Reviewing and Responding to Risks
When threats are detected, Microsoft 365 Defender will create incidents and alerts. You can monitor and manage alerts and incidents from the Microsoft 365 Defender portal.
Tip
Microsoft 365 Defender provides sample files that you can use to understand how to detect and process risks. The examples in this section were generated using the automated investigation (backdoor) simulation, available for download at https://security.microsoft.com/tutorials/simulations. We recommend deploying a simulation to a test environment so you can more deeply understand the vulnerability management experience and interface.
Microsoft Defender 365 has some basic terminology you’ll need to understand in order to be successful—both on the MS-102 exam as well as managing security operations:
- Alert: A detected event that generates a notification. In the context of Microsoft 365 Defender, an alert is specific to some sort of suspicious or threat...