Chapter 6: An Overview: Microsoft Defender for Endpoint Alerts, Incidents, Evidence, and Dashboards
One of the requirements from a skill set standpoint that you will need as the Microsoft security operations analyst for your enterprise will be the skill set in fully understanding the Microsoft Defender for Endpoint portal. You will need to know with quick precision where to go for various alerts, tasks, and reports. This knowledge will prove to be crucial daily, but especially during a time of an active incident or attack. During this chapter, we will go through an in-depth overview of the Microsoft Defender for Endpoint portal so that you are more quickly able to apply this knowledge both in the SC-200 exam and in your role as the Microsoft security operations analyst for your enterprise!
Topics we will cover include the following:
- Creating your lab environment
- General portal navigation
- Alerts and incidents
- How to suppress an alert and create a new suppression...