You have a Microsoft 365 E5 subscription that contains Windows 11 devices.
All the devices are onboarded to Microsoft Defender for Endpoint.
You need to compare the configuration of the devices against industry standard benchmarks.
What should you use?
A. Initiatives
B. Events
C. Security baselines assessment
D. Attack surface map
Show Answer
Correct Answer: C
Explanation: Security baselines assessment in Microsoft Defender for Endpoint compares device configurations against Microsoft-recommended and industry security baselines, helping identify deviations from benchmark configurations. The other options do not provide configuration benchmark assessment: Initiatives are part of Defender/Cloud security posture, Events are telemetry, and Attack surface map visualizes exposed assets rather than configuration compliance.
Question 94
HOTSPOT
-
Your company has offices in Montreal, Seattle, and New York City.
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
The offices have the IP addresses shown in the following table.
From Microsoft Defender for Cloud Apps, you create the activity policy shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: The policy triggers on repeated Download activities (30 within 1 minute) and only for matching Raw IP ranges. Montreal's configured filter is 10.10.0.0/24, which does not cover the full Montreal office range (10.10.0.0/16), so the statement is not guaranteed true. Seattle matches the configured raw IP range (194.25.2.0/24) and exceeds the threshold. New York does not match the configured IP filters.
Question 95
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3.
You use Microsoft Entra ID Protection.
You configure the Users at risk detected alerts setting to send an alert when a user risk level of low or above is detected.
Users are assigned the risk levels shown in the following table.
By the end of the day, how many alerts were generated for User1, and how many alerts were generated for User2 and User3? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1: 3
User2 and User3: 4
Explanation: Alerts are sent for users reaching the configured risk threshold, but email notifications are throttled to one email per 5-second window and aggregate multiple users if they occur within that window. User1 has one event suppressed at 8:02:04 because it is within 5 seconds of the 8:02:00 alert. User2 and User3 have simultaneous events aggregated at 8:00:00 and 8:03:01, with separate alerts at 8:10:00 and 9:00:00.
Question 96
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware.
Solution: You create a Standard preset security policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: A
Explanation: Yes. Microsoft Defender for Office 365 includes preset security policies with two profiles: Standard and Strict. The Standard preset security policy is the balanced baseline protection profile, providing recommended protection against spam, phishing, and malware for most users. Therefore, creating a Standard preset security policy meets the stated goal.
Question 97
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a user named User1. User1 has a Windows 11 device named Device1 that is onboarded to Microsoft Defender for Endpoint.
User1 reports that various files were deleted from Device1.
You need to create a filter to identify which service deleted the files.
Which settings should you configure, and which type of filter should you create in the Microsoft Defender portal? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Settings: Devices
Filter type: Timeline for Device1
Explanation: To determine which Microsoft Defender service or component deleted files on an onboarded endpoint, investigate the device's Timeline in the Devices section. The device timeline records file actions and identifies the initiating process or security service responsible.
Question 98
HOTSPOT
-
You have a Microsoft 365 subscription.
You integrate Microsoft Defender for Cloud Apps with Microsoft Defender for Endpoint.
You need to create a policy to block users from accessing discovered apps that have a risk score of 4 or lower.
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Filter: Risk score ≤ 4
Governance action: Tag app as unsanctioned
Explanation: Create a Cloud Discovery policy that matches apps with a risk score of 4 or lower and automatically tags them as unsanctioned. With Defender for Cloud Apps integrated with Defender for Endpoint, unsanctioned apps are blocked.
Question 99
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You use Microsoft Entra ID Protection.
For the Users at risk detected alerts setting, you configure the following:
• Recipient: Admin1
• Alert on user risk level at or above: Medium
User1 signs in to Microsoft 365 services and is assigned the detected risk levels shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: Email alerts are generated for each detected user risk event at or above the configured threshold (Medium). The explicitly configured recipient (Admin1) receives alerts, and Security Readers are included by default if they have a valid email. User Administrators are not included by default.
Question 100
You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365.
You need to implement a social engineering awareness solution that meets the following requirements:
• To reset a user's password, emulate an email message that contains a link.
• Track any users that selects the email message link.
• Suggest further social engineering training.
What should you use in the Microsoft Defender portal?
A. Exposure insights
B. Learning hub
C. Attack simulation training
D. Threat tracker
Show Answer
Correct Answer: C
Explanation: Attack simulation training in Microsoft Defender for Office 365 is designed to run phishing and other social engineering simulations, including credential harvest campaigns that present a link, track which users click or submit credentials, and automatically assign or recommend targeted training through integrated training experiences. Exposure insights provides security posture insights, Learning hub is for learning content, and Threat tracker monitors threat trends rather than conducting user simulations.
Question 101
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription.
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.
Solution: You configure a device configuration profile.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: A
Explanation: Yes. Configuring a device configuration profile can onboard Windows devices to Microsoft Defender for Endpoint when they enroll in Intune. Although Endpoint security > Endpoint detection and response (EDR) policies are the newer recommended approach, device configuration profiles are also a supported onboarding method, so the proposed solution meets the stated goal.
Sources:
https://www.secexams.com/exams/Microsoft/md-102/view/34
Question 102
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a Windows 11 device named Device1.
Device1 is onboarded to Microsoft Defender for Endpoint.
You need to ensure that Device1 is blocked from connecting to IP address 131.107.10.15.
What should you configure in the Microsoft Defender Endpoint settings? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: To block a specific IP address in Microsoft Defender for Endpoint, enable Custom network indicators under Advanced features, then create an IP indicator under Rules > Indicators with the action set to block.
$19
Get all 430 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.