Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard
A Microsoft 365 administrator is investigating an alert in Microsoft Defender XDR that indicates a potential supply chain attack. The alert shows that a digitally signed application, which is typically trusted, has exhibited highly suspicious behavior, including attempting to inject code into another process and making unusual network connections. The organization wants to ensure that even trusted applications are monitored for anomalous behavior. Which Defender for Endpoint capability would be most effective in detecting this type of post-execution suspicious behavior from a seemingly legitimate application?
- AEndpoint Detection and Response (EDR)
- BAntivirus scanning
- CDevice Discovery
- DApplication Control
Show answer & explanationAnswer & explanation
Correct answer: A. Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) focuses on monitoring and analyzing post-execution behaviors and advanced attacks, including suspicious activities from otherwise legitimate or signed applications, making it ideal for detecting supply chain attacks and anomalous behavior.
Why the other options are wrong
- B. Antivirus scanning primarily detects known malware signatures or heuristic patterns at the point of access or execution, but it may not catch anomalous behavior from a trusted, signed application post-execution.
- C. Device Discovery identifies unmanaged devices on the network and is not related to detecting suspicious behavior from applications.
- D. Application Control (e.g., Windows Defender Application Control) is used to explicitly allow or block applications from running based on rules, not to detect anomalous post-execution behavior from an already allowed application.
Defender for Endpoint EDR
Endpoint Detection and Response (EDR) in Microsoft Defender for Endpoint continuously monitors endpoint activity, detects advanced threats and post-breach behaviors, and provides investigation and response capabilities.
- Focuses on post-execution detection and behavioral analysis.
- Identifies sophisticated attacks like fileless malware, supply chain attacks, and lateral movement.
- Provides deep visibility into endpoint events (processes, network, files, registry).
- Enables automated investigation and remediation.
Memory trick: For POST-EXECUTION suspicious behavior, EDR is the DETECTIVE.