Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection flashcards as text
What is 'Advanced Hunting' in Microsoft 365 Defender?
Answer: A query-based threat hunting tool using Kusto Query Language (KQL) to search across security data
Advanced Hunting is a proactive threat hunting tool in Microsoft 365 Defender that uses KQL to query up to 30 days of raw security data across endpoints, identities, email, and cloud apps.
Which Microsoft Defender for Identity alert indicates that an attacker may be attempting to enumerate all users and groups in Active Directory?
Answer: LDAP reconnaissance
LDAP reconnaissance alerts in Defender for Identity signal that an attacker is querying Active Directory via LDAP to map out users, groups, and organizational structure.
What is the 'Zero Trust' principle that Microsoft Defender Threat Protection products help enforce by continuously validating signals?
Answer: Assume breach
The 'Assume breach' Zero Trust principle drives Microsoft Defender products to continuously monitor and validate signals, minimizing blast radius by assuming attackers may already be inside.
Which component of Microsoft Defender for Cloud provides a regulatory compliance dashboard to track adherence to standards like PCI DSS and ISO 27001?
Answer: Regulatory Compliance
The Regulatory Compliance dashboard in Defender for Cloud maps your resource configurations against controls in compliance frameworks like PCI DSS, ISO 27001, and NIST.
What is the primary purpose of Microsoft Defender for Endpoint's 'Endpoint Detection and Response' (EDR) capability?
Answer: Detecting and investigating advanced threats that bypassed preventive controls
EDR provides advanced detection and investigation capabilities for threats that evade preventive controls, offering behavioral analytics, threat hunting, and response actions.
In Microsoft Defender for Office 365, what does 'Safe Links' protection do when a user clicks a URL in an email?
Answer: Rewrites the URL and checks it against Microsoft's threat intelligence at time-of-click
Safe Links rewrites URLs in emails and documents and performs a real-time reputation check at the moment a user clicks the link, protecting against URLs that become malicious after delivery.
Which Microsoft service provides a unified portal at security.microsoft.com that brings together Microsoft 365 Defender products?
Answer: Microsoft 365 Defender portal
The Microsoft 365 Defender portal at security.microsoft.com provides a unified interface for managing incidents, alerts, and investigations across Defender for Endpoint, Office 365, Identity, and Cloud Apps.