Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A security analyst is investigating a suspicious file detected on an endpoint by Microsoft Defender for Endpoint. The analyst needs to quickly gather comprehensive information about this specific file, including its prevalence in the organization, associated alerts, and submission details to Microsoft for analysis. Which section within the Microsoft 365 Defender portal provides this centralized view for a specific file?

  1. AIncidents page
  2. BDevices page
  3. CFile page
  4. DAutomated investigations page
Show answer & explanation

Correct answer: C. File page

The 'File page' in the Microsoft 365 Defender portal is specifically designed to provide a comprehensive, centralized view of a particular file. It aggregates information such as its prevalence, associated alerts, observed activities, and any analysis submissions, which is exactly what the analyst needs.

Why the other options are wrong

  • A. The Incidents page groups related alerts, but doesn't focus on a single file's comprehensive details.
  • B. The Devices page provides information about an endpoint, not a specific file across the organization.
  • D. The Automated investigations page shows the status and results of automated investigations, not a file's detailed profile.

Microsoft 365 Defender File Page

A dedicated page within the Microsoft 365 Defender portal that provides a comprehensive, centralized view of a specific file, including its global and organizational prevalence, associated alerts, observed activities, and analysis submissions.

  • Aggregates data from Defender for Endpoint and other sources.
  • Helps analysts quickly assess the impact and nature of a suspicious file.
  • Includes details like file hash, name, size, and associated threats.

Memory trick: Files get their own page for deep dives.

More Mitigate threats using Microsoft Defender XDR questions