Security Investigation Quiz

5 questions Pass: 70% +25 pts

Quiz covering Security Operations

Security Investigation Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which Microsoft solution acts as a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) platform?

  2. 2

    In Microsoft Defender XDR, what is the primary purpose of an 'Incident'?

  3. 3

    You are investigating a phishing attack. Which feature in Microsoft Defender for Office 365 allows you to automatically remove malicious emails from user inboxes across the organization?

  4. 4

    A security analyst needs to perform a deep-dive investigation into a suspicious process execution on a Windows device. Which tool should they use to run live queries against the device?

  5. 5

    During a cross-platform investigation in Microsoft Sentinel, you need to correlate logs from an on-premises firewall with sign-in logs from Entra ID. What is the most efficient way to perform this analysis?