nerdexam
Microsoft

MS-102 · Question #81

Your company has a Microsoft 365 E5 subscription. You onboard a device on the company's network to Microsoft Defender for Endpoint. In the Microsoft 365 Defender portal, you notice that the device…

The correct answer is C. basic discovery. Microsoft Defender for Endpoint offers two device discovery modes. Standard Discovery actively probes the network using onboarded devices to find unmanaged endpoints - this is the 'polling' behavior the question wants to prevent. Basic Discovery is passive: onboarded devices…

Submitted by sofia.br· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

Your company has a Microsoft 365 E5 subscription. You onboard a device on the company's network to Microsoft Defender for Endpoint. In the Microsoft 365 Defender portal, you notice that the device inventory displays many devices that have an Onboarding status of Can be onboarded. You need to ensure that onboarded devices are prevented from polling the network for device discovery but can still discover devices with which they communicate directly. What should you configure in the Microsoft 365 Defender portal?

Options

  • Astandard discovery
  • Bdevice discovery exclusions
  • Cbasic discovery
  • Da network assessment job

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    8% (2)
  • C
    80% (20)
  • D
    4% (1)

Explanation

Microsoft Defender for Endpoint offers two device discovery modes. Standard Discovery actively probes the network using onboarded devices to find unmanaged endpoints - this is the 'polling' behavior the question wants to prevent. Basic Discovery is passive: onboarded devices only collect telemetry from devices they naturally communicate with (via existing network traffic), without actively scanning or polling the broader network. Since the requirement is to stop active network polling while still allowing discovery through direct communication, Basic Discovery is the correct setting.

Topics

#Microsoft Defender for Endpoint#Device Discovery#Security Configuration#Microsoft 365 Defender portal

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice