MD-101 Endpoint Security and Microsoft Defender for Endpoint 2 — Questions and Answers
Question 1: What is Microsoft Defender for Endpoint's 'Controlled Folder Access' designed to protect against?
- Unauthorized USB device connections
- Ransomware and untrusted apps modifying protected folder contents (Correct answer)
- Data exfiltration via email
- Credential theft from the browser
Correct answer: Ransomware and untrusted apps modifying protected folder contents
Controlled Folder Access protects designated folders (Documents, Desktop, etc.) from being modified by untrusted applications, blocking ransomware from encrypting user files.
Question 2: Which Intune security baseline type provides pre-configured security settings based on Microsoft security guidance for Windows 10/11?
- Compliance policy baseline
- Microsoft Security Baseline for Windows 10/11 in Endpoint security (Correct answer)
- Windows Update baseline
- Device restrictions template
Correct answer: Microsoft Security Baseline for Windows 10/11 in Endpoint security
Microsoft Security Baselines in Intune Endpoint security provide preconfigured, Microsoft-recommended security settings for Windows 10/11, covering hundreds of hardening configurations.
Question 3: What is 'Tamper Protection' in Microsoft Defender Antivirus, and why is it important?
- Encryption of Defender logs to prevent tampering
- A feature that prevents unauthorized changes to Defender Antivirus settings by malware or users (Correct answer)
- A setting that protects Intune policies from being modified
- Monitoring of hardware tampering attempts
Correct answer: A feature that prevents unauthorized changes to Defender Antivirus settings by malware or users
Tamper Protection prevents malware and unauthorized users from disabling or modifying Microsoft Defender Antivirus settings, ensuring security tools remain active.
Question 4: An organization onboards devices to Microsoft Defender for Endpoint. Which Intune policy type deploys the MDE onboarding configuration package?
- Device compliance policy
- Endpoint detection and response (EDR) policy under Endpoint security (Correct answer)
- Win32 app deployment
- Administrative Templates profile
Correct answer: Endpoint detection and response (EDR) policy under Endpoint security
The Endpoint detection and response policy in Intune Endpoint security deploys the MDE onboarding package that connects devices to the MDE service.
Question 5: What information does the Microsoft Defender for Endpoint 'Device Inventory' in the Microsoft 365 Defender portal provide?
- A list of all Azure AD users and their devices
- A comprehensive list of onboarded devices with risk level, OS version, and last seen information (Correct answer)
- An inventory of all installed apps across the organization
- A report of all Intune compliance violations
Correct answer: A comprehensive list of onboarded devices with risk level, OS version, and last seen information
The Device Inventory in Microsoft 365 Defender shows all MDE-onboarded devices with risk levels, exposure scores, OS details, and last activity timestamps.
Question 6: Which Microsoft Defender for Endpoint capability scores and prioritizes device security misconfigurations and vulnerabilities?
- Advanced Threat Hunting
- Microsoft Defender Vulnerability Management (MDVM) with Secure Score for Devices (Correct answer)
- Endpoint Detection and Response alerts
- Network Protection telemetry
Correct answer: Microsoft Defender Vulnerability Management (MDVM) with Secure Score for Devices
Microsoft Defender Vulnerability Management provides a Secure Score for Devices that quantifies the organization's security posture and prioritizes misconfigurations and CVEs to remediate.
What is Microsoft Defender for Endpoint's 'Controlled Folder Access' designed to protect against?