MS-102 · Question #378
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune. All devices run Windows 11 and are Microsoft Entra joined. You are alerted to a zero-day…
The correct answer is A. From Threat analytics, view the list of vulnerable devices. D. Select the affected devices and request remediation. To identify devices affected by a zero-day attack and request remediation, use Threat analytics to view vulnerable devices and then initiate remediation requests through the Defender portal.
Question
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune. All devices run Windows 11 and are Microsoft Entra joined. You are alerted to a zero-day attack. You need to identify which devices were affected by the attack and send a request to Intune administrators to update the affected devices. Which two actions should you perform in the Microsoft Defender portal? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- AFrom Threat analytics, view the list of vulnerable devices.
- BFrom Incidents & alerts, select the latest incident.
- CFrom Vulnerability management, open the security recommendation.
- DSelect the affected devices and request remediation.
How the community answered
(43 responses)- A84% (36)
- B12% (5)
- C5% (2)
Why each option
To identify devices affected by a zero-day attack and request remediation, use Threat analytics to view vulnerable devices and then initiate remediation requests through the Defender portal.
Threat analytics in Microsoft Defender XDR provides detailed reports on active threats, including zero-day attacks, and specifically lists devices in the organization that are exposed to or affected by the specific threat.
While incidents provide alerts, Threat analytics offers a more consolidated and comprehensive view of the overall impact and affected devices for an organizational threat campaign like a zero-day attack.
Vulnerability management focuses on proactively identifying and addressing software and configuration weaknesses rather than reactively identifying devices actively impacted by a specific zero-day attack.
After identifying the affected devices, the Microsoft Defender portal allows selection of those devices to initiate a remediation request, which integrates with Microsoft Intune for deployment by administrators.
Concept tested: Identifying affected devices and initiating remediation for zero-day threats
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/threat-analytics?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.