Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A security operations team is reviewing their Microsoft Defender for Endpoint deployment. They need to ensure that all newly onboarded devices automatically receive the latest security intelligence updates and are configured for real-time protection, without requiring manual intervention from administrators for each device. Which Defender for Endpoint capability directly addresses this requirement?
- AEndpoint detection and response (EDR)
- BAttack Surface Reduction rules
- CAntivirus and next-generation protection
- DAutomated investigation and remediation
Show answer & explanationAnswer & explanation
Correct answer: C. Antivirus and next-generation protection
Antivirus and next-generation protection in Microsoft Defender for Endpoint provides automatic updates for security intelligence and real-time protection, which are essential for newly onboarded devices without manual intervention.
Why the other options are wrong
- A. EDR focuses on detecting and investigating advanced threats post-breach, not the initial setup of antivirus definitions or real-time protection.
- B. Attack Surface Reduction rules help prevent common attack vectors but don't primarily manage automatic updates or real-time protection configuration.
- D. Automated investigation and remediation handles post-detection actions, not the initial provisioning of protection capabilities like security intelligence updates.
Antivirus and Next-Generation Protection
The core component of Microsoft Defender for Endpoint providing real-time protection, behavioral monitoring, and automatic updates for security intelligence.
- Prevents malware and viruses.
- Uses cloud-delivered protection and machine learning.
- Includes automatic security intelligence updates.
Memory trick: Defender's Core Protections Always Keep Devices Safe.