Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A company is implementing Microsoft Defender for Endpoint across its Windows servers and workstations. The security team wants to ensure that all endpoints are configured with the recommended security settings and that any deviations are automatically remediated. Which Defender for Endpoint capability should they utilize for this purpose?

  1. ASecurity recommendations within Threat and Vulnerability Management
  2. BAttack Surface Reduction rules
  3. CAutomated investigation and remediation
  4. DEndpoint detection and response (EDR)
Show answer & explanation

Correct answer: A. Security recommendations within Threat and Vulnerability Management

Security recommendations, found within Threat and Vulnerability Management in Defender for Endpoint, provide prioritized lists of actions to improve security posture and can be configured to automatically remediate deviations from recommended settings.

Why the other options are wrong

  • B. Attack Surface Reduction rules prevent specific behaviors commonly used by malware, but they don't assess overall security configuration or remediate deviations.
  • C. Automated investigation and remediation automates the response to detected threats or alerts, not the proactive management of security configurations.
  • D. Endpoint detection and response (EDR) focuses on detecting and responding to active threats, not proactively managing security configurations and deviations.

Security Recommendations (TVM)

A feature within Threat and Vulnerability Management (TVM) in Microsoft Defender for Endpoint that identifies security misconfigurations and provides actionable advice to improve an organization's security posture.

  • Prioritizes recommendations based on risk.
  • Integrates with Microsoft Intune for remediation.
  • Helps achieve compliance and reduce attack surface.

Memory trick: To build a strong endpoint, follow the architect's security recommendations.

More Mitigate threats using Microsoft Defender XDR questions