1/86
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is Microsoft Defender for Endpoint (MDE)
A security platform that prevents, detects, investigates, and responds to threats on devices
Core capabilities of Defender for Endpoint
Threat and Vulnerability Management; Attack Surface Reduction; Endpoint Detection and Response; Automated Investigation and Remediation; Secure Score
Threat and Vulnerability Management (TVM)
Finds and fixes endpoint vulnerabilities
Attack Surface Reduction (ASR)
Blocks risky behaviors to reduce attack surface
Endpoint Detection and Response (EDR)
Detects and investigates advanced endpoint threats
Automated Investigation and Remediation (AIR)
Automates investigation and fixes threats
Microsoft Secure Score
Measures and improves security posture
Device Inventory
List of onboarded devices
Device Timeline
Chronological view of device events
Device Investigation
Analyzing alerts and evidence on a device
Live Response
Remote command-line session for investigation
Collect Investigation Package
Downloads forensic logs and system info
Isolate Device
Cuts device off from network while keeping Defender connection
Restrict App Execution
Blocks non‑essential or unsigned apps
Run Antivirus Scan
Triggers Defender Antivirus scan
Offboarding a Device
Stops device from sending security data
Evidence
Artifacts like files or processes
Entities
Users, devices, or IPs linked to alerts
Action Center
Tracks and approves remediation actions
Endpoint Alert
Notification of suspicious activity
Endpoint Incident
Collection of related alerts forming an attack story
Endpoint Hunting
Proactive search for threats
Advanced Hunting
KQL queries across endpoint data
What are onboarding methods
Group Policy; Intune; ConfigMgr; Script; MDM
Exposure Score
Shows device vulnerability level
Security Configuration
Policies enforcing endpoint security
Vulnerability Remediation
Fixing patches and risky configs
Alert Suppression
Reduce false positives with rules
Role-Based Access Control (RBAC)
Defines SOC roles and permissions
Integration with Microsoft Sentinel
Sends alerts/incidents to SIEM
Integration with Microsoft Defender XDR
Unified incident management across domains
Integration with Microsoft Intune
Shares device health/compliance data
Integration with Microsoft Defender Antivirus
Layered protection with antivirus
Integration with Threat Intelligence
Enrich alerts with intel feeds
Integration with Security Copilot
AI‑driven summaries and guided responses
Alert Triage
Prioritizing alerts for investigation
Incident Queue
List of active incidents
Investigation Graph
Visual map of alerts and entities
Remediation Workflow
Steps to contain and recover
What triggers Automated Investigation?
Malware or suspicious activity
What are Automation levels
None; Semi (approval for any remediation, core folder remediation, non-temp folder); Full automation
Threat Analytics
Reports on emerging threats
What are Reports?
Information about security trends and track the protection status of your identities, data, devices, apps, and infrastructure.
What is Permissions Management?
Controls access to Defender features
Role of SOC Analyst?
Investigates alerts and hunts threats
Role of Security Administrator?
Configures policies and onboarding
Global Administrator role
Full control of Defender services
Investigator role
Performs deep incident analysis
Remediation Specialist role
Executes containment and recovery
Threat Hunter role
Runs proactive hunting queries
Compliance Officer role
Ensures regulatory alignment
IT Administrator role
Manages onboarding and patching
Incident Responder role
Coordinates SOC and IT response
Automation Engineer role
Designs automated workflows
Security Architect role
Defines endpoint security strategy
Forensic Analyst role
Analyzes evidence for legal cases
Threat Intelligence Analyst role
Adds external intel to alerts
Helpdesk Technician role
Supports users during remediation
MDE data storage location modification after setup
Not allowed; determined by tenant geolocation
Maximum data retention period for MDE
180 days
Data retention period for Advanced Hunting queries
30 days
Supported operating systems in MDE
Windows, macOS, Linux, Android, iOS
'Assume Breach' mindset
Operate as if attackers are already inside
Alert Tuning (Suppression Rules)
Reduce alert noise without losing visibility
Indicators of Compromise (IoCs)
Custom rules to allow, block, or audit files, IPs, URLs, certificates
IoC types that allow 'Remediate'
Files and Certificates
IoC actions for IPs and URLs
Allow, Audit, Block execution
Defender Vulnerability Management
Monitors for missing patches and misconfigurations
Remediation View (Vulnerability Management)
Portal section tracking active fixes and exceptions
Weaknesses page (Vulnerability Management)
Lists CVEs across the network
Method to limit admin access to computers
Device Groups and RBAC
Standard Discovery
Recommended setting for unmanaged device discovery
'Full Automation' in AIR
Investigates and fixes threats without approval
'Semi-Automation' in AIR
Investigates threats but requires approval
Device limit for onboarding via Local Script
Up to 10 devices
Best methods to onboard hundreds of devices
Intune, Group Policy, MECM
ASR rules examples
Block Office child processes, USB auto-run
'Audit Mode' in ASR rules
Logs activity without blocking
'Block Mode' in ASR rules
Prevents malicious behaviors from executing
KQL table for program starts/stops
DeviceProcessEvents
KQL table for network connections
DeviceNetworkEvents
KQL table for file changes
DeviceFileEvents
KQL table for user sign-ins
DeviceLogonEvents
Stop and Quarantine File
Kills malicious process and moves file to safe folder
Web Content Filtering
Blocks risky or inappropriate websites
Microsoft Secure Score for Devices
Shows device security level based on configuration
Consult a Threat Expert
Request Microsoft assistance for complex threats