SC-200 · Question #324
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to identify all the entities affected by an incident. Which tab should you use in the Microsoft Defender portal?
The correct answer is C. Evidence and Response. To view all entities affected by a Microsoft Defender XDR incident, such as devices, users, or files, the 'Evidence and Response' tab within the incident details page provides a consolidated list.
Question
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to identify all the entities affected by an incident. Which tab should you use in the Microsoft Defender portal?
Options
- AInvestigations
- BAssets
- CEvidence and Response
- DAlerts
How the community answered
(65 responses)- A9% (6)
- B5% (3)
- C85% (55)
- D2% (1)
Why each option
To view all entities affected by a Microsoft Defender XDR incident, such as devices, users, or files, the 'Evidence and Response' tab within the incident details page provides a consolidated list.
The 'Evidence and Response' tab within a Microsoft Defender XDR incident is specifically designed to provide a comprehensive view of all affected entities, including devices, users, mailboxes, and files. This tab consolidates the evidence that links these entities to the incident and displays any response actions taken or pending, offering a complete scope of impacted entities.
The 'Alerts' tab lists the individual security alerts that collectively form the incident, but it does not provide a single, consolidated list of all unique entities affected across all those alerts.
Concept tested: Microsoft Defender XDR incident investigation workflow
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/investigate-incidents-in-m365d?view=o365-worldwide
Community Discussion
No community discussion yet for this question.