SC-200 Lab 8 – Microsoft Sentinel: Incidents, Playbooks & Investigation

Microsoft Security Operations Analyst — Lab 8

Lab 8 – Microsoft Sentinel: Incidents, Playbooks & Investigation

SC-200: Microsoft Security Operations Analyst

Overview


Investigated Sentinel incidents generated from the simulated attacks in Lab 7, triaged and managed incident workflows, then built a Logic Apps playbook triggered by Sentinel incidents for automated response. Managed Sentinel content using repositories. Supplemented with Microsoft Learn exercises for incident setup and investigation.

Tasks Completed


Environment: Employer-provided Azure subscription (resources deleted after lab).

Source Material


Completed using Exercise 7: Investigate Incidents and Exercise 10: Content Management from the SC-200T00A MicrosoftLearning GitHub repository; and Microsoft Learn exercises Incident Management Setup, Investigate an Incident, Playbook Setup, and Create a Playbook. Completed in an employer-provided Azure subscription.