SC-200 Respond to security incidents • Set 32
SC-200 Respond to security incidents Practice Test 32 — 15 questions with explanations. Free, no signup.
Your company uses Microsoft Sentinel with the Microsoft Defender XDR connector. You receive an incident: 'Suspicious mailbox forwarding rule created.' The incident indicates that a user's mailbox in Exchange Online has a forwarding rule to an external email address. The user's account shows no other suspicious activity. You need to respond to the incident. The company policy requires preserving evidence for 30 days. Which action should you take FIRST?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.