MS-102 Microsoft 365 Administrator Expert Managing Defender for Endpoint 4 — Questions and Answers
Question 1: An administrator wants to configure Defender for Endpoint to send alerts to a SIEM solution. Which integration method is recommended for Microsoft Sentinel?
- Export alerts via email
- Use the Microsoft 365 Defender connector in Microsoft Sentinel (Correct answer)
- Manually download CSV reports
- Configure an SMTP relay on the Defender portal
Correct answer: Use the Microsoft 365 Defender connector in Microsoft Sentinel
The Microsoft 365 Defender data connector in Microsoft Sentinel natively ingests incidents and alerts from Defender for Endpoint without requiring custom scripting.
Question 2: Which Defender for Endpoint feature provides a risk-based prioritization of vulnerabilities by correlating asset exposure with threat intelligence?
- Secure Score for Devices
- Threat and Vulnerability Management (TVM) (Correct answer)
- Advanced hunting queries
- Endpoint behavioral sensors
Correct answer: Threat and Vulnerability Management (TVM)
TVM continuously assesses device vulnerabilities and correlates them with active exploit activity and threat intelligence to prioritize remediation.
Question 3: A security team wants to create a custom alert when a specific process is executed on any onboarded device. Which Defender for Endpoint capability supports this?
- Alert suppression rules
- Custom detection rules (Correct answer)
- ASR rules in audit mode
- Threat analytics reports
Correct answer: Custom detection rules
Custom detection rules run scheduled KQL queries against advanced hunting data and generate alerts or take actions when the query returns results.
Question 4: What happens to a device's status in the Defender for Endpoint portal if it has not communicated with the service for more than 7 days?
- It is automatically offboarded
- Its status changes to 'Inactive' (Correct answer)
- It is quarantined automatically
- Its alerts are deleted
Correct answer: Its status changes to 'Inactive'
Devices that do not report to the Defender for Endpoint service for more than 7 days are marked as 'Inactive' but remain in the device inventory.
Question 5: Which onboarding package type should be used when deploying Defender for Endpoint to Windows 10 devices using Microsoft Intune?
- Local script
- Group Policy
- Mobile Device Management (MDM) (Correct answer)
- System Center Configuration Manager (SCCM) package
Correct answer: Mobile Device Management (MDM)
When using Intune, the MDM onboarding package is selected in the Defender for Endpoint portal and deployed as an Intune device configuration policy.
Question 6: An organization needs to allow a security operations team to view alerts and device details but not take any remediation actions. Which built-in Defender for Endpoint role should be assigned?
- Security Administrator
- Security Operator
- Security Reader (Correct answer)
- Global Administrator
Correct answer: Security Reader
The Security Reader role provides read-only access to alerts, devices, and reports in Defender for Endpoint without the ability to take response actions.
Question 7: Which Microsoft Defender for Endpoint capability specifically helps identify unmanaged devices on the network that have not been onboarded?
- Threat analytics
- Device discovery (Correct answer)
- Vulnerability assessment
- Live response
Correct answer: Device discovery
Device discovery uses onboarded devices as probes to passively or actively identify unmanaged endpoints and network devices on the corporate network.
An administrator wants to configure Defender for Endpoint to send alerts to a SIEM solution.
Which integration method is recommended for Microsoft Sentinel?