MS-102 · Question #106
You have a Microsoft 365 E5 subscription. You need to ensure that administrators receive an email when Microsoft 365 Defender detects a sign-in from a risky IP address. What should you create?
The correct answer is B. an alert. To ensure administrators receive email notifications when Microsoft 365 Defender detects a sign-in from a risky IP address, you should create or configure an alert.
Question
You have a Microsoft 365 E5 subscription. You need to ensure that administrators receive an email when Microsoft 365 Defender detects a sign-in from a risky IP address. What should you create?
Options
- Aa vulnerability notification rule
- Ban alert
- Can incident assignment filter
- Dan incident notification rule
How the community answered
(27 responses)- B89% (24)
- C4% (1)
- D7% (2)
Why each option
To ensure administrators receive email notifications when Microsoft 365 Defender detects a sign-in from a risky IP address, you should create or configure an alert.
A vulnerability notification rule is typically related to vulnerability management and patching, not specific real-time sign-in risk detections.
In Microsoft 365 Defender, alerts are generated for specific detections like risky IP sign-ins, and these alerts can be configured to send email notifications to administrators directly when triggered.
An incident assignment filter is used to automatically assign incidents to specific personnel, not to send email notifications for initial alert detections.
An incident notification rule sends emails when an incident (which aggregates alerts) is created or updated, but the most direct way to notify for a specific detection is via the alert itself.
Concept tested: Microsoft 365 Defender alert notification configuration
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/alert-policies?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.