SC-200: Mitigate threats using Microsoft Defender XDR

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/95

flashcard set

Earn XP

Description and Tags

SC-200 Topic 1 - V2

Last updated 3:17 PM on 8/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

96 Terms

1
New cards

What is the primary function of Microsoft Defender XDR?

Correlates alerts across domains into incidents for investigation and response.

2
New cards

Which security domains does Microsoft Defender XDR correlate signals from?

Endpoints, Email/collaboration, Identities, Cloud apps, (plus vulnerability/IoT signals).

3
New cards

What is the difference between XDR and SIEM (Microsoft Sentinel)?

XDR = Microsoft signals correlated into incidents; SIEM (Sentinel) = ingests ANY data source for analytics/hunting.

4
New cards

What is the purpose of SOAR in a security operations center?

Automation of repetitive response steps (orchestration + automated playbooks).

5
New cards

What does the phrase 'collection is not detection' mean?

Having lots of telemetry data does not equal actionable detections.

6
New cards

Which key metric does modern security operations aim to reduce?

MTTR - Mean Time to Remediate.

7
New cards

What are the seven stages of the Lockheed Martin Cyber Kill Chain, in order?

Recon > Weaponize > Delivery > Exploit > Install > C2 > Actions on Objectives.

8
New cards

What is a limitation of the Cyber Kill Chain model?

Legacy/linear - doesn't reflect modern lateral movement.

9
New cards

How does the MITRE ATT&CK framework categorize adversary behavior?

Tactics (the WHY/stage) and techniques (the HOW).

10
New cards

What are the first three tactics in the MITRE ATT&CK Enterprise framework?

Reconnaissance, Resource Development, Initial Access.

11
New cards

What are the final three tactics in the MITRE ATT&CK Enterprise framework?

Command and Control, Exfiltration, Impact.

12
New cards

What does the PETE attack model stand for, and who is it designed for?

Prepare, Enter, Traverse, Execute (simple model for non-technical stakeholders).

13
New cards

Which attack model is designed for business leaders and emphasizes lateral movement?

PETE.

14
New cards

Which workloads does Microsoft Defender for Office 365 protect?

Email + collaboration (Exchange Online, SharePoint, OneDrive, Teams).

15
New cards

Which assets does Microsoft Defender for Endpoint protect?

Devices: workstations, servers, mobile (EDR + automated investigation).

16
New cards

What is the primary signal source for Microsoft Defender for Identity?

On-premises AD (and AD FS) traffic via sensors.

17
New cards

What signals does Microsoft Entra ID Protection analyze?

Cloud identity: sign-in behavior + user risk (threat intel + ML).

18
New cards

What does Microsoft Defender for Cloud Apps provide?

SaaS/PaaS cloud apps: discovery, control, anomaly detection, OAuth apps.

19
New cards

What does Microsoft Defender for Cloud protect?

Azure/cloud workloads: VMs, containers, SQL, APIs, DevOps (CWPP+CSPM).

20
New cards

What is the purpose of Microsoft Defender Vulnerability Management?

Risk-based vulnerability assessment and remediation tracking.

21
New cards

What is Microsoft Sentinel, and how does it integrate with Defender XDR?

Cloud-native SIEM + SOAR; can ingest Defender XDR incidents and hunting events.

22
New cards

What is the URL of the Microsoft Defender portal?

security.microsoft.com

23
New cards

What is an incident in Microsoft Defender XDR?

Correlated alerts + associated data telling the story of an attack.

24
New cards

What is an alert, and how does it relate to an incident?

A single detection; incidents group related alerts.

25
New cards

What are the main sections of an incident page in the Microsoft Defender portal?

Attack story, Alerts, Assets, Investigations, Evidence & Response, Summary.

26
New cards

What should you review first when investigating an incident?

Attack story / summary: severity, scope, affected entities.

27
New cards

What management actions can you take on an incident?

Assign, set status, classify, tag/comment, take actions, close.

28
New cards

What are the incident classification options when closing an incident?

True positive, False positive, Informational (expected activity).

29
New cards

When is it appropriate to close an incident?

Only after validating ALL alerts/entities are remediated - not after one action.

30
New cards

How does automatic attack disruption appear in the incident queue and incident page?

'Attack Disruption' tag/label on incident queue + yellow banner on incident page.

31
New cards

What does automatic attack disruption do, and what must the analyst still do?

Automatically contains active attacks (e.g., disables user, blocks device) - analyst still validates.

32
New cards

What does the Action Center in the Microsoft Defender portal display?

Pending + completed (History) remediation actions across devices, email, identities.

33
New cards

What does the Pending tab in the Action Center show?

Actions awaiting your approval/rejection.

34
New cards

What does the History tab in the Action Center show?

Audit log: automated actions, SOC-approved actions, Live Response, Defender AV actions.

35
New cards

What is the purpose of the Submissions page in the Microsoft Defender portal?

Sending emails/URLs/attachments to Microsoft for analysis.

36
New cards

What information is evaluated when you submit an email message for analysis?

Email authentication results, policy hits, payload reputation/detonation, grader analysis.

37
New cards

What is Automated Investigation and Response (AIR)?

Automated Investigation and Response: playbooks that investigate alerts and remediate automatically.

38
New cards

Which remediation actions can Automated Investigation and Response take in Microsoft Defender for Office 365?

Soft-delete messages/clusters, block URL (time-of-click), turn off mail forwarding, turn off delegation.

39
New cards

Which automation level does Microsoft recommend for automated investigation and remediation?

Full automation - proven reliable and safe.

40
New cards

What are the four phases of the Microsoft Defender for Office 365 email filtering stack, in order?

Edge protection > Sender intelligence > Content filtering > Post-delivery protection.

41
New cards

What does Safe Attachments protect against?

Unknown malware/zero-day in attachments (detonation scanning).

42
New cards

What are the five response options for unknown malware in a Safe Attachments policy?

Off, Monitor, Block, Replace, Dynamic Delivery.

43
New cards

What happens when Safe Attachments is set to Monitor?

Deliver message, track scan results.

44
New cards

What happens when Safe Attachments is set to Block?

Block current AND future mail/attachments with that malware.

45
New cards

What happens when Safe Attachments is set to Replace?

Remove attachment, deliver message body.

46
New cards

What happens when Safe Attachments is set to Dynamic Delivery?

Deliver body immediately, reattach file if safe.

47
New cards

What does Safe Links protect users from, and in which apps?

Malicious URLs at time-of-click (email, Teams, Office apps).

48
New cards

What threats do anti-phishing policies defend against?

Impersonation and spoofing.

49
New cards

What are preset security policies in Microsoft Defender for Office 365?

Microsoft-managed Standard/Strict policy bundles.

50
New cards

What does the Configuration Analyzer do?

Compares your settings vs Microsoft recommended (Standard/Strict).

51
New cards

What are the three threat investigation and response tool categories in Microsoft Defender for Office 365?

Threat trackers, Threat Explorer (Real-time detections), Attack Simulator.

52
New cards

What information do threat trackers provide?

Trending malware/campaigns; noteworthy, trending, tracked queries, saved queries.

53
New cards

What does Threat Explorer allow you to do?

Recent email threats: top threats, targeted users, malware families, URLs, attachments.

54
New cards

Which attack scenarios can you simulate with Attack Simulation Training?

Spear phishing, credential harvesting, malicious attachment, password spray, brute force.

55
New cards

When would you use Threat Explorer instead of Submissions?

Explorer = investigate threats in your org; Submissions = send sample to Microsoft.

56
New cards

What is sign-in risk in Microsoft Entra ID Protection?

Probability a specific authentication is not from the legitimate user.

57
New cards

What is user risk in Microsoft Entra ID Protection?

Probability the identity/account itself is compromised.

58
New cards

Which three reports does Microsoft Entra ID Protection provide for investigating risk?

Risky users, Risky sign-ins, Risk detections.

59
New cards

How far back does the risk detections report contain filterable data?

90 days (filterable).

60
New cards

Which license is required for Microsoft Entra ID Protection risk policies?

Entra ID Premium P2.

61
New cards

What is Microsoft's recommended configuration for the user risk policy?

Require secure password change when risk = High.

62
New cards

What is Microsoft's recommended configuration for the sign-in risk policy?

Require MFA when risk = Medium or High.

63
New cards

What must a user be registered for to self-remediate identity risk?

User registered for MFA + SSPR.

64
New cards

What are the two ways risk can be remediated in Microsoft Entra ID Protection?

Self-remediation (MFA/SSPR) or admin remediation (reset password, dismiss, confirm compromise).

65
New cards

What is the difference between dismissing user risk and confirming compromise?

Dismiss = investigated, not a threat; Confirm compromise = verified compromised, forces response.

66
New cards

How can an administrator unblock a user who was blocked by a sign-in risk policy?

Sign in from trusted location/device, exclude from policy, or fix policy.

67
New cards

Which three Microsoft Graph APIs are used with Microsoft Entra ID Protection?

riskDetection, riskyUsers, signIn.

68
New cards

Name at least five risk detections in Microsoft Entra ID Protection.

Leaked credentials, Anonymous IP, Atypical travel, Malicious IP, Password spray (also: unfamiliar properties, Entra threat intel, anomalous token, token issuer anomaly, suspicious browser, verified threat actor IP).

69
New cards

Where can Microsoft Defender for Identity sensors be installed?

Domain controllers and AD FS servers directly (no port mirroring needed).

70
New cards

What are the five detection themes of Microsoft Defender for Identity?

Reconnaissance, Compromised credentials, Lateral movement, Privilege escalation, Domain dominance.

71
New cards

How does Microsoft Defender for Identity use behavioral baselining?

Learns normal user/entity activity to spot anomalies.

72
New cards

What is a Lateral Movement Path (LMP) in Microsoft Defender for Identity?

Lateral Movement Path - visual map of how an attacker could move between identities.

73
New cards

Which advanced hunting table is used to investigate identity directory events?

IdentityDirectoryEvents

74
New cards

What are the four core pillars of Microsoft Defender for Cloud Apps?

1) Control Shadow IT 2) Protect sensitive info 3) Detect cyberthreats/anomalies 4) Assess app compliance.

75
New cards

What information does Cloud Discovery provide?

Sanctioned/unsanctioned app usage, top users/IPs, categories, risk scores.

76
New cards

What does an access policy control in Microsoft Defender for Cloud Apps?

Blocks or allows ACCESS to a cloud app.

77
New cards

What does a session policy control in Microsoft Defender for Cloud Apps?

Controls activities WITHIN a session (monitor, block download, label).

78
New cards

What does a file policy do in Microsoft Defender for Cloud Apps?

Inspects cloud files, applies governance (e.g., remove external sharing).

79
New cards

What does an activity policy do in Microsoft Defender for Cloud Apps?

Triggers on specific activities/behaviors with governance actions.

80
New cards

Which policy type should you use to block downloads during a live cloud app session?

Session policy.

81
New cards

Which policy type should you use to block all access to an unsanctioned cloud app?

Access policy.

82
New cards

Which policy type should you use to inspect files and remove external sharing?

File policy.

83
New cards

What is OAuth app governance in Microsoft Defender for Cloud Apps?

Assess/monitor third-party app permissions and risky app behavior.

84
New cards

What does Conditional Access App Control enable?

Reverse-proxy session controls: monitor/block actions in supported apps.

85
New cards

How much raw data can advanced hunting explore?

Up to 30 days of raw data.

86
New cards

What are the two most common outcomes of advanced hunting?

Root cause analysis + create custom detections.

87
New cards

Which table contains Microsoft Entra sign-in events when hunting in the Microsoft Defender portal?

AADSignInEventsBeta

88
New cards

Which table contains Microsoft Entra sign-in events when querying in Microsoft Sentinel?

SigninLogs

89
New cards

What is a custom detection rule?

Hunting query that runs on schedule, generates alerts/incidents + actions.

90
New cards

Which Microsoft Graph API endpoint runs an advanced hunting query?

POST /v1.0/security/runHuntingQuery

91
New cards

What does Microsoft Secure Score measure?

Security posture via completed recommended improvement actions.

92
New cards

What does Threat Analytics provide?

Emerging threat reports: impact, exposure, targeted assets, mitigations.

93
New cards

Where do you configure Microsoft Defender XDR email notifications?

Settings > Microsoft Defender XDR > General > Email notifications.

94
New cards

What is the key principle of Microsoft Defender XDR Unified role-based access control (RBAC)?

Least privilege - fewest permissions needed; replaces individual product RBAC when enabled.

95
New cards

What should you verify before taking a remediation action?

Permission, correct entity, evidence, business impact.

96
New cards

What is the least-disruptive effective action principle in incident response?

Pick the least disruptive action that still contains/remediates the threat.