Free SC-900 Microsoft Defender for Endpoint Questions and Answers — Questions and Answers
Question 1: Which Microsoft Defender for Endpoint capability is designed to discover, prioritize, and remediate software vulnerabilities and misconfigurations on devices?
- Attack Surface Reduction (ASR)
- Endpoint Detection and Response (EDR)
- Threat & Vulnerability Management (Correct answer)
- Automated Investigation and Remediation (AIR)
Correct answer: Threat & Vulnerability Management
Threat & Vulnerability Management provides a risk-based approach to the discovery, prioritization, and remediation of endpoint vulnerabilities and misconfigurations. It helps organizations reduce their overall exposure to threats.
Question 2: An analyst observes suspicious process creation and lateral movement activities on a workstation. Which Defender for Endpoint feature provides the detailed event timeline and process tree to investigate these activities?
- Next-generation protection
- Endpoint Detection and Response (EDR) (Correct answer)
- Attack Surface Reduction (ASR)
- Microsoft Secure Score
Correct answer: Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) capabilities provide near real-time and actionable detections of threats. It collects and analyzes behavioral signals from endpoints, allowing security analysts to investigate the full scope of a breach through detailed timelines and process information.
Question 3: What is the primary goal of Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint?
- To scan for and remove existing malware on a device.
- To provide security recommendations to improve device configuration.
- To investigate and respond to security alerts after they occur.
- To prevent malware from running by blocking common malicious behaviors. (Correct answer)
Correct answer: To prevent malware from running by blocking common malicious behaviors.
Attack Surface Reduction (ASR) rules are designed to prevent common attack techniques used by malware. They target specific software behaviors, such as Office apps creating executable content or scripts launching downloaded payloads, to stop attacks at the pre-execution stage.
Question 4: A security alert is triggered on a device, and Defender for Endpoint automatically quarantines a malicious file and stops a suspicious process. Which capability performed these actions?
- Automated Investigation and Remediation (AIR) (Correct answer)
- Threat & Vulnerability Management
- Next-generation protection
- Advanced hunting
Correct answer: Automated Investigation and Remediation (AIR)
Automated Investigation and Remediation (AIR) is designed to mimic the actions of a security analyst at machine speed and scale. When an alert is triggered, AIR can automatically investigate the alert, determine the root cause, and apply remediation actions like quarantining files or stopping processes.
Question 5: Which component of Microsoft Defender for Endpoint uses cloud-based machine learning, behavior analysis, and heuristics to provide real-time malware protection?
- Endpoint Detection and Response (EDR)
- Next-generation protection (Correct answer)
- Attack Surface Reduction (ASR)
- Threat & Vulnerability Management
Correct answer: Next-generation protection
Next-generation protection is the real-time antivirus and antimalware component of Defender for Endpoint. It goes beyond traditional signature-based detection, using advanced cloud-powered techniques to block new and emerging threats.
Question 6: A security operations team wants to proactively search for signs of compromise across all their onboarded devices using custom Kusto Query Language (KQL) queries. Which Defender for Endpoint feature should they use?
- Automated Investigation and Remediation (AIR)
- Live Response
- Advanced hunting (Correct answer)
- Threat Analytics
Correct answer: Advanced hunting
Advanced hunting is a query-based threat hunting tool that lets you explore up to 30 days of raw event data from your endpoints. You can use Kusto Query Language (KQL) to proactively hunt for threats, anomalies, and indicators of compromise.
Which Microsoft Defender for Endpoint capability is designed to discover, prioritize, and remediate software vulnerabilities and misconfigurations on devices?