Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDREasy
A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint to protect client devices. The organization requires a solution that can automatically block known malicious files and processes based on behavioral analysis and cloud-delivered protection, even when devices are offline. Which Defender for Endpoint capability should the administrator enable to meet this requirement?
- AAutomated investigation and remediation
- BEndpoint detection and response (EDR)
- CAttack Surface Reduction (ASR) rules
- DNext-generation protection
Show answer & explanationAnswer & explanation
Correct answer: D. Next-generation protection
Next-generation protection in Microsoft Defender for Endpoint includes antivirus capabilities that use behavioral analysis and cloud-delivered protection to block malware, even when devices are offline. This directly addresses the requirement for automatic blocking of known malicious files and processes.
Why the other options are wrong
- A. Automated investigation and remediation automates post-detection actions, not the initial blocking of known malicious files offline.
- B. EDR focuses on post-breach detection, investigation, and response, rather than primary, real-time, offline blocking of known threats.
- C. ASR rules focus on preventing malicious behaviors and exploits, not primarily on blocking known malicious files offline.
Next-generation protection
The core antivirus and anti-malware capabilities of Microsoft Defender for Endpoint, utilizing behavioral analysis, heuristics, and cloud-delivered protection to detect and block threats in real-time, even when devices are offline.
- Includes antivirus, anti-malware, and behavioral monitoring.
- Leverages cloud-delivered protection for up-to-date threat intelligence.
- Provides offline protection against known threats.
Memory trick: Next-gen protection is like a smart guard, always on duty, even when the internet is off.