Microsoft 365 Fundamentals — Question 371
A company is using Microsoft 365 Defender.
The company requires the ability to filter alerts and recommend actions that a security team can approve or reject.
You need to identify the component that filters and recommends actions.
Which component should you use?
Answer options
- A. Cloud Access Security Broker
- B. threat trackers
- C. automated investigation and response
- D. advanced hunting
- E. threat analytics
Correct answer: C
Explanation
The correct answer is C, automated investigation and response, as it is specifically designed to filter alerts and suggest actions. The other options do not provide the same level of automated recommendations or filtering capability necessary for the security team's needs.