MS-900 · Question #449
Drag and Drop Question A company plans to use Microsoft 365 Defender. You need to identify the tools that support the Microsoft 365 Defender features. Which tool should you identify? To answer, drag…
The correct answer is Incidents; Advanced hunting; Secure Score. In Microsoft 365 Defender, 'Incidents' is used to correlate and manage related alerts and investigations across the environment, providing a unified view of an attack. 'Advanced Hunting' supports proactive threat hunting using Kusto Query Language (KQL) to query up to 30 days…
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- Incidents
- Advanced hunting
- Secure Score
Explanation
In Microsoft 365 Defender, 'Incidents' is used to correlate and manage related alerts and investigations across the environment, providing a unified view of an attack. 'Advanced Hunting' supports proactive threat hunting using Kusto Query Language (KQL) to query up to 30 days of raw data across endpoints, emails, identities, and apps. 'Secure Score' measures an organization's security posture and provides recommendations to improve it, acting as a benchmark and improvement tool. 'Threat Analytics' is a valid Microsoft 365 Defender feature as well (used by security analysts to understand active threats), so its exclusion from the correct arrangement suggests the target features in this drag-and-drop map specifically to Incidents, Advanced Hunting, and Secure Score for the described use cases.
Topics
Community Discussion
No community discussion yet for this question.
