โ† All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection flashcards as text
  1. What type of attack does Microsoft Defender for Identity specifically detect when an attacker uses a stolen Kerberos ticket-granting ticket to impersonate any user?

    Answer: Golden Ticket attack

    A Golden Ticket attack uses a forged Kerberos TGT (often created using the KRBTGT account hash) to impersonate any user, and Defender for Identity is designed to detect this lateral movement technique.

  2. Which Defender for Cloud feature assigns a numeric score to a subscription to reflect its overall security health?

    Answer: Secure score

    The Secure Score in Defender for Cloud quantifies an organization's security posture, with higher scores indicating that more security recommendations have been implemented.

  3. What is 'Automated Investigation and Response' (AIR) in Microsoft Defender for Endpoint designed to do?

    Answer: Automatically investigate alerts and take remediation actions to reduce analyst workload

    AIR automatically investigates triggered alerts using the same logic a security analyst would apply and can take approved remediation actions, dramatically reducing alert fatigue and response time.

  4. Which Microsoft Defender product would BEST protect against a business email compromise (BEC) attack where an attacker impersonates a CEO?

    Answer: Microsoft Defender for Office 365

    Microsoft Defender for Office 365 includes anti-phishing policies with impersonation protection specifically designed to detect and block BEC and executive impersonation attacks in email.

  5. In SC-900 terms, what does 'SIEM' stand for and which Microsoft product fulfills this role?

    Answer: Security Information and Event Management; Microsoft Sentinel

    SIEM stands for Security Information and Event Management, and Microsoft Sentinel is Microsoft's cloud-native SIEM solution that collects, analyzes, and responds to security events across the environment.

  6. What is the purpose of 'Attack Simulation Training' in Microsoft Defender for Office 365 Plan 2?

    Answer: To run simulated phishing and social engineering campaigns to train employees and measure risk

    Attack Simulation Training sends simulated phishing emails to employees, measures who clicks or provides credentials, and delivers targeted training to improve human security awareness.

  7. Which capability helps Microsoft Defender for Endpoint identify software with known vulnerabilities that need patching across managed devices?

    Answer: Microsoft Defender Vulnerability Management

    Microsoft Defender Vulnerability Management continuously discovers and prioritizes software vulnerabilities and misconfigurations across endpoints, integrating with Intune and SCCM for remediation.