Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A Microsoft 365 administrator is investigating a series of alerts in Microsoft Defender XDR related to a compromised user account. The alerts indicate that the account was used to access multiple cloud applications from unusual geographic locations and that large volumes of data were downloaded shortly after. The administrator needs to review a unified timeline of all activities related to this user account across various Microsoft 365 services (Azure AD, Exchange Online, SharePoint Online, etc.) to understand the full scope of the compromise. Which feature within Microsoft Defender XDR provides this comprehensive, cross-domain activity timeline for a user account?

  1. ACloud Discovery dashboard in Defender for Cloud Apps
  2. BDevice timeline in Defender for Endpoint
  3. CUser entity page in Defender for Identity
  4. DUnified activity timeline in Microsoft Defender XDR portal
Show answer & explanation

Correct answer: D. Unified activity timeline in Microsoft Defender XDR portal

The unified activity timeline in the Microsoft Defender XDR portal aggregates alerts, incidents, and raw activity logs from all integrated Defender components (Endpoint, Identity, Office 365, Cloud Apps) into a single, comprehensive view for a user, device, or other entity, providing the cross-domain visibility needed for a full investigation.

Why the other options are wrong

  • A. The Cloud Discovery dashboard in Defender for Cloud Apps focuses on shadow IT and app risk assessment, not a detailed activity timeline for a specific user across all services.
  • B. The device timeline in Defender for Endpoint focuses on activities occurring on a specific endpoint, not across various cloud services for a user.
  • C. The user entity page in Defender for Identity primarily focuses on identity-related activities and alerts, not a unified timeline across all Microsoft 365 services.

Defender XDR Unified Activity Timeline

The unified activity timeline within the Microsoft Defender XDR portal consolidates alerts, incidents, and raw activity logs from all integrated security components (Endpoint, Identity, Office 365, Cloud Apps) into a single, correlated view for entities like users or devices.

  • Provides cross-domain visibility for investigations.
  • Correlates events from endpoint, identity, email, and cloud app sources.
  • Essential for understanding the full attack chain and scope of a compromise.
  • Accessed via the 'Incidents & alerts' or 'Unified activity' sections in the portal.

Memory trick: For a UNIFIED view of ALL user activity, use the XDR UNIFIED TIMELINE.

More Implement and manage Microsoft Defender XDR questions