Microsoft Security Operations Analyst Associate SC-200 Practice Question
A security analyst is reviewing a high-severity alert in the Microsoft 365 Defender portal that was generated by a Microsoft Purview insider risk policy for potential data exfiltration. The analyst must determine exactly which files the user copied to a personal cloud storage location and preserve the evidence for possible legal review without alerting the user. Which action should the analyst perform first?
Create an eDiscovery (Premium) hold from the alert to add the content to a new case.
Run an immediate Microsoft Purview content search scoped to the user's OneDrive and download the results.
Publish a Microsoft Purview retention policy that retains all OneDrive files for the user for seven years.
Disable the user's account in Microsoft Entra ID and reset the password.
When an insider risk alert is opened in the Microsoft 365 Defender portal, selecting Create an eDiscovery (Premium) hold from the alert allows the analyst to immediately preserve the exact files, their versions, and related audit information in a dedicated eDiscovery case. This protects the evidence from alteration or deletion and keeps the user unaware of the investigation. Creating a retention policy, disabling the user account, or running a content search would not automatically place the items on legal hold and therefore would not guarantee evidence preservation at the required forensic standard.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is eDiscovery (Premium) hold in Microsoft 365 Defender?
Open an interactive chat with Bash
Why is an insider risk policy useful in identifying potential data exfiltration?
Open an interactive chat with Bash
What is the difference between a retention policy and an eDiscovery hold?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .