ExamQuestions.com

Register
Login
Microsoft Security Operations Analyst (SC-200) Exam Questions

Microsoft

Microsoft Security Operations Analyst (SC-200)

48 / 130

Question 48:

You are using the Microsoft 365 Defender portal to conduct an investigation into a multi-stage incident related to a suspected malicious document. After reviewing all the details, you have determined that the alert tied to this potentially malicious document is also related to another incident in your environment. However, the alert is not currently listed as a part of that second incident. 
Your investigation into the alert is ongoing, as is your investigation into the two related incidents. 
You need to appropriately categorize the alert and ensure that it is associated with the second incident. 
What two actions should you take in the Manage alert pane to fulfill this part of the investigation? Each correct answer presents a part of the solution. Choose the correct answers

Answer options:

A.Set status to In progress
B.Set status to New
C.Set classification to True alert
D.Enter the Incident ID of the related incident in the Comment section.
E.Select the Link alert to another incident option.