MS-102 Microsoft 365 Administrator Expert Managing Defender for Endpoint 5 — Questions and Answers
Question 1: An administrator needs to ensure that endpoint detection data from Defender for Endpoint is stored within the European Union. Where is this configured?
- In the Microsoft Intune admin center under Tenant settings
- During initial Defender for Endpoint setup when selecting the data storage location (Correct answer)
- In the Microsoft Purview compliance portal
- In Azure Active Directory tenant properties
Correct answer: During initial Defender for Endpoint setup when selecting the data storage location
The data storage location (US, EU, or UK) for Defender for Endpoint is selected during the initial service setup and cannot be changed without offboarding.
Question 2: What is the function of 'Alert suppression rules' in Microsoft Defender for Endpoint?
- Permanently delete alerts from the database
- Automatically hide recurring known-benign alerts to reduce alert fatigue (Correct answer)
- Block the process generating the alerts
- Escalate alerts to Microsoft support
Correct answer: Automatically hide recurring known-benign alerts to reduce alert fatigue
Suppression rules allow administrators to define conditions under which specific alerts are automatically suppressed, reducing noise from known legitimate activity.
Question 3: A Defender for Endpoint investigation reveals a suspicious PowerShell script. An analyst uses Live Response to collect the script file for offline analysis. Which command should they use?
- get-file <path> (Correct answer)
- collect <path>
- download <path>
- export <path>
Correct answer: get-file <path>
The 'get-file' command in Live Response downloads a file from the device to the portal for offline forensic analysis.
Question 4: Which attack surface reduction rule helps prevent credential theft by blocking attempts to dump credentials from the Windows LSASS process?
- Block executable files from running unless they meet prevalence criteria
- Block credential stealing from the Windows local security authority subsystem (Correct answer)
- Block Office applications from creating executable content
- Block untrusted and unsigned processes from running from USB
Correct answer: Block credential stealing from the Windows local security authority subsystem
The ASR rule 'Block credential stealing from the Windows local security authority subsystem' prevents tools like Mimikatz from dumping LSASS memory.
Question 5: What does the 'Exposure score' in Defender for Endpoint's Threat and Vulnerability Management represent?
- The number of CVEs found on a single device
- The aggregate vulnerability exposure level of the entire organization's device fleet (Correct answer)
- The percentage of devices that are onboarded
- The number of high-severity alerts in the last 30 days
Correct answer: The aggregate vulnerability exposure level of the entire organization's device fleet
The exposure score aggregates vulnerability data across all devices to represent the organization's overall susceptibility to exploitation.
Question 6: An administrator wants to ensure Microsoft Defender Antivirus does not interfere with a third-party security product already installed. What mode should Defender Antivirus be configured to?
- Active mode
- Passive mode (Correct answer)
- Block mode
- Disabled mode
Correct answer: Passive mode
Passive mode allows Defender Antivirus to coexist with a primary third-party AV product, providing EDR data without actively scanning or remediating threats.
Question 7: Which Microsoft 365 Defender feature provides a unified view correlating alerts from Defender for Endpoint, Defender for Identity, and Defender for Office 365 into a single incident?
- Microsoft Secure Score
- Incidents queue (Correct answer)
- Action center
- Threat analytics
Correct answer: Incidents queue
The incidents queue in Microsoft 365 Defender automatically correlates related alerts from multiple Defender products into a single incident for unified investigation.
An administrator needs to ensure that endpoint detection data from Defender for Endpoint is stored within the European Union.
Where is this configured?