Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A security operations team is implementing Microsoft Defender for Endpoint across their organization. They want to ensure that all newly onboarded devices are automatically configured with a standardized set of security settings and policies. Which feature in Microsoft Defender for Endpoint should they leverage for this purpose?

  1. AAutomated Investigation and Remediation (AIR)
  2. BSecurity Baselines
  3. CAttack Surface Reduction (ASR) rules
  4. DThreat and Vulnerability Management (TVM)
Show answer & explanation

Correct answer: B. Security Baselines

Security Baselines in Microsoft Defender for Endpoint provide a standardized, hardened configuration that can be automatically applied to devices upon onboarding, ensuring consistent security posture.

Why the other options are wrong

  • A. AIR focuses on automated responses to detected threats, not initial configuration.
  • C. ASR rules are specific controls to prevent common attack techniques, not a comprehensive configuration baseline.
  • D. TVM focuses on identifying and remediating vulnerabilities, not applying initial security configurations.

Security Baselines (MDE)

Standardized, pre-configured security settings that can be deployed to devices to ensure a consistent and hardened security posture across the organization.

  • Ensures consistent security configuration.
  • Applied automatically to onboarded devices.
  • Based on industry best practices.

Memory trick: Baselines build the secure foundation, not just fight the current fire.

More Mitigate threats using Microsoft Defender XDR questions