TechNuggets Academy

Manage incident response

Free Microsoft Certified: Security Operations Analyst Associate practice — 6 questions on Manage incident response, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Manage incident response
During an automated investigation and remediation (AIR) run in Microsoft Defender XDR, a suspicious file remediation action shows a status of 'Pending' instead of executing automatically. The device belongs to a device group configured with the automation level 'Semi - require approval for any remediation'. What must a SOC analyst do to complete the remediation?
Device groups set to a 'Semi' automation level require a human to review and approve remediation actions in the Action center before they are executed; nothing happens automatically until an analyst approves it.
Question 2 of 6 · Manage incident response
An analyst opens a complex incident in Microsoft Defender XDR involving 40 correlated alerts across email, identity, and endpoints. The analyst wants Microsoft Security Copilot to quickly generate a natural-language overview of the attack chain, affected entities, and relevant MITRE ATT&CK techniques. Which Security Copilot capability should the analyst use?
Security Copilot's incident summarization capability ingests all correlated alerts, entities, and evidence within an incident and produces a natural-language narrative including MITRE ATT&CK technique mapping, which is exactly what the scenario requires.
Question 3 of 6 · Manage incident response
A phishing campaign delivered a malicious attachment to 200 mailboxes, and several users already moved the message to Deleted Items. The SOC needs to guarantee the email is completely removed from all mailboxes, including Deleted Items and Recoverable Items, so it cannot be recovered by end users. Which remediation action in Threat Explorer should the analyst choose?
Hard delete in Threat Explorer permanently removes the message from the mailbox, including Deleted Items and the Recoverable Items folder, so it cannot be restored by the end user through normal recovery.
Question 4 of 6 · Manage incident response
Microsoft Sentinel raises an impossible travel alert for a user account, and Microsoft Defender for Cloud Apps logs show the same user authorized a new OAuth application named 'DataSync Pro' with full mailbox read/write permissions immediately after the anomalous sign-in. Which action should the analyst take FIRST to contain the threat while preserving the user's ability to continue working?
The malicious OAuth app grant is the active attack vector giving persistent mailbox access even if credentials are later reset. Revoking its permissions via app governance immediately cuts off attacker access to the mailbox without disrupting the legitimate user's account.
Question 5 of 6 · Manage incident response
A ransomware binary is actively encrypting files on a compromised endpoint. The SOC analyst wants to immediately stop the malicious process while keeping the machine reachable over the network for Live Response and the RDP-based forensic tools the response team is already using, without cutting off that network connectivity. Which Microsoft Defender for Endpoint response action should the analyst apply?
Restrict app execution blocks all executables from running unless signed by a Microsoft trusted signer, stopping the ransomware process, while leaving normal network connectivity intact — unlike full device isolation, which would also sever the RDP session in use.
Question 6 of 6 · Manage incident response
During investigation, a SOC analyst determines that an alert for 'Suspicious PowerShell download' on one endpoint and a separate alert for 'Anomalous Entra ID sign-in' on the same user account are part of the same attack chain, but Microsoft Defender XDR placed them into two different incidents because they did not share a common correlated entity. What should the analyst do to consolidate investigation and response actions?
Microsoft Defender XDR allows analysts to manually link or merge related alerts into a single incident when automatic correlation misses the connection, ensuring a unified investigation and response workflow.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →