โ† All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection Flashcards

6 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection flashcards as text
  1. An employee receives an email with a link to a new file-sharing website. Which Microsoft Defender for Office 365 feature is specifically designed to protect the user by scanning the URL at the time of click to block malicious sites?

    Answer: Safe Links

    Microsoft Defender for Office 365 Safe Links provides time-of-click verification of URLs in emails and Office documents. It rewrites URLs and scans the destination for malicious content whenever a user clicks the link, protecting against phishing and other threats.

  2. A security analyst is investigating a potential breach. They suspect an attacker has compromised a user's on-premises Active Directory credentials and is attempting to move laterally across the network. Which Microsoft Defender component specializes in detecting and investigating such identity-based threats by analyzing signals from on-premises domain controllers?

    Answer: Microsoft Defender for Identity

    Microsoft Defender for Identity is a cloud-based security solution that leverages signals from your on-premises Active Directory to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.

  3. An organization wants to prevent users from accidentally running malicious code hidden in email attachments. They need a solution that opens attachments in a virtual environment to observe their behavior before they are delivered to the recipient. Which Microsoft Defender for Office 365 feature provides this 'detonation' capability?

    Answer: Safe Attachments

    Safe Attachments in Microsoft Defender for Office 365 protects against unknown malware and viruses by using a virtual environment (a process known as detonation) to check email attachments for malicious behavior before they are delivered to recipients.

  4. A company is concerned about the use of unsanctioned cloud applications (Shadow IT) and wants to gain visibility into the cloud apps being used by employees. They also need to enforce security policies and protect data within these apps. Which Microsoft Defender service is designed to address these requirements as a Cloud Access Security Broker (CASB)?

    Answer: Microsoft Defender for Cloud Apps

    Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility, data control, and threat protection for your cloud apps. It is designed to help organizations discover Shadow IT, assess risk, enforce policies, and investigate activities.

  5. Which of the following capabilities is a core function of Microsoft Defender for Endpoint?

    Answer: Providing endpoint detection and response (EDR) and attack surface reduction.

    Microsoft Defender for Endpoint is an enterprise endpoint security platform that provides capabilities such as attack surface reduction, next-generation protection, and endpoint detection and response (EDR) to prevent, detect, investigate, and respond to advanced threats on devices.

  6. A security operations team uses the Microsoft Defender portal as their primary interface for incident response. What is the primary benefit of this unified portal?

    Answer: It aggregates signals from multiple Defender services into single, correlated incidents.

    The Microsoft Defender portal (part of Microsoft Defender XDR) provides a unified experience by aggregating signals, alerts, and incidents from various services like Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps. This correlation provides a complete view of an attack chain, enabling more efficient investigation and response.