Questions
To make sure you understand the extended detection and response subjects covered in this chapter, why not test yourself with the following questions?
- Which of the following is a device response action? Choose all that apply:
- Isolate device
- Run an antivirus scan
- Delete the device
- Collect investigation package
- Which of the following describes how an XDR differs from a SIEM solution?
- XDR platforms integrate with SaaS platform logs, but SIEM solutions cannot
- XDR platforms do not have native response capabilities, but traditional SIEM solutions do
- An XDR can be offered as a managed service but a traditional SIEM solution cannot
- An XDR also adds the response capability, which a traditional SIEM solution doesn’t provide natively
- Which of the following is the last stage of incident response, and not one really covered by Microsoft 365 Defender?
- Forensics
- Automated actions
- Recovery