FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 7

Question 240

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains a macOS device named Device1. You need to investigate a Defender for Endpoint agent alert on Device1. The solution must meet the following requirements: • Identify all the active network connections on Device1. • Identify all the running processes on Device1. • Retrieve the login history of Device1. • Minimize administrative effort. What should you do first from the Microsoft Defender portal?

  • AFrom Devices, click Collect investigation package for Device1.
  • BFrom Advanced features in Endpoints, enable Live Response unsigned script execution.
  • CFrom Devices, initiate a live response session on Device1.
  • DFrom Advanced features in Endpoints, disable Authenticated telemetry.