SC-200 · Question #119
You have a Microsoft 365 subscription that uses Microsoft 365 Defender. You need to identify all the entities affected by an incident. Which tab should you use in the Microsoft 365 Defender portal?
The correct answer is C. Evidence and Response. In the Microsoft 365 Defender portal, the 'Evidence and Response' tab within an incident shows all entities associated with that incident, including users, devices, files, IP addresses, URLs, emails, and mailboxes. This tab consolidates all affected artifacts and their…
Question
You have a Microsoft 365 subscription that uses Microsoft 365 Defender. You need to identify all the entities affected by an incident. Which tab should you use in the Microsoft 365 Defender portal?
Options
- AInvestigations
- BDevices
- CEvidence and Response
- DAlerts
How the community answered
(16 responses)- B13% (2)
- C81% (13)
- D6% (1)
Explanation
In the Microsoft 365 Defender portal, the 'Evidence and Response' tab within an incident shows all entities associated with that incident, including users, devices, files, IP addresses, URLs, emails, and mailboxes. This tab consolidates all affected artifacts and their investigation status, making it the correct place to identify every entity impacted by an incident. 'Alerts' (D) shows the individual alerts that make up the incident. 'Devices' (B) shows only device entities. 'Investigations' (A) shows automated investigation results but does not provide a consolidated entity view.
Topics
Community Discussion
No community discussion yet for this question.