Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint are consistently configured according to a predefined set of security policies and best practices. They want a solution that can automatically identify deviations from these baselines and provide recommendations for remediation. Which Microsoft Defender for Endpoint capability is best suited for this requirement?

  1. AVulnerability management
  2. BAutomated Investigation and Remediation (AIR)
  3. CSecurity baselines
  4. DAttack Surface Reduction (ASR) rules
Show answer & explanation

Correct answer: C. Security baselines

Microsoft Defender for Endpoint's 'Security baselines' capability allows administrators to deploy and monitor security configurations based on industry best practices (e.g., CIS benchmarks, Microsoft security baselines). It automatically identifies endpoints that deviate from these baselines and provides recommendations for remediation, ensuring consistent security posture.

Why the other options are wrong

  • A. Vulnerability management focuses on identifying and prioritizing software vulnerabilities, not configuration adherence.
  • B. AIR automatically investigates and remediates active threats, not configuration drift from baselines.
  • D. ASR rules prevent specific attack behaviors, but don't manage overall configuration baselines.

MDE Security Baselines

A capability in Microsoft Defender for Endpoint that allows organizations to enforce and monitor security configurations on devices based on industry best practices (e.g., CIS benchmarks, Microsoft security baselines), identifying and recommending remediation for deviations.

  • Ensures consistent security configurations across endpoints.
  • Compares current configurations against predefined baselines.
  • Provides recommendations to bring non-compliant devices into line.

Memory trick: Baselines keep endpoints in line.

More Mitigate threats using Microsoft Defender XDR questions