Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint to monitor critical servers within the organization. These servers host sensitive applications and require a high level of security monitoring. The administrator wants to ensure that all process creations, network connections, file modifications, and registry changes on these servers are comprehensively logged and available for advanced hunting. Which type of data collection should be explicitly enabled or verified for these servers in Defender for Endpoint?

  1. AVulnerability Management insights
  2. BBasic event logging
  3. CAttack Surface Reduction (ASR) rules
  4. DEndpoint detection and response (EDR) capabilities
Show answer & explanation

Correct answer: D. Endpoint detection and response (EDR) capabilities

Endpoint detection and response (EDR) capabilities in Defender for Endpoint are responsible for collecting detailed event data such as process creations, network connections, file modifications, and registry changes. This data is then used for advanced hunting, incident investigation, and automated remediation on the servers.

Why the other options are wrong

  • A. Vulnerability Management insights focus on identifying and prioritizing software vulnerabilities and misconfigurations, not on real-time activity logging for threat detection.
  • B. Basic event logging in Windows might capture some events, but EDR provides a much richer, correlated, and actionable dataset specifically for security monitoring and advanced hunting.
  • C. ASR rules are preventative controls that block certain behaviors; they do not primarily focus on comprehensive logging for advanced hunting.

Defender for Endpoint EDR

Endpoint detection and response (EDR) in Microsoft Defender for Endpoint collects and analyzes rich behavioral data from endpoints, such as process activities, network connections, and file changes, to detect, investigate, and respond to advanced and persistent threats.

  • Collects detailed endpoint telemetry.
  • Used for advanced hunting and threat intelligence.
  • Enables real-time detection of suspicious activities.
  • Facilitates incident investigation and automated response.

Memory trick: EDR is like a hyper-detailed security camera, recording everything crucial happening on your servers.

More Implement and manage Microsoft Defender XDR questions