Manage a security operations environment (40–45%)
- Configure email notifications in Microsoft Defender XDR, including incidents, actions, and threat analytics
- Configure alert notifications in Microsoft Defender XDR, including tuning, suppression, and correlation
- Configure Microsoft Defender for Endpoint advanced features
- Configure rules settings in Microsoft Defender for Endpoint
- Configure custom data collection in Microsoft Defender for Endpoint
- Configure security policies for Microsoft Defender for Endpoint, including attack surface reduction (ASR) rules
- Manage automated investigation and response capabilities in Microsoft Defender XDR
- Configure automatic attack disruption in Microsoft Defender XDR
- Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint
- Create and configure automation rules in Microsoft Sentinel
- Create and configure Microsoft Sentinel playbooks
- Specify Microsoft Sentinel roles