Microsoft SC-200 Defender For Office Purview And Defender For Cloud Incident Response Practice Test

 

Skills 2.1 • 40 original questions

This Microsoft SC-200 Security Operations Analyst practice test focuses on defender for office purview and defender for cloud incident response through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a endpoint containment exercise at Blue Yonder Airlines, the SOC analyst must investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action most directly satisfies the requirement for the identity-response team, response wave 1? The design priority is to avoid changing an unrelated control plane.

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: A

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 2

Trey Research is revising its SOC runbook after a phishing investigation. Analysts need to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which implementation should the Defender administrator select for the endpoint-response team, response wave 1 while trying to improve detection coverage?

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: E

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 3

A ticket escalated to the incident responder at Lucerne Publishing states one non-negotiable goal: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which choice is the strongest fit for the cloud-security team, response wave 1? The team also wants to support repeatable response.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: D

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 4

For the night shift, response wave 2 at Litware Manufacturing, a SOC handoff review can proceed only if the team can investigate and remediate the malicious email or collaboration threat with Defender for Office 365. What should the SOC analyst configure first if the operational goal is to support repeatable response?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: D

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 5

The security architecture review at Woodgrove Bank focuses on this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which Microsoft security action is most appropriate for the EMEA SOC, response wave 2, given the need to separate collection from detection logic?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: A

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 6

A change advisory board at Blue Yonder Airlines asks how to investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context during a audit investigation. Which proposed action should the incident responder approve for the Americas SOC, response wave 2? The change should preserve investigation context.

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Correct answer: A

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 7

  1. Datum has ruled out a manual one-off workaround. For the privileged-users group, response wave 3, the remaining requirement is to investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which choice best addresses it and helps preserve investigation context?
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  6. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: B

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 8

During post-incident review at Contoso Health, the Defender administrator identifies a gap: the SOC still needs to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which action should be added for the server fleet, response wave 3 before the next incident, with an emphasis on trying to minimize manual analyst steps?

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: D

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 9

The incident responder at Litware Manufacturing is comparing several Microsoft security options for a cloud-workload incident. Which one directly enables the team to investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context for the remote-user fleet, response wave 3 while helping retain evidence for follow-up analysis?

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: D

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 10

A security-operations workshop at Proseware Services defines the desired outcome as follows: investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which implementation should be chosen for the research subscription, response wave 4? The team wants to retain evidence for follow-up analysis.

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Correct answer: A

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 11

Which Microsoft security action best matches this technical purpose for the regulated workload segment, response wave 4: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. The SOC is trying to avoid unnecessary alert noise.

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 12

An analyst at A. Datum describes the needed capability this way: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. Which option should be associated with that requirement for the Tier 1 queue, response wave 4 while the team tries to preserve least privilege?

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Correct answer: E

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 13

During a design validation for the identity-response team, response wave 5, Fabrikam Retail documents the following behavior: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. Which Microsoft security feature or action is being described? The objective is to preserve least privilege.

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: B

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 14

The Defender administrator must identify the Microsoft security capability that provides this function for the endpoint-response team, response wave 5: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. Which choice is correct if the SOC also needs to reduce mean time to respond?

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: D

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 15

A runbook for the cloud-security team, response wave 5 contains this description: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. Which implementation belongs in that runbook during a SOC handoff review? The process should scope the change to the affected security domain.

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Correct answer: B

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 16

Wide World Importers is troubleshooting a post-incident review. Evidence shows that the decisive requirement is to investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action should the SOC analyst investigate first for the night shift, response wave 6, without losing the ability to scope the change to the affected security domain?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: C

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 17

After eliminating network and licensing causes, the Defender administrator at Wingtip Toys determines that success depends on the ability to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which security action should be checked next for the EMEA SOC, response wave 6? The team must keep the workflow auditable.

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: C

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 18

A service-desk escalation during a data-ingestion rollout has been narrowed to one security-operations requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which configuration is the most relevant starting point for the Americas SOC, response wave 6 if the SOC wants to avoid changing an unrelated control plane?

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation

Correct answer: C

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 19

The failure pattern at Tailspin Toys affects the privileged-users group, response wave 7. Before making unrelated policy changes, the SOC analyst needs a solution that will investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action is most directly relevant and helps avoid changing an unrelated control plane?

  1. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Correct answer: E

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 20

While investigating a SOC tuning initiative, Alpine Ski House confirms the environment must investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which Microsoft security capability should be validated for the server fleet, response wave 7? The investigation should improve detection coverage.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow

Correct answer: C

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 21

Two teams at Wide World Importers propose different approaches for the remote-user fleet, response wave 7. The selection criterion is simple: the chosen approach must investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which option should win the technical comparison if the SOC also wants to support repeatable response?

  1. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: B

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 22

For the research subscription, response wave 8, Lucerne Publishing wants the least indirect solution to this goal: investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action aligns most closely with that requirement and the need to support repeatable response?

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: B

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 23

A modernization plan at Northwind Traders includes a multi-cloud monitoring rollout. The Defender administrator is asked to choose the control that specifically helps the organization investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which choice fits best for the regulated workload segment, response wave 8 while supporting the goal to separate collection from detection logic?

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: C

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 24

The Tier 1 queue, response wave 8 is moving into a controlled rollout at Tailspin Toys. Which action should be included when the stated security objective is to investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context? The operational standard is to preserve investigation context.

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: D

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 25

Blue Yonder Airlines is replacing an ad hoc process during a endpoint containment exercise. The replacement must reliably investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which security-operations approach should the SOC analyst implement for the identity-response team, response wave 9 if the team also wants to preserve investigation context?

  1. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response

Correct answer: C

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 26

An audit finding for the endpoint-response team, response wave 9 says the current process does not consistently investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which Microsoft security action most directly closes that gap while helping the SOC minimize manual analyst steps?

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: E

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 27

The incident responder at Lucerne Publishing needs a repeatable configuration for the cloud-security team, response wave 9. It must investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which choice should be implemented instead of relying on manual incident work if the goal is to retain evidence for follow-up analysis?

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: D

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 28

During readiness testing at Litware Manufacturing, the night shift, response wave 10 fails a business requirement because analysts cannot yet investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action should be implemented before rollout continues? The SOC also needs to retain evidence for follow-up analysis.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  4. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  5. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation

Correct answer: B

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 29

A governance review asks the Defender administrator to justify the control selected for the EMEA SOC, response wave 10. The requirement is to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which action has the clearest technical alignment while supporting the goal to avoid unnecessary alert noise?

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Correct answer: E

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 30

For a audit investigation, Blue Yonder Airlines needs a Microsoft security capability with this effect: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. Which option most accurately provides that capability for the Americas SOC, response wave 10? The process should preserve least privilege.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Correct answer: B

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 31

The operational standard for the privileged-users group, response wave 11 is being rewritten. Which action should be documented when the standard requires analysts to investigate and remediate the malicious email or collaboration threat with Defender for Office 365 and the SOC wants to preserve least privilege?

  1. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  4. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: B

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 32

Contoso Health is creating a response playbook for the server fleet, response wave 11. Which Microsoft security step belongs in the playbook when the objective is to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation? The playbook should also help reduce mean time to respond.

  1. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Correct answer: D

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 33

During a cloud-workload incident at Litware Manufacturing, the incident responder must investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which action most directly satisfies the requirement for the remote-user fleet, response wave 11? The design priority is to scope the change to the affected security domain.

  1. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  2. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  3. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement

Correct answer: C

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 34

Proseware Services is revising its SOC runbook after a security automation project. Analysts need to investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which implementation should the SOC analyst select for the research subscription, response wave 12 while trying to scope the change to the affected security domain?

  1. Use Microsoft Defender for Cloud Apps to investigate the risky cloud-app activity and apply the appropriate session, user, file, or app remediation
  2. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  5. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action

Correct answer: D

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Defender for Cloud Apps provides cloud-app activity, risk, governance, and control context that is appropriate for investigating risky SaaS usage and entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 35

A ticket escalated to the Defender administrator at Fourth Coffee states one non-negotiable goal: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation. Which choice is the strongest fit for the regulated workload segment, response wave 12? The team also wants to keep the workflow auditable.

  1. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  2. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 36

For the Tier 1 queue, response wave 12 at A. Datum, a endpoint containment exercise can proceed only if the team can investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. What should the incident responder configure first if the operational goal is to avoid changing an unrelated control plane?

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  3. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: D

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 37

The security architecture review at Fabrikam Retail focuses on this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which Microsoft security action is most appropriate for the identity-response team, response wave 13, given the need to avoid changing an unrelated control plane?

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  3. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Correct answer: C

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Question 38

A change advisory board at Adventure Works asks how to investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation during a threat-hunting campaign. Which proposed action should the Defender administrator approve for the endpoint-response team, response wave 13? The change should improve detection coverage.

  1. Open and investigate the Microsoft Sentinel incident, review its entities and evidence, and perform the required remediation workflow
  2. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  5. Use Microsoft Defender for Identity alert and entity context to investigate the suspicious identity activity and remediate the affected account or infrastructure

Correct answer: C

Why: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Option review:

A: Sentinel incidents aggregate alerts and related entities into a case for triage, investigation, assignment, status tracking, and response. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

B: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. This directly addresses the requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

D: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

E: Defender for Identity correlates identity and directory activity to detect suspicious behavior in identity infrastructure and provides entity context for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the Purview-identified risky or compromised entity and take the appropriate data-governance remediation.

Learning point: Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity

Question 39

Proseware Services has ruled out a manual one-off workaround. For the cloud-security team, response wave 13, the remaining requirement is to investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context. Which choice best addresses it and helps support repeatable response?

  1. Use the incident case-management fields and workflow to assign ownership, document status, track evidence, and coordinate response
  2. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource
  5. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Correct answer: D

Why: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Option review:

A: Case management provides the operational structure for ownership, status, comments, tasks, and collaboration throughout the incident lifecycle. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

B: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

D: Defender for Cloud workload protections surface resource-specific security alerts and context for cloud workloads so the SOC can investigate and remediate the affected resource. This directly addresses the requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate the cloud workload alert and remediate the affected resource through Defender for Cloud context.

Learning point: Use Microsoft Defender for Cloud workload-protection alerts and recommendations to investigate and remediate the affected cloud resource

Question 40

During post-incident review at Wide World Importers, the SOC analyst identifies a gap: the SOC still needs to investigate and remediate the malicious email or collaboration threat with Defender for Office 365. Which action should be added for the night shift, response wave 14 before the next incident, with an emphasis on trying to support repeatable response?

  1. Investigate the Microsoft Entra ID identity risk and remediate the compromised account using the appropriate identity-protection action
  2. Correlate the incident across identities, endpoints, cloud resources, and other affected domains to reconstruct the attack sequence and lateral movement
  3. Use the relevant Microsoft Purview investigation experience and remediation workflow for the identified risky or compromised entity
  4. Use the embedded Microsoft Security Copilot or agentic investigation capability to summarize, analyze, and accelerate the incident investigation
  5. Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Correct answer: E

Why: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Option review:

A: Microsoft Entra ID risk detections and identity-protection controls are the primary source for investigating compromised identities and enforcing identity remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

B: Complex attacks span multiple stages or security domains, so the analyst must connect related evidence and entity activity rather than investigating each alert in isolation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

C: Purview surfaces data-governance and insider/compliance signals that can identify risky activity or entities requiring investigation and policy-driven remediation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

D: Security Copilot can synthesize incident context, explain security data, and assist analysts while the analyst remains responsible for validating evidence and response decisions. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

E: Defender for Office 365 provides message, campaign, and entity investigation with remediation actions and can participate in coordinated attack disruption for eligible attacks. This directly addresses the requirement: investigate and remediate the malicious email or collaboration threat with Defender for Office 365.

Learning point: Use Microsoft Defender for Office 365 investigation and remediation actions for the malicious message, campaign, or collaboration threat

Popular posts

img