MS-102 - Microsoft 365 Administrator Expert Managing Defender for Endpoint Questions and Answers — Questions and Answers
Question 1: An administrator needs to onboard a large number of existing Windows 10 devices, which are all managed by Microsoft Configuration Manager, to Microsoft Defender for Endpoint. What is the most appropriate and efficient method to accomplish this?
- Use Group Policy to deploy the onboarding script to all devices.
- Manually run the local onboarding script on each device.
- Create a device collection in Configuration Manager and deploy the Defender for Endpoint onboarding configuration package to it. (Correct answer)
- Enroll each device into Microsoft Intune and then deploy an onboarding policy.
Correct answer: Create a device collection in Configuration Manager and deploy the Defender for Endpoint onboarding configuration package to it.
For environments where devices are already managed by Configuration Manager, the most integrated and efficient method is to leverage the existing infrastructure. This involves creating a specific device collection for the target machines and then deploying the onboarding package directly to that collection.
Question 2: A security team is concerned that a sophisticated attacker, upon gaining local administrator rights, could disable or alter Microsoft Defender Antivirus settings to evade detection. Which Microsoft Defender for Endpoint feature should be enabled to specifically prevent these unauthorized changes to security settings?
- Attack Surface Reduction (ASR)
- Tamper Protection (Correct answer)
- Network Protection
- Controlled Folder Access
Correct answer: Tamper Protection
Tamper Protection is designed to prevent malicious apps and unauthorized users (including local administrators) from changing critical Microsoft Defender Antivirus settings. When enabled, it locks down configurations like real-time protection and cloud-delivered protection, preventing them from being disabled.
Question 3: A security operations center (SOC) is experiencing a high volume of security alerts. To improve efficiency, they want to leverage a Defender for Endpoint capability that uses AI to automatically investigate alerts, correlate evidence, and apply remediation actions for confirmed threats without manual intervention. Which feature should they configure and use?
- Automated investigation and response (AIR) (Correct answer)
- Advanced Hunting
- Threat and Vulnerability Management
- Live Response
Correct answer: Automated investigation and response (AIR)
Automated investigation and response (AIR) is the feature specifically designed to address this need. It automatically examines alerts, collects and analyzes data, and can either recommend or automatically take remediation actions, significantly reducing alert fatigue and allowing analysts to focus on more complex threats.
Question 4: While reviewing the Threat and Vulnerability Management dashboard, a security administrator identifies a critical vulnerability on several devices related to outdated application software. What is the most direct, integrated action the administrator can take from the security recommendation within the Microsoft 365 Defender portal to initiate remediation?
- Use Live Response to connect to each device and manually uninstall the software.
- Isolate all affected devices from the network until they are patched.
- Create a remediation task that can be tracked and sent to the IT administration team via Microsoft Intune. (Correct answer)
- Deploy a new Attack Surface Reduction rule to block the vulnerable application.
Correct answer: Create a remediation task that can be tracked and sent to the IT administration team via Microsoft Intune.
The Threat and Vulnerability Management module is integrated with Microsoft Intune to streamline the remediation workflow. From a specific security recommendation, an administrator can create a remediation request, which generates a security task in Intune for the IT team to act upon. This bridges the gap between security discovery and IT operations.
Question 5: Which of the following BEST describes the primary purpose of implementing Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint?
- To scan for and report on software vulnerabilities and device misconfigurations.
- To provide a remote shell for in-depth, real-time investigation on a compromised device.
- To prevent common malware infection techniques by blocking specific software behaviors and actions, such as Office apps creating executable content. (Correct answer)
- To automatically quarantine malicious files based on cloud-delivered protection intelligence.
Correct answer: To prevent common malware infection techniques by blocking specific software behaviors and actions, such as Office apps creating executable content.
Attack Surface Reduction (ASR) rules are a set of controls that prevent software behaviors often leveraged by malware to infect machines. They target specific actions, like scripts launching downloaded content or credential theft from LSASS, rather than relying on traditional file-based signatures. This reduces the number of ways an attacker can exploit a device.
Question 6: A security analyst needs to perform a deep, interactive investigation on a specific device that has triggered a high-severity alert. The analyst requires the ability to run advanced commands, collect forensic artifacts like the MFT and registry hives, and run custom scripts in real-time. Which Defender for Endpoint feature provides this remote shell capability?
- Live Response (Correct answer)
- Automated Investigation
- Threat Analytics
- Advanced Hunting
Correct answer: Live Response
Live Response provides a security operations team with instantaneous remote shell access to a device. This allows for in-depth investigative work, such as running commands, downloading files, running scripts, and taking immediate remediation actions in real-time.
An administrator needs to onboard a large number of existing Windows 10 devices, which are all managed by Microsoft Configuration Manager, to Microsoft Defender for Endpoint.
What is the most appropriate and efficient method to accomplish this?