MD-101 Endpoint Security and Microsoft Defender for Endpoint 1 — Questions and Answers
Question 1: Which Intune integration enables security administrators to manage Microsoft Defender for Endpoint settings directly from the Intune admin center?
- Azure Security Center connector
- Microsoft Defender for Endpoint — Intune connector via security settings management (Correct answer)
- Microsoft Sentinel integration
- Azure AD Identity Protection
Correct answer: Microsoft Defender for Endpoint — Intune connector via security settings management
The Microsoft Defender for Endpoint connector in Intune enables MDE security settings management, allowing Intune to push Defender configurations to onboarded devices.
Question 2: What is the purpose of Microsoft Defender for Endpoint's 'Attack Surface Reduction (ASR)' rules?
- To block all internet access from managed devices
- To prevent specific behaviors commonly exploited by malware, such as Office macro spawning processes (Correct answer)
- To encrypt device storage before threats can access files
- To scan email attachments in real time
Correct answer: To prevent specific behaviors commonly exploited by malware, such as Office macro spawning processes
ASR rules block specific attack vectors used by malware, such as Office applications spawning child processes, executing content from email, and credential theft from LSASS.
Question 3: Which Intune endpoint security policy type configures Microsoft Defender Antivirus scan settings and exclusions?
- Endpoint detection and response (EDR) policy
- Antivirus policy under Endpoint security (Correct answer)
- Device restrictions profile
- Security baseline
Correct answer: Antivirus policy under Endpoint security
Endpoint security Antivirus policies in Intune configure Microsoft Defender Antivirus settings including scan type, schedule, exclusions, and cloud protection level.
Question 4: What does Microsoft Defender for Endpoint's 'Endpoint Detection and Response (EDR)' capability primarily provide?
- Real-time antivirus scanning
- Post-breach detection, investigation, and response capabilities for advanced threats (Correct answer)
- Network firewall management
- Email security and anti-phishing
Correct answer: Post-breach detection, investigation, and response capabilities for advanced threats
EDR provides advanced post-breach detection by continuously monitoring device behavior, enabling security teams to investigate and respond to threats that bypassed prevention.
Question 5: An administrator configures an ASR rule in 'Audit mode'. What is the effect on devices?
- The rule blocks the behavior and logs it
- The rule logs what would have been blocked without actually preventing the action (Correct answer)
- The rule is disabled and does nothing
- The rule only applies to new processes, not existing ones
Correct answer: The rule logs what would have been blocked without actually preventing the action
Audit mode logs ASR rule trigger events to Windows Event Log and Microsoft Defender for Endpoint without blocking the action, allowing testing before enforcement.
Question 6: Which Microsoft Defender for Endpoint feature provides network-level protection by blocking connections to malicious IPs and URLs?
- Attack Surface Reduction rules
- Network Protection (Correct answer)
- Controlled Folder Access
- Exploit Protection
Correct answer: Network Protection
Network Protection extends SmartScreen to block outbound connections to malicious IPs, domains, and URLs at the network layer on managed endpoints.
Which Intune integration enables security administrators to manage Microsoft Defender for Endpoint settings directly from the Intune admin center?