SC-200 · Question #169
Microsoft 365 Defender gives a purpose-based UI to manage and examine security incidents and alerts across Microsoft 365 services. You are a SOC Analyst working at a company XYZ that has configured…
The correct answer is B. True alert. In Microsoft 365 Defender, an incident is created from correlated, verified security events - specifically 'true alerts,' meaning genuine threats confirmed by the system. A 'true alert' is a real security event as opposed to a false positive or a test. 'Test alert' is used to…
Question
Microsoft 365 Defender gives a purpose-based UI to manage and examine security incidents and alerts across Microsoft 365 services. You are a SOC Analyst working at a company XYZ that has configured Microsoft 365 Defender solutions, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Cloud App Security. You are required to monitor related alerts across all the solutions as a single incident to observe the incident's full impact and do an RCA (root cause investigation). The Microsoft Security center portal has a fused view of incidents and actions taken on them. Which of the following can be classified as an Incident?
Options
- ATest alert
- BTrue alert
- CHigh alert
- DPositive alert
How the community answered
(62 responses)- A2% (1)
- B92% (57)
- C2% (1)
- D5% (3)
Explanation
In Microsoft 365 Defender, an incident is created from correlated, verified security events - specifically 'true alerts,' meaning genuine threats confirmed by the system. A 'true alert' is a real security event as opposed to a false positive or a test. 'Test alert' is used to validate configurations, 'High alert' refers to severity level (not incident classification), and 'Positive alert' is not a standard Microsoft classification term.
Topics
Community Discussion
No community discussion yet for this question.