SC-200 Microsoft Defender for Endpoint 1 — Questions and Answers
Question 1: Which portal serves as the unified security console for managing Microsoft Defender for Endpoint?
- Microsoft 365 Defender portal (security.microsoft.com) (Correct answer)
- Azure Portal (portal.azure.com)
- Microsoft Endpoint Manager (endpoint.microsoft.com)
- Microsoft Defender Security Center (legacy securitycenter.windows.com)
Correct answer: Microsoft 365 Defender portal (security.microsoft.com)
The Microsoft 365 Defender portal at security.microsoft.com is the unified console for managing Defender for Endpoint alongside other Microsoft security products.
Question 2: What is the primary purpose of Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint?
- To encrypt endpoint data at rest
- To block behaviors commonly used by malware before malicious activity occurs (Correct answer)
- To monitor network traffic for anomalous patterns
- To generate vulnerability reports for patch management teams
Correct answer: To block behaviors commonly used by malware before malicious activity occurs
ASR rules proactively block specific behaviors commonly exploited by malware — such as running obfuscated scripts or launching executable content from email — preventing attacks before they can execute.
Question 3: In Microsoft Defender for Endpoint, what is the relationship between an 'alert' and an 'incident'?
- Alerts come from third-party tools; incidents originate from Microsoft Defender tools
- An alert represents a single suspicious event; an incident is a collection of correlated alerts (Correct answer)
- Incidents are low-severity findings; alerts are always high-severity
- Alerts require manual investigation; incidents are always auto-remediated
Correct answer: An alert represents a single suspicious event; an incident is a collection of correlated alerts
An alert represents a single suspicious activity detection, while an incident is Microsoft Defender's grouping of correlated alerts that together describe a broader attack story.
Question 4: What does the 'Live Response' feature in Microsoft Defender for Endpoint enable a security analyst to do?
- View a real-time video feed of the endpoint user's screen
- Access a remote shell to investigate and remediate a device in real time (Correct answer)
- Automatically deploy security patches to a compromised endpoint
- Stream security event logs to a SIEM in real time
Correct answer: Access a remote shell to investigate and remediate a device in real time
Live Response provides an interactive remote shell connection to a device, allowing analysts to run commands, collect forensic artifacts, and perform remediation actions without physically accessing the machine.
Question 5: Which onboarding method is recommended for deploying Microsoft Defender for Endpoint sensors to a large number of Windows enterprise devices managed by Microsoft Endpoint Configuration Manager?
- Local script executed on each device individually
- Group Policy Object (GPO) deployment
- Microsoft Endpoint Configuration Manager (Correct answer)
- Manual download from the Microsoft 365 Defender portal
Correct answer: Microsoft Endpoint Configuration Manager
Microsoft Endpoint Configuration Manager is the recommended method for large-scale enterprise onboarding because it provides centralized, scalable deployment and management of the Defender for Endpoint sensor package.
Question 6: Which Microsoft Defender for Endpoint capability uses behavioral analysis and machine learning to detect advanced threats that evade signature-based antivirus?
- Endpoint Detection and Response (EDR) (Correct answer)
- Next-generation antivirus protection
- Network Protection
- Controlled Folder Access
Correct answer: Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) uses behavioral analytics and machine learning to detect sophisticated threats — such as fileless attacks — that traditional signature-based antivirus cannot identify.
Question 7: What is the primary function of 'Automated Investigation and Remediation' (AIR) in Microsoft Defender for Endpoint?
- Manually reviewing alerts to identify false positives
- Automatically investigating alerts and taking remediation actions to reduce analyst workload (Correct answer)
- Generating compliance reports for security auditors
- Scheduling periodic vulnerability scans across endpoints
Correct answer: Automatically investigating alerts and taking remediation actions to reduce analyst workload
AIR automatically investigates alerts using the same decision logic a security analyst would apply and takes remediation actions such as quarantining malicious files, significantly reducing the volume of alerts requiring manual investigation.
Which portal serves as the unified security console for managing Microsoft Defender for Endpoint?