Exam AB-900 Topic 2 Question 2 Discussion

Actual exam question for Microsoft's AB-900 exam
Question #: 2
Topic #: 2
Your organization has a Microsoft 365 subscription.
You need to investigate security incidents and alerts raised from the Windows 11 devices in your organization. What should you use?

Suggested Answer: C Vote an answer

The correct answer is C. Microsoft Defender for Endpoint . Microsoft documents that Defender for Endpoint is the Microsoft security solution for endpoint devices , including Windows 11 , and that it lets security teams investigate incidents, alerts, affected devices, files, processes, and remediation actions in the Microsoft Defender portal. Microsoft's investigation guidance specifically describes using Defender for Endpoint to review alerts and investigate affected devices from the devices list, alerts queue, and incident views.
The other options do not match this requirement. Microsoft Entra ID Protection is for risky users and risky sign-ins, not device incident investigation. Microsoft Purview Insider Risk Management focuses on risky user behavior such as data theft or exfiltration, not endpoint security alerts from Windows devices. Microsoft Defender for Identity monitors on-premises and hybrid identity signals from Active Directory environments, not Windows 11 endpoint incidents. For security incidents and alerts raised from organization-managed Windows 11 devices, Microsoft's documented solution is Microsoft Defender for Endpoint .

by Laura at Jun 29, 2026, 01:03 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10