Microsoft SC-200 Defender For Cloud Apps Entra ID And Defender For Identity Response Practice Test

 

Skills 2.1 • 40 original questions

This Microsoft SC-200 Security Operations Analyst practice test focuses on defender for cloud apps entra id and defender for identity response through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a multi-cloud monitoring rollout at Fourth Coffee, the security engineer must investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which action most directly satisfies the requirement for the cloud-security team, response wave 1? The design priority is to keep the workflow auditable.

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: A

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 2

  1. Datum is revising its SOC runbook after a ransomware response. Analysts need to investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which implementation should the Tier 2 analyst select for the messaging-security team, response wave 1 while trying to avoid changing an unrelated control plane?
  2. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  6. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: E

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 3

A ticket escalated to the threat hunter at Contoso Health states one non-negotiable goal: investigate the identity-infrastructure alert raised by Defender for Identity. Which choice is the strongest fit for the night shift, response wave 1? The team also wants to improve detection coverage.

  1. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: C

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 4

For the Americas SOC, response wave 2 at Adventure Works, a phishing investigation can proceed only if the team can investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. What should the security engineer configure first if the operational goal is to improve detection coverage?

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: E

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 5

The security architecture review at Proseware Services focuses on this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which Microsoft security action is most appropriate for the high-value-assets group, response wave 2, given the need to support repeatable response?

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: C

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 6

A change advisory board at Fourth Coffee asks how to investigate the identity-infrastructure alert raised by Defender for Identity during a telemetry modernization. Which proposed action should the threat hunter approve for the privileged-users group, response wave 2? The change should separate collection from detection logic.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: A

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 7

Wingtip Toys has ruled out a manual one-off workaround. For the remote-user fleet, response wave 3, the remaining requirement is to investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which choice best addresses it and helps separate collection from detection logic?

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: D

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 8

During post-incident review at Fabrikam Retail, the Tier 2 analyst identifies a gap: the SOC still needs to investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which action should be added for the production subscription, response wave 3 before the next incident, with an emphasis on trying to preserve investigation context?

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: C

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 9

The threat hunter at Adventure Works is comparing several Microsoft security options for a SOC tuning initiative. Which one directly enables the team to investigate the identity-infrastructure alert raised by Defender for Identity for the research subscription, response wave 3 while helping minimize manual analyst steps?

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: E

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 10

A security-operations workshop at Alpine Ski House defines the desired outcome as follows: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which implementation should be chosen for the Tier 1 queue, response wave 4? The team wants to minimize manual analyst steps.

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: E

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 11

Which Microsoft security action best matches this technical purpose for the Tier 2 queue, response wave 4: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. The SOC is trying to retain evidence for follow-up analysis.

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: B

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 12

An analyst at Wingtip Toys describes the needed capability this way: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. Which option should be associated with that requirement for the identity-response team, response wave 4 while the team tries to avoid unnecessary alert noise?

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: A

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 13

During a design validation for the cloud-security team, response wave 5, Northwind Traders documents the following behavior: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. Which Microsoft security feature or action is being described? The objective is to avoid unnecessary alert noise.

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 14

The Tier 2 analyst must identify the Microsoft security capability that provides this function for the messaging-security team, response wave 5: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. Which choice is correct if the SOC also needs to preserve least privilege?

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: D

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 15

A runbook for the night shift, response wave 5 contains this description: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. Which implementation belongs in that runbook during a phishing investigation? The process should reduce mean time to respond.

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: E

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 16

Trey Research is troubleshooting a threat-hunting campaign. Evidence shows that the decisive requirement is to investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which action should the security engineer investigate first for the Americas SOC, response wave 6, without losing the ability to reduce mean time to respond?

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: D

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 17

After eliminating network and licensing causes, the Tier 2 analyst at Lucerne Publishing determines that success depends on the ability to investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which security action should be checked next for the high-value-assets group, response wave 6? The team must scope the change to the affected security domain.

  1. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: C

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 18

A service-desk escalation during a detection-engineering sprint has been narrowed to one security-operations requirement: investigate the identity-infrastructure alert raised by Defender for Identity. Which configuration is the most relevant starting point for the privileged-users group, response wave 6 if the SOC wants to keep the workflow auditable?

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: C

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 19

The failure pattern at Woodgrove Bank affects the remote-user fleet, response wave 7. Before making unrelated policy changes, the security engineer needs a solution that will investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which action is most directly relevant and helps keep the workflow auditable?

  1. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: C

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 20

While investigating a data-ingestion rollout, Blue Yonder Airlines confirms the environment must investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which Microsoft security capability should be validated for the production subscription, response wave 7? The investigation should avoid changing an unrelated control plane.

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: B

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 21

Two teams at Trey Research propose different approaches for the research subscription, response wave 7. The selection criterion is simple: the chosen approach must investigate the identity-infrastructure alert raised by Defender for Identity. Which option should win the technical comparison if the SOC also wants to improve detection coverage?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: E

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 22

For the Tier 1 queue, response wave 8, Contoso Health wants the least indirect solution to this goal: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which action aligns most closely with that requirement and the need to improve detection coverage?

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Correct answer: A

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 23

A modernization plan at Litware Manufacturing includes a security automation project. The Tier 2 analyst is asked to choose the control that specifically helps the organization investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which choice fits best for the Tier 2 queue, response wave 8 while supporting the goal to support repeatable response?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: B

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 24

The identity-response team, response wave 8 is moving into a controlled rollout at Woodgrove Bank. Which action should be included when the stated security objective is to investigate the identity-infrastructure alert raised by Defender for Identity? The operational standard is to separate collection from detection logic.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: A

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 25

Fourth Coffee is replacing an ad hoc process during a multi-cloud monitoring rollout. The replacement must reliably investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which security-operations approach should the security engineer implement for the cloud-security team, response wave 9 if the team also wants to separate collection from detection logic?

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: D

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 26

An audit finding for the messaging-security team, response wave 9 says the current process does not consistently investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which Microsoft security action most directly closes that gap while helping the SOC preserve investigation context?

  1. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  2. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: C

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 27

The threat hunter at Contoso Health needs a repeatable configuration for the night shift, response wave 9. It must investigate the identity-infrastructure alert raised by Defender for Identity. Which choice should be implemented instead of relying on manual incident work if the goal is to minimize manual analyst steps?

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: B

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 28

During readiness testing at Adventure Works, the Americas SOC, response wave 10 fails a business requirement because analysts cannot yet investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which action should be implemented before rollout continues? The SOC also needs to minimize manual analyst steps.

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: E

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 29

A governance review asks the Tier 2 analyst to justify the control selected for the high-value-assets group, response wave 10. The requirement is to investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which action has the clearest technical alignment while supporting the goal to retain evidence for follow-up analysis?

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: E

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 30

For a telemetry modernization, Fourth Coffee needs a Microsoft security capability with this effect: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. Which option most accurately provides that capability for the privileged-users group, response wave 10? The process should avoid unnecessary alert noise.

  1. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: D

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 31

The operational standard for the remote-user fleet, response wave 11 is being rewritten. Which action should be documented when the standard requires analysts to investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation and the SOC wants to avoid unnecessary alert noise?

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: D

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 32

Fabrikam Retail is creating a response playbook for the production subscription, response wave 11. Which Microsoft security step belongs in the playbook when the objective is to investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky? The playbook should also help preserve least privilege.

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: E

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 33

During a SOC tuning initiative at Adventure Works, the threat hunter must investigate the identity-infrastructure alert raised by Defender for Identity. Which action most directly satisfies the requirement for the research subscription, response wave 11? The design priority is to reduce mean time to respond.

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: B

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 34

Alpine Ski House is revising its SOC runbook after a lateral-movement investigation. Analysts need to investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which implementation should the security engineer select for the Tier 1 queue, response wave 12 while trying to reduce mean time to respond?

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: C

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 35

A ticket escalated to the Tier 2 analyst at Wide World Importers states one non-negotiable goal: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky. Which choice is the strongest fit for the Tier 2 queue, response wave 12? The team also wants to scope the change to the affected security domain.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: D

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 36

For the identity-response team, response wave 12 at Wingtip Toys, a multi-cloud monitoring rollout can proceed only if the team can investigate the identity-infrastructure alert raised by Defender for Identity. What should the threat hunter configure first if the operational goal is to keep the workflow auditable?

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: A

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 37

The security architecture review at Northwind Traders focuses on this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which Microsoft security action is most appropriate for the cloud-security team, response wave 13, given the need to keep the workflow auditable?

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: A

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Question 38

A change advisory board at Tailspin Toys asks how to investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky during a endpoint containment exercise. Which proposed action should the Tier 2 analyst approve for the messaging-security team, response wave 13? The change should avoid changing an unrelated control plane.

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. This directly addresses the requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the identity that Microsoft Entra ID has identified as compromised or risky.

Learning point: Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Question 39

Alpine Ski House has ruled out a manual one-off workaround. For the night shift, response wave 13, the remaining requirement is to investigate the identity-infrastructure alert raised by Defender for Identity. Which choice best addresses it and helps improve detection coverage?

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: D

Why: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. This directly addresses the requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the identity-infrastructure alert raised by Defender for Identity.

Learning point: Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Question 40

During post-incident review at Trey Research, the security engineer identifies a gap: the SOC still needs to investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation. Which action should be added for the Americas SOC, response wave 14 before the next incident, with an emphasis on trying to improve detection coverage?

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: B

Why: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. This directly addresses the requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the risky SaaS or cloud-app behavior and apply a Defender for Cloud Apps remediation.

Learning point: Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Popular posts

img