SC-900 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection 2 — Questions and Answers
Question 1: Which Microsoft Defender product provides security posture management and threat protection specifically for cloud workloads across Azure, AWS, and GCP?
- Microsoft Defender for Endpoint
- Microsoft Defender for Cloud (Correct answer)
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
Correct answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud provides unified security management and threat protection across multicloud environments including Azure, AWS, and GCP.
Question 2: What does Microsoft Defender for Identity use as its primary data source to detect suspicious activities?
- Azure Active Directory sign-in logs
- On-premises Active Directory Domain Controller traffic (Correct answer)
- Microsoft 365 email metadata
- Endpoint telemetry from Windows devices
Correct answer: On-premises Active Directory Domain Controller traffic
Microsoft Defender for Identity monitors on-premises Active Directory Domain Controller traffic to detect advanced threats and compromised identities.
Question 3: In Microsoft Defender for Endpoint, what is the purpose of 'Attack Surface Reduction' (ASR) rules?
- To detect malware after it has executed
- To block risky behaviors commonly used by malware before an attack occurs (Correct answer)
- To quarantine infected devices from the network
- To generate alerts when suspicious network traffic is detected
Correct answer: To block risky behaviors commonly used by malware before an attack occurs
ASR rules proactively block behaviors commonly exploited by malware, such as Office macros launching child processes, reducing attack surface before threats execute.
Question 4: Which capability in Microsoft 365 Defender correlates alerts from multiple Defender products into a single unified incident?
- Secure Score
- Automated Investigation and Response (AIR)
- Incident correlation (Correct answer)
- Threat Analytics
Correct answer: Incident correlation
Microsoft 365 Defender automatically correlates alerts across Defender for Endpoint, Office 365, Identity, and Cloud Apps into unified incidents for streamlined investigation.
Question 5: What is the primary function of Microsoft Defender for Cloud Apps (formerly MCAS)?
- Protecting endpoints from malware
- Providing visibility and control over cloud application usage (Shadow IT) (Correct answer)
- Scanning email attachments for malicious content
- Managing firewall rules for Azure resources
Correct answer: Providing visibility and control over cloud application usage (Shadow IT)
Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB) that provides visibility into Shadow IT and controls over sanctioned and unsanctioned cloud apps.
Question 6: Which Microsoft Defender for Office 365 feature detonates suspicious email attachments in a virtual environment to detect malware?
- Anti-phishing policies
- Safe Attachments (Correct answer)
- Safe Links
- Mail flow rules
Correct answer: Safe Attachments
Safe Attachments opens suspicious email attachments in a secure sandbox environment to detect zero-day malware before delivering the email to the recipient.
Question 7: What does the 'Secure Score' in Microsoft Defender portals represent?
- A real-time count of active threats in your environment
- A numerical measure of an organization's security posture based on implemented controls (Correct answer)
- The percentage of endpoints protected by Defender for Endpoint
- A risk score assigned to individual users based on their behavior
Correct answer: A numerical measure of an organization's security posture based on implemented controls
Microsoft Secure Score is a measurement of an organization's security posture, with higher scores indicating more recommended security controls have been implemented.
Which Microsoft Defender product provides security posture management and threat protection specifically for cloud workloads across Azure, AWS, and GCP?