Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint. The organization requires that all newly detected vulnerabilities on managed devices are automatically assigned to the IT security team for remediation, and that high-severity vulnerabilities trigger an immediate notification to the security operations center (SOC). Which feature in Microsoft Defender for Endpoint should the administrator configure to meet these requirements?

  1. AAutomation rules in Defender Vulnerability Management
  2. BDevice groups with automated remediation levels
  3. CAttack Surface Reduction rules
  4. DCustom detection rules in Advanced Hunting
Show answer & explanation

Correct answer: A. Automation rules in Defender Vulnerability Management

Automation rules in Defender Vulnerability Management allow for automatic actions, such as assigning remediation tasks and sending notifications, based on vulnerability severity and other criteria. This directly addresses the organization's requirements for automatic assignment and immediate SOC notification for high-severity vulnerabilities.

Why the other options are wrong

  • B. Device groups with automated remediation levels primarily define how automatic remediation actions are applied to devices within a group, not the assignment of remediation tasks or custom notifications for vulnerabilities.
  • C. Attack Surface Reduction rules prevent specific behaviors that are often exploited by malware, rather than managing vulnerability remediation workflows.
  • D. Custom detection rules in Advanced Hunting are used for proactive threat hunting and alert generation based on observed events, not for automating vulnerability remediation tasks.

Defender Vulnerability Management Automation Rules

Automation rules in Microsoft Defender Vulnerability Management allow for the automatic assignment of security recommendations and the triggering of notifications based on defined conditions such as vulnerability severity, asset tags, or recommendation types.

  • Automate remediation task assignment.
  • Trigger notifications for critical vulnerabilities.
  • Based on conditions like severity or asset tags.
  • Streamlines vulnerability management workflows.

Memory trick: Automated rules bring order to vulnerability chaos, assigning tasks and alerting the guards.

More Implement and manage Microsoft Defender XDR questions