nerdexam
Microsoft

SC-200 · Question #225

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. You need to identify any devices that triggered a malware alert and collect evidence related to the alert. The…

The correct answer is C. Investigations. The Investigations page in the Microsoft 365 Defender portal displays automated investigation results, including all collected evidence (files, processes, network connections, registry entries) linked to triggered alerts. Critically, it also surfaces response actions…

Submitted by femi9· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. You need to identify any devices that triggered a malware alert and collect evidence related to the alert. The solution must ensure that you can use the results to initiate device isolation for the affected devices. What should you use in the Microsoft 365 Defender portal?

Options

  • Aincidents
  • BRemediation
  • CInvestigations
  • DAdvanced hunting

How the community answered

(24 responses)
  • A
    17% (4)
  • B
    8% (2)
  • C
    71% (17)
  • D
    4% (1)

Explanation

The Investigations page in the Microsoft 365 Defender portal displays automated investigation results, including all collected evidence (files, processes, network connections, registry entries) linked to triggered alerts. Critically, it also surfaces response actions - including device isolation - that can be applied directly to the affected devices from within the investigation context. Incidents (A) provide a high-level view but don't consolidate evidence for action. Remediation (B) shows pending remediation actions already in progress. Advanced hunting (D) is a manual KQL query tool that can identify devices but does not natively bundle evidence collection and response actions in the same workflow.

Topics

#Microsoft Defender for Endpoint#Automated investigations#Device isolation#Threat response

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice