Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint are continuously assessed for software vulnerabilities and misconfigurations. They also want to receive actionable recommendations to prioritize and remediate the most critical issues based on their potential impact on the organization. Which specific Microsoft Defender for Endpoint capability directly provides this functionality?
- AAutomated Investigation and Remediation (AIR)
- BThreat and Vulnerability Management (TVM)
- CEndpoint Detection and Response (EDR)
- DAttack Surface Reduction (ASR) rules
Show answer & explanationAnswer & explanation
Correct answer: B. Threat and Vulnerability Management (TVM)
Threat and Vulnerability Management (TVM) within Microsoft Defender for Endpoint is specifically designed to continuously discover, prioritize, and remediate software vulnerabilities and misconfigurations. It provides security recommendations with contextual insights to help organizations improve their security posture.
Why the other options are wrong
- A. AIR automates responses to *detected threats*, not proactive vulnerability assessment.
- C. EDR focuses on detecting and responding to active threats, not proactively managing vulnerabilities.
- D. ASR rules prevent specific attack behaviors, not vulnerability assessment and management.
MDE Threat and Vulnerability Management (TVM)
A Microsoft Defender for Endpoint capability that continuously discovers, prioritizes, and provides actionable recommendations for remediating software vulnerabilities and misconfigurations across endpoints.
- Continuously scans for vulnerabilities.
- Prioritizes based on threat landscape and organizational context.
- Provides actionable security recommendations.
Memory trick: TVM is like a diligent health check for your endpoints, finding weaknesses and telling you how to fix them.