Skip to content

SentinelOne Singularity: agents, policy modes, Storyline and mitigation

For technicians and admins who run SentinelOne Singularity Endpoint: enrolling agents with the Site Token, the difference between Detect and Protect modes, reading a Storyline, choosing mitigation actions (kill, quarantine, remediate, rollback), and using Network Control, Device Control and Remote Shell carefully.

Level
Intermediate
Length
About 45 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 2 Oct 2026
  • SentinelOne

Skills you'll practise

  • Enroll an agent to the correct site using its Site Token and verify it in the console
  • Explain the difference between Detect mode and Protect mode and choose one for a stated situation
  • Read a Storyline to find how an attack started and what it changed
  • Choose between kill, quarantine, remediate and rollback for a stated incident, including the Windows VSS dependency for rollback
  • Describe what Network Control, Device Control and Remote Shell are for and the care each needs

Course outline

  1. 1.SentinelOne Singularity essentialsVideo · 2 min
  2. 2.Agents, sites and policy modesLesson · 15 min
  3. 3.Storyline and mitigation actionsLesson · 16 min
  4. 4.Control features and safe administrationLesson · 14 min
  5. 5.SentinelOne Singularity: agents, policy modes, Storyline and mitigation: knowledge checkKnowledge check · 16 questions
  6. 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.