Microsoft SC-200 Defender For Endpoint Device Timelines Live Response And Investigation Packages Practice Test

 

Skills 2.2 • 35 original questions

This Microsoft SC-200 Security Operations Analyst practice test focuses on defender for endpoint device timelines live response and investigation packages through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a lateral-movement investigation at Trey Research, the threat hunter must reconstruct what happened on the affected endpoint in chronological order. Which action most directly satisfies the requirement for the Americas SOC, response wave 1? The design priority is to reduce mean time to respond.

  1. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: A

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 2

Lucerne Publishing is revising its SOC runbook after a cloud-workload incident. Analysts need to interact with the endpoint remotely or collect its investigation artifacts for analysis. Which implementation should the SOC analyst select for the high-value-assets group, response wave 1 while trying to scope the change to the affected security domain?

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Correct answer: B

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 3

A ticket escalated to the Tier 2 analyst at Litware Manufacturing states one non-negotiable goal: reconstruct what happened on the affected endpoint in chronological order. Which choice is the strongest fit for the server fleet, response wave 2? The team also wants to scope the change to the affected security domain.

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: B

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 4

For the remote-user fleet, response wave 2 at Woodgrove Bank, a identity compromise review can proceed only if the team can interact with the endpoint remotely or collect its investigation artifacts for analysis. What should the threat hunter configure first if the operational goal is to keep the workflow auditable?

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Correct answer: A

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 5

The security architecture review at Fourth Coffee focuses on this requirement: reconstruct what happened on the affected endpoint in chronological order. Which Microsoft security action is most appropriate for the research subscription, response wave 3, given the need to keep the workflow auditable?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: B

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 6

A change advisory board at A. Datum asks how to interact with the endpoint remotely or collect its investigation artifacts for analysis during a ransomware response. Which proposed action should the Tier 2 analyst approve for the regulated workload segment, response wave 3? The change should avoid changing an unrelated control plane.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Correct answer: E

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 7

Fabrikam Retail has ruled out a manual one-off workaround. For the Tier 2 queue, response wave 4, the remaining requirement is to reconstruct what happened on the affected endpoint in chronological order. Which choice best addresses it and helps avoid changing an unrelated control plane?

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  4. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: B

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 8

During post-incident review at Adventure Works, the security engineer identifies a gap: the SOC still needs to interact with the endpoint remotely or collect its investigation artifacts for analysis. Which action should be added for the identity-response team, response wave 4 before the next incident, with an emphasis on trying to improve detection coverage?

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  5. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Correct answer: E

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 9

The security operations analyst at Alpine Ski House is comparing several Microsoft security options for a threat-hunting campaign. Which one directly enables the team to reconstruct what happened on the affected endpoint in chronological order for the cloud-security team, response wave 5 while helping improve detection coverage?

  1. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  5. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Correct answer: E

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 10

A security-operations workshop at Wide World Importers defines the desired outcome as follows: interact with the endpoint remotely or collect its investigation artifacts for analysis. Which implementation should be chosen for the messaging-security team, response wave 5? The team wants to support repeatable response.

  1. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  2. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  3. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Correct answer: E

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 11

Which Microsoft security action best matches this technical purpose for the EMEA SOC, response wave 6: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. The SOC is trying to support repeatable response.

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: D

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 12

An analyst at Northwind Traders describes the needed capability this way: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. Which option should be associated with that requirement for the Americas SOC, response wave 6 while the team tries to separate collection from detection logic?

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  3. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  4. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  5. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Correct answer: A

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 13

During a design validation for the privileged-users group, response wave 7, Woodgrove Bank documents the following behavior: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. Which Microsoft security feature or action is being described? The objective is to separate collection from detection logic.

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  5. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Correct answer: D

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 14

The incident responder must identify the Microsoft security capability that provides this function for the server fleet, response wave 7: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. Which choice is correct if the SOC also needs to preserve investigation context?

  1. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  4. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: C

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 15

A runbook for the production subscription, response wave 8 contains this description: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. Which implementation belongs in that runbook during a data-ingestion rollout? The process should preserve investigation context.

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  4. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  5. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Correct answer: E

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 16

Contoso Health is troubleshooting a lateral-movement investigation. Evidence shows that the decisive requirement is to interact with the endpoint remotely or collect its investigation artifacts for analysis. Which action should the Defender administrator investigate first for the research subscription, response wave 8, without losing the ability to minimize manual analyst steps?

  1. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 17

After eliminating network and licensing causes, the threat hunter at Adventure Works determines that success depends on the ability to reconstruct what happened on the affected endpoint in chronological order. Which security action should be checked next for the Tier 1 queue, response wave 9? The team must minimize manual analyst steps.

  1. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  2. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  5. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Correct answer: D

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 18

A service-desk escalation during a security automation project has been narrowed to one security-operations requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis. Which configuration is the most relevant starting point for the Tier 2 queue, response wave 9 if the SOC wants to retain evidence for follow-up analysis?

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: A

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 19

The failure pattern at Wide World Importers affects the endpoint-response team, response wave 10. Before making unrelated policy changes, the Tier 2 analyst needs a solution that will reconstruct what happened on the affected endpoint in chronological order. Which action is most directly relevant and helps retain evidence for follow-up analysis?

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  4. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: B

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 20

While investigating a multi-cloud monitoring rollout, Wingtip Toys confirms the environment must interact with the endpoint remotely or collect its investigation artifacts for analysis. Which Microsoft security capability should be validated for the cloud-security team, response wave 10? The investigation should avoid unnecessary alert noise.

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Correct answer: A

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 21

Two teams at Northwind Traders propose different approaches for the night shift, response wave 11. The selection criterion is simple: the chosen approach must reconstruct what happened on the affected endpoint in chronological order. Which option should win the technical comparison if the SOC also wants to avoid unnecessary alert noise?

  1. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  2. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: A

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 22

For the EMEA SOC, response wave 11, Tailspin Toys wants the least indirect solution to this goal: interact with the endpoint remotely or collect its investigation artifacts for analysis. Which action aligns most closely with that requirement and the need to preserve least privilege?

  1. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  2. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: B

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 23

A modernization plan at Blue Yonder Airlines includes a ransomware response. The Sentinel administrator is asked to choose the control that specifically helps the organization reconstruct what happened on the affected endpoint in chronological order. Which choice fits best for the high-value-assets group, response wave 12 while supporting the goal to preserve least privilege?

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  3. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: C

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 24

The privileged-users group, response wave 12 is moving into a controlled rollout at Trey Research. Which action should be included when the stated security objective is to interact with the endpoint remotely or collect its investigation artifacts for analysis? The operational standard is to reduce mean time to respond.

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Correct answer: A

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 25

Contoso Health is replacing an ad hoc process during a phishing investigation. The replacement must reliably reconstruct what happened on the affected endpoint in chronological order. Which security-operations approach should the security operations analyst implement for the remote-user fleet, response wave 13 if the team also wants to reduce mean time to respond?

  1. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: A

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 26

An audit finding for the production subscription, response wave 13 says the current process does not consistently interact with the endpoint remotely or collect its investigation artifacts for analysis. Which Microsoft security action most directly closes that gap while helping the SOC scope the change to the affected security domain?

  1. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: D

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 27

The incident responder at Proseware Services needs a repeatable configuration for the regulated workload segment, response wave 14. It must reconstruct what happened on the affected endpoint in chronological order. Which choice should be implemented instead of relying on manual incident work if the goal is to scope the change to the affected security domain?

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Correct answer: E

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 28

During readiness testing at Fourth Coffee, the Tier 1 queue, response wave 14 fails a business requirement because analysts cannot yet interact with the endpoint remotely or collect its investigation artifacts for analysis. Which action should be implemented before rollout continues? The SOC also needs to keep the workflow auditable.

  1. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  2. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Correct answer: B

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 29

A governance review asks the Defender administrator to justify the control selected for the identity-response team, response wave 15. The requirement is to reconstruct what happened on the affected endpoint in chronological order. Which action has the clearest technical alignment while supporting the goal to keep the workflow auditable?

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  4. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  5. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Correct answer: B

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 30

For a data-ingestion rollout, Fabrikam Retail needs a Microsoft security capability with this effect: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. Which option most accurately provides that capability for the endpoint-response team, response wave 15? The process should avoid changing an unrelated control plane.

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  3. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  4. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  5. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Correct answer: E

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 31

The operational standard for the messaging-security team, response wave 16 is being rewritten. Which action should be documented when the standard requires analysts to reconstruct what happened on the affected endpoint in chronological order and the SOC wants to avoid changing an unrelated control plane?

  1. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: B

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 32

Alpine Ski House is creating a response playbook for the night shift, response wave 16. Which Microsoft security step belongs in the playbook when the objective is to interact with the endpoint remotely or collect its investigation artifacts for analysis? The playbook should also help improve detection coverage.

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: D

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 33

During a lateral-movement investigation at Trey Research, the threat hunter must reconstruct what happened on the affected endpoint in chronological order. Which action most directly satisfies the requirement for the Americas SOC, response wave 17? The design priority is to improve detection coverage.

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  3. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Correct answer: C

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Question 34

Lucerne Publishing is revising its SOC runbook after a cloud-workload incident. Analysts need to interact with the endpoint remotely or collect its investigation artifacts for analysis. Which implementation should the SOC analyst select for the high-value-assets group, response wave 17 while trying to support repeatable response?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  5. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Correct answer: E

Why: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

D: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. This directly addresses the requirement: interact with the endpoint remotely or collect its investigation artifacts for analysis.

Learning point: Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Question 35

A ticket escalated to the Tier 2 analyst at Litware Manufacturing states one non-negotiable goal: reconstruct what happened on the affected endpoint in chronological order. Which choice is the strongest fit for the server fleet, response wave 18? The team also wants to support repeatable response.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Correct answer: E

Why: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: reconstruct what happened on the affected endpoint in chronological order.

E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. This directly addresses the requirement: reconstruct what happened on the affected endpoint in chronological order.

Learning point: Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Popular posts

img