You have a Microsoft 365 tenant. You plan to manage incidents in the tenant by using the Microsoft 365 Defender. Which Microsoft service source will appear on the Incidents page of the Microsoft 365 Defender portal?
Microsoft Sentinel is a SIEM system and will not forward alerts to M365 Defender. Events will rather be forwarded from M365 Defender TO Sentinel. Azure ARC and Defender for Cloud (not Defender for Cloud Apps) will send their alerts to Sentinel. That leaves MS Defender for Identity and that will indeed send alerts to M365 Defender interface.
By choosing a specific source, you can only select answer D and NOT A, B, C. For more details read the next link:
https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/microsoft-365-defender-incident-overview/2174343
On the Incidents page, you can filter for Service Source
The options are:
Defender for Cloud Apps
Defender for Endpoint
Defender XDR
Defender for Office 365
App Governance
AAD Identity Protection
Data Loss Prevention
M365 defender now called XDR consists of Defender for identity, office apps, endpoints etc. Sentinel, defender for cloud, azure arc are in Azure Cloud so totally different from M365 defender(XDR). So answer is D.
It also seems to depend on what you have licensed.. looking in my trial tenant I only see "Defender for Cloud Apps" but looking in my production tenant I can filter it on "Defender for Cloud"
You can filter the alerts based on the Service Sources:
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/alerts-queue?view=o365-worldwide#service-sources
D is correct
https://www.examtopics.com/discussions/microsoft/view/56970-exam-ms-101-topic-2-question-70-discussion/
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.MS-102 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Shloeb
Highly Voted 1 year, 6 months agoNrdAlrt
1 year, 5 months agoGenPatton
Highly Voted 1 year, 6 months agoA320
Most Recent 3 days, 12 hours agoOdy
5 months, 1 week agofabiomartinsnet
4 weeks, 1 day agowakh
8 months, 2 weeks agoBlixa
1 year, 4 months agoGLLimaBR
1 year agogomezmax
1 year, 7 months agoCasticod
1 year, 7 months agocb0900
1 year, 7 months agoGreatone1
1 year, 7 months ago