Microsoft 365 Administrator — Question 272

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.

You need to ensure that when a user-based alert is triggered in Defender for Cloud Apps, the user is marked as compromised.

Which two options can you use to automate the response? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point

Answer options

Correct answer: A, E

Explanation

The correct answers are A and E. A Microsoft Power Automate playbook can create workflows that automate responses to alerts, while an automated remediation level can define actions to take when alerts are triggered. Options B, C, and D do not provide direct automation for marking users as compromised in response to alerts.