Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A security operations team is implementing Microsoft Defender for Endpoint across their organization. They need to ensure that all newly discovered devices, including unmanaged workstations and network devices, are automatically onboarded to Defender for Endpoint for continuous monitoring and vulnerability assessment. Which Microsoft Defender XDR capability should they leverage to achieve this goal?

  1. AThreat and Vulnerability Management (TVM)
  2. BDevice Discovery
  3. CAutomated Investigation and Remediation (AIR)
  4. DAttack Surface Reduction (ASR) rules
Show answer & explanation

Correct answer: B. Device Discovery

Device Discovery in Microsoft Defender for Endpoint actively scans the network to find unmanaged devices, including workstations, servers, and network equipment, and provides options to onboard them. This directly addresses the requirement of discovering and onboarding newly found devices.

Why the other options are wrong

  • A. TVM focuses on identifying, assessing, and remediating vulnerabilities on already onboarded devices, not discovering new ones.
  • C. AIR automates the response to detected threats on onboarded devices, not the discovery or initial onboarding of devices.
  • D. ASR rules prevent malicious activities on endpoints but do not contribute to the discovery or onboarding of new devices.

Device Discovery (MDE)

A Microsoft Defender for Endpoint capability that actively finds unmanaged devices connected to an organization's network and provides options for onboarding them.

  • Identifies workstations, servers, and network devices.
  • Helps achieve comprehensive endpoint coverage.
  • Facilitates onboarding for continuous monitoring.

Memory trick: Device Discovery is like a network detective, finding all the hidden endpoints.

More Mitigate threats using Microsoft Defender XDR questions