Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a suspicious email reported by a user. The email contains a malicious attachment that was not blocked by Microsoft Defender for Office 365 (MDO). The analyst needs to understand why the attachment bypassed existing security controls and identify its characteristics for future prevention. Which MDO feature should the analyst use to gain detailed insights into the attachment's analysis and detonation?
- ASafe Attachments
- BSubmissions
- CThreat Explorer
- DAutomated Investigation and Remediation (AIR)
Show answer & explanationAnswer & explanation
Correct answer: B. Submissions
The Submissions feature in Microsoft Defender for Office 365 allows security analysts to submit suspicious content (like emails or attachments) for re-analysis, providing detailed insights into the detonation process and results, which helps understand why it bypassed initial controls.
Why the other options are wrong
- A. Safe Attachments is a policy feature that detonates attachments, not a tool for post-incident analysis of unblocked items.
- C. Threat Explorer is for searching and investigating emails, but not for re-submitting content for detailed analysis of bypasses.
- D. AIR in MDO automates response actions for detected threats, it doesn't provide detailed post-detonation analysis for bypassing cases.
MDO Submissions
A feature in Microsoft Defender for Office 365 that allows security teams to manually submit suspicious emails, attachments, or URLs to Microsoft for re-analysis, and receive detailed reports on their findings.
- Used for re-analysis of suspicious content.
- Provides detailed detonation reports.
- Helps improve detection capabilities.
Memory trick: When a threat slips past, submit it to understand the 'why' and to train the system.