Skip to content

Commit 23f7789

Browse files
committed
fixed up tutorial security incident
1 parent 61eb5b0 commit 23f7789

File tree

1 file changed

+9
-6
lines changed

1 file changed

+9
-6
lines changed

articles/defender-for-cloud/tutorial-security-incident.md

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,14 @@ description: In this tutorial, you'll learn how to triage security alerts and de
44
ms.assetid: 181e3695-cbb8-4b4e-96e9-c4396754862f
55
ms.topic: tutorial
66
ms.custom: ignite-2022
7-
ms.date: 11/09/2021
7+
ms.date: 01/08/2023
88
---
99

1010
# Tutorial: Triage, investigate, and respond to security alerts
1111

1212
Microsoft Defender for Cloud continuously analyzes your hybrid cloud workloads using advanced analytics and threat intelligence to alert you about potentially malicious activities in your cloud resources. You can also integrate alerts from other security products and services into Defender for Cloud. Once an alert is raised, swift action is needed to investigate and remediate the potential security issue.
1313

14-
In this tutorial, you will learn how to:
14+
In this tutorial, you'll learn how to:
1515

1616
> [!div class="checklist"]
1717
> * Triage security alerts
@@ -21,7 +21,9 @@ In this tutorial, you will learn how to:
2121
If you don't have an Azure subscription, create a [free account](https://azure.microsoft.com/free/) before you begin.
2222

2323
## Prerequisites
24-
To step through the features covered in this tutorial, you must have Defender for Cloud's enhanced security features enabled. You can try these at no cost. To learn more, see the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/). The quickstart [Get started with Defender for Cloud](get-started.md) walks you through how to upgrade.
24+
To step through the features covered in this tutorial, you must have Defender for Cloud's enhanced security features enabled. To learn more about Defender for Cloud's pricing, see the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/).
25+
26+
The quickstart, [Get started with Defender for Cloud](get-started.md) walks you through the upgrade process.
2527

2628

2729
## Triage security alerts
@@ -78,7 +80,7 @@ After you've investigated a security alert and understood its scope, you can res
7880

7981
:::image type="content" source="./media/tutorial-security-incident/set-status-dismissed.png" alt-text="Setting an alert's status":::
8082

81-
This removes the alert from the main alerts list. You can use the filter from the alerts list page to view all alerts with **Dismissed** status.
83+
The alert is then removed from the main list of alerts. You can use the filter from the alerts list page to view all alerts with **Dismissed** status.
8284

8385
1. We encourage you to provide feedback about the alert to Microsoft:
8486
1. Marking the alert as **Useful** or **Not useful**.
@@ -89,7 +91,7 @@ After you've investigated a security alert and understood its scope, you can res
8991
> [!TIP]
9092
> We review your feedback to improve our algorithms and provide better security alerts.
9193

92-
## End the tutorial
94+
## CLean up resources
9395

9496
Other quickstarts and tutorials in this collection build upon this quickstart. If you plan to continue to work with subsequent quickstarts and tutorials, keep automatic provisioning and Defender for Cloud's enhanced security features enabled.
9597

@@ -115,7 +117,8 @@ If you don't plan to continue, or you want to disable either of these features:
115117
> Disabling extensions does not remove the Log Analytics agent from Azure VMs that already have the agent, but does limits security monitoring for your resources.
116118
117119
## Next steps
118-
In this tutorial, you learned about Defender for Cloud features to be used when responding to a security alert. For related material see:
120+
121+
In this tutorial, you learned about Defender for Cloud features to be used when responding to a security alert. For related material, see:
119122

120123
- [Respond to Microsoft Defender for Key Vault alerts](defender-for-key-vault-usage.md)
121124
- [Security alerts - a reference guide](alerts-reference.md)

0 commit comments

Comments
 (0)