โ† All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection flashcards as text
  1. Which Microsoft Defender product provides security posture management and threat protection specifically for cloud workloads across Azure, AWS, and GCP?

    Answer: Microsoft Defender for Cloud

    Microsoft Defender for Cloud provides unified security management and threat protection across multicloud environments including Azure, AWS, and GCP.

  2. What does Microsoft Defender for Identity use as its primary data source to detect suspicious activities?

    Answer: On-premises Active Directory Domain Controller traffic

    Microsoft Defender for Identity monitors on-premises Active Directory Domain Controller traffic to detect advanced threats and compromised identities.

  3. In Microsoft Defender for Endpoint, what is the purpose of 'Attack Surface Reduction' (ASR) rules?

    Answer: To block risky behaviors commonly used by malware before an attack occurs

    ASR rules proactively block behaviors commonly exploited by malware, such as Office macros launching child processes, reducing attack surface before threats execute.

  4. Which capability in Microsoft 365 Defender correlates alerts from multiple Defender products into a single unified incident?

    Answer: Incident correlation

    Microsoft 365 Defender automatically correlates alerts across Defender for Endpoint, Office 365, Identity, and Cloud Apps into unified incidents for streamlined investigation.

  5. What is the primary function of Microsoft Defender for Cloud Apps (formerly MCAS)?

    Answer: Providing visibility and control over cloud application usage (Shadow IT)

    Microsoft Defender for Cloud Apps functions as a Cloud Access Security Broker (CASB) that provides visibility into Shadow IT and controls over sanctioned and unsanctioned cloud apps.

  6. Which Microsoft Defender for Office 365 feature detonates suspicious email attachments in a virtual environment to detect malware?

    Answer: Safe Attachments

    Safe Attachments opens suspicious email attachments in a secure sandbox environment to detect zero-day malware before delivering the email to the recipient.

  7. What does the 'Secure Score' in Microsoft Defender portals represent?

    Answer: A numerical measure of an organization's security posture based on implemented controls

    Microsoft Secure Score is a measurement of an organization's security posture, with higher scores indicating more recommended security controls have been implemented.