Quiz 7 Question 12 of 20

A security team is investigating a Microsoft Defender XDR incident where a device used for AI model development shows signs of compromise. The device has Azure ML SDK and Azure CLI installed. The team is concerned that the attacker may have exfiltrated Azure credentials from the development environment. Which Defender XDR investigation step directly identifies if cached Azure credentials were accessed?

Select an answer to reveal the explanation.

Motivation