Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A security administrator needs to ensure that all endpoints managed by Microsoft Defender for Endpoint have the latest security updates, OS patches, and application vulnerabilities remediated promptly. They also need a clear, actionable report that prioritizes remediation efforts based on risk. Which Microsoft Defender for Endpoint capability directly provides this functionality?

  1. AAttack Surface Reduction (ASR) rules
  2. BThreat and Vulnerability Management (TVM)
  3. CEndpoint Detection and Response (EDR)
  4. DAutomated Investigation and Remediation (AIR)
Show answer & explanation

Correct answer: B. Threat and Vulnerability Management (TVM)

Threat and Vulnerability Management (TVM) in Microsoft Defender for Endpoint is specifically designed to discover, prioritize, and remediate software vulnerabilities and misconfigurations, providing actionable recommendations based on risk.

Why the other options are wrong

  • A. ASR rules are specific controls to prevent attack techniques, not a comprehensive vulnerability management solution.
  • C. EDR focuses on detecting and responding to active threats on endpoints, not proactive vulnerability management.
  • D. AIR focuses on automated responses to active threats, not proactive vulnerability remediation.

Threat and Vulnerability Management (TVM)

A capability within Microsoft Defender for Endpoint that continuously discovers, assesses, prioritizes, and remediates software vulnerabilities and misconfigurations on endpoints.

  • Identifies software vulnerabilities.
  • Prioritizes remediation based on risk.
  • Provides actionable security recommendations.

Memory trick: For 'threats' and 'vulnerabilities', 'TVM' is your proactive management tool.

More Mitigate threats using Microsoft Defender XDR questions