Microsoft SC-200 Microsoft Purview Audit eDiscovery Content Search And Graph Activity Logs Practice Test

 

Skills 2.3 • 35 original questions

This Microsoft SC-200 Security Operations Analyst practice test focuses on microsoft purview audit ediscovery content search and graph activity logs through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a telemetry modernization at Wingtip Toys, the Defender administrator must determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action most directly satisfies the requirement for the remote-user fleet, response wave 1? The design priority is to avoid unnecessary alert noise.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  4. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: D

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 2

Fabrikam Retail is revising its SOC runbook after a data-ingestion rollout. Analysts need to locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which implementation should the incident responder select for the production subscription, response wave 1 while trying to preserve least privilege?

  1. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  2. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  3. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  4. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: B

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 3

A ticket escalated to the security operations analyst at Adventure Works states one non-negotiable goal: investigate suspicious Microsoft Graph API or application activity. Which choice is the strongest fit for the research subscription, response wave 1? The team also wants to reduce mean time to respond.

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  4. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  5. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Correct answer: C

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

D: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

E: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 4

For the Tier 1 queue, response wave 2 at Alpine Ski House, a SOC tuning initiative can proceed only if the team can determine which Microsoft 365 user or administrator action occurred during the investigation window. What should the Defender administrator configure first if the operational goal is to reduce mean time to respond?

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  4. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: C

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 5

The security architecture review at Wide World Importers focuses on this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which Microsoft security action is most appropriate for the Tier 2 queue, response wave 2, given the need to scope the change to the affected security domain?

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  3. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: A

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 6

A change advisory board at Wingtip Toys asks how to investigate suspicious Microsoft Graph API or application activity during a identity compromise review. Which proposed action should the security operations analyst approve for the identity-response team, response wave 2? The change should keep the workflow auditable.

  1. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: D

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 7

Northwind Traders has ruled out a manual one-off workaround. For the cloud-security team, response wave 3, the remaining requirement is to determine which Microsoft 365 user or administrator action occurred during the investigation window. Which choice best addresses it and helps keep the workflow auditable?

  1. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: A

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 8

During post-incident review at Tailspin Toys, the incident responder identifies a gap: the SOC still needs to locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which action should be added for the messaging-security team, response wave 3 before the next incident, with an emphasis on trying to avoid changing an unrelated control plane?

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Correct answer: E

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 9

The security operations analyst at Alpine Ski House is comparing several Microsoft security options for a threat-hunting campaign. Which one directly enables the team to investigate suspicious Microsoft Graph API or application activity for the night shift, response wave 3 while helping improve detection coverage?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Correct answer: C

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 10

A security-operations workshop at Trey Research defines the desired outcome as follows: determine which Microsoft 365 user or administrator action occurred during the investigation window. Which implementation should be chosen for the Americas SOC, response wave 4? The team wants to improve detection coverage.

  1. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Correct answer: A

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 11

Which Microsoft security action best matches this technical purpose for the high-value-assets group, response wave 4: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. The SOC is trying to support repeatable response.

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  3. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: C

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 12

An analyst at Northwind Traders describes the needed capability this way: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. Which option should be associated with that requirement for the privileged-users group, response wave 4 while the team tries to separate collection from detection logic?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Correct answer: E

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 13

During a design validation for the remote-user fleet, response wave 5, Woodgrove Bank documents the following behavior: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. Which Microsoft security feature or action is being described? The objective is to separate collection from detection logic.

  1. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  2. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 14

The incident responder must identify the Microsoft security capability that provides this function for the production subscription, response wave 5: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. Which choice is correct if the SOC also needs to preserve investigation context?

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 15

A runbook for the research subscription, response wave 5 contains this description: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. Which implementation belongs in that runbook during a SOC tuning initiative? The process should minimize manual analyst steps.

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: D

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 16

Contoso Health is troubleshooting a lateral-movement investigation. Evidence shows that the decisive requirement is to determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action should the Defender administrator investigate first for the Tier 1 queue, response wave 6, without losing the ability to minimize manual analyst steps?

  1. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  2. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: A

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 17

After eliminating network and licensing causes, the incident responder at Litware Manufacturing determines that success depends on the ability to locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which security action should be checked next for the Tier 2 queue, response wave 6? The team must retain evidence for follow-up analysis.

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: B

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 18

A service-desk escalation during a multi-cloud monitoring rollout has been narrowed to one security-operations requirement: investigate suspicious Microsoft Graph API or application activity. Which configuration is the most relevant starting point for the identity-response team, response wave 6 if the SOC wants to avoid unnecessary alert noise?

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  4. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  5. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window

Correct answer: D

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

E: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 19

The failure pattern at Fourth Coffee affects the cloud-security team, response wave 7. Before making unrelated policy changes, the Defender administrator needs a solution that will determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action is most directly relevant and helps avoid unnecessary alert noise?

  1. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  2. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  3. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  4. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: A

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 20

While investigating a endpoint containment exercise, A. Datum confirms the environment must locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which Microsoft security capability should be validated for the messaging-security team, response wave 7? The investigation should preserve least privilege.

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: A

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 21

Two teams at Contoso Health propose different approaches for the night shift, response wave 7. The selection criterion is simple: the chosen approach must investigate suspicious Microsoft Graph API or application activity. Which option should win the technical comparison if the SOC also wants to reduce mean time to respond?

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  5. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Correct answer: E

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

D: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

E: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 22

For the Americas SOC, response wave 8, Adventure Works wants the least indirect solution to this goal: determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action aligns most closely with that requirement and the need to reduce mean time to respond?

  1. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: A

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 23

A modernization plan at Proseware Services includes a SOC handoff review. The incident responder is asked to choose the control that specifically helps the organization locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which choice fits best for the high-value-assets group, response wave 8 while supporting the goal to scope the change to the affected security domain?

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  3. Review the automatic attack disruption actions and incident evidence, then validate or complete the required remediation
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Correct answer: B

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Attack disruption may automatically contain affected assets during an active attack, but analysts still need to review the incident and complete or validate remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 24

The privileged-users group, response wave 8 is moving into a controlled rollout at Fourth Coffee. Which action should be included when the stated security objective is to investigate suspicious Microsoft Graph API or application activity? The operational standard is to keep the workflow auditable.

  1. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators
  2. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: B

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 25

Wingtip Toys is replacing an ad hoc process during a telemetry modernization. The replacement must reliably determine which Microsoft 365 user or administrator action occurred during the investigation window. Which security-operations approach should the Defender administrator implement for the remote-user fleet, response wave 9 if the team also wants to keep the workflow auditable?

  1. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  2. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  3. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  4. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: B

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 26

An audit finding for the production subscription, response wave 9 says the current process does not consistently locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which Microsoft security action most directly closes that gap while helping the SOC avoid changing an unrelated control plane?

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  3. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Pivot through Defender evidence and entity pages to validate the affected files, processes, users, devices, and related indicators

Correct answer: A

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Evidence and entity investigation connects artifacts and identities to the incident so analysts can validate scope, relationships, and remediation targets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 27

The security operations analyst at Adventure Works needs a repeatable configuration for the research subscription, response wave 9. It must investigate suspicious Microsoft Graph API or application activity. Which choice should be implemented instead of relying on manual incident work if the goal is to improve detection coverage?

  1. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Correct answer: A

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

E: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 28

During readiness testing at Alpine Ski House, the Tier 1 queue, response wave 10 fails a business requirement because analysts cannot yet determine which Microsoft 365 user or administrator action occurred during the investigation window. Which action should be implemented before rollout continues? The SOC also needs to improve detection coverage.

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  3. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  4. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  5. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Correct answer: B

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 29

A governance review asks the incident responder to justify the control selected for the Tier 2 queue, response wave 10. The requirement is to locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which action has the clearest technical alignment while supporting the goal to support repeatable response?

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  3. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: A

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 30

For a identity compromise review, Wingtip Toys needs a Microsoft security capability with this effect: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. Which option most accurately provides that capability for the identity-response team, response wave 10? The process should separate collection from detection logic.

  1. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  2. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

D: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 31

The operational standard for the cloud-security team, response wave 11 is being rewritten. Which action should be documented when the standard requires analysts to determine which Microsoft 365 user or administrator action occurred during the investigation window and the SOC wants to separate collection from detection logic?

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: D

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 32

Tailspin Toys is creating a response playbook for the messaging-security team, response wave 11. Which Microsoft security step belongs in the playbook when the objective is to locate the relevant Microsoft 365 messages or files that match the investigation criteria? The playbook should also help preserve investigation context.

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package

Correct answer: B

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Question 33

During a threat-hunting campaign at Alpine Ski House, the security operations analyst must investigate suspicious Microsoft Graph API or application activity. Which action most directly satisfies the requirement for the night shift, response wave 11? The design priority is to minimize manual analyst steps.

  1. Use the appropriate Defender for Endpoint device action, such as live response or collection of an investigation package
  2. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  3. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  4. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  5. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Correct answer: C

Why: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

Option review:

A: Live response supports remote investigation and command execution on supported endpoints, while investigation packages collect endpoint artifacts for deeper analysis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

B: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

C: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. This directly addresses the requirement: investigate suspicious Microsoft Graph API or application activity.

D: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

E: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate suspicious Microsoft Graph API or application activity.

Learning point: Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat

Question 34

Trey Research is revising its SOC runbook after a phishing investigation. Analysts need to determine which Microsoft 365 user or administrator action occurred during the investigation window. Which implementation should the Defender administrator select for the Americas SOC, response wave 12 while trying to minimize manual analyst steps?

  1. Query Microsoft Graph activity logs to investigate the application or API activity associated with the suspected threat
  2. Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window
  3. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: B

Why: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Option review:

A: Microsoft Graph activity logs provide request-level visibility into Graph API activity and are appropriate when the investigation centers on application or API access to Microsoft 365 data. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

B: Purview Audit provides searchable Microsoft 365 audit events that help analysts establish who performed an action, on which object, and when. This directly addresses the requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

C: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: determine which Microsoft 365 user or administrator action occurred during the investigation window.

Learning point: Search Microsoft Purview Audit for the relevant user, admin, file, or service activity during the investigation window

Question 35

A ticket escalated to the incident responder at Lucerne Publishing states one non-negotiable goal: locate the relevant Microsoft 365 messages or files that match the investigation criteria. Which choice is the strongest fit for the high-value-assets group, response wave 12? The team also wants to retain evidence for follow-up analysis.

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Review the Microsoft Defender for Endpoint device timeline for the affected endpoint and time window
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: B

Why: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

B: Content search is designed to find content across supported Microsoft 365 locations using investigation criteria and is appropriate when the analyst needs the actual discoverable content. This directly addresses the requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

D: The device timeline provides chronological endpoint events and alerts so analysts can reconstruct process, file, network, registry, and user activity around the incident. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: locate the relevant Microsoft 365 messages or files that match the investigation criteria.

Learning point: Use Microsoft Purview eDiscovery Content search to locate the relevant messages, files, or other discoverable Microsoft 365 content

Popular posts

img