1/95
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the primary function of Microsoft Defender XDR?
Correlates alerts across domains into incidents for investigation and response.
Which security domains does Microsoft Defender XDR correlate signals from?
Endpoints, Email/collaboration, Identities, Cloud apps, (plus vulnerability/IoT signals).
What is the difference between XDR and SIEM (Microsoft Sentinel)?
XDR = Microsoft signals correlated into incidents; SIEM (Sentinel) = ingests ANY data source for analytics/hunting.
What is the purpose of SOAR in a security operations center?
Automation of repetitive response steps (orchestration + automated playbooks).
What does the phrase 'collection is not detection' mean?
Having lots of telemetry data does not equal actionable detections.
Which key metric does modern security operations aim to reduce?
MTTR - Mean Time to Remediate.
What are the seven stages of the Lockheed Martin Cyber Kill Chain, in order?
Recon > Weaponize > Delivery > Exploit > Install > C2 > Actions on Objectives.
What is a limitation of the Cyber Kill Chain model?
Legacy/linear - doesn't reflect modern lateral movement.
How does the MITRE ATT&CK framework categorize adversary behavior?
Tactics (the WHY/stage) and techniques (the HOW).
What are the first three tactics in the MITRE ATT&CK Enterprise framework?
Reconnaissance, Resource Development, Initial Access.
What are the final three tactics in the MITRE ATT&CK Enterprise framework?
Command and Control, Exfiltration, Impact.
What does the PETE attack model stand for, and who is it designed for?
Prepare, Enter, Traverse, Execute (simple model for non-technical stakeholders).
Which attack model is designed for business leaders and emphasizes lateral movement?
PETE.
Which workloads does Microsoft Defender for Office 365 protect?
Email + collaboration (Exchange Online, SharePoint, OneDrive, Teams).
Which assets does Microsoft Defender for Endpoint protect?
Devices: workstations, servers, mobile (EDR + automated investigation).
What is the primary signal source for Microsoft Defender for Identity?
On-premises AD (and AD FS) traffic via sensors.
What signals does Microsoft Entra ID Protection analyze?
Cloud identity: sign-in behavior + user risk (threat intel + ML).
What does Microsoft Defender for Cloud Apps provide?
SaaS/PaaS cloud apps: discovery, control, anomaly detection, OAuth apps.
What does Microsoft Defender for Cloud protect?
Azure/cloud workloads: VMs, containers, SQL, APIs, DevOps (CWPP+CSPM).
What is the purpose of Microsoft Defender Vulnerability Management?
Risk-based vulnerability assessment and remediation tracking.
What is Microsoft Sentinel, and how does it integrate with Defender XDR?
Cloud-native SIEM + SOAR; can ingest Defender XDR incidents and hunting events.
What is the URL of the Microsoft Defender portal?
security.microsoft.com
What is an incident in Microsoft Defender XDR?
Correlated alerts + associated data telling the story of an attack.
What is an alert, and how does it relate to an incident?
A single detection; incidents group related alerts.
What are the main sections of an incident page in the Microsoft Defender portal?
Attack story, Alerts, Assets, Investigations, Evidence & Response, Summary.
What should you review first when investigating an incident?
Attack story / summary: severity, scope, affected entities.
What management actions can you take on an incident?
Assign, set status, classify, tag/comment, take actions, close.
What are the incident classification options when closing an incident?
True positive, False positive, Informational (expected activity).
When is it appropriate to close an incident?
Only after validating ALL alerts/entities are remediated - not after one action.
How does automatic attack disruption appear in the incident queue and incident page?
'Attack Disruption' tag/label on incident queue + yellow banner on incident page.
What does automatic attack disruption do, and what must the analyst still do?
Automatically contains active attacks (e.g., disables user, blocks device) - analyst still validates.
What does the Action Center in the Microsoft Defender portal display?
Pending + completed (History) remediation actions across devices, email, identities.
What does the Pending tab in the Action Center show?
Actions awaiting your approval/rejection.
What does the History tab in the Action Center show?
Audit log: automated actions, SOC-approved actions, Live Response, Defender AV actions.
What is the purpose of the Submissions page in the Microsoft Defender portal?
Sending emails/URLs/attachments to Microsoft for analysis.
What information is evaluated when you submit an email message for analysis?
Email authentication results, policy hits, payload reputation/detonation, grader analysis.
What is Automated Investigation and Response (AIR)?
Automated Investigation and Response: playbooks that investigate alerts and remediate automatically.
Which remediation actions can Automated Investigation and Response take in Microsoft Defender for Office 365?
Soft-delete messages/clusters, block URL (time-of-click), turn off mail forwarding, turn off delegation.
Which automation level does Microsoft recommend for automated investigation and remediation?
Full automation - proven reliable and safe.
What are the four phases of the Microsoft Defender for Office 365 email filtering stack, in order?
Edge protection > Sender intelligence > Content filtering > Post-delivery protection.
What does Safe Attachments protect against?
Unknown malware/zero-day in attachments (detonation scanning).
What are the five response options for unknown malware in a Safe Attachments policy?
Off, Monitor, Block, Replace, Dynamic Delivery.
What happens when Safe Attachments is set to Monitor?
Deliver message, track scan results.
What happens when Safe Attachments is set to Block?
Block current AND future mail/attachments with that malware.
What happens when Safe Attachments is set to Replace?
Remove attachment, deliver message body.
What happens when Safe Attachments is set to Dynamic Delivery?
Deliver body immediately, reattach file if safe.
What does Safe Links protect users from, and in which apps?
Malicious URLs at time-of-click (email, Teams, Office apps).
What threats do anti-phishing policies defend against?
Impersonation and spoofing.
What are preset security policies in Microsoft Defender for Office 365?
Microsoft-managed Standard/Strict policy bundles.
What does the Configuration Analyzer do?
Compares your settings vs Microsoft recommended (Standard/Strict).
What are the three threat investigation and response tool categories in Microsoft Defender for Office 365?
Threat trackers, Threat Explorer (Real-time detections), Attack Simulator.
What information do threat trackers provide?
Trending malware/campaigns; noteworthy, trending, tracked queries, saved queries.
What does Threat Explorer allow you to do?
Recent email threats: top threats, targeted users, malware families, URLs, attachments.
Which attack scenarios can you simulate with Attack Simulation Training?
Spear phishing, credential harvesting, malicious attachment, password spray, brute force.
When would you use Threat Explorer instead of Submissions?
Explorer = investigate threats in your org; Submissions = send sample to Microsoft.
What is sign-in risk in Microsoft Entra ID Protection?
Probability a specific authentication is not from the legitimate user.
What is user risk in Microsoft Entra ID Protection?
Probability the identity/account itself is compromised.
Which three reports does Microsoft Entra ID Protection provide for investigating risk?
Risky users, Risky sign-ins, Risk detections.
How far back does the risk detections report contain filterable data?
90 days (filterable).
Which license is required for Microsoft Entra ID Protection risk policies?
Entra ID Premium P2.
What is Microsoft's recommended configuration for the user risk policy?
Require secure password change when risk = High.
What is Microsoft's recommended configuration for the sign-in risk policy?
Require MFA when risk = Medium or High.
What must a user be registered for to self-remediate identity risk?
User registered for MFA + SSPR.
What are the two ways risk can be remediated in Microsoft Entra ID Protection?
Self-remediation (MFA/SSPR) or admin remediation (reset password, dismiss, confirm compromise).
What is the difference between dismissing user risk and confirming compromise?
Dismiss = investigated, not a threat; Confirm compromise = verified compromised, forces response.
How can an administrator unblock a user who was blocked by a sign-in risk policy?
Sign in from trusted location/device, exclude from policy, or fix policy.
Which three Microsoft Graph APIs are used with Microsoft Entra ID Protection?
riskDetection, riskyUsers, signIn.
Name at least five risk detections in Microsoft Entra ID Protection.
Leaked credentials, Anonymous IP, Atypical travel, Malicious IP, Password spray (also: unfamiliar properties, Entra threat intel, anomalous token, token issuer anomaly, suspicious browser, verified threat actor IP).
Where can Microsoft Defender for Identity sensors be installed?
Domain controllers and AD FS servers directly (no port mirroring needed).
What are the five detection themes of Microsoft Defender for Identity?
Reconnaissance, Compromised credentials, Lateral movement, Privilege escalation, Domain dominance.
How does Microsoft Defender for Identity use behavioral baselining?
Learns normal user/entity activity to spot anomalies.
What is a Lateral Movement Path (LMP) in Microsoft Defender for Identity?
Lateral Movement Path - visual map of how an attacker could move between identities.
Which advanced hunting table is used to investigate identity directory events?
IdentityDirectoryEvents
What are the four core pillars of Microsoft Defender for Cloud Apps?
1) Control Shadow IT 2) Protect sensitive info 3) Detect cyberthreats/anomalies 4) Assess app compliance.
What information does Cloud Discovery provide?
Sanctioned/unsanctioned app usage, top users/IPs, categories, risk scores.
What does an access policy control in Microsoft Defender for Cloud Apps?
Blocks or allows ACCESS to a cloud app.
What does a session policy control in Microsoft Defender for Cloud Apps?
Controls activities WITHIN a session (monitor, block download, label).
What does a file policy do in Microsoft Defender for Cloud Apps?
Inspects cloud files, applies governance (e.g., remove external sharing).
What does an activity policy do in Microsoft Defender for Cloud Apps?
Triggers on specific activities/behaviors with governance actions.
Which policy type should you use to block downloads during a live cloud app session?
Session policy.
Which policy type should you use to block all access to an unsanctioned cloud app?
Access policy.
Which policy type should you use to inspect files and remove external sharing?
File policy.
What is OAuth app governance in Microsoft Defender for Cloud Apps?
Assess/monitor third-party app permissions and risky app behavior.
What does Conditional Access App Control enable?
Reverse-proxy session controls: monitor/block actions in supported apps.
How much raw data can advanced hunting explore?
Up to 30 days of raw data.
What are the two most common outcomes of advanced hunting?
Root cause analysis + create custom detections.
Which table contains Microsoft Entra sign-in events when hunting in the Microsoft Defender portal?
AADSignInEventsBeta
Which table contains Microsoft Entra sign-in events when querying in Microsoft Sentinel?
SigninLogs
What is a custom detection rule?
Hunting query that runs on schedule, generates alerts/incidents + actions.
Which Microsoft Graph API endpoint runs an advanced hunting query?
POST /v1.0/security/runHuntingQuery
What does Microsoft Secure Score measure?
Security posture via completed recommended improvement actions.
What does Threat Analytics provide?
Emerging threat reports: impact, exposure, targeted assets, mitigations.
Where do you configure Microsoft Defender XDR email notifications?
Settings > Microsoft Defender XDR > General > Email notifications.
What is the key principle of Microsoft Defender XDR Unified role-based access control (RBAC)?
Least privilege - fewest permissions needed; replaces individual product RBAC when enabled.
What should you verify before taking a remediation action?
Permission, correct entity, evidence, business impact.
What is the least-disruptive effective action principle in incident response?
Pick the least disruptive action that still contains/remediates the threat.