SC-401 Practice Question 3655
Exam: SC-401
Domain: Manage risks, alerts, and activities
Difficulty: hard
What feature in Microsoft Purview allows security teams to correlate alerts generated across DLP, Insider Risk Management, and Defender into unified incident investigations?
Answer Options
A
Microsoft Defender XDR incident integration
B
Local Windows Event Viewer forwarding only
C
Exchange Message Trace delivery log
D
Azure Cost Management budget alerts
Correct Answer
A: Microsoft Defender XDR incident integration
Explanation
Microsoft Defender XDR incident integration aggregates Microsoft Purview data security alerts alongside endpoint, identity, and cloud app alerts in the unified security portal.