Microsoft SC-200 Microsoft Purview Audit eDiscovery Content Search And Graph Activity Logs Practice Test
Skills 2.3 • 35 original questions
This Microsoft SC-200 Security Operations Analyst practice test focuses on microsoft purview audit ediscovery content search and graph activity logs through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a telemetry modernization at Wingtip Toys, the Defender administrator must determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action most directly satisfies the requirement for the remote-user fleet, response wave 1? The design priority is to avoid unnecessary alert noise.
Correct answer: D
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
Fabrikam Retail is revising its SOC runbook after a data-ingestion rollout. Analysts need to locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which implementation should the incident responder select for the production subscription, response wave 1 while trying to preserve least privilege?
Correct answer: B
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
A ticket escalated to the security operations analyst at Adventure Works states one non-negotiable goal: investigate suspicious Microsoft Graph API or application activity. Which choice is the strongest fit for the research subscription, response wave 1? The team also wants to reduce mean time to respond.
Correct answer: C
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
D: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
E: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
For the Tier 1 queue, response wave 2 at Alpine Ski House, a SOC tuning initiative can proceed only if the team can determine which Microsoft 365 user or administrator action occurred during the investigation window. What should the Defender administrator configure first if the operational goal is to reduce mean time to respond?
Correct answer: C
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
The security architecture review at Wide World Importers focuses on this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which Microsoft security action is most appropriate for the Tier 2 queue, response wave 2, given the need to scope the change to the affected security domain?
Correct answer: A
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
A change advisory board at Wingtip Toys asks how to investigate suspicious Microsoft Graph API or application activity during a identity compromise review. Which proposed action should the security operations analyst approve for the identity-response team, response wave 2? The change should keep the workflow auditable.
Correct answer: D
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
Northwind Traders has ruled out a manual one-off workaround. For the cloud-security team, response wave 3, the remaining requirement is to determine which Microsoft 365 user or administrator action occurred during the investigation window. Which choice best addresses it and helps keep the workflow auditable?
Correct answer: A
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
During post-incident review at Tailspin Toys, the incident responder identifies a gap: the SOC still needs to locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which action should be added for the messaging-security team, response wave 3 before the next incident, with an emphasis on trying to avoid changing an unrelated control plane?
Correct answer: E
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
The security operations analyst at Alpine Ski House is comparing several Microsoft security options for a threat-hunting campaign. Which one directly enables the team to investigate suspicious Microsoft Graph API or application activity for the night shift, response wave 3 while helping improve detection coverage?
Correct answer: C
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
A security-operations workshop at Trey Research defines the desired outcome as follows: determine which Microsoft 365 user or administrator action occurred during the investigation window. Which implementation should be chosen for the Americas SOC, response wave 4? The team wants to improve detection coverage.
Correct answer: A
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
Which Microsoft security action best matches this technical purpose for the high-value-assets group, response wave 4: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. The SOC is trying to support repeatable response.
Correct answer: C
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
An analyst at Northwind Traders describes the needed capability this way: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. Which option should be associated with that requirement for the privileged-users group, response wave 4 while the team tries to separate collection from detection logic?
Correct answer: E
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
During a design validation for the remote-user fleet, response wave 5, Woodgrove Bank documents the following behavior: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. Which Microsoft security feature or action is being described? The objective is to separate collection from detection logic.
Correct answer: D
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
The incident responder must identify the Microsoft security capability that provides this function for the production subscription, response wave 5: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. Which choice is correct if the SOC also needs to preserve investigation context?
Correct answer: D
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
A runbook for the research subscription, response wave 5 contains this description: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. Which implementation belongs in that runbook during a SOC tuning initiative? The process should minimize manual analyst steps.
Correct answer: D
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
Contoso Health is troubleshooting a lateral-movement investigation. Evidence shows that the decisive requirement is to determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action should the Defender administrator investigate first for the Tier 1 queue, response wave 6, without losing the ability to minimize manual analyst steps?
Correct answer: A
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
After eliminating network and licensing causes, the incident responder at Litware Manufacturing determines that success depends on the ability to locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which security action should be checked next for the Tier 2 queue, response wave 6? The team must retain evidence for follow-up analysis.
Correct answer: B
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
A service-desk escalation during a multi-cloud monitoring rollout has been narrowed to one security-operations requirement: investigate suspicious Microsoft Graph API or application activity. Which configuration is the most relevant starting point for the identity-response team, response wave 6 if the SOC wants to avoid unnecessary alert noise?
Correct answer: D
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
The failure pattern at Fourth Coffee affects the cloud-security team, response wave 7. Before making unrelated policy changes, the Defender administrator needs a solution that will determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action is most directly relevant and helps avoid unnecessary alert noise?
Correct answer: A
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
While investigating a endpoint containment exercise, A. Datum confirms the environment must locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which Microsoft security capability should be validated for the messaging-security team, response wave 7? The investigation should preserve least privilege.
Correct answer: A
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
Two teams at Contoso Health propose different approaches for the night shift, response wave 7. The selection criterion is simple: the chosen approach must investigate suspicious Microsoft Graph API or application activity. Which option should win the technical comparison if the SOC also wants to reduce mean time to respond?
Correct answer: E
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
D: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
For the Americas SOC, response wave 8, Adventure Works wants the least indirect solution to this goal: determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action aligns most closely with that requirement and the need to reduce mean time to respond?
Correct answer: A
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
A modernization plan at Proseware Services includes a SOC handoff review. The incident responder is asked to choose the control that specifically helps the organization locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which choice fits best for the high-value-assets group, response wave 8 while supporting the goal to scope the change to the affected security domain?
Correct answer: B
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
The privileged-users group, response wave 8 is moving into a controlled rollout at Fourth Coffee. Which action should be included when the stated security objective is to investigate suspicious Microsoft Graph API or application activity? The operational standard is to keep the workflow auditable.
Correct answer: B
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
Wingtip Toys is replacing an ad hoc process during a telemetry modernization. The replacement must reliably determine which Microsoft 365 user or administrator action occurred during the investigation window. Which security-operations approach should the Defender administrator implement for the remote-user fleet, response wave 9 if the team also wants to keep the workflow auditable?
Correct answer: B
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
An audit finding for the production subscription, response wave 9 says the current process does not consistently locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which Microsoft security action most directly closes that gap while helping the SOC avoid changing an unrelated control plane?
Correct answer: A
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
The security operations analyst at Adventure Works needs a repeatable configuration for the research subscription, response wave 9. It must investigate suspicious Microsoft Graph API or application activity. Which choice should be implemented instead of relying on manual incident work if the goal is to improve detection coverage?
Correct answer: A
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
E: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
During readiness testing at Alpine Ski House, the Tier 1 queue, response wave 10 fails a business requirement because analysts cannot yet determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action should be implemented before rollout continues? The SOC also needs to improve detection coverage.
Correct answer: B
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
A governance review asks the incident responder to justify the control selected for the Tier 2 queue, response wave 10. The requirement is to locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which action has the clearest technical alignment while supporting the goal to support repeatable response?
Correct answer: A
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
For a identity compromise review, Wingtip Toys needs a Microsoft security capability with this effect: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. Which option most accurately provides that capability for the identity-response team, response wave 10? The process should separate collection from detection logic.
Correct answer: D
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
The operational standard for the cloud-security team, response wave 11 is being rewritten. Which action should be documented when the standard requires analysts to determine which Microsoft 365 user or administrator action occurred during the investigation window and the SOC wants to separate collection from detection logic?
Correct answer: D
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
Tailspin Toys is creating a response playbook for the messaging-security team, response wave 11. Which Microsoft security step belongs in the playbook when the objective is to locate the relevant Microsoft 365 messages or files that match the investigation criteria? The playbook should also help preserve investigation context.
Correct answer: B
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
During a threat-hunting campaign at Alpine Ski House, the security operations analyst must investigate suspicious Microsoft Graph API or application activity. Which action most directly satisfies the requirement for the night shift, response wave 11? The design priority is to minimize manual analyst steps.
Correct answer: C
Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
Option review:
A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
B: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.
D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
E: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.
Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
Trey Research is revising its SOC runbook after a phishing investigation. Analysts need to determine which Microsoft 365 user or administrator action occurred during the investigation window. Which implementation should the Defender administrator select for the Americas SOC, response wave 12 while trying to minimize manual analyst steps?
Correct answer: B
Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Option review:
A: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.
Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
A ticket escalated to the incident responder at Lucerne Publishing states one non-negotiable goal: locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which choice is the strongest fit for the high-value-assets group, response wave 12? The team also wants to retain evidence for follow-up analysis.
Correct answer: B
Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Option review:
A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.
Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
Popular posts
Recent Posts
