SC-900 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Defender Threat Protection 5 — Questions and Answers
Question 1: What type of attack does Microsoft Defender for Identity specifically detect when an attacker uses a stolen Kerberos ticket-granting ticket to impersonate any user?
- Pass-the-Hash
- Golden Ticket attack (Correct answer)
- Credential stuffing
- Spear phishing
Correct answer: Golden Ticket attack
A Golden Ticket attack uses a forged Kerberos TGT (often created using the KRBTGT account hash) to impersonate any user, and Defender for Identity is designed to detect this lateral movement technique.
Question 2: Which Defender for Cloud feature assigns a numeric score to a subscription to reflect its overall security health?
- Compliance score
- Secure score (Correct answer)
- Risk score
- Threat score
Correct answer: Secure score
The Secure Score in Defender for Cloud quantifies an organization's security posture, with higher scores indicating that more security recommendations have been implemented.
Question 3: What is 'Automated Investigation and Response' (AIR) in Microsoft Defender for Endpoint designed to do?
- Manually escalate every alert to the SOC team for review
- Automatically investigate alerts and take remediation actions to reduce analyst workload (Correct answer)
- Generate compliance reports for endpoint configurations
- Provide threat intelligence feeds from external sources
Correct answer: Automatically investigate alerts and take remediation actions to reduce analyst workload
AIR automatically investigates triggered alerts using the same logic a security analyst would apply and can take approved remediation actions, dramatically reducing alert fatigue and response time.
Question 4: Which Microsoft Defender product would BEST protect against a business email compromise (BEC) attack where an attacker impersonates a CEO?
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365 (Correct answer)
- Microsoft Defender for Identity
- Microsoft Defender for Cloud
Correct answer: Microsoft Defender for Office 365
Microsoft Defender for Office 365 includes anti-phishing policies with impersonation protection specifically designed to detect and block BEC and executive impersonation attacks in email.
Question 5: In SC-900 terms, what does 'SIEM' stand for and which Microsoft product fulfills this role?
- Security Intelligence and Event Management; Microsoft Defender for Endpoint
- Security Information and Event Management; Microsoft Sentinel (Correct answer)
- Secure Identity and Endpoint Management; Microsoft Entra ID
- System Integrity and Error Monitoring; Microsoft Intune
Correct answer: Security Information and Event Management; Microsoft Sentinel
SIEM stands for Security Information and Event Management, and Microsoft Sentinel is Microsoft's cloud-native SIEM solution that collects, analyzes, and responds to security events across the environment.
Question 6: What is the purpose of 'Attack Simulation Training' in Microsoft Defender for Office 365 Plan 2?
- To test firewall rules against known attack patterns
- To run simulated phishing and social engineering campaigns to train employees and measure risk (Correct answer)
- To simulate DDoS attacks on an organization's infrastructure
- To automatically test and validate endpoint security configurations
Correct answer: To run simulated phishing and social engineering campaigns to train employees and measure risk
Attack Simulation Training sends simulated phishing emails to employees, measures who clicks or provides credentials, and delivers targeted training to improve human security awareness.
Question 7: Which capability helps Microsoft Defender for Endpoint identify software with known vulnerabilities that need patching across managed devices?
- Threat Analytics
- Microsoft Defender Vulnerability Management (Correct answer)
- Advanced Hunting
- Conditional Access integration
Correct answer: Microsoft Defender Vulnerability Management
Microsoft Defender Vulnerability Management continuously discovers and prioritizes software vulnerabilities and misconfigurations across endpoints, integrating with Intune and SCCM for remediation.
What type of attack does Microsoft Defender for Identity specifically detect when an attacker uses a stolen Kerberos ticket-granting ticket to impersonate any user?