Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A Microsoft 365 administrator is investigating a sophisticated attack where an attacker managed to compromise a user account and then attempted to escalate privileges by exploiting a known vulnerability in an outdated operating system component. The administrator needs to identify the specific vulnerability exploited and understand its potential impact across the organization's endpoints. Which Microsoft Defender XDR capability provides the most comprehensive information for this investigation, including vulnerability details, affected devices, and remediation steps?

  1. AAdvanced hunting in Microsoft 365 Defender
  2. BAutomated investigation and remediation
  3. CMicrosoft Defender Vulnerability Management
  4. DThreat analytics
Show answer & explanation

Correct answer: C. Microsoft Defender Vulnerability Management

Microsoft Defender Vulnerability Management provides a comprehensive view of vulnerabilities and misconfigurations across the organization, including details on specific exploits, affected devices, and prioritized remediation recommendations, which is exactly what's needed for this investigation.

Why the other options are wrong

  • A. Advanced hunting is a powerful tool for proactive threat hunting and investigation of raw data, but it requires the investigator to know what to query for and doesn't inherently provide a consolidated view of 'vulnerability details, affected devices, and remediation steps' in the same way Vulnerability Management does.
  • B. Automated investigation and remediation focuses on automatically responding to alerts and resolving threats, not on providing a comprehensive overview of exploited vulnerabilities and their organizational impact.
  • D. Threat analytics provides expert-level reports on emerging threats and active attacks, offering context and recommended actions, but it focuses on broader threat intelligence rather than specific vulnerability details and remediation for an organization's specific exploited vulnerability.

Defender Vulnerability Management

Microsoft Defender Vulnerability Management is a module within Microsoft Defender for Endpoint that provides continuous visibility into an organization's vulnerabilities and misconfigurations, prioritizing them based on risk and offering actionable remediation guidance.

  • Discovers and assesses software vulnerabilities.
  • Identifies misconfigurations.
  • Prioritizes based on threat landscape and asset value.
  • Provides remediation recommendations.

Memory trick: Investigating requires hunting, managing vulnerabilities, automating responses, and understanding threats.

More Implement and manage Microsoft Defender XDR questions