SC-200 · Question #179
You have an Azure subscription that uses Microsoft Defender for Cloud. You need to filter the security alerts view to show the following alerts: - Unusual user accessed a key vault - Log on from an…
The correct answer is C. Medium. The three alerts listed - 'Unusual user accessed a key vault,' 'Log on from an unusual location,' and 'Impossible travel activity' - are all classified as Medium severity in Microsoft Defender for Cloud. They represent suspicious behaviors that may indicate a compromise but are…
Question
You have an Azure subscription that uses Microsoft Defender for Cloud. You need to filter the security alerts view to show the following alerts:
- Unusual user accessed a key vault
- Log on from an unusual location
- Impossible travel activity
Which severity should you use?
Options
- AInformational
- BLow
- CMedium
- DHigh
How the community answered
(36 responses)- A6% (2)
- B14% (5)
- C78% (28)
- D3% (1)
Explanation
The three alerts listed - 'Unusual user accessed a key vault,' 'Log on from an unusual location,' and 'Impossible travel activity' - are all classified as Medium severity in Microsoft Defender for Cloud. They represent suspicious behaviors that may indicate a compromise but are not confirmed active attacks. High severity is reserved for imminent or confirmed threats, while Low and Informational are for minor anomalies or policy notifications. Filtering by Medium will surface all three of these alerts.
Topics
Community Discussion
No community discussion yet for this question.