FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 6

Question 235

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have a Microsoft 365 subscription. The subscription contains 500 Windows 11 devices that are onboarded to Microsoft Defender for Endpoint. You have 500 devices that run Linux. Users sign in to the Windows and Linux devices by using their Microsoft Entra credentials. You need to recommend a response process for Microsoft Defender XDR security incidents associated with a compromised Linux endpoint. The solution must ensure that the compromised device is prevented from communicating with all devices onboarded to Defender for Endpoint. Which response action should you include in the recommendation?

  • AContain user
  • BContain device
  • CIsolate device
  • DConfirm user compromised