Microsoft SC-200 Endpoint Custom Data Security Policies And Automated Investigation Practice Test
Skills 1.1 • 30 original questions
This Microsoft SC-200 Security Operations Analyst practice test focuses on endpoint custom data security policies and automated investigation through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a identity compromise review at Northwind Traders, the security engineer must collect the required custom endpoint telemetry in Defender for Endpoint. Which action most directly satisfies the requirement for the cloud-security team, response wave 1? The design priority is to avoid unnecessary alert noise.
Correct answer: C
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
Tailspin Toys is revising its SOC runbook after a endpoint containment exercise. Analysts need to apply the required Defender for Endpoint security policy or attack surface reduction control. Which implementation should the Tier 2 analyst select for the messaging-security team, response wave 1 while trying to preserve least privilege?
Correct answer: E
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
A ticket escalated to the threat hunter at Alpine Ski House states one non-negotiable goal: use automated investigation and response to investigate and remediate supported Defender XDR alerts. Which choice is the strongest fit for the night shift, response wave 1? The team also wants to reduce mean time to respond.
Correct answer: A
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
For the Americas SOC, response wave 2 at Trey Research, a threat-hunting campaign can proceed only if the team can collect the required custom endpoint telemetry in Defender for Endpoint. What should the security engineer configure first if the operational goal is to reduce mean time to respond?
Correct answer: C
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
The security architecture review at Lucerne Publishing focuses on this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control. Which Microsoft security action is most appropriate for the high-value-assets group, response wave 2, given the need to scope the change to the affected security domain?
Correct answer: A
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
A change advisory board at Northwind Traders asks how to use automated investigation and response to investigate and remediate supported Defender XDR alerts during a detection-engineering sprint. Which proposed action should the threat hunter approve for the privileged-users group, response wave 2? The change should keep the workflow auditable.
Correct answer: B
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
Woodgrove Bank has ruled out a manual one-off workaround. For the remote-user fleet, response wave 3, the remaining requirement is to collect the required custom endpoint telemetry in Defender for Endpoint. Which choice best addresses it and helps keep the workflow auditable?
Correct answer: A
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
During post-incident review at Blue Yonder Airlines, the Tier 2 analyst identifies a gap: the SOC still needs to apply the required Defender for Endpoint security policy or attack surface reduction control. Which action should be added for the production subscription, response wave 3 before the next incident, with an emphasis on trying to avoid changing an unrelated control plane?
Correct answer: E
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
The threat hunter at Trey Research is comparing several Microsoft security options for a lateral-movement investigation. Which one directly enables the team to use automated investigation and response to investigate and remediate supported Defender XDR alerts for the research subscription, response wave 3 while helping improve detection coverage?
Correct answer: A
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
A security-operations workshop at Contoso Health defines the desired outcome as follows: collect the required custom endpoint telemetry in Defender for Endpoint. Which implementation should be chosen for the Tier 1 queue, response wave 4? The team wants to improve detection coverage.
Correct answer: B
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
Which Microsoft security action best matches this technical purpose for the Tier 2 queue, response wave 4: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. The SOC is trying to support repeatable response.
Correct answer: B
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
An analyst at Woodgrove Bank describes the needed capability this way: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. Which option should be associated with that requirement for the identity-response team, response wave 4 while the team tries to separate collection from detection logic?
Correct answer: D
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
During a design validation for the cloud-security team, response wave 5, Fourth Coffee documents the following behavior: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. Which Microsoft security feature or action is being described? The objective is to separate collection from detection logic.
Correct answer: E
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
The Tier 2 analyst must identify the Microsoft security capability that provides this function for the messaging-security team, response wave 5: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. Which choice is correct if the SOC also needs to preserve investigation context?
Correct answer: B
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
A runbook for the night shift, response wave 5 contains this description: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. Which implementation belongs in that runbook during a threat-hunting campaign? The process should minimize manual analyst steps.
Correct answer: B
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
Adventure Works is troubleshooting a phishing investigation. Evidence shows that the decisive requirement is to collect the required custom endpoint telemetry in Defender for Endpoint. Which action should the security engineer investigate first for the Americas SOC, response wave 6, without losing the ability to minimize manual analyst steps?
Correct answer: A
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
After eliminating network and licensing causes, the Tier 2 analyst at Proseware Services determines that success depends on the ability to apply the required Defender for Endpoint security policy or attack surface reduction control. Which security action should be checked next for the high-value-assets group, response wave 6? The team must retain evidence for follow-up analysis.
Correct answer: A
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
A service-desk escalation during a telemetry modernization has been narrowed to one security-operations requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts. Which configuration is the most relevant starting point for the privileged-users group, response wave 6 if the SOC wants to avoid unnecessary alert noise?
Correct answer: C
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
The failure pattern at Wingtip Toys affects the remote-user fleet, response wave 7. Before making unrelated policy changes, the security engineer needs a solution that will collect the required custom endpoint telemetry in Defender for Endpoint. Which action is most directly relevant and helps avoid unnecessary alert noise?
Correct answer: A
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
While investigating a audit investigation, Fabrikam Retail confirms the environment must apply the required Defender for Endpoint security policy or attack surface reduction control. Which Microsoft security capability should be validated for the production subscription, response wave 7? The investigation should preserve least privilege.
Correct answer: E
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
Two teams at Adventure Works propose different approaches for the research subscription, response wave 7. The selection criterion is simple: the chosen approach must use automated investigation and response to investigate and remediate supported Defender XDR alerts. Which option should win the technical comparison if the SOC also wants to reduce mean time to respond?
Correct answer: E
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
For the Tier 1 queue, response wave 8, Alpine Ski House wants the least indirect solution to this goal: collect the required custom endpoint telemetry in Defender for Endpoint. Which action aligns most closely with that requirement and the need to reduce mean time to respond?
Correct answer: D
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
A modernization plan at Wide World Importers includes a cloud-workload incident. The Tier 2 analyst is asked to choose the control that specifically helps the organization apply the required Defender for Endpoint security policy or attack surface reduction control. Which choice fits best for the Tier 2 queue, response wave 8 while supporting the goal to scope the change to the affected security domain?
Correct answer: A
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
The identity-response team, response wave 8 is moving into a controlled rollout at Wingtip Toys. Which action should be included when the stated security objective is to use automated investigation and response to investigate and remediate supported Defender XDR alerts? The operational standard is to keep the workflow auditable.
Correct answer: A
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
Northwind Traders is replacing an ad hoc process during a identity compromise review. The replacement must reliably collect the required custom endpoint telemetry in Defender for Endpoint. Which security-operations approach should the security engineer implement for the cloud-security team, response wave 9 if the team also wants to keep the workflow auditable?
Correct answer: E
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
An audit finding for the messaging-security team, response wave 9 says the current process does not consistently apply the required Defender for Endpoint security policy or attack surface reduction control. Which Microsoft security action most directly closes that gap while helping the SOC avoid changing an unrelated control plane?
Correct answer: B
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
The threat hunter at Alpine Ski House needs a repeatable configuration for the night shift, response wave 9. It must use automated investigation and response to investigate and remediate supported Defender XDR alerts. Which choice should be implemented instead of relying on manual incident work if the goal is to improve detection coverage?
Correct answer: C
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
During readiness testing at Trey Research, the Americas SOC, response wave 10 fails a business requirement because analysts cannot yet collect the required custom endpoint telemetry in Defender for Endpoint. Which action should be implemented before rollout continues? The SOC also needs to improve detection coverage.
Correct answer: A
Why: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Option review:
A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. This directly addresses the requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required custom endpoint telemetry in Defender for Endpoint.
Learning point: Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
A governance review asks the Tier 2 analyst to justify the control selected for the high-value-assets group, response wave 10. The requirement is to apply the required Defender for Endpoint security policy or attack surface reduction control. Which action has the clearest technical alignment while supporting the goal to support repeatable response?
Correct answer: E
Why: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Option review:
A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. This directly addresses the requirement: apply the required Defender for Endpoint security policy or attack surface reduction control.
Learning point: Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
For a detection-engineering sprint, Northwind Traders needs a Microsoft security capability with this effect: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. Which option most accurately provides that capability for the privileged-users group, response wave 10? The process should separate collection from detection logic.
Correct answer: A
Why: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Option review:
A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. This directly addresses the requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: use automated investigation and response to investigate and remediate supported Defender XDR alerts.
Learning point: Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
Popular posts
Recent Posts
