Skip to content
SC-200
Respond to security incidents
medium
Question 3 of 73

An endpoint investigation requires examining suspicious files, processes, URLs, and IP addresses as related evidence. Which Defender for Endpoint capability best matches this work?

AEvidence and entity investigation
BCompany branding
CAccess reviews
DCustom security attributes

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion