Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A security operations team is implementing Microsoft Defender for Endpoint across their organization. They want to ensure that all newly onboarded devices are automatically configured with a standardized set of security settings and policies. Which feature in Microsoft Defender for Endpoint should they leverage for this purpose?
- AAutomated Investigation and Remediation (AIR)
- BSecurity Baselines
- CAttack Surface Reduction (ASR) rules
- DThreat and Vulnerability Management (TVM)
Show answer & explanationAnswer & explanation
Correct answer: B. Security Baselines
Security Baselines in Microsoft Defender for Endpoint provide a standardized, hardened configuration that can be automatically applied to devices upon onboarding, ensuring consistent security posture.
Why the other options are wrong
- A. AIR focuses on automated responses to detected threats, not initial configuration.
- C. ASR rules are specific controls to prevent common attack techniques, not a comprehensive configuration baseline.
- D. TVM focuses on identifying and remediating vulnerabilities, not applying initial security configurations.
Security Baselines (MDE)
Standardized, pre-configured security settings that can be deployed to devices to ensure a consistent and hardened security posture across the organization.
- Ensures consistent security configuration.
- Applied automatically to onboarded devices.
- Based on industry best practices.
Memory trick: Baselines build the secure foundation, not just fight the current fire.