Module 4: Defender fo Endpoint SC-200

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/86

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:15 AM on 9/18/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

87 Terms

1
New cards

What is Microsoft Defender for Endpoint (MDE)

A security platform that prevents, detects, investigates, and responds to threats on devices

2
New cards

Core capabilities of Defender for Endpoint

Threat and Vulnerability Management; Attack Surface Reduction; Endpoint Detection and Response; Automated Investigation and Remediation; Secure Score

3
New cards

Threat and Vulnerability Management (TVM)

Finds and fixes endpoint vulnerabilities

4
New cards

Attack Surface Reduction (ASR)

Blocks risky behaviors to reduce attack surface

5
New cards

Endpoint Detection and Response (EDR)

Detects and investigates advanced endpoint threats

6
New cards

Automated Investigation and Remediation (AIR)

Automates investigation and fixes threats

7
New cards

Microsoft Secure Score

Measures and improves security posture

8
New cards

Device Inventory

List of onboarded devices

9
New cards

Device Timeline

Chronological view of device events

10
New cards

Device Investigation

Analyzing alerts and evidence on a device

11
New cards

Live Response

Remote command-line session for investigation

12
New cards

Collect Investigation Package

Downloads forensic logs and system info

13
New cards

Isolate Device

Cuts device off from network while keeping Defender connection

14
New cards

Restrict App Execution

Blocks non‑essential or unsigned apps

15
New cards

Run Antivirus Scan

Triggers Defender Antivirus scan

16
New cards

Offboarding a Device

Stops device from sending security data

17
New cards

Evidence

Artifacts like files or processes

18
New cards

Entities

Users, devices, or IPs linked to alerts

19
New cards

Action Center

Tracks and approves remediation actions

20
New cards

Endpoint Alert

Notification of suspicious activity

21
New cards

Endpoint Incident

Collection of related alerts forming an attack story

22
New cards

Endpoint Hunting

Proactive search for threats

23
New cards

Advanced Hunting

KQL queries across endpoint data

24
New cards

What are onboarding methods

Group Policy; Intune; ConfigMgr; Script; MDM

25
New cards

Exposure Score

Shows device vulnerability level

26
New cards

Security Configuration

Policies enforcing endpoint security

27
New cards

Vulnerability Remediation

Fixing patches and risky configs

28
New cards

Alert Suppression

Reduce false positives with rules

29
New cards

Role-Based Access Control (RBAC)

Defines SOC roles and permissions

30
New cards

Integration with Microsoft Sentinel

Sends alerts/incidents to SIEM

31
New cards

Integration with Microsoft Defender XDR

Unified incident management across domains

32
New cards

Integration with Microsoft Intune

Shares device health/compliance data

33
New cards

Integration with Microsoft Defender Antivirus

Layered protection with antivirus

34
New cards

Integration with Threat Intelligence

Enrich alerts with intel feeds

35
New cards

Integration with Security Copilot

AI‑driven summaries and guided responses

36
New cards

Alert Triage

Prioritizing alerts for investigation

37
New cards

Incident Queue

List of active incidents

38
New cards

Investigation Graph

Visual map of alerts and entities

39
New cards

Remediation Workflow

Steps to contain and recover

40
New cards

What triggers Automated Investigation?

Malware or suspicious activity

41
New cards

What are Automation levels

None; Semi (approval for any remediation, core folder remediation, non-temp folder); Full automation

42
New cards

Threat Analytics

Reports on emerging threats

43
New cards

What are Reports?

Information about security trends and track the protection status of your identities, data, devices, apps, and infrastructure.

44
New cards

What is Permissions Management?

Controls access to Defender features

45
New cards

Role of SOC Analyst?

Investigates alerts and hunts threats

46
New cards

Role of Security Administrator?

Configures policies and onboarding

47
New cards

Global Administrator role

Full control of Defender services

48
New cards

Investigator role

Performs deep incident analysis

49
New cards

Remediation Specialist role

Executes containment and recovery

50
New cards

Threat Hunter role

Runs proactive hunting queries

51
New cards

Compliance Officer role

Ensures regulatory alignment

52
New cards

IT Administrator role

Manages onboarding and patching

53
New cards

Incident Responder role

Coordinates SOC and IT response

54
New cards

Automation Engineer role

Designs automated workflows

55
New cards

Security Architect role

Defines endpoint security strategy

56
New cards

Forensic Analyst role

Analyzes evidence for legal cases

57
New cards

Threat Intelligence Analyst role

Adds external intel to alerts

58
New cards

Helpdesk Technician role

Supports users during remediation

59
New cards

MDE data storage location modification after setup

Not allowed; determined by tenant geolocation

60
New cards

Maximum data retention period for MDE

180 days

61
New cards

Data retention period for Advanced Hunting queries

30 days

62
New cards

Supported operating systems in MDE

Windows, macOS, Linux, Android, iOS

63
New cards

'Assume Breach' mindset

Operate as if attackers are already inside

64
New cards

Alert Tuning (Suppression Rules)

Reduce alert noise without losing visibility

65
New cards

Indicators of Compromise (IoCs)

Custom rules to allow, block, or audit files, IPs, URLs, certificates

66
New cards

IoC types that allow 'Remediate'

Files and Certificates

67
New cards

IoC actions for IPs and URLs

Allow, Audit, Block execution

68
New cards

Defender Vulnerability Management

Monitors for missing patches and misconfigurations

69
New cards

Remediation View (Vulnerability Management)

Portal section tracking active fixes and exceptions

70
New cards

Weaknesses page (Vulnerability Management)

Lists CVEs across the network

71
New cards

Method to limit admin access to computers

Device Groups and RBAC

72
New cards

Standard Discovery

Recommended setting for unmanaged device discovery

73
New cards

'Full Automation' in AIR

Investigates and fixes threats without approval

74
New cards

'Semi-Automation' in AIR

Investigates threats but requires approval

75
New cards

Device limit for onboarding via Local Script

Up to 10 devices

76
New cards

Best methods to onboard hundreds of devices

Intune, Group Policy, MECM

77
New cards

ASR rules examples

Block Office child processes, USB auto-run

78
New cards

'Audit Mode' in ASR rules

Logs activity without blocking

79
New cards

'Block Mode' in ASR rules

Prevents malicious behaviors from executing

80
New cards

KQL table for program starts/stops

DeviceProcessEvents

81
New cards

KQL table for network connections

DeviceNetworkEvents

82
New cards

KQL table for file changes

DeviceFileEvents

83
New cards

KQL table for user sign-ins

DeviceLogonEvents

84
New cards

Stop and Quarantine File

Kills malicious process and moves file to safe folder

85
New cards

Web Content Filtering

Blocks risky or inappropriate websites

86
New cards

Microsoft Secure Score for Devices

Shows device security level based on configuration

87
New cards

Consult a Threat Expert

Request Microsoft assistance for complex threats