SC-900 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection 3 — Questions and Answers
Question 1: Which Microsoft Defender for Endpoint capability allows security teams to remotely isolate a compromised device while maintaining communication with the Defender portal?
- Live Response
- Device Isolation (Correct answer)
- Automated Remediation
- Network Protection
Correct answer: Device Isolation
Device Isolation in Defender for Endpoint cuts off a compromised machine from the network while keeping the management channel to the Defender portal open for investigation.
Question 2: In the context of SC-900, what is 'Threat Intelligence' as provided by Microsoft Defender Threat Protection?
- Automated scripts that patch vulnerabilities
- Information about known threat actors, tactics, and indicators of compromise used to improve defenses (Correct answer)
- A dashboard showing real-time network traffic
- Policies that restrict user access based on risk level
Correct answer: Information about known threat actors, tactics, and indicators of compromise used to improve defenses
Threat Intelligence provides contextual information about threat actors, their TTPs (tactics, techniques, and procedures), and indicators of compromise to help security teams proactively defend against known threats.
Question 3: Which plan of Microsoft Defender for Office 365 adds threat hunting, attack simulation training, and campaign views?
- Microsoft Defender for Office 365 Plan 1
- Microsoft Defender for Office 365 Plan 2 (Correct answer)
- Microsoft 365 Business Basic
- Exchange Online Protection (EOP)
Correct answer: Microsoft Defender for Office 365 Plan 2
Defender for Office 365 Plan 2 adds advanced capabilities including Threat Explorer, attack simulation training, automated investigation, and campaign views on top of Plan 1 features.
Question 4: What is the role of Microsoft Sentinel in relation to Microsoft Defender products?
- It replaces all Defender products with a single unified tool
- It acts as a cloud-native SIEM/SOAR that ingests alerts from Defender products for broader correlation (Correct answer)
- It is a standalone antivirus solution for endpoints
- It manages user identities and access policies
Correct answer: It acts as a cloud-native SIEM/SOAR that ingests alerts from Defender products for broader correlation
Microsoft Sentinel is a cloud-native SIEM and SOAR that ingests security data from Defender products and other sources, providing broader threat correlation, hunting, and automated response.
Question 5: Which feature in Microsoft Defender for Endpoint provides a timeline of all observed behaviors and events on a device during an investigation?
- Threat Analytics
- Device Timeline (Correct answer)
- Advanced Hunting
- Vulnerability Management
Correct answer: Device Timeline
The Device Timeline in Defender for Endpoint shows a chronological view of all recorded events, processes, network connections, and file changes on an endpoint to support forensic investigation.
Question 6: What does Microsoft Defender Vulnerability Management primarily help organizations identify?
- Misconfigured Azure network security groups
- Software vulnerabilities and misconfigurations on endpoints that should be remediated (Correct answer)
- Compromised user credentials in Azure AD
- Malicious email campaigns targeting employees
Correct answer: Software vulnerabilities and misconfigurations on endpoints that should be remediated
Microsoft Defender Vulnerability Management discovers, prioritizes, and helps remediate software vulnerabilities and security misconfigurations on endpoints.
Question 7: In Microsoft Defender for Cloud, what is a 'security recommendation'?
- An email alert sent to the subscription owner about active attacks
- Actionable guidance to harden resources and improve the secure score (Correct answer)
- A compliance report generated for auditors
- A firewall rule automatically applied to protect a resource
Correct answer: Actionable guidance to harden resources and improve the secure score
Security recommendations in Defender for Cloud are actionable steps organizations can take to reduce risk and improve their secure score by hardening misconfigurations in cloud resources.
Which Microsoft Defender for Endpoint capability allows security teams to remotely isolate a compromised device while maintaining communication with the Defender portal?