Capabilities of Microsoft Identity Flashcards
5 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 5 Capabilities of Microsoft Identity flashcards as text
What feature in Microsoft Defender for Endpoint provides the first line of defense against cyberthreats by reducing the attack surface?
Answer: network protection
Network protection in Microsoft Defender for Endpoint serves as a crucial first line of defense against cyberthreats by reducing the attack surface. It prevents users from accessing dangerous domains that might host phishing scams, exploits, and other malicious content. By blocking access to untrusted URLs, it significantly mitigates the risk of web-based attacks.
Which two types of resources can be protected by using Azure Firewall? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Answer: Azure virtual networks
Azure Firewall is a cloud-native, intelligent network firewall security service that provides threat protection for your cloud workloads. It can protect Azure virtual networks by filtering traffic to and from virtual machines and subnets. Additionally, Azure Firewall can be used to filter outbound traffic from Azure resources to internet destinations, including Microsoft SharePoint Online sites, to ensure secure access and prevent data exfiltration.
You plan to implement a security strategy and place multiple layers of defense throughout a network infrastructure. Which security methodology does this represent?
Answer: defense in depth
Defense in depth is a security methodology that employs multiple, overlapping layers of security controls throughout an IT infrastructure. The principle is that if one security layer fails, another layer will still be in place to provide protection. This approach creates a robust and resilient security posture, making it significantly more difficult for attackers to breach the entire system.
What can you use to scan email attachments and forward the attachments to recipients only if the attachments are free from malware?
Answer: Microsoft Defender for Office 365
Microsoft Defender for Office 365 provides advanced protection against sophisticated threats like phishing, business email compromise, and malware in email attachments. Its Safe Attachments feature scans email attachments in a sandbox environment before they reach the recipient's inbox. This ensures that only malware-free attachments are delivered, effectively protecting users from malicious content.
Which feature provides the extended detection and response (XDR) capability of Azure Sentinel?
Answer: integration with Microsoft 365 Defender
Azure Sentinel (now Microsoft Sentinel) provides extended detection and response (XDR) capabilities through its deep integration with Microsoft 365 Defender. This integration allows Sentinel to ingest security data from endpoints, identities, email, and applications across the Microsoft 365 ecosystem. This unified view enables comprehensive threat detection, investigation, and automated response across the entire digital estate.