SC-200 Web TestEngine demo

Exit VCEDump SC-200 Microsoft Security Operations Analyst
Question 36 of 61
0% complete
Q36 Single choice

You have an on-premises network.

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity.

From the Microsoft Defender portal, you investigate an incident on a device named Device1 of a user named User1. The incident contains the following Defender for Identity alert.

Suspected identity theft (pass-the-ticket) (external ID 2018)

You need to contain the incident without affecting users and devices. The solution must minimize administrative effort.

What should you do?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in