SC-900 · Question #10
SC-900 Question #10: Real Exam Question with Answer & Explanation
The correct answer is B: Reports. The Reports section in the Microsoft 365 Defender portal provides dashboards and visualizations for security trends over time, including the protection status of identities, devices, email, and apps. It aggregates telemetry into trend charts and summary metrics that help security
Question
What should you use in the Microsoft 365 Defender portal to view security trends and track the protection status of identities?
Options
- AAttack simulator
- BReports
- CHunting
- DIncidents
Explanation
The Reports section in the Microsoft 365 Defender portal provides dashboards and visualizations for security trends over time, including the protection status of identities, devices, email, and apps. It aggregates telemetry into trend charts and summary metrics that help security teams understand the overall security posture. Attack simulator (A) is used to run phishing and attack simulations for training. Hunting (C) is for writing and running advanced KQL queries to proactively search for threats. Incidents (D) is the incident queue for managing active alerts and investigations - it reflects current events, not historical trends or identity protection status.
Topics
Community Discussion
No community discussion yet for this question.