โ† All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection flashcards as text
  1. Which Microsoft Defender for Endpoint capability allows security teams to remotely isolate a compromised device while maintaining communication with the Defender portal?

    Answer: Device Isolation

    Device Isolation in Defender for Endpoint cuts off a compromised machine from the network while keeping the management channel to the Defender portal open for investigation.

  2. In the context of SC-900, what is 'Threat Intelligence' as provided by Microsoft Defender Threat Protection?

    Answer: Information about known threat actors, tactics, and indicators of compromise used to improve defenses

    Threat Intelligence provides contextual information about threat actors, their TTPs (tactics, techniques, and procedures), and indicators of compromise to help security teams proactively defend against known threats.

  3. Which plan of Microsoft Defender for Office 365 adds threat hunting, attack simulation training, and campaign views?

    Answer: Microsoft Defender for Office 365 Plan 2

    Defender for Office 365 Plan 2 adds advanced capabilities including Threat Explorer, attack simulation training, automated investigation, and campaign views on top of Plan 1 features.

  4. What is the role of Microsoft Sentinel in relation to Microsoft Defender products?

    Answer: It acts as a cloud-native SIEM/SOAR that ingests alerts from Defender products for broader correlation

    Microsoft Sentinel is a cloud-native SIEM and SOAR that ingests security data from Defender products and other sources, providing broader threat correlation, hunting, and automated response.

  5. Which feature in Microsoft Defender for Endpoint provides a timeline of all observed behaviors and events on a device during an investigation?

    Answer: Device Timeline

    The Device Timeline in Defender for Endpoint shows a chronological view of all recorded events, processes, network connections, and file changes on an endpoint to support forensic investigation.

  6. What does Microsoft Defender Vulnerability Management primarily help organizations identify?

    Answer: Software vulnerabilities and misconfigurations on endpoints that should be remediated

    Microsoft Defender Vulnerability Management discovers, prioritizes, and helps remediate software vulnerabilities and security misconfigurations on endpoints.

  7. In Microsoft Defender for Cloud, what is a 'security recommendation'?

    Answer: Actionable guidance to harden resources and improve the secure score

    Security recommendations in Defender for Cloud are actionable steps organizations can take to reduce risk and improve their secure score by hardening misconfigurations in cloud resources.