Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A security analyst is investigating a potential phishing attempt targeting executives within the organization. The analyst needs to quickly identify if any malicious URLs or attachments were delivered to executive mailboxes and prevent further access to these threats. Which Microsoft Defender for Office 365 capability should the analyst leverage first?
- AThreat Explorer
- BAutomated investigation and remediation (AIR)
- CAttack simulation training
- DSafe Attachments
Show answer & explanationAnswer & explanation
Correct answer: A. Threat Explorer
Threat Explorer in Microsoft Defender for Office 365 allows security analysts to quickly search for, investigate, and remediate threats related to email, including malicious URLs and attachments.
Why the other options are wrong
- B. Automated investigation and remediation (AIR) is a subsequent step after initial detection and investigation, designed for automated response, not the initial identification of threats.
- C. Attack simulation training is used for educating users and testing their susceptibility to phishing, not for real-time threat investigation and remediation.
- D. Safe Attachments protects against unknown malware and viruses by opening attachments in a sandboxed environment, but it's a preventative measure, not an investigation tool for already delivered threats.
Threat Explorer
A powerful security tool within Microsoft Defender for Office 365 that allows security teams to investigate and respond to email-borne threats like phishing, malware, and spam.
- Provides real-time visibility into email threats.
- Enables search by sender, recipient, subject, attachment, and URL.
- Facilitates remediation actions such as blocking senders or deleting emails.
Memory trick: To explore email threats, you need a good map and a flashlight.