A security operations team opens a Microsoft Defender XDR threat analytics report for an active ransomware campaign and must prioritise remediation. They need to read two organisation-specific lists straight from the report, without writing any query: the assets that the campaign's techniques have already affected in the tenant, and the devices that are currently misconfigured or unpatched in ways that leave them open to those same techniques. Which TWO elements of the threat analytics report together surface both of these tenant-specific lists? Select TWO.
- AThe impacted assets view, which lists the devices and identities in the organisation that the report's techniques have already affected, so already-hit assets are surfaced. Correct
- BThe exposure and mitigations view, which lists the organisation's devices that remain misconfigured or unpatched against the report's techniques, so still-exposed devices are surfaced. Correct
- CThe analyst report write-up, which describes the actor's techniques, indicators, and recommended detections in prose so the team can build their own hunting queries.
- DThe related incidents view, which links the report to the cases the platform has already opened in the tenant for this campaign so triage can continue on real detections.
Why A is correct: The impacted assets view is the report element that names the organisation's devices and identities already touched by the campaign, giving the team the already-affected list.
Why B is correct: The exposure and mitigations view reports which devices still lack the recommended configurations and updates, giving the team the currently-exposed list to harden.
Why C is wrong: The analyst report explains the threat behaviour and detection guidance in narrative form, but it does not enumerate the tenant's specific affected or exposed assets.
Why D is wrong: Related incidents points to existing tenant cases for the campaign, which is useful, but it lists incidents rather than the affected-asset and exposed-device inventories.