Microsoft Defender for Office 365 detects a high-confidence business email compromise in which an internal mailbox is sending fraudulent messages to colleagues in real time. The security architect wants automatic attack disruption in Microsoft Defender XDR to contain the compromised mailbox autonomously within minutes, with no analyst initiating the response. Which TWO conditions must both be satisfied so the disruption containment action can be applied to the compromised account? Select TWO.
- AMicrosoft Defender for Office 365 must be onboarded so its high-confidence email signals feed the Microsoft Defender XDR correlation that drives automatic attack disruption. Correct
- BAutomated investigation and response must be active in the tenant so the platform has the automation pipeline through which disruption applies its containment action. Correct
- CA scheduled analytics rule must be authored in Microsoft Sentinel so it raises the incident that automatic attack disruption then waits for and acts upon.
- DA custom detection rule must be created in Microsoft Defender XDR with the disable-user response action so disruption has an action to invoke.
Why A is correct: Attack disruption acts on correlated cross-workload signals, so the Office 365 workload must be onboarded for its detections to trigger the disruption decision.
Why B is correct: Disruption relies on the automated investigation and response infrastructure to carry out its automatic containment, so AIR must be running for the action to be applied.
Why C is wrong: Attack disruption is built into Microsoft Defender XDR and uses its own high-confidence detections, so it needs no hand-written Sentinel scheduled rule to fire.
Why D is wrong: Disruption supplies its own automatic containment actions and does not depend on a custom detection rule being configured to disable the account.