Skip to content
SC-200
Respond to security incidents
medium
Question 10 of 73

A SOC receives an incident involving malicious email delivery, phishing links, and suspicious mailbox activity. Which Microsoft workload is most directly associated with investigating and remediating that threat in Defender XDR?

AMicrosoft Defender for Office 365
BMicrosoft Entra ID
CWindows Event Forwarding
DMicrosoft Sentinel workbook

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion