common mistake

Configuring anti-phishing, anti-spam, anti-malware

Forgetting to test policy changes, which can lead to legitimate emails being blocked.

Securing Email and Collaboration with Defender for O365

Common mistake

Configuring anti-phishing, anti-spam, anti-malware

Not setting appropriate policy priorities, causing less stringent policies to override more critical ones.

Securing Email and Collaboration with Defender for O365

Common mistake

Configuring anti-phishing, anti-spam, anti-malware

Over-relying on default policies without customizing them for specific organizational needs and risks.

Securing Email and Collaboration with Defender for O365

Key term

Zero-day threat

A vulnerability or exploit unknown to security vendors.

Securing Email and Collaboration with Defender for O365

Key term

Sandboxing

Executing code in an isolated environment to observe its behavior.

Securing Email and Collaboration with Defender for O365

Key term

Dynamic Delivery

Safe Attachments option to deliver email body while attachment scans.

Securing Email and Collaboration with Defender for O365

Key term

URL rewriting

Safe Links process of changing original URLs to MDO-controlled ones.

Securing Email and Collaboration with Defender for O365

Key term

Threat policies

Category in M365 Defender portal for configuring protection features.

Securing Email and Collaboration with Defender for O365

Key term

Quarantine

A secure location where suspicious items are held for review.

Securing Email and Collaboration with Defender for O365

Memory trick

Managing Safe Attachments and Safe Links in MDO

Imagine a 'SAFE' (Safe Attachments For Email) detective who 'LINKS' (Safe Links) up with a 'SANDBOX' (sandboxing) to catch 'ZERO' (zero-day) bad guys before they click!

Securing Email and Collaboration with Defender for O365

Exam tip

Managing Safe Attachments and Safe Links in MDO

For the exam, remember that Safe Attachments protects against zero-day malware in attachments by using sandboxing, and Safe Links protects against malicious URLs by rewriting and scanning them at the time of click. Keywords to spot include 'zero-day,' 'sandboxing,' 'time of click,' and 'URL rewriting.'

Securing Email and Collaboration with Defender for O365

Common mistake

Managing Safe Attachments and Safe Links in MDO

Forgetting to apply policies to the correct users or groups, leaving some unprotected.

Securing Email and Collaboration with Defender for O365

Common mistake

Managing Safe Attachments and Safe Links in MDO

Overly broad 'Do not rewrite' URL lists in Safe Links, which can create security blind spots.

Securing Email and Collaboration with Defender for O365

Common mistake

Managing Safe Attachments and Safe Links in MDO

Not periodically reviewing quarantined items, potentially missing legitimate emails or false positives.

Securing Email and Collaboration with Defender for O365

Key term

Threat Explorer

Real-time tool in Defender for O365 for investigating email threats.

Securing Email and Collaboration with Defender for O365

Key term

Delivery Action

How an email was handled (e.g., delivered, quarantined, blocked).

Securing Email and Collaboration with Defender for O365

Key term

Email Headers

Metadata containing routing info, sender, recipient, and subject.

Securing Email and Collaboration with Defender for O365

Key term

Soft Delete

Removes an email from a user's inbox, but it may be recoverable.

Securing Email and Collaboration with Defender for O365

Memory trick

Investigating Threats with Explorer and Incident Response

To 'EXPLORE' threats, you need to FILTER, ANALYZE, and REMEDIATE. F-A-R, like a far-reaching investigation!

Securing Email and Collaboration with Defender for O365

Exam tip

Investigating Threats with Explorer and Incident Response

The exam often tests your ability to differentiate between Explorer and other reporting tools. Remember that Explorer is for *investigation and remediation* of specific threats, while reports provide *aggregate data* and trends. Keywords like 'investigate,' 'trace,' 'remediate,' or 'identify specific emails' point to Explorer.

Securing Email and Collaboration with Defender for O365

Common mistake

Investigating Threats with Explorer and Incident Response

Overlooking the time range filter, which can lead to sifting through irrelevant data.

Securing Email and Collaboration with Defender for O365

Common mistake

Investigating Threats with Explorer and Incident Response

Not utilizing all available filters (sender, recipient, subject, threat type) to quickly narrow down results.

Securing Email and Collaboration with Defender for O365

Common mistake

Investigating Threats with Explorer and Incident Response

Failing to document remediation actions, making it difficult to track incident progress or conduct post-incident reviews.

Securing Email and Collaboration with Defender for O365

Key term

Quarantine Policy

Rules defining user access and notifications for quarantined items.

Securing Email and Collaboration with Defender for O365

Key term

Release Message

Action to deliver a quarantined item to its original recipient.

Securing Email and Collaboration with Defender for O365

Key term

High-Confidence Spam

Spam detected with a very high probability of being unsolicited junk mail.

Securing Email and Collaboration with Defender for O365

Key term

End-User Quarantine Notification

Email informing users about items in their quarantine.

Securing Email and Collaboration with Defender for O365

Key term

Microsoft 365 Defender Portal

Centralized portal for managing security in Microsoft 365 services.

Securing Email and Collaboration with Defender for O365

Memory trick

Reviewing and Managing Quarantined Items

Remember 'QR Code' for Quarantine Review: Q for Quarantine, R for Review, Code for Confirm/Delete/Execute (release).

Securing Email and Collaboration with Defender for O365

Exam tip

Reviewing and Managing Quarantined Items

The exam often tests the specific navigation path to the Quarantine in the Microsoft 365 Defender portal (Email & collaboration > Review > Quarantine) and the difference between 'Release message' and 'Release message and report as false positive.'

Securing Email and Collaboration with Defender for O365

Common mistake

Reviewing and Managing Quarantined Items

Releasing a quarantined item without thoroughly reviewing the quarantine reason and sender/recipient details.

Securing Email and Collaboration with Defender for O365

Common mistake

Reviewing and Managing Quarantined Items

Not configuring end-user quarantine notifications, leading to users contacting the help desk for every blocked email.

Securing Email and Collaboration with Defender for O365

Common mistake

Reviewing and Managing Quarantined Items

Failing to report false positives, which hinders the improvement of detection capabilities for the organization.

Securing Email and Collaboration with Defender for O365

Key term

Defender for Identity (MDI)

Cloud-based security solution for protecting Active Directory identities.

Identity Protection with Defender for Identity

Key term

MDI Sensor

Lightweight agent deployed on DCs or servers to capture AD traffic.

Identity Protection with Defender for Identity

Key term

Domain Controller (DC)

Server that responds to security authentication requests in a Windows domain.

Identity Protection with Defender for Identity

Key term

Access Key

Unique key from MDI portal used to register sensors with the cloud service.

Identity Protection with Defender for Identity

Key term

Lateral Movement

Technique used by attackers to gain access to other systems on a network.

Identity Protection with Defender for Identity

Key term

Defender Portal

Centralized web console for managing Microsoft Defender security services.

Identity Protection with Defender for Identity

Memory trick

Deploying and Configuring Defender for Identity Sensors

Think 'MDI: My Domain's Identity' – the sensors are the 'eyes' on your domain controllers, watching for identity threats.

Identity Protection with Defender for Identity

Exam tip

Deploying and Configuring Defender for Identity Sensors

The exam often tests the placement of MDI sensors. Remember that sensors are primarily installed on Domain Controllers, but can also be installed on dedicated servers for specific scenarios, such as when a DC cannot meet resource requirements or for monitoring specific network segments.

Identity Protection with Defender for Identity

Common mistake

Deploying and Configuring Defender for Identity Sensors

Forgetting to check network connectivity and firewall rules before installation, leading to 'disconnected' sensors.

Identity Protection with Defender for Identity

Common mistake

Deploying and Configuring Defender for Identity Sensors

Installing sensors on machines that do not meet minimum hardware or software requirements, causing performance issues.

Identity Protection with Defender for Identity

Common mistake

Deploying and Configuring Defender for Identity Sensors

Using an outdated or incorrect access key, preventing the sensor from registering with the MDI cloud service.

Identity Protection with Defender for Identity

Key term

Investigation Path

A visual representation of an attacker's potential steps within an alert.

Identity Protection with Defender for Identity

Key term

True Positive

A genuine security threat correctly identified by a security system.

Identity Protection with Defender for Identity

Key term

Domain Dominance

Attacker's goal to gain full control over an Active Directory domain.

Identity Protection with Defender for Identity

Memory trick

Monitoring and Investigating Identity Threats

To remember the alert investigation steps, think 'ALERT': Analyze, Look, Evaluate, Respond, Track.

Identity Protection with Defender for Identity

Exam tip

Monitoring and Investigating Identity Threats

The exam often tests your ability to interpret alert details and understand their implications. Pay close attention to the 'Investigation path' and the different stages of an attack (reconnaissance, credential compromise, lateral movement, domain dominance) that Defender for Identity detects.

Identity Protection with Defender for Identity

Common mistake

Monitoring and Investigating Identity Threats

Ignoring low-severity alerts: Even low-severity alerts can be early indicators of a larger attack or part of a reconnaissance phase.

Identity Protection with Defender for Identity

Common mistake

Monitoring and Investigating Identity Threats

Failing to correlate alerts: Investigating an alert in isolation without looking for related activities or other security signals can lead to missed context.

Identity Protection with Defender for Identity

Common mistake

Monitoring and Investigating Identity Threats

Not documenting investigations: Proper documentation of findings, actions taken, and resolutions is crucial for auditing and future reference.

Identity Protection with Defender for Identity

Key term

Pass-the-Hash (PtH)

Attacker uses NTLM hash to authenticate without password.

Identity Protection with Defender for Identity

Key term

Pass-the-Ticket (PtT)

Attacker uses Kerberos ticket to authenticate.

Identity Protection with Defender for Identity

Key term

Reconnaissance

Attacker gathering information about the network.

Identity Protection with Defender for Identity

Memory trick

Responding to Suspicious Activities and Lateral Movement

To remember the response steps, think 'T.I.C.E.R.P.' - Triage, Investigate, Contain, Eradicate, Recover, Post-review. Like a 'TICKER' for your security heart!

Identity Protection with Defender for Identity

Exam tip

Responding to Suspicious Activities and Lateral Movement

The exam often tests your knowledge of specific lateral movement techniques like Pass-the-Hash (PtH) and Pass-the-Ticket (PtT), and how Defender for Identity detects them. Memorize these terms and their implications.

Identity Protection with Defender for Identity

Common mistake

Responding to Suspicious Activities and Lateral Movement

Ignoring low-severity alerts; even seemingly minor alerts can be precursors to larger attacks.

Identity Protection with Defender for Identity

Common mistake

Responding to Suspicious Activities and Lateral Movement

Failing to document response actions; this hinders post-incident analysis and compliance.

Identity Protection with Defender for Identity

Common mistake

Responding to Suspicious Activities and Lateral Movement

Not integrating with other Defender XDR components; this limits visibility and automated response capabilities.

Identity Protection with Defender for Identity

Key term

Microsoft Defender XDR

Unified security platform for detection and response.

Identity Protection with Defender for Identity

Key term

Unified Incident

Correlated alerts from multiple sources into one security event.

Identity Protection with Defender for Identity

Key term

Automated Investigation and Response (AIR)

Automated actions to mitigate threats.

Identity Protection with Defender for Identity

Memory trick

Integrating Defender for Identity with XDR

Think of XDR as an 'eXtra Detective pRotection' system that brings all the individual Defender agents together like a super-sleuth team!

Identity Protection with Defender for Identity

Exam tip

Integrating Defender for Identity with XDR

On the exam, be prepared to distinguish between the individual Defender products (like Defender for Identity) and the overarching Defender XDR platform. Keywords to watch for are 'unified portal,' 'incident correlation,' and 'automated response' when discussing XDR.

Identity Protection with Defender for Identity

Common mistake

Integrating Defender for Identity with XDR

Confusing Defender for Identity as a standalone product instead of a component of Defender XDR for comprehensive security.

Identity Protection with Defender for Identity

Common mistake

Integrating Defender for Identity with XDR

Underestimating the importance of unified incident management, leading to fragmented investigations.

Identity Protection with Defender for Identity

Common mistake

Integrating Defender for Identity with XDR

Not leveraging advanced hunting across all XDR data sources to proactively find threats.

Identity Protection with Defender for Identity

Key term

Shadow IT

Cloud apps/services used without official IT approval.

Cloud App Security with Defender for Cloud Apps

Key term

CASB

Cloud Access Security Broker; enforces security policies for cloud apps.

Cloud App Security with Defender for Cloud Apps

Key term

Log Collector

Component that forwards traffic logs from firewalls/proxies.

Cloud App Security with Defender for Cloud Apps

Key term

API Connector

Integrates Defender for Cloud Apps directly with sanctioned cloud apps.

Cloud App Security with Defender for Cloud Apps

Key term

Sanctioned App

A cloud application officially approved for use by the organization.

Cloud App Security with Defender for Cloud Apps

Key term

Unsanctioned App

A cloud application not approved for use, often blocked.

Cloud App Security with Defender for Cloud Apps

Key term

Risk Score

Assessment of an app's security and compliance posture.

Cloud App Security with Defender for Cloud Apps

Memory trick

Connecting Cloud Apps & Discovering Shadow IT

To remember the two main connection types: 'Logs Discover Shadows, APIs Control Approved Apps.'

Cloud App Security with Defender for Cloud Apps

Exam tip

Connecting Cloud Apps & Discovering Shadow IT

The exam frequently tests your understanding of how Defender for Cloud Apps discovers Shadow IT. Remember that log collectors (from firewalls/proxies) are key for discovery, while API connectors are for deeper integration with sanctioned apps.

Cloud App Security with Defender for Cloud Apps

Common mistake

Connecting Cloud Apps & Discovering Shadow IT

Confusing log collection (for discovery) with API connectors (for deeper control of sanctioned apps).

Cloud App Security with Defender for Cloud Apps

Common mistake

Connecting Cloud Apps & Discovering Shadow IT

Underestimating the security risks posed by seemingly harmless Shadow IT applications.

Cloud App Security with Defender for Cloud Apps

Common mistake

Connecting Cloud Apps & Discovering Shadow IT

Forgetting that Defender for Cloud Apps assesses risk based on numerous factors, not just whether an app is sanctioned.

Cloud App Security with Defender for Cloud Apps

Key term

Access Policy

Controls initial access to cloud apps based on conditions.

Cloud App Security with Defender for Cloud Apps

Key term

Session Policy

Monitors and controls user actions during an active session.

Cloud App Security with Defender for Cloud Apps

Key term

Conditional Access

Azure AD feature for enforcing access policies.

Cloud App Security with Defender for Cloud Apps

Key term

Reverse Proxy

Architecture used by Defender for Cloud Apps for session control.

Cloud App Security with Defender for Cloud Apps

Key term

Unmanaged Device

A device not controlled or secured by the organization.

Cloud App Security with Defender for Cloud Apps

Key term

Data Exfiltration

Unauthorized transfer of data out of an organization.

Cloud App Security with Defender for Cloud Apps

Memory trick

Configuring Access and Session Policies

ACCESS is like a 'bouncer' at the club door – decides if you get in. SESSION is like the 'bartender' inside – controls what you can do once you're in.

Cloud App Security with Defender for Cloud Apps

Exam tip

Configuring Access and Session Policies

The exam frequently tests the distinction between access and session policies. Remember: access policies are about *if* you can get in, session policies are about *what you can do* once you're in. Look for keywords like 'block access', 'allow access only if' for access policies, and 'prevent download', 'monitor activity', 'restrict copy/paste' for session policies.

Cloud App Security with Defender for Cloud Apps

Common mistake

Configuring Access and Session Policies

Confusing access policies with session policies. Access policies control initial entry; session policies control in-session activities.

Cloud App Security with Defender for Cloud Apps

Common mistake

Configuring Access and Session Policies

Not testing policies thoroughly before deployment, leading to unintended user blocks or data access issues.

Cloud App Security with Defender for Cloud Apps

Common mistake

Configuring Access and Session Policies

Forgetting that session policies require traffic to be routed through the Defender for Cloud Apps reverse proxy, which might have performance implications or require specific network configurations.

Cloud App Security with Defender for Cloud Apps

Key term

Anomaly Detection

Identifying deviations from normal behavior patterns.

Cloud App Security with Defender for Cloud Apps

Key term

User Behavior Analytics (UBA)

Analyzing user activity to detect suspicious patterns.

Cloud App Security with Defender for Cloud Apps

Key term

Impossible Travel

Logins from geographically impossible locations within a short time.

Cloud App Security with Defender for Cloud Apps

Key term

Mass Download

Unusually large volume of data downloaded by a user.

Cloud App Security with Defender for Cloud Apps

Key term

Alert Severity

Categorization of alerts based on potential impact and urgency.

Cloud App Security with Defender for Cloud Apps

Key term

Baseline

Established normal activity patterns for users or entities.

Cloud App Security with Defender for Cloud Apps

Memory trick

Investigating Alerts and User Behavior Analytics

To remember the alert investigation steps: A.G.R.A.I.D. - Anomaly, Generate, Review, Assess, Investigate, Determine.

Cloud App Security with Defender for Cloud Apps

Exam tip

Investigating Alerts and User Behavior Analytics

The exam often tests your ability to differentiate between various alert types and their implications. Pay close attention to scenario-based questions involving 'impossible travel,' 'mass download,' and 'activity from infrequent country.' Remember that high-severity alerts typically demand immediate response.

Cloud App Security with Defender for Cloud Apps

Common mistake

Investigating Alerts and User Behavior Analytics

Ignoring low-severity alerts, as they can sometimes be precursors to larger incidents.

Cloud App Security with Defender for Cloud Apps

Common mistake

Investigating Alerts and User Behavior Analytics

Failing to gather sufficient context before making a decision on an alert, leading to false positives or missed threats.

Cloud App Security with Defender for Cloud Apps

Common mistake

Investigating Alerts and User Behavior Analytics

Not integrating Defender for Cloud Apps alerts with a centralized SIEM or XDR solution for a holistic view.

Cloud App Security with Defender for Cloud Apps

Key term

Cloud Access Security Broker (CASB)

Software that sits between cloud service users and cloud applications, monitoring activity.

Cloud App Security with Defender for Cloud Apps

Key term

Microsoft Purview Information Protection (MPIP)

Unified solution for discovering, classifying, labeling, and protecting sensitive data.

Cloud App Security with Defender for Cloud Apps

Key term

Sensitive Information Types (SITs)

Predefined or custom patterns used to identify specific types of sensitive data.

Cloud App Security with Defender for Cloud Apps

Key term

File Policy

MDCA policy that scans files in cloud apps for sensitive content and enforces actions.

Cloud App Security with Defender for Cloud Apps

Memory trick

Managing Information Protection Policies

Think 'MDCA PROTECTS': Policies, Real-time, On-demand, Text, Exfiltration prevention, Classify, Tag, Secure.

Cloud App Security with Defender for Cloud Apps

Exam tip

Managing Information Protection Policies

Memorize the relationship between Defender for Cloud Apps and Microsoft Purview Information Protection. MDCA leverages MPIP's classification and labeling for deeper data protection. Look for questions that ask how MDCA enforces policies based on sensitivity labels.

Cloud App Security with Defender for Cloud Apps

Common mistake

Managing Information Protection Policies

Forgetting to integrate MDCA with Microsoft Purview Information Protection, limiting its data classification capabilities.

Cloud App Security with Defender for Cloud Apps

Common mistake

Managing Information Protection Policies

Creating overly broad policies that generate too many false positives, leading to alert fatigue.

Cloud App Security with Defender for Cloud Apps

Common mistake

Managing Information Protection Policies

Not regularly reviewing and updating policies as data types and compliance requirements evolve.

Cloud App Security with Defender for Cloud Apps

Key term

Secure Score

A numerical representation of an organization's security posture.

Planning and Implementing Defender for Cloud

Key term

CSPM

Cloud Security Posture Management; assesses and improves security posture.

Planning and Implementing Defender for Cloud

Key term

CWP

Cloud Workload Protection; provides advanced threat protection for workloads.

Planning and Implementing Defender for Cloud

Key term

Azure Policy

A service used to create, assign, and manage policies in Azure.

Planning and Implementing Defender for Cloud

Key term

Log Analytics agent

Software that collects logs and performance data from resources.

Planning and Implementing Defender for Cloud

Key term

Just-in-Time VM access

Feature that locks down inbound traffic to Azure VMs until access is requested.

Planning and Implementing Defender for Cloud

Key term

Cloud Security Explorer

Tool to proactively hunt for security risks using graph-based queries.

Planning and Implementing Defender for Cloud

Memory trick

Overview of Defender for Cloud features and architecture

Think of DEFENDER as 'Detect, Evaluate, Fortify, Enhance, Nurture, Defend, Ensure, Respond.' Each letter reminds you of a core function.

Planning and Implementing Defender for Cloud

Exam tip

Overview of Defender for Cloud features and architecture

The exam often distinguishes between the free CSPM features (Secure Score, basic recommendations) and the paid CWP features (advanced threat protection for specific workloads like servers, storage, SQL). Memorize that enabling specific Defender plans unlocks CWP.

Planning and Implementing Defender for Cloud

Common mistake

Overview of Defender for Cloud features and architecture

Confusing the free CSPM features with the paid CWP plans; they are distinct.

Planning and Implementing Defender for Cloud

Common mistake

Overview of Defender for Cloud features and architecture

Assuming Defender for Cloud only protects Azure resources; it extends to hybrid and multi-cloud.

Planning and Implementing Defender for Cloud

Common mistake

Overview of Defender for Cloud features and architecture

Not understanding that agents (Log Analytics/Azure Monitor) are crucial for data collection from VMs.

Planning and Implementing Defender for Cloud

Key term

Azure Arc

Extends Azure management to non-Azure resources.

Planning and Implementing Defender for Cloud

Key term

Azure Monitor Agent (AMA)

Collects monitoring data from machines.

Planning and Implementing Defender for Cloud

Key term

Log Analytics Workspace

Central repository for log data in Azure Monitor.

Planning and Implementing Defender for Cloud

Key term

Defender Plans

Specific security protections for resource types.

Planning and Implementing Defender for Cloud

Key term

Hybrid Cloud

Mix of on-premises and public cloud resources.

Planning and Implementing Defender for Cloud

Key term

Multi-cloud

Using multiple public cloud providers.

Planning and Implementing Defender for Cloud

Key term

RBAC

Azure Role-Based Access Control permissions.

Planning and Implementing Defender for Cloud

Memory trick

Onboarding Subscriptions and Non-Azure Resources

ARC-AMA-LOG: Azure Arc enables, Azure Monitor Agent collects, Log Analytics workspace stores.

Planning and Implementing Defender for Cloud

Exam tip

Onboarding Subscriptions and Non-Azure Resources

The exam often tests the mechanism for onboarding non-Azure resources. Remember the sequence: Azure Arc first, then Azure Monitor Agent, connecting to a Log Analytics workspace.

Planning and Implementing Defender for Cloud

Common mistake

Onboarding Subscriptions and Non-Azure Resources

Forgetting to enable specific Defender plans after onboarding a subscription, leading to incomplete protection.

Planning and Implementing Defender for Cloud

Common mistake

Onboarding Subscriptions and Non-Azure Resources

Not checking network connectivity or firewall rules for non-Azure machines, causing agent installation or data collection failures.

Planning and Implementing Defender for Cloud

Common mistake

Onboarding Subscriptions and Non-Azure Resources

Attempting to onboard non-Azure machines without first connecting them via Azure Arc.

Planning and Implementing Defender for Cloud

Key term

Security Policy

A set of rules defining security controls for Azure resources.

Planning and Implementing Defender for Cloud

Key term

Security Initiative

A collection of security policies grouped for a specific goal.

Planning and Implementing Defender for Cloud

Key term

Assignment Scope

The target (e.g., subscription, management group) where policies apply.

Planning and Implementing Defender for Cloud

Key term

Custom Policy

A user-defined security rule tailored to specific needs.

Planning and Implementing Defender for Cloud

Key term

Regulatory Compliance

Dashboard showing adherence to industry standards via initiatives.

Planning and Implementing Defender for Cloud

Memory trick

Configuring Security Policies and Initiatives

P-I-A: Policies are Individual rules, Initiatives are collections, and Assignments make them active. PIA!

Planning and Implementing Defender for Cloud

Exam tip

Configuring Security Policies and Initiatives

The exam often tests the difference between a 'policy' (single rule) and an 'initiative' (collection of policies). Remember that initiatives are assigned, which then applies all policies within them. Keywords to spot: 'enforce standards', 'track compliance', 'custom requirements'.

Planning and Implementing Defender for Cloud

Common mistake

Configuring Security Policies and Initiatives

Confusing a security policy with a security initiative; remember, an initiative is a collection of policies.

Planning and Implementing Defender for Cloud

Common mistake

Configuring Security Policies and Initiatives

Forgetting to assign a policy or initiative after creating it, rendering it ineffective.

Planning and Implementing Defender for Cloud

Common mistake

Configuring Security Policies and Initiatives

Attempting to create a custom policy when a built-in one already perfectly meets the requirement.

Planning and Implementing Defender for Cloud

Key term

Security Contact

Individual or group receiving security notifications.

Planning and Implementing Defender for Cloud

Key term

Email Notifications

Automated emails about security alerts and recommendations.

Planning and Implementing Defender for Cloud

Key term

Distribution List

An email address that forwards messages to multiple recipients.

Planning and Implementing Defender for Cloud

Key term

Azure Monitor Action Group

A collection of notification preferences and actions for alerts.

Planning and Implementing Defender for Cloud

Key term

Azure Logic Apps

Cloud service for building automated workflows and integrations.

Planning and Implementing Defender for Cloud

Key term

ITSM

Information Technology Service Management, often with a ticketing system.

Planning and Implementing Defender for Cloud

Memory trick

Managing Security Contacts and Email Notifications

Remember 'SECURE': S-ettings, E-mail, C-ontacts, U-rgency (severity), R-esponse (automation), E-nsure coverage.

Planning and Implementing Defender for Cloud

Exam tip

Managing Security Contacts and Email Notifications

The exam often tests your knowledge of WHERE to configure these settings in the Azure portal and the BEST PRACTICES for contact types (e.g., distribution lists). Look for questions asking about 'who should receive' or 'how to ensure multiple people are notified'.

Planning and Implementing Defender for Cloud

Common mistake

Managing Security Contacts and Email Notifications

Using individual email addresses instead of distribution lists, leading to missed alerts when a person is out.

Planning and Implementing Defender for Cloud

Common mistake

Managing Security Contacts and Email Notifications

Not configuring notification severity, resulting in alert fatigue from low-priority emails.

Planning and Implementing Defender for Cloud

Common mistake

Managing Security Contacts and Email Notifications

Forgetting to test the notification setup after configuration to ensure emails are being received.

Planning and Implementing Defender for Cloud

Key term

Security Recommendation

Actionable suggestions from Defender for Cloud to improve security posture.

Security Posture Management in Defender for Cloud

Key term

Security Posture

The overall strength of an organization's security defenses against threats.

Security Posture Management in Defender for Cloud

Key term

Continuous Assessment

Ongoing evaluation of resources against security best practices and policies.

Security Posture Management in Defender for Cloud

Key term

Impact

The potential effect of a security recommendation on the overall Secure Score.

Security Posture Management in Defender for Cloud

Memory trick

Understanding Secure Score and Security Recommendations

SCORE: S-ecurity C-hecks O-rganized R-ecommendations E-nhance.

Security Posture Management in Defender for Cloud

Exam tip

Understanding Secure Score and Security Recommendations

The exam often tests your understanding of how Secure Score is calculated and how recommendations contribute to it. Look for questions about prioritizing recommendations based on their impact or potential points, and how to interpret the score.

Security Posture Management in Defender for Cloud

Common mistake

Understanding Secure Score and Security Recommendations

Focusing only on the overall Secure Score number without understanding the underlying recommendations.

Security Posture Management in Defender for Cloud

Common mistake

Understanding Secure Score and Security Recommendations

Ignoring low-impact recommendations, as they can still contribute to overall security and compliance.

Security Posture Management in Defender for Cloud

Common mistake

Understanding Secure Score and Security Recommendations

Believing a perfect Secure Score means absolute security; it's a guide, not a guarantee.

Security Posture Management in Defender for Cloud

Key term

Quick Fix

One-click automated remediation for Defender for Cloud recommendations.

Security Posture Management in Defender for Cloud

Key term

Workflow Automation

Using tools like Logic Apps to automate security tasks and responses.

Security Posture Management in Defender for Cloud

Key term

Exemption

A documented decision to not remediate a specific security recommendation.

Security Posture Management in Defender for Cloud

Key term

Misconfiguration

Incorrect or insecure settings in a system or application.

Security Posture Management in Defender for Cloud

Memory trick

Remediating Vulnerabilities and Misconfigurations

Remember 'RAM': **R**emediate, **A**utomate, **M**onitor. This covers the core actions for handling security findings.

Security Posture Management in Defender for Cloud

Exam tip

Remediating Vulnerabilities and Misconfigurations

The exam often tests your understanding of the different remediation methods: manual, Quick Fix, and workflow automation. Pay attention to scenarios where one method is more appropriate than another.

Security Posture Management in Defender for Cloud

Common mistake

Remediating Vulnerabilities and Misconfigurations

Ignoring low-severity recommendations, as they can combine to create a larger vulnerability.

Security Posture Management in Defender for Cloud

Common mistake

Remediating Vulnerabilities and Misconfigurations

Applying Quick Fixes without understanding the full impact on the resource or application.

Security Posture Management in Defender for Cloud

Common mistake

Remediating Vulnerabilities and Misconfigurations

Failing to document exemptions or setting them indefinitely without periodic review.

Security Posture Management in Defender for Cloud

Key term

Compliance Dashboard

Centralized view of an organization's compliance posture.

Security Posture Management in Defender for Cloud

Key term

Compliance Standard

A set of rules or guidelines (e.g., GDPR, PCI DSS).

Security Posture Management in Defender for Cloud

Key term

Security Control

Specific requirement within a compliance standard.

Security Posture Management in Defender for Cloud

Key term

Attestation

Manual confirmation of compliance for certain controls.

Security Posture Management in Defender for Cloud

Key term

Continuous Monitoring

Ongoing assessment of compliance posture.

Security Posture Management in Defender for Cloud

Key term

Azure Security Benchmark

Microsoft's foundational security and compliance best practices.

Security Posture Management in Defender for Cloud