SC-900 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection 4 — Questions and Answers
Question 1: What is 'Advanced Hunting' in Microsoft 365 Defender?
- An automated scan that runs weekly to detect threats
- A query-based threat hunting tool using Kusto Query Language (KQL) to search across security data (Correct answer)
- A feature that automatically blocks advanced persistent threats
- A dashboard showing the most advanced attackers targeting your industry
Correct answer: A query-based threat hunting tool using Kusto Query Language (KQL) to search across security data
Advanced Hunting is a proactive threat hunting tool in Microsoft 365 Defender that uses KQL to query up to 30 days of raw security data across endpoints, identities, email, and cloud apps.
Question 2: Which Microsoft Defender for Identity alert indicates that an attacker may be attempting to enumerate all users and groups in Active Directory?
- Pass-the-Hash attack
- LDAP reconnaissance (Correct answer)
- Brute force attack
- Golden Ticket attack
Correct answer: LDAP reconnaissance
LDAP reconnaissance alerts in Defender for Identity signal that an attacker is querying Active Directory via LDAP to map out users, groups, and organizational structure.
Question 3: What is the 'Zero Trust' principle that Microsoft Defender Threat Protection products help enforce by continuously validating signals?
- Assume breach (Correct answer)
- Implicit trust
- Perimeter security
- Static policy enforcement
Correct answer: Assume breach
The 'Assume breach' Zero Trust principle drives Microsoft Defender products to continuously monitor and validate signals, minimizing blast radius by assuming attackers may already be inside.
Question 4: Which component of Microsoft Defender for Cloud provides a regulatory compliance dashboard to track adherence to standards like PCI DSS and ISO 27001?
- Defender CSPM
- Regulatory Compliance (Correct answer)
- Workload Protections
- Security Alerts
Correct answer: Regulatory Compliance
The Regulatory Compliance dashboard in Defender for Cloud maps your resource configurations against controls in compliance frameworks like PCI DSS, ISO 27001, and NIST.
Question 5: What is the primary purpose of Microsoft Defender for Endpoint's 'Endpoint Detection and Response' (EDR) capability?
- Preventing all malware from executing on endpoints
- Detecting and investigating advanced threats that bypassed preventive controls (Correct answer)
- Managing software updates across enrolled devices
- Encrypting endpoint data to prevent data loss
Correct answer: Detecting and investigating advanced threats that bypassed preventive controls
EDR provides advanced detection and investigation capabilities for threats that evade preventive controls, offering behavioral analytics, threat hunting, and response actions.
Question 6: In Microsoft Defender for Office 365, what does 'Safe Links' protection do when a user clicks a URL in an email?
- Blocks all external URLs by default
- Rewrites the URL and checks it against Microsoft's threat intelligence at time-of-click (Correct answer)
- Scans the destination website for malware before rendering it
- Redirects users to a company-approved URL whitelist
Correct answer: Rewrites the URL and checks it against Microsoft's threat intelligence at time-of-click
Safe Links rewrites URLs in emails and documents and performs a real-time reputation check at the moment a user clicks the link, protecting against URLs that become malicious after delivery.
Question 7: Which Microsoft service provides a unified portal at security.microsoft.com that brings together Microsoft 365 Defender products?
- Azure Security Center
- Microsoft 365 Defender portal (Correct answer)
- Microsoft Endpoint Manager
- Azure Defender
Correct answer: Microsoft 365 Defender portal
The Microsoft 365 Defender portal at security.microsoft.com provides a unified interface for managing incidents, alerts, and investigations across Defender for Endpoint, Office 365, Identity, and Cloud Apps.
What is 'Advanced Hunting' in Microsoft 365 Defender?