Microsoft Certified Security Compliance And Identity Fundamentals · Free Practice Question Easy

Question 14

An admin needs to identify users affected by a security alert in the Microsoft 365 Defender portal. Where can he find this information?


  • A

    Action center

  • B

    Incidents

  • C

    Classification

  • D

    Reports

Reveal correct answer

Correct answer: B

Explanation

He can find this information in the Incidents section. In fact, not only users, he can find all the devices and mailboxes too that were affected by the alerts.



Option Incidents is the correct answer.

Reference Link: https://learn.microsoft.com/en-us/training/modules/describe-threat-protection-with-microsoft-365-defender/7-describe-microsoft-defender-portal#incidents-and-alerts


The reports section in Microsoft 365 Defender portal displays cards covering different areas like identities, devices, and data.



Option Reports is an incorrect choice.

Reference Link: https://learn.microsoft.com/en-us/training/modules/describe-threat-protection-with-microsoft-365-defender/7-describe-microsoft-defender-portal#reports


In the Action center, you will approve or reject pending remediation actions. It is an incorrect choice.

Reference Link: https://docs.microsoft.com/en-us/microsoft-365/security/defender/m365d-autoir-actions?view=o365-worldwide


Classification refers to data classification capabilities in the Microsoft Purview Compliance portal. Classification is not related to the Defender portal. It is an incorrect choice too.

Reference Link: https://learn.microsoft.com/en-us/training/modules/describe-information-protection-governance-capabilities-microsoft-365/3-describe-data-classification-capabilities-compliance-portal

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need