Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint are regularly scanned for vulnerabilities and misconfigurations. The administrator also wants to receive prioritized recommendations to address the most critical risks on these devices. Which specific capability within Microsoft Defender for Endpoint provides this functionality?
- AAttack surface reduction rules
- BAutomated investigation and remediation
- CVulnerability management
- DEndpoint detection and response (EDR)
Show answer & explanationAnswer & explanation
Correct answer: C. Vulnerability management
Vulnerability management in Microsoft Defender for Endpoint continuously discovers, prioritizes, and remediates software vulnerabilities and misconfigurations across devices, providing actionable security recommendations.
Why the other options are wrong
- A. Attack surface reduction rules prevent specific attack behaviors but don't perform comprehensive vulnerability scanning or provide prioritized recommendations.
- B. Automated investigation and remediation handles post-detection actions for threats, not vulnerability assessments.
- D. EDR focuses on detecting and responding to active threats, not proactive vulnerability scanning and management.
Vulnerability Management (MDE)
A capability within Microsoft Defender for Endpoint that continuously assesses endpoints for vulnerabilities and misconfigurations, providing prioritized recommendations.
- Discovers software vulnerabilities and misconfigurations.
- Prioritizes risks based on threat landscape and organizational context.
- Provides actionable remediation recommendations.
Memory trick: Vulnerability Management Finds Weaknesses First.