MS-900 · Question #279
Hotspot Question A company uses Microsoft 365. Select the answer that correctly completes the sentence. Answer:
The correct answer is To provide a tool for security analyst triage, incident response, threat hunting, vulnerability management workflows, and recent security articles from Microsoft, the company should use: Defender Threat Intelligence. The correct answer is Defender Threat Intelligence because its capabilities directly align with providing a comprehensive tool for security analyst triage, incident response, threat hunting, vulnerability management workflows, and access to Microsoft's security articles.
Question
Exhibit
Answer Area
- To provide a tool for security analyst triage, incident response, threat hunting, vulnerability management workflows, and recent security articles from Microsoft, the company should useDefender Threat IntelligenceDefender for Cloud AppsDefender for Office 365Defender Threat IntelligenceDefender Vulnerability Management
Explanation
The correct answer is Defender Threat Intelligence because its capabilities directly align with providing a comprehensive tool for security analyst triage, incident response, threat hunting, vulnerability management workflows, and access to Microsoft's security articles.
Approach. The test-taker must click on the dropdown menu and select 'Defender Threat Intelligence'. This is the correct choice because Microsoft Defender Threat Intelligence (MDTI) is specifically designed to provide proactive threat intelligence, deep insights into adversary infrastructure and methods, and tools for threat hunting, incident response, and vulnerability management workflows. It aggregates global threat data from Microsoft's vast ecosystem and makes it accessible for security analysts, including recent security articles and research, to enhance an organization's security posture and response capabilities. The description in the question directly matches the core functions of MDTI.
Common mistakes.
- common_mistake. Selecting any option other than 'Defender Threat Intelligence' would be incorrect because their primary focus areas do not encompass the full range of capabilities described in the question:
Concept tested. The core concept being tested is the understanding of the specific capabilities and scope of different Microsoft Defender services, particularly their roles in a security operations center (SOC) context, including threat intelligence, incident response, threat hunting, and vulnerability management.
Topics
Community Discussion
No community discussion yet for this question.
