ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 270 - SC-200 discussion

Report
Export

You have an on-premises network.

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity.

From the Microsoft Defender portal, you investigate an incident on a device named Device1 of a user named User1. The incident contains the following Defender for Identity alert.

Suspected identity theft (pass-the-ticket) (external ID 2018)

You need to contain the incident without affecting users and devices. The solution must minimize administrative effort.

What should you do?

A.

Disable User 1 only.

Answers
A.

Disable User 1 only.

B.

Quarantine Device1 only.

Answers
B.

Quarantine Device1 only.

C.

Reset the password for all the accounts that previously signed in to Device1.

Answers
C.

Reset the password for all the accounts that previously signed in to Device1.

D.

DisableUser1 and quarantine Device1.

Answers
D.

DisableUser1 and quarantine Device1.

E.

Disable User1, quarantine Device1, and reset the password for all the accounts that previously signed in to Device1.

Answers
E.

Disable User1, quarantine Device1, and reset the password for all the accounts that previously signed in to Device1.

Suggested answer: A
asked 05/10/2024
Rene Claassen
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first