Implement and manage threat protection Flashcards
How do you set up Azure ATP?
After you enter your info in the ATP Portal, you can download the sensor setup file. This zip file will install the Azure ATP agent on a DC or the Azure ATP Standalone agent on a non-domain controller, it contains the installer and a configuration file. you will also have to copy the Access Key which is used to establish the initial connection to your Azure ATP instance.
How is Azure ATP authentication managed?
Once installed all authentication is through certificates
How does Azure ATP establish its connection?
An Access Key is used to establish the initial connection to your Azure ATP instance
In Azure ATP, where is it managed?
Workspace Health - where issues such as connectivity, disconnected sensors, or service account authentication are reported. The Health icon will indicate whether there is any detected problem by displaying a red dot.
What happens when you log in to ATP Portal for the first time?
You will create the instance of Azure ATP for your environment, you will be prompted for the username (NETBIOS) password, Active Directory domain name for the service account you will use, this account should only have read-only access to your environment
What is involved to install and configure ATP?
involved connecting to the portal, providing information for your setup, downloading the install pkg, and deploying it to the servers
How do you plan for capacity when planning Azure Advanced Threat Protection? (ATP)
You need to download and run the Azure ATP sizing tool,
-> TriSizingTool.exe from Microsoft
What 4 report types are in Azure ATP reports?
- > Summary
- > Modifications to Sensitive Groups
- > Password Exposed in clear text
- > Lateral Movements Paths to Sensitive Accounts
How do you enable Azure ATP integration with Microsoft Defender ATP?
You must do so in both Azure ATP Portal and Microsoft Defender ATP Security Center
What alerts are included in the Azure ATP Portal Security Alerts Timeline?
- > User, computer, and/or resources involved
- > The time of the activity
- > Severity
- > Staus
How are ATP alerts categorized?
Alerts align with the phases in an attack-kill chain:
- > Reconnaissance
- > Compromised Credentials
- > Lateral Movement
- > Domain Dominance
- > Data Exfiltration
What licensing is required for Microsoft Defender ATP?
Microsoft Defender ATP is licensed as part of the M365 E5 suite and is also available with Windows Enterprise E5 (and the educational versions)
With Microsoft Defender ATP how do you protect servers?
To protect servers, you must onboard them to the Azure Security Center, which charges based on a consumption model.
What are the 5 deployment methods for Microsoft Defender ATP?
- > Locally run script
- > Group Policy Object
- > SCCM
- > Intue
- > Third-Party MDM & Software deployment solutions
In Microsoft Defender ATP, can you change the location where your data will be stored?
Once selected, you cannot change this, if you later change your mind, you must tear down and start over again.
How do you access the Microsoft Defender ATP portal?
securitycenter.windows.com
What are the 13 areas of the Microsoft Defender ATP console?
1-> Dashboards 2-> Incidents 3-> Machines List 4-> Alerts queue 5-> Automated Investigations 6-> Advanced Hunting 7-> Reports 8-> Partners & APIs 9-> Threat & Vulnerability Mgmt Dashboard 10-> Simulations & Tutorials (Evaluations) 11-> Service Health 12-> Machine Configuration Mgmt 13-> Settings
What is the Microsoft Defender ATP area - Dashboard?
includes information you would want to see first or even to keep on display in a security operations center (SOC) offers high-level insights. The Dashboard includes Security Operations, Secure Score, Threat Analytics
What is the Microsoft Defender ATP area - Incidents?
Anything Microsoft Defender ATP detects is tracked as an incident. The incidents area allows you to view and work with incidents. You can filter, classify, and assign incidents and see details
What is the Microsoft Defender ATP area - Machines List?
Displays all machines enrolled. Allows you to see all details of the machine.
What is the Microsoft Defender ATP area - Alerts queue?
Shows all alerts in your Microsoft Defender ATP tenant.
What is the Microsoft Defender ATP area - Automated Investigations?
lists investigations automatically created by the system. Default only shows past seven days.
What is the Microsoft Defender ATP area - Advanced Hunting?
Provides an interface to create or paste queries to search data within Microsoft Defender ATP
What is the Microsoft Defender ATP area - Reports subsections?
1-> Threat Protection - view alert trends
2-> Machine Health & Compliance - you can view machine trends and machine summary for Health State, AV Status, OS & version.
What is the Microsoft Defender ATP area - Reports -subsection Threat Protection include?
Unsolved Alert summary includes Detection Source Category Severity Status Classification and Determination
What is the Microsoft Defender ATP area - Partners & APIs?
Partner Applications - displays the many 3rd party applications that can be integrated
Data Export section - is where you can choose the data export settings which are used to push data to other applications, such as SIEMs
What is the Microsoft Defender ATP area - Threat & Vulnerability Mgmt Dashboard?
Gives admins a risk-based, real-time way to discover vulnerabilities in their environments prioritize based on risk, and remediate them easily.