Lab 8 – Microsoft Sentinel: Incidents, Playbooks & Investigation
SC-200: Microsoft Security Operations Analyst
Overview
Investigated Sentinel incidents generated from the simulated attacks in Lab 7, triaged and managed incident workflows, then built a Logic Apps playbook triggered by Sentinel incidents for automated response. Managed Sentinel content using repositories. Supplemented with Microsoft Learn exercises for incident setup and investigation.
Tasks Completed
- Reviewed Sentinel incidents generated from the Lab 7 attack simulations and analytics rules
- Triaged incidents: set severity, assigned owner, added comments, and updated incident status
- Investigated an incident using the Sentinel investigation graph to map entity relationships and attack paths
- Created a Logic Apps playbook triggered by a Sentinel incident alert rule
- Configured the playbook to post incident details to a Teams channel as an automated response action
- Attached the playbook to a Sentinel analytics rule as an automated response action
- Managed Sentinel content using the Repositories feature to connect a GitHub repository for content deployment
- Configured incident management settings and investigated a simulated incident via Microsoft Learn exercises
Environment: Employer-provided Azure subscription (resources deleted after lab).
Source Material
Completed using Exercise 7: Investigate Incidents and Exercise 10: Content Management from the SC-200T00A MicrosoftLearning GitHub repository; and Microsoft Learn exercises Incident Management Setup, Investigate an Incident, Playbook Setup, and Create a Playbook. Completed in an employer-provided Azure subscription.
← Back to SC-200 Labs