SC-200 · Question #242
You have a Microsoft Sentinel workspace that uses the Microsoft 365 Defender data connector. From Microsoft Sentinel, you investigate a Microsoft 365 incident. You need to update the incident to…
The correct answer is D. the Alerts page in the Microsoft 365 Defender portal. Open the Microsoft 365 Defender portal and select Alerts. Find the alert that you want to add to the incident and select it. In the alert details page, select Add to existing incident. In the Add alert to incident pane, select the incident that you want to update and then…
Question
You have a Microsoft Sentinel workspace that uses the Microsoft 365 Defender data connector. From Microsoft Sentinel, you investigate a Microsoft 365 incident. You need to update the incident to include an alert generated by Microsoft Defender for Cloud Apps. What should you use?
Options
- Athe entity side panel of the Timeline card in Microsoft Sentinel
- Bthe Timeline tab on the incidents page of Microsoft Sentinel
- Cthe investigation graph on the incidents page of Microsoft Sentinel
- Dthe Alerts page in the Microsoft 365 Defender portal
How the community answered
(15 responses)- A20% (3)
- B7% (1)
- D73% (11)
Explanation
Open the Microsoft 365 Defender portal and select Alerts. Find the alert that you want to add to the incident and select it. In the alert details page, select Add to existing incident. In the Add alert to incident pane, select the incident that you want to update and then select Add. This will add the alert to the incident in both Microsoft 365 Defender and Microsoft Sentinel portals. Any changes you make to the incident in Microsoft 365 Defender will be synchronized to the same incident in Microsoft Sentinel
Topics
Community Discussion
No community discussion yet for this question.