Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a suspicious file detected on an endpoint by Microsoft Defender for Endpoint. The analyst needs to determine the file's reputation, see if it has been observed in other organizations globally, and identify any associated behaviors or indicators of compromise (IOCs). Which view within the Microsoft 365 Defender portal should the analyst use to gather this comprehensive information about the file?
- ADevice page
- BAlerts page
- CIncidents page
- DFile page
Show answer & explanationAnswer & explanation
Correct answer: D. File page
The 'File page' (or File entity page) in the Microsoft 365 Defender portal provides a centralized view of all known information about a specific file, including its global prevalence, reputation, associated alerts, observed behaviors, and related devices.
Why the other options are wrong
- A. The device page provides information about a specific endpoint, not detailed global intelligence on a file.
- B. The alerts page lists all alerts but doesn't consolidate global file intelligence.
- C. The incidents page aggregates alerts related to an attack, but to deep dive into a specific file's global context, the file page is more appropriate.
File Page (M365 Defender)
A dedicated entity page in the Microsoft 365 Defender portal that provides aggregated intelligence and context for a specific file across the entire Defender ecosystem.
- Shows file reputation and global prevalence.
- Lists associated alerts, incidents, and observed behaviors.
- Helps determine if a file is malicious and its impact.
Memory trick: Entity Pages Provide Deep Dive Context.