MS-102 · Question #505
Your company has 5,000 Windows 10 devices. All the devices are protected by using Windows Defender Advanced Threat Protection (ATP). You need to view which Windows Defender ATP alert events have a…
The correct answer is B. Automated investigations. In Windows Defender ATP, Automated investigations surfaces alerts that have been triaged and investigated automatically, grouped by severity and time range, making it the intended interface for reviewing high-severity alert events within a specific window like the last seven…
Question
Your company has 5,000 Windows 10 devices. All the devices are protected by using Windows Defender Advanced Threat Protection (ATP). You need to view which Windows Defender ATP alert events have a high severity and occurred during the last seven days. What should you use in Windows Defender ATP?
Options
- Athe threat intelligence API
- BAutomated investigations
- CThreat analytics
- DAdvanced hunting
How the community answered
(24 responses)- A4% (1)
- B83% (20)
- C8% (2)
- D4% (1)
Explanation
In Windows Defender ATP, Automated investigations surfaces alerts that have been triaged and investigated automatically, grouped by severity and time range, making it the intended interface for reviewing high-severity alert events within a specific window like the last seven days. Advanced hunting (D) is a KQL-based raw query tool suited for proactive threat hunting across telemetry data - it is more powerful but not the designed workflow for reviewing curated alert summaries by severity and recency. Threat analytics (C) provides macro-level intelligence on threat actor campaigns and techniques, not individual alert filtering. The threat intelligence API (A) is a programmatic interface for integrating external SIEM or SOAR platforms, not an in-portal alert review tool.
Topics
Community Discussion
No community discussion yet for this question.