Summary
We wanted to ensure that the content is digestible and, quite frankly, there is a lot here to digest. We hope you were able to acquire an in-depth understanding of the importance of alerts and incidents within Microsoft Defender for Endpoint. These will be the first two areas that you will be required to know in your daily life as the Microsoft security operations analyst for your company, and of course, use this knowledge to pass the Microsoft SC-200 exam!
We will cover the following remaining topics in the next chapter:
- MDI concepts
- Understanding and investigating alerts
- Triaging and responding to alerts
We look forward to walking alongside you on the preceding topics. Now, go get yourself a coffee, take a break, and let's get going into the next chapter!