Microsoft Certified Security Compliance And Identity Fundamentals · Free Practice Question Easy
Question 14
An admin needs to identify users affected by a security alert in the Microsoft 365 Defender portal. Where can he find this information?

-
A
Action center
-
B
Incidents
-
C
Classification
-
D
Reports
Reveal correct answer
Correct answer: B
Explanation
He can find this information in the Incidents section. In fact, not only users, he can find all the devices and mailboxes too that were affected by the alerts.

Option Incidents is the correct answer.
The reports section in Microsoft 365 Defender portal displays cards covering different areas like identities, devices, and data.

Option Reports is an incorrect choice.
In the Action center, you will approve or reject pending remediation actions. It is an incorrect choice.
Reference Link: https://docs.microsoft.com/en-us/microsoft-365/security/defender/m365d-autoir-actions?view=o365-worldwide
Classification refers to data classification capabilities in the Microsoft Purview Compliance portal. Classification is not related to the Defender portal. It is an incorrect choice too.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
