Microsoft 365 Administrator — Question 272
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.
You need to ensure that when a user-based alert is triggered in Defender for Cloud Apps, the user is marked as compromised.
Which two options can you use to automate the response? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point
Answer options
- A. a Microsoft Power Automate playbook
- B. a user tag
- C. a custom detection rule
- D. a block script
- E. an automated remediation level
Correct answer: A, E
Explanation
The correct answers are A and E. A Microsoft Power Automate playbook can create workflows that automate responses to alerts, while an automated remediation level can define actions to take when alerts are triggered. Options B, C, and D do not provide direct automation for marking users as compromised in response to alerts.