SC-900 - Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection Questions and Answers — Questions and Answers
Question 1: An employee receives an email with a link to a new file-sharing website. Which Microsoft Defender for Office 365 feature is specifically designed to protect the user by scanning the URL at the time of click to block malicious sites?
- Safe Attachments
- Anti-phishing policies
- Safe Links (Correct answer)
- Threat Explorer
Correct answer: Safe Links
Microsoft Defender for Office 365 Safe Links provides time-of-click verification of URLs in emails and Office documents. It rewrites URLs and scans the destination for malicious content whenever a user clicks the link, protecting against phishing and other threats.
Question 2: A security analyst is investigating a potential breach. They suspect an attacker has compromised a user's on-premises Active Directory credentials and is attempting to move laterally across the network. Which Microsoft Defender component specializes in detecting and investigating such identity-based threats by analyzing signals from on-premises domain controllers?
- Microsoft Defender for Endpoint
- Microsoft Defender for Cloud Apps
- Microsoft Defender Vulnerability Management
- Microsoft Defender for Identity (Correct answer)
Correct answer: Microsoft Defender for Identity
Microsoft Defender for Identity is a cloud-based security solution that leverages signals from your on-premises Active Directory to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
Question 3: An organization wants to prevent users from accidentally running malicious code hidden in email attachments. They need a solution that opens attachments in a virtual environment to observe their behavior before they are delivered to the recipient. Which Microsoft Defender for Office 365 feature provides this 'detonation' capability?
- Safe Links
- Safe Attachments (Correct answer)
- Anti-spam policies
- Attack simulation training
Correct answer: Safe Attachments
Safe Attachments in Microsoft Defender for Office 365 protects against unknown malware and viruses by using a virtual environment (a process known as detonation) to check email attachments for malicious behavior before they are delivered to recipients.
Question 4: A company is concerned about the use of unsanctioned cloud applications (Shadow IT) and wants to gain visibility into the cloud apps being used by employees. They also need to enforce security policies and protect data within these apps. Which Microsoft Defender service is designed to address these requirements as a Cloud Access Security Broker (CASB)?
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps (Correct answer)
- Microsoft Defender for Cloud
Correct answer: Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility, data control, and threat protection for your cloud apps. It is designed to help organizations discover Shadow IT, assess risk, enforce policies, and investigate activities.
Question 5: Which of the following capabilities is a core function of Microsoft Defender for Endpoint?
- Rewriting URLs in emails to scan for malicious content at time-of-click.
- Using sensors on domain controllers to detect compromised identities.
- Discovering and controlling the use of unapproved SaaS applications.
- Providing endpoint detection and response (EDR) and attack surface reduction. (Correct answer)
Correct answer: Providing endpoint detection and response (EDR) and attack surface reduction.
Microsoft Defender for Endpoint is an enterprise endpoint security platform that provides capabilities such as attack surface reduction, next-generation protection, and endpoint detection and response (EDR) to prevent, detect, investigate, and respond to advanced threats on devices.
Question 6: A security operations team uses the Microsoft Defender portal as their primary interface for incident response. What is the primary benefit of this unified portal?
- It provides a way to purchase additional Microsoft security licenses.
- It is used exclusively for managing on-premises Active Directory security.
- It aggregates signals from multiple Defender services into single, correlated incidents. (Correct answer)
- It only displays alerts related to email and phishing threats.
Correct answer: It aggregates signals from multiple Defender services into single, correlated incidents.
The Microsoft Defender portal (part of Microsoft Defender XDR) provides a unified experience by aggregating signals, alerts, and incidents from various services like Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps. This correlation provides a complete view of an attack chain, enabling more efficient investigation and response.
An employee receives an email with a link to a new file-sharing website.
Which Microsoft Defender for Office 365 feature is specifically designed to protect the user by scanning the URL at the time of click to block malicious sites?