SC-200 · Question #225
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. You need to identify any devices that triggered a malware alert and collect evidence related to the alert. The…
The correct answer is C. Investigations. The Investigations page in the Microsoft 365 Defender portal displays automated investigation results, including all collected evidence (files, processes, network connections, registry entries) linked to triggered alerts. Critically, it also surfaces response actions…
Question
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. You need to identify any devices that triggered a malware alert and collect evidence related to the alert. The solution must ensure that you can use the results to initiate device isolation for the affected devices. What should you use in the Microsoft 365 Defender portal?
Options
- Aincidents
- BRemediation
- CInvestigations
- DAdvanced hunting
How the community answered
(24 responses)- A17% (4)
- B8% (2)
- C71% (17)
- D4% (1)
Explanation
The Investigations page in the Microsoft 365 Defender portal displays automated investigation results, including all collected evidence (files, processes, network connections, registry entries) linked to triggered alerts. Critically, it also surfaces response actions - including device isolation - that can be applied directly to the affected devices from within the investigation context. Incidents (A) provide a high-level view but don't consolidate evidence for action. Remediation (B) shows pending remediation actions already in progress. Advanced hunting (D) is a manual KQL query tool that can identify devices but does not natively bundle evidence collection and response actions in the same workflow.
Topics
Community Discussion
No community discussion yet for this question.