MS-102 Microsoft 365 Administrator Expert Managing Defender for Endpoint 2 — Questions and Answers
Question 1: An administrator needs to isolate a compromised device from the network while keeping it connected to the Defender for Endpoint service for investigation. Which action should they take in the Microsoft 365 Defender portal?
- Run antivirus scan
- Contain device (Correct answer)
- Offboard device
- Restrict app execution
Correct answer: Contain device
The 'Contain device' action isolates the device from the network while maintaining the Defender for Endpoint management channel for investigation.
Question 2: Which Defender for Endpoint feature uses behavioral sensors embedded in Windows to collect and process signals from the operating system?
- Cloud-delivered protection
- Endpoint Detection and Response (EDR) (Correct answer)
- Attack Surface Reduction (ASR)
- Network protection
Correct answer: Endpoint Detection and Response (EDR)
EDR uses behavioral sensors embedded in the OS to continuously collect telemetry signals that are processed in the Microsoft cloud.
Question 3: A security analyst wants to hunt for threats across devices using custom queries. Which tool in Microsoft 365 Defender should they use?
- Vulnerability management dashboard
- Advanced hunting (Correct answer)
- Action center
- Device inventory
Correct answer: Advanced hunting
Advanced hunting allows analysts to write Kusto Query Language (KQL) queries to proactively search for threats across devices and other data sources.
Question 4: What is the default data retention period for Defender for Endpoint raw data in the Microsoft 365 Defender portal?
- 30 days
- 90 days
- 180 days (Correct answer)
- 365 days
Correct answer: 180 days
Defender for Endpoint retains raw telemetry data for 180 days by default, giving analysts a six-month window for threat hunting and investigation.
Question 5: An organization wants to prevent users from accessing known malicious IP addresses at the network level on Windows 10 devices. Which Defender for Endpoint feature should be enabled?
- Web content filtering
- Network protection (Correct answer)
- Attack surface reduction rules
- Controlled folder access
Correct answer: Network protection
Network protection extends SmartScreen to block outbound connections to malicious IP addresses and domains at the kernel level.
Question 6: Which Microsoft Defender for Endpoint plan is required to access the Threat and Vulnerability Management (TVM) feature?
- Defender for Endpoint Plan 1 only
- Defender for Endpoint Plan 2 (Correct answer)
- Microsoft Defender Antivirus standalone
- Microsoft 365 Business Basic
Correct answer: Defender for Endpoint Plan 2
Threat and Vulnerability Management is a Plan 2 feature that provides real-time device discovery and risk-based vulnerability prioritization.
Question 7: A Defender for Endpoint alert is classified as 'Informational' severity. What does this indicate?
- The alert requires immediate remediation
- The activity is suspicious but has low impact on the organization (Correct answer)
- The alert is a false positive and can be dismissed
- No further investigation is needed
Correct answer: The activity is suspicious but has low impact on the organization
Informational alerts indicate activity that may not be harmful in isolation but could be part of a larger attack pattern worth monitoring.
An administrator needs to isolate a compromised device from the network while keeping it connected to the Defender for Endpoint service for investigation.
Which action should they take in the Microsoft 365 Defender portal?