Select all of the following which are key features of Microsoft Defender for Endpoint. (Choose three.)
A.
Perform host enrichment actions to gather more information about the endpoint, which includes host details, logged-in users, and observable related machines details.
B.
Find indicators of compromise (IoC) and enrich security incidents with threat intelligence data.
C.
Perform Enterprise Security Search to sight potential malicious observables across endpoints, and take remediation actions.
D.
Perform response actions such as Isolate host, Remove isolation, Restrict app execution, Run antivirus scan, Remove app restriction, and Stop and quarantine file.
Key features
Microsoft Defender for Endpoint has the following key features:
Perform Enterprise Security Search to sight potential malicious observables across endpoints, and take remediation actions.
Perform response actions such as Isolate host, Remove isolation, Restrict app execution, Run antivirus scan, Remove app restriction, and Stop and quarantine file.
Create or update indicators.
Perform observable enrichment and retrieve data related to indicators.
https://www.servicenow.com/docs/bundle/xanadu-security-management/page/product/secops-integration-sir/secops-integration-ms-defender-endpoint/concept/microsoft-defender-for-endpoint-integration.html
Explanation: ebook p.159, Microsft Defender for Endpoint:
- Enables you to proactively inspect, analyze, and contain known and unkonw threats (A)
- Help Security Analysts effeciently investigate and remediate security incidents without having to navigate between tools
- Requests to isolate any machine from accessing the networks or remove the machines from isolation (D)
- Enables you to perform actions that includes Run Antivirus Scan, Restrict App Execution, Remove App Restrictions, Stop and Quarantine Files
- Provides indicator-related actions such as Enrich Observable, Create Indicators, and Udpate Indicators (B)
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
NokoNice
1 day, 18 hours agoZbtinjo
5 months, 3 weeks agosephereth
11 months, 2 weeks ago