Microsoft SC-200 Defender For Office Purview And Defender For Cloud Incident Response Practice Test
Skills 2.1 • 40 original questions
This Microsoft SC-200 Security Operations Analyst practice test focuses on defender for office purview and defender for cloud incident response through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a endpoint containment exercise at Blue Yonder Airlines, the SOC analyst must investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action most directly satisfies the requirement for the identity-response team, response wave 1? The design priority is to avoid changing an unrelated control plane.
Correct answer: A
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
Trey Research is revising its SOC runbook after a phishing investigation. Analysts need to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which implementation should the Defender administrator select for the endpoint-response team, response wave 1 while trying to improve detection coverage?
Correct answer: E
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
A ticket escalated to the incident responder at Lucerne Publishing states one non-negotiable goal: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which choice is the strongest fit for the cloud-security team, response wave 1? The team also wants to support repeatable response.
Correct answer: D
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
For the night shift, response wave 2 at Litware Manufacturing, a SOC handoff review can proceed only if the team can investigate and remediate the malicious email or collaboration threat with Defender for Office 365. What should the SOC analyst configure first if the operational goal is to support repeatable response?
Correct answer: D
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
The security architecture review at Woodgrove Bank focuses on this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which Microsoft security action is most appropriate for the EMEA SOC, response wave 2, given the need to separate collection from detection logic?
Correct answer: A
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
A change advisory board at Blue Yonder Airlines asks how to investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context during a audit investigation. Which proposed action should the incident responder approve for the Americas SOC, response wave 2? The change should preserve investigation context.
Correct answer: A
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
Correct answer: B
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
During post-incident review at Contoso Health, the Defender administrator identifies a gap: the SOC still needs to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which action should be added for the server fleet, response wave 3 before the next incident, with an emphasis on trying to minimize manual analyst steps?
Correct answer: D
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
The incident responder at Litware Manufacturing is comparing several Microsoft security options for a cloud-workload incident. Which one directly enables the team to investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context for the remote-user fleet, response wave 3 while helping retain evidence for follow-up analysis?
Correct answer: D
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
A security-operations workshop at Proseware Services defines the desired outcome as follows: investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which implementation should be chosen for the research subscription, response wave 4? The team wants to retain evidence for follow-up analysis.
Correct answer: A
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
Which Microsoft security action best matches this technical purpose for the regulated workload segment, response wave 4: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. The SOC is trying to avoid unnecessary alert noise.
Correct answer: D
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
An analyst at A. Datum describes the needed capability this way: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. Which option should be associated with that requirement for the Tier 1 queue, response wave 4 while the team tries to preserve least privilege?
Correct answer: E
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
During a design validation for the identity-response team, response wave 5, Fabrikam Retail documents the following behavior: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. Which Microsoft security feature or action is being described? The objective is to preserve least privilege.
Correct answer: B
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
The Defender administrator must identify the Microsoft security capability that provides this function for the endpoint-response team, response wave 5: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. Which choice is correct if the SOC also needs to reduce mean time to respond?
Correct answer: D
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
A runbook for the cloud-security team, response wave 5 contains this description: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. Which implementation belongs in that runbook during a SOC handoff review? The process should scope the change to the affected security domain.
Correct answer: B
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
Wide World Importers is troubleshooting a post-incident review. Evidence shows that the decisive requirement is to investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action should the SOC analyst investigate first for the night shift, response wave 6, without losing the ability to scope the change to the affected security domain?
Correct answer: C
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
After eliminating network and licensing causes, the Defender administrator at Wingtip Toys determines that success depends on the ability to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which security action should be checked next for the EMEA SOC, response wave 6? The team must keep the workflow auditable.
Correct answer: C
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
A service-desk escalation during a data-ingestion rollout has been narrowed to one security-operations requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which configuration is the most relevant starting point for the Americas SOC, response wave 6 if the SOC wants to avoid changing an unrelated control plane?
Correct answer: C
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
The failure pattern at Tailspin Toys affects the privileged-users group, response wave 7. Before making unrelated policy changes, the SOC analyst needs a solution that will investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action is most directly relevant and helps avoid changing an unrelated control plane?
Correct answer: E
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
While investigating a SOC tuning initiative, Alpine Ski House confirms the environment must investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which Microsoft security capability should be validated for the server fleet, response wave 7? The investigation should improve detection coverage.
Correct answer: C
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
Two teams at Wide World Importers propose different approaches for the remote-user fleet, response wave 7. The selection criterion is simple: the chosen approach must investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which option should win the technical comparison if the SOC also wants to support repeatable response?
Correct answer: B
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
For the research subscription, response wave 8, Lucerne Publishing wants the least indirect solution to this goal: investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action aligns most closely with that requirement and the need to support repeatable response?
Correct answer: B
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
A modernization plan at Northwind Traders includes a multi-cloud monitoring rollout. The Defender administrator is asked to choose the control that specifically helps the organization investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which choice fits best for the regulated workload segment, response wave 8 while supporting the goal to separate collection from detection logic?
Correct answer: C
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
The Tier 1 queue, response wave 8 is moving into a controlled rollout at Tailspin Toys. Which action should be included when the stated security objective is to investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context? The operational standard is to preserve investigation context.
Correct answer: D
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
Blue Yonder Airlines is replacing an ad hoc process during a endpoint containment exercise. The replacement must reliably investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which security-operations approach should the SOC analyst implement for the identity-response team, response wave 9 if the team also wants to preserve investigation context?
Correct answer: C
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
An audit finding for the endpoint-response team, response wave 9 says the current process does not consistently investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which Microsoft security action most directly closes that gap while helping the SOC minimize manual analyst steps?
Correct answer: E
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
The incident responder at Lucerne Publishing needs a repeatable configuration for the cloud-security team, response wave 9. It must investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which choice should be implemented instead of relying on manual incident work if the goal is to retain evidence for follow-up analysis?
Correct answer: D
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
During readiness testing at Litware Manufacturing, the night shift, response wave 10 fails a business requirement because analysts cannot yet investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action should be implemented before rollout continues? The SOC also needs to retain evidence for follow-up analysis.
Correct answer: B
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
A governance review asks the Defender administrator to justify the control selected for the EMEA SOC, response wave 10. The requirement is to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which action has the clearest technical alignment while supporting the goal to avoid unnecessary alert noise?
Correct answer: E
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
For a audit investigation, Blue Yonder Airlines needs a Microsoft security capability with this effect: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. Which option most accurately provides that capability for the Americas SOC, response wave 10? The process should preserve least privilege.
Correct answer: B
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
The operational standard for the privileged-users group, response wave 11 is being rewritten. Which action should be documented when the standard requires analysts to investigate and remediate the malicious email or collaboration threat with Defender for Office 365 and the SOC wants to preserve least privilege?
Correct answer: B
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
Contoso Health is creating a response playbook for the server fleet, response wave 11. Which Microsoft security step belongs in the playbook when the objective is to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation? The playbook should also help reduce mean time to respond.
Correct answer: D
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
During a cloud-workload incident at Litware Manufacturing, the incident responder must investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which action most directly satisfies the requirement for the remote-user fleet, response wave 11? The design priority is to scope the change to the affected security domain.
Correct answer: C
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
Proseware Services is revising its SOC runbook after a security automation project. Analysts need to investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which implementation should the SOC analyst select for the research subscription, response wave 12 while trying to scope the change to the affected security domain?
Correct answer: D
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
A ticket escalated to the Defender administrator at Fourth Coffee states one non-negotiable goal: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which choice is the strongest fit for the regulated workload segment, response wave 12? The team also wants to keep the workflow auditable.
Correct answer: D
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
For the Tier 1 queue, response wave 12 at A. Datum, a endpoint containment exercise can proceed only if the team can investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. What should the incident responder configure first if the operational goal is to avoid changing an unrelated control plane?
Correct answer: D
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
The security architecture review at Fabrikam Retail focuses on this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which Microsoft security action is most appropriate for the identity-response team, response wave 13, given the need to avoid changing an unrelated control plane?
Correct answer: C
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
A change advisory board at Adventure Works asks how to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation during a threat-hunting campaign. Which proposed action should the Defender administrator approve for the endpoint-response team, response wave 13? The change should improve detection coverage.
Correct answer: C
Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Option review:
A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.
Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
Proseware Services has ruled out a manual one-off workaround. For the cloud-security team, response wave 13, the remaining requirement is to investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which choice best addresses it and helps support repeatable response?
Correct answer: D
Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.
Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
During post-incident review at Wide World Importers, the SOC analyst identifies a gap: the SOC still needs to investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action should be added for the night shift, response wave 14 before the next incident, with an emphasis on trying to support repeatable response?
Correct answer: E
Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Option review:
A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.
Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
Popular posts
Recent Posts
