Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDREasy

A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint to protect client devices. The organization requires a solution that can automatically block known malicious files and processes based on behavioral analysis and cloud-delivered protection, even when devices are offline. Which Defender for Endpoint capability should the administrator enable to meet this requirement?

  1. AAutomated investigation and remediation
  2. BEndpoint detection and response (EDR)
  3. CAttack Surface Reduction (ASR) rules
  4. DNext-generation protection
Show answer & explanation

Correct answer: D. Next-generation protection

Next-generation protection in Microsoft Defender for Endpoint includes antivirus capabilities that use behavioral analysis and cloud-delivered protection to block malware, even when devices are offline. This directly addresses the requirement for automatic blocking of known malicious files and processes.

Why the other options are wrong

  • A. Automated investigation and remediation automates post-detection actions, not the initial blocking of known malicious files offline.
  • B. EDR focuses on post-breach detection, investigation, and response, rather than primary, real-time, offline blocking of known threats.
  • C. ASR rules focus on preventing malicious behaviors and exploits, not primarily on blocking known malicious files offline.

Next-generation protection

The core antivirus and anti-malware capabilities of Microsoft Defender for Endpoint, utilizing behavioral analysis, heuristics, and cloud-delivered protection to detect and block threats in real-time, even when devices are offline.

  • Includes antivirus, anti-malware, and behavioral monitoring.
  • Leverages cloud-delivered protection for up-to-date threat intelligence.
  • Provides offline protection against known threats.

Memory trick: Next-gen protection is like a smart guard, always on duty, even when the internet is off.

More Implement and manage Microsoft Defender XDR questions