SC-900 Security Operations & Threat Protection 4 — Questions and Answers
Question 1: Which Microsoft Defender for Endpoint capability prevents malicious processes from running by comparing file hashes against a known-bad database?
- Attack Surface Reduction rules
- Next-generation antivirus protection (Correct answer)
- Endpoint Detection and Response
- Threat & Vulnerability Management
Correct answer: Next-generation antivirus protection
Next-generation antivirus (Microsoft Defender Antivirus) uses cloud-delivered protection and hash-based detection to block known malware before execution.
Question 2: What is the MITRE ATT&CK framework primarily used for in a security operations context?
- Assigning CVE severity scores to vulnerabilities
- Mapping adversary tactics, techniques, and procedures (TTPs) (Correct answer)
- Automating incident response playbooks
- Rating cloud service security compliance
Correct answer: Mapping adversary tactics, techniques, and procedures (TTPs)
MITRE ATT&CK is a knowledge base of adversary TTPs that security teams use to understand, detect, and respond to real-world attack patterns.
Question 3: A Security Operations Center (SOC) analyst needs to visualize trends in security alerts over the past 30 days. Which Microsoft Sentinel feature is best suited for this?
- Playbooks
- Incidents queue
- Workbooks (Correct answer)
- Analytics rules
Correct answer: Workbooks
Workbooks in Microsoft Sentinel provide customizable dashboards and visualizations for monitoring trends and KPIs from ingested security data.
Question 4: Which Microsoft Defender for Endpoint feature restricts the actions that Office applications can take, such as preventing them from spawning child processes?
- Network Protection
- Attack Surface Reduction (ASR) rules (Correct answer)
- Controlled Folder Access
- Web Content Filtering
Correct answer: Attack Surface Reduction (ASR) rules
Attack Surface Reduction rules block specific behaviors that are commonly exploited, such as Office apps launching child processes or injecting into other processes.
Question 5: What is the key difference between SIEM and SOAR in a security operations context?
- SIEM stores logs; SOAR only blocks network traffic
- SIEM aggregates and analyzes data; SOAR automates response workflows (Correct answer)
- SIEM is cloud-only; SOAR is on-premises only
- SIEM handles identity; SOAR handles endpoints
Correct answer: SIEM aggregates and analyzes data; SOAR automates response workflows
SIEM (Security Information and Event Management) collects and analyzes security data, while SOAR (Security Orchestration, Automation and Response) automates responses to detected threats.
Question 6: Which Microsoft service provides behavioral analytics on Azure resources and detects threats such as crypto mining and lateral movement in cloud workloads?
- Microsoft Purview
- Microsoft Defender for Cloud (Correct answer)
- Microsoft Entra ID Protection
- Microsoft Intune
Correct answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud uses behavioral analytics and threat intelligence to detect threats across Azure, hybrid, and multicloud workloads.
Question 7: When Microsoft Defender for Endpoint performs an 'automated investigation,' what is the primary outcome it aims to achieve?
- Generate a compliance report for auditors
- Automatically resolve or scope an incident with minimal human intervention (Correct answer)
- Patch all vulnerable software on the affected device
- Send phishing simulation emails to the affected user
Correct answer: Automatically resolve or scope an incident with minimal human intervention
Automated investigation in Defender for Endpoint analyzes alerts, collects evidence, and takes remediation actions automatically to resolve threats faster.
Which Microsoft Defender for Endpoint capability prevents malicious processes from running by comparing file hashes against a known-bad database?