SC-900 Practice Test 22 Hard Questions

SC-900 Exam Practice Test 22 (Hard) - Microsoft Defender for Endpoint Deep-Dive

SC-900 Exam Practice Tests

1 / 15

Which Microsoft Defender for Endpoint capability continuously monitors endpoint behavior, detecting and alerting on suspicious activity such as an unusual process execution chain?

2 / 15

Which Microsoft Defender for Endpoint component provides built-in, real-time protection against known malware based on signatures and heuristics?

3 / 15

Which Microsoft Defender for Endpoint feature allows a security analyst to isolate a compromised device from the network to prevent further spread of an attack, while retaining remote investigation capability?

4 / 15

Which Microsoft Defender for Endpoint feature provides a chronological view of observed behaviors and events on a specific device, aiding forensic investigation?

5 / 15

Which Microsoft Defender for Endpoint capability assigns a numerical score to a discovered vulnerability, helping security teams prioritize which vulnerabilities to remediate first?

6 / 15

Which Microsoft Defender for Endpoint feature allows security teams to view software inventory across all managed devices, identifying outdated or vulnerable software versions?

7 / 15

Which attack surface reduction rule category specifically targets blocking behaviors commonly associated with Office application exploitation, such as creating child processes?

8 / 15

Which Microsoft Defender for Endpoint feature protects specific, designated folders from unauthorized changes, such as those attempted by ransomware attempting to encrypt files?

9 / 15

Which Microsoft Defender for Endpoint feature blocks access to known malicious websites and phishing sites at the network level, regardless of which browser is being used?

10 / 15

Which Microsoft Defender for Endpoint feature allows an organization to restrict or block the use of USB drives and other removable storage media on managed devices?

11 / 15

Which Microsoft Defender for Endpoint automated investigation outcome level requires manual analyst approval before a suggested remediation action is actually applied?

12 / 15

Which Microsoft Defender for Endpoint feature evaluates a device's exposure level based on unpatched vulnerabilities, misconfigurations, and other risk factors, contributing to an overall organizational exposure score?

13 / 15

Which Microsoft Defender for Endpoint feature provides recommended security configuration baselines and tracks an organization's adherence to those baselines across managed devices?

14 / 15

Which term describes a simulated, controlled attack scenario that an organization can run within Microsoft Defender for Endpoint to validate detection and response capabilities without causing actual harm?

15 / 15

Which Microsoft Defender for Endpoint capability provides threat intelligence context about a detected file or IP address, such as whether it is associated with a known threat actor group?

Your score is

The average score is 0%

0%