You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint You need to identify any devices that triggered a malware alert and collect evidence related to the alert. The solution must ensure that you can use the results to initiate device isolation for the affected devices.
What should you use in the Microsoft 365 Defender portal?
Correct Answer: B
In Microsoft Defender for Endpoint , an Investigation (also known as an Automated Investigation and Response - AIR ) collects evidence related to alerts, analyzes device behavior, and enables response actions such as device isolation, file quarantine, or remediation .
While Incidents aggregate multiple alerts for a single attack chain, and Advanced hunting is used for custom KQL queries, Investigations are specifically designed to automate evidence collection and analysis for triggered malware alerts.
From the investigation results, analysts can then initiate isolation of affected endpoints directly in the portal.
# Answer: B. Investigations