Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security analyst is investigating a series of suspicious login attempts originating from unusual geographic locations for several users. The analyst needs to quickly identify all users who have exhibited similar anomalous login patterns over the past week and determine if any of these logins resulted in successful access. Which Microsoft Defender for Identity feature should the analyst use for this investigation?

  1. AAdvanced hunting
  2. BIdentity security score
  3. CSecurity posture assessments
  4. DSensitive group modification alerts
Show answer & explanation

Correct answer: A. Advanced hunting

Advanced hunting in Microsoft Defender for Identity (accessible via Microsoft Defender XDR) allows security analysts to craft complex Kusto Query Language (KQL) queries to search raw data for specific patterns, such as anomalous login attempts from unusual locations and their success status, across the organization's identity data.

Why the other options are wrong

  • B. Identity security score measures the organization's security configuration, not for investigating specific login patterns or incidents.
  • C. Security posture assessments provide recommendations for improving security but are not for active threat investigation of specific incidents.
  • D. Sensitive group modification alerts notify about changes to critical security groups, which is a different type of alert than anomalous login patterns.

Advanced Hunting (Defender for Identity)

A query-based threat hunting tool in Microsoft Defender XDR that allows security teams to proactively inspect data from Defender for Identity and other Defender services.

  • Uses Kusto Query Language (KQL).
  • Provides access to raw security event data.
  • Enables complex searches for specific threats and behaviors.

Memory trick: Hunting for Identity Clues Requires Deep Queries.

More Mitigate threats using Microsoft Defender XDR questions