Microsoft SC-200 Endpoint Custom Data Security Policies And Automated Investigation Practice Test

 

Skills 1.1 • 30 original questions

This Microsoft SC-200 Security Operations Analyst practice test focuses on endpoint custom data security policies and automated investigation through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a identity compromise review at Northwind Traders, the security engineer must collect the required custom endpoint telemetry in Defender for Endpoint. Which action most directly satisfies the requirement for the cloud-security team, response wave 1? The design priority is to avoid unnecessary alert noise.

  1. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  4. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  5. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal

Correct answer: C

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 2

Tailspin Toys is revising its SOC runbook after a endpoint containment exercise. Analysts need to apply the required Defender for Endpoint security policy or attack surface reduction control. Which implementation should the Tier 2 analyst select for the messaging-security team, response wave 1 while trying to preserve least privilege?

  1. Configure Defender for Endpoint device groups with the required permissions and automation level
  2. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: E

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 3

A ticket escalated to the threat hunter at Alpine Ski House states one non-negotiable goal: use automated investigation and response to investigate and remediate supported Defender XDR alerts. Which choice is the strongest fit for the night shift, response wave 1? The team also wants to reduce mean time to respond.

  1. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: A

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 4

For the Americas SOC, response wave 2 at Trey Research, a threat-hunting campaign can proceed only if the team can collect the required custom endpoint telemetry in Defender for Endpoint. What should the security engineer configure first if the operational goal is to reduce mean time to respond?

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  3. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  4. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  5. Configure the appropriate email notification rule in Microsoft Defender XDR

Correct answer: C

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 5

The security architecture review at Lucerne Publishing focuses on this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control. Which Microsoft security action is most appropriate for the high-value-assets group, response wave 2, given the need to scope the change to the affected security domain?

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action

Correct answer: A

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 6

A change advisory board at Northwind Traders asks how to use automated investigation and response to investigate and remediate supported Defender XDR alerts during a detection-engineering sprint. Which proposed action should the threat hunter approve for the privileged-users group, response wave 2? The change should keep the workflow auditable.

  1. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  2. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  3. Configure the appropriate email notification rule in Microsoft Defender XDR
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal

Correct answer: B

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 7

Woodgrove Bank has ruled out a manual one-off workaround. For the remote-user fleet, response wave 3, the remaining requirement is to collect the required custom endpoint telemetry in Defender for Endpoint. Which choice best addresses it and helps keep the workflow auditable?

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Configure the appropriate email notification rule in Microsoft Defender XDR
  4. Configure Defender for Endpoint device groups with the required permissions and automation level
  5. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Correct answer: A

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 8

During post-incident review at Blue Yonder Airlines, the Tier 2 analyst identifies a gap: the SOC still needs to apply the required Defender for Endpoint security policy or attack surface reduction control. Which action should be added for the production subscription, response wave 3 before the next incident, with an emphasis on trying to avoid changing an unrelated control plane?

  1. Configure the appropriate email notification rule in Microsoft Defender XDR
  2. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: E

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 9

The threat hunter at Trey Research is comparing several Microsoft security options for a lateral-movement investigation. Which one directly enables the team to use automated investigation and response to investigate and remediate supported Defender XDR alerts for the research subscription, response wave 3 while helping improve detection coverage?

  1. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: A

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 10

A security-operations workshop at Contoso Health defines the desired outcome as follows: collect the required custom endpoint telemetry in Defender for Endpoint. Which implementation should be chosen for the Tier 1 queue, response wave 4? The team wants to improve detection coverage.

  1. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  2. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: B

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 11

Which Microsoft security action best matches this technical purpose for the Tier 2 queue, response wave 4: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. The SOC is trying to support repeatable response.

  1. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal

Correct answer: B

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 12

An analyst at Woodgrove Bank describes the needed capability this way: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. Which option should be associated with that requirement for the identity-response team, response wave 4 while the team tries to separate collection from detection logic?

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  3. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  4. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  5. Configure the appropriate email notification rule in Microsoft Defender XDR

Correct answer: D

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 13

During a design validation for the cloud-security team, response wave 5, Fourth Coffee documents the following behavior: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. Which Microsoft security feature or action is being described? The objective is to separate collection from detection logic.

  1. Configure the appropriate email notification rule in Microsoft Defender XDR
  2. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Correct answer: E

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 14

The Tier 2 analyst must identify the Microsoft security capability that provides this function for the messaging-security team, response wave 5: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. Which choice is correct if the SOC also needs to preserve investigation context?

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  4. Configure Defender for Endpoint device groups with the required permissions and automation level
  5. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Correct answer: B

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 15

A runbook for the night shift, response wave 5 contains this description: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. Which implementation belongs in that runbook during a threat-hunting campaign? The process should minimize manual analyst steps.

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: B

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 16

Adventure Works is troubleshooting a phishing investigation. Evidence shows that the decisive requirement is to collect the required custom endpoint telemetry in Defender for Endpoint. Which action should the security engineer investigate first for the Americas SOC, response wave 6, without losing the ability to minimize manual analyst steps?

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  5. Configure the appropriate email notification rule in Microsoft Defender XDR

Correct answer: A

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 17

After eliminating network and licensing causes, the Tier 2 analyst at Proseware Services determines that success depends on the ability to apply the required Defender for Endpoint security policy or attack surface reduction control. Which security action should be checked next for the high-value-assets group, response wave 6? The team must retain evidence for follow-up analysis.

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: A

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 18

A service-desk escalation during a telemetry modernization has been narrowed to one security-operations requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts. Which configuration is the most relevant starting point for the privileged-users group, response wave 6 if the SOC wants to avoid unnecessary alert noise?

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Correct answer: C

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 19

The failure pattern at Wingtip Toys affects the remote-user fleet, response wave 7. Before making unrelated policy changes, the security engineer needs a solution that will collect the required custom endpoint telemetry in Defender for Endpoint. Which action is most directly relevant and helps avoid unnecessary alert noise?

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: A

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 20

While investigating a audit investigation, Fabrikam Retail confirms the environment must apply the required Defender for Endpoint security policy or attack surface reduction control. Which Microsoft security capability should be validated for the production subscription, response wave 7? The investigation should preserve least privilege.

  1. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: E

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 21

Two teams at Adventure Works propose different approaches for the research subscription, response wave 7. The selection criterion is simple: the chosen approach must use automated investigation and response to investigate and remediate supported Defender XDR alerts. Which option should win the technical comparison if the SOC also wants to reduce mean time to respond?

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  3. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Correct answer: E

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 22

For the Tier 1 queue, response wave 8, Alpine Ski House wants the least indirect solution to this goal: collect the required custom endpoint telemetry in Defender for Endpoint. Which action aligns most closely with that requirement and the need to reduce mean time to respond?

  1. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  2. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  3. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal

Correct answer: D

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 23

A modernization plan at Wide World Importers includes a cloud-workload incident. The Tier 2 analyst is asked to choose the control that specifically helps the organization apply the required Defender for Endpoint security policy or attack surface reduction control. Which choice fits best for the Tier 2 queue, response wave 8 while supporting the goal to scope the change to the affected security domain?

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  5. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal

Correct answer: A

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 24

The identity-response team, response wave 8 is moving into a controlled rollout at Wingtip Toys. Which action should be included when the stated security objective is to use automated investigation and response to investigate and remediate supported Defender XDR alerts? The operational standard is to keep the workflow auditable.

  1. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  2. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  3. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action

Correct answer: A

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 25

Northwind Traders is replacing an ad hoc process during a identity compromise review. The replacement must reliably collect the required custom endpoint telemetry in Defender for Endpoint. Which security-operations approach should the security engineer implement for the cloud-security team, response wave 9 if the team also wants to keep the workflow auditable?

  1. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  2. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Configure Defender for Endpoint device groups with the required permissions and automation level
  5. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Correct answer: E

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 26

An audit finding for the messaging-security team, response wave 9 says the current process does not consistently apply the required Defender for Endpoint security policy or attack surface reduction control. Which Microsoft security action most directly closes that gap while helping the SOC avoid changing an unrelated control plane?

  1. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow

Correct answer: B

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 27

The threat hunter at Alpine Ski House needs a repeatable configuration for the night shift, response wave 9. It must use automated investigation and response to investigate and remediate supported Defender XDR alerts. Which choice should be implemented instead of relying on manual incident work if the goal is to improve detection coverage?

  1. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  2. Configure the appropriate email notification rule in Microsoft Defender XDR
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: C

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Question 28

During readiness testing at Trey Research, the Americas SOC, response wave 10 fails a business requirement because analysts cannot yet collect the required custom endpoint telemetry in Defender for Endpoint. Which action should be implemented before rollout continues? The SOC also needs to improve detection coverage.

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: A

Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.

Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Question 29

A governance review asks the Tier 2 analyst to justify the control selected for the high-value-assets group, response wave 10. The requirement is to apply the required Defender for Endpoint security policy or attack surface reduction control. Which action has the clearest technical alignment while supporting the goal to support repeatable response?

  1. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: E

Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Option review:

A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.

Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Question 30

For a detection-engineering sprint, Northwind Traders needs a Microsoft security capability with this effect: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. Which option most accurately provides that capability for the privileged-users group, response wave 10? The process should separate collection from detection logic.

  1. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: A

Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Option review:

A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.

Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Popular posts

img