GregLab | Exam Prep

Security

Microsoft Defender XDR

A unified security operations experience that correlates signals from supported identities, endpoints, email, applications, and cloud services into incidents.

Key points

  • Incidents correlate related alerts
  • Advanced hunting supports investigation
  • Automated investigation can assist remediation

When to use it

  • Investigate a cross-workload attack
  • Review related entities and alerts

Exam tips

  • Defender XDR does not assign content permissions
  • Threat intelligence adds context but an alert still needs investigation

Free Microsoft 365 Copilot and Agent Administration Fundamentals prep

Build focused AB-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, clearly labeled supplemental exercises, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Build a quiz

Exam Weights

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not identify the specific item types that will appear on an individual exam before delivery. This lane counts multiple-choice and multiple-response items as exam-style practice. Ordering and matching are supplemental learning exercises and do not count toward exam-style accuracy. Difficulty labels are calibrated to AB-900 Fundamentals, not a Microsoft-published question rating.

Reference

AB-900 topics and reference map

Study links

AB-900 resources