FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 6

Question 218

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR and contains a Windows device named Device1. You investigate Device1 for malicious activity and discover a suspicious file named File1.exe. You collect an investigation package from Device1. You need to review the following forensic data points: • Is an attacker currently accessing Device1 remotely? • When was File1.exe first executed? Which folder in the investigation package should you review for each data point? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question 218