SEC, MDO365 Microsoft Defender For Endpoints Flashcards

1
Q

What does MDO P1 include

A

EOP, zero day malware, phish and business email compromise
PROTECT DETECT 1/2INVESTIGATE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does MDO P2 include

A

P1 EOP and post breach investigation, hunting, response, automation and training simulation
PROTECT DETECT INVESTIGATE RESPOND

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is EOP

A

Exchange online protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does EOP do

A

Prevents broad, volume based, known attack and is present in any sub with exchange online mailboxes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What endpoints does Microsoft defender for Endpoints protect?

A

Laptops, phones, tablets, PCs access points, routers, firewalls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name everything Microsoft Defender for Endpoint includes

A

Core defender vulnerability management;
Attack surface reduction;
Next generation protection;
Endpoint detection and response;
Automated investigation and remediation AIR;
Microsoft secure scope for devices;
Microsoft threat experts;
Management and APIs;

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Core Defender Vulnerability Management

A

Uses a risk based approach to discovery, assessment, prioritization and remediation of endpoint vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Attack surface reduction

A

First line of defense shrink down number of vulnerabilities, by ensuring configuration settings such as blocking IPs, websites, etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Next generation protection

A

Antivirus, cloud delivered protection.
Dedicated protection and product updates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Endpoint detection and response

A

Advanced attacked detections so sec ops can prioritize alerts see the full scope of a breach and take response actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AIR

A

Automated investigation and remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Microsoft secure scope for devices

A

Assess security state of enterprise network, identify unprotected systems, take recommended actions to improve security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Microsoft threat experts

A

Managed threat hunting service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Management and API

A

Authorization authentification model using entra id

How well did you know this?
1
Not at all
2
3
4
5
Perfectly