Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsEasy

A Microsoft 365 administrator is investigating a potential security incident involving suspicious email activity and malware detections across several user devices. They need a centralized portal to review security alerts, manage threat protection policies, and respond to incidents. Which portal should the administrator use?

  1. AMicrosoft 365 admin center
  2. BMicrosoft Purview compliance portal
  3. CMicrosoft 365 Defender portal
  4. DAzure Active Directory admin center
Show answer & explanation

Correct answer: C. Microsoft 365 Defender portal

The Microsoft 365 Defender portal (formerly Microsoft 365 security center) is specifically designed for managing security alerts, threat protection, and incident response across various Microsoft 365 security services.

Why the other options are wrong

  • A. The Microsoft 365 admin center is for general tenant administration, user management, and service health, but not for detailed security incident management.
  • B. The Microsoft Purview compliance portal is used for data governance, compliance, and risk management, not for active threat investigation and response.
  • D. The Azure Active Directory admin center is for identity and access management, not for managing security incidents related to email and malware.

Microsoft 365 Defender portal

A unified security operations platform that helps protect against, detect, and respond to sophisticated threats across Microsoft 365 services.

  • Centralizes security alerts and threat intelligence
  • Manages threat protection policies across email, endpoints, identities, and apps
  • Provides tools for incident investigation and automated response

Memory trick: Defender defends against digital dangers.

More Describe core Microsoft 365 services and concepts questions