nerdexam
Microsoft

SC-100 · Question #174

You are designing a security operations strategy based on the Zero Trust framework. You need to minimize the operational load on Tier 1 Microsoft Security Operations Center (SOC) analysts. What…

The correct answer is B. Enable self-healing in Microsoft 365 Defender. Enabling self-healing in Microsoft 365 Defender (Automated Investigation and Remediation, or AIR) directly reduces the operational burden on Tier 1 SOC analysts by automatically investigating alerts and taking approved remediation actions without requiring manual analyst…

Design security operations, identity, and compliance capabilities

Question

You are designing a security operations strategy based on the Zero Trust framework. You need to minimize the operational load on Tier 1 Microsoft Security Operations Center (SOC) analysts. What should you do?

Options

  • AEnable built-in compliance policies in Azure Policy.
  • BEnable self-healing in Microsoft 365 Defender.
  • CAutomate data classification.
  • DCreate hunting queries in Microsoft 365 Defender.

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    72% (36)
  • C
    8% (4)
  • D
    16% (8)

Explanation

Enabling self-healing in Microsoft 365 Defender (Automated Investigation and Remediation, or AIR) directly reduces the operational burden on Tier 1 SOC analysts by automatically investigating alerts and taking approved remediation actions without requiring manual analyst intervention. Common, high-volume, low-complexity incidents (malware quarantine, suspicious email removal, etc.) are handled automatically, freeing Tier 1 analysts to focus on genuine escalations. Option A (Azure Policy compliance) addresses governance of cloud resources, not SOC analyst workload. Option C (automated data classification) is a data governance capability with no direct impact on alert triage workload. Option D (creating hunting queries) actually increases analyst work by generating more investigative tasks-it is a proactive threat-hunting activity suited for Tier 3 analysts, not a load-reduction measure for Tier 1.

Topics

#SOC Operations#Automated Remediation#Microsoft 365 Defender#Zero Trust

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice