SC-200 Practice Question 3773
Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
You need to investigate an alert where a compromised user inbox rule was created to auto-forward financial emails to an external cybercriminal address. What tool in Defender for Office 365 identifies this rule?
Answer Options
A
Automated Investigation and Response (AIR) in Defender for Office 365
B
Windows Disk Management console
C
Active Directory Sites and Services
D
Public DNS registrar control panel
Correct Answer
A: Automated Investigation and Response (AIR) in Defender for Office 365
Explanation
Automated Investigation and Response (AIR) identifies the malicious inbox forwarding rule and provides an automated remediation action to remove the unauthorized rule.