Respond to alerts and incidents in Microsoft Defender XDR
7 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
Using the Evidence and Response tab to see all entities affected by a Defender XDR incident
To identify all entities affected by a Microsoft Defender XDR incident, use the Evidence and Response tab, which aggregates every related entity (devi
Containing a Defender for Identity pass-the-ticket alert by quarantining only the affected device
A Defender for Identity 'Suspected identity theft (pass-the-ticket)' alert on Device1 means a forged Kerberos ticket resides on that device; quarantin
Identifying the incident remediation action that requires manual action despite full automation
With AIR in Defender for Office 365 and full automation in Defender for Endpoint, email remediation (soft/hard delete) and many device actions are aut
Querying IdentityLogonEvents to hunt LDAP simple binds to AD DS domain controllers
To hunt LDAP simple binds to on-premises Active Directory Domain Services domain controllers in Defender for Identity advanced hunting, query the Iden
Submitting only PE files for Microsoft Defender XDR deep analysis
In Microsoft Defender XDR deep analysis, only portable executable (PE) files (.exe and .dll) are supported; the PowerShell script File1.ps1 is not a P
Using a Conditional Access policy to revoke or force re-authentication of a compromised Outlook on the web session
To ensure a compromised user's Outlook on the web session token can be revoked, configure a Microsoft Entra Conditional Access policy (for example, ba
Using Defender XDR alert tuning rules to hide or resolve alerts and reduce alert fatigue
To tune alerts from a commonly used executable that causes alert fatigue in Defender XDR, an alert tuning rule can hide the alerts (remove them from t