Security Operations & Threat Protection Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations & Threat Protection flashcards as text
Which Microsoft Defender for Endpoint capability prevents malicious processes from running by comparing file hashes against a known-bad database?
Answer: Next-generation antivirus protection
Next-generation antivirus (Microsoft Defender Antivirus) uses cloud-delivered protection and hash-based detection to block known malware before execution.
What is the MITRE ATT&CK framework primarily used for in a security operations context?
Answer: Mapping adversary tactics, techniques, and procedures (TTPs)
MITRE ATT&CK is a knowledge base of adversary TTPs that security teams use to understand, detect, and respond to real-world attack patterns.
A Security Operations Center (SOC) analyst needs to visualize trends in security alerts over the past 30 days. Which Microsoft Sentinel feature is best suited for this?
Answer: Workbooks
Workbooks in Microsoft Sentinel provide customizable dashboards and visualizations for monitoring trends and KPIs from ingested security data.
Which Microsoft Defender for Endpoint feature restricts the actions that Office applications can take, such as preventing them from spawning child processes?
Answer: Attack Surface Reduction (ASR) rules
Attack Surface Reduction rules block specific behaviors that are commonly exploited, such as Office apps launching child processes or injecting into other processes.
What is the key difference between SIEM and SOAR in a security operations context?
Answer: SIEM aggregates and analyzes data; SOAR automates response workflows
SIEM (Security Information and Event Management) collects and analyzes security data, while SOAR (Security Orchestration, Automation and Response) automates responses to detected threats.
Which Microsoft service provides behavioral analytics on Azure resources and detects threats such as crypto mining and lateral movement in cloud workloads?
Answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud uses behavioral analytics and threat intelligence to detect threats across Azure, hybrid, and multicloud workloads.
When Microsoft Defender for Endpoint performs an 'automated investigation,' what is the primary outcome it aims to achieve?
Answer: Automatically resolve or scope an incident with minimal human intervention
Automated investigation in Defender for Endpoint analyzes alerts, collects evidence, and takes remediation actions automatically to resolve threats faster.