MS-102 Microsoft 365 Administrator Expert Managing Defender for Endpoint 3 — Questions and Answers
Question 1: An administrator needs to deploy Defender for Endpoint to Linux servers. Which onboarding method is supported for Linux?
- Microsoft Intune MDM
- Local script or Ansible/Puppet/Chef (Correct answer)
- Group Policy Object (GPO)
- Windows Configuration Designer
Correct answer: Local script or Ansible/Puppet/Chef
Linux devices can be onboarded using a local shell script or configuration management tools like Ansible, Puppet, or Chef.
Question 2: What is the purpose of the 'Live Response' feature in Microsoft Defender for Endpoint?
- Automatically quarantine malware files
- Provide a remote shell session to investigate and remediate a device in real time (Correct answer)
- Send real-time alerts to the security team
- Block network traffic on a compromised endpoint
Correct answer: Provide a remote shell session to investigate and remediate a device in real time
Live Response gives security analysts a remote shell connection to a device, allowing them to run commands, collect files, and remediate threats interactively.
Question 3: Which role-based access control (RBAC) permission is required in Microsoft 365 Defender to approve or reject pending remediation actions in the Action center?
- Security Reader
- Global Reader
- Active remediation actions permission (Correct answer)
- Compliance Administrator
Correct answer: Active remediation actions permission
The 'Active remediation actions' permission within Defender for Endpoint RBAC allows users to approve or reject pending automated investigation actions.
Question 4: An organization enables automated investigation and remediation (AIR) at the full automation level. What happens when malware is detected on a device?
- An analyst must manually approve every remediation step
- Defender automatically investigates and remediates threats without human approval (Correct answer)
- Only a notification is sent; no action is taken
- The device is immediately offboarded
Correct answer: Defender automatically investigates and remediates threats without human approval
Full automation allows AIR to automatically investigate and remediate threats without requiring manual approval from security analysts.
Question 5: A company wants to block specific file hashes known to be malicious across all onboarded devices. Which Defender for Endpoint capability should they use?
- Custom detection rules
- Indicators of Compromise (IoC) — file hash block (Correct answer)
- Attack surface reduction rules
- Microsoft Secure Score recommendations
Correct answer: Indicators of Compromise (IoC) — file hash block
Custom file hash IoCs can be configured to alert, allow, or block specific files identified by their SHA-1, SHA-256, or MD5 hash across onboarded devices.
Question 6: What is the significance of the 'Risk score' assigned to a device in Defender for Endpoint?
- It measures the device's network bandwidth consumption
- It reflects the level of active threats and vulnerabilities on the device (Correct answer)
- It indicates the user's compliance score
- It shows how long the device has been onboarded
Correct answer: It reflects the level of active threats and vulnerabilities on the device
The device risk score is calculated based on active alerts, vulnerability exposure, and threat intelligence signals to help prioritize investigation efforts.
Question 7: Which Windows event logs are collected by the Defender for Endpoint sensor for endpoint detection and response?
- Only Application and System logs
- Security, System, Application, and Sysmon logs among others (Correct answer)
- Only Windows Defender operational logs
- Only failed login event logs
Correct answer: Security, System, Application, and Sysmon logs among others
The Defender for Endpoint sensor collects a broad range of Windows event logs including Security, System, Application, and Sysmon events for comprehensive EDR coverage.
An administrator needs to deploy Defender for Endpoint to Linux servers.
Which onboarding method is supported for Linux?