MS-900 · Question #438
Hotspot Question A company is evaluating threat protection solutions of Microsoft 365. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each…
The correct answer is Microsoft Sentinel only allows for built-in workbooks. = No; Microsoft Sentinel only allows for built-in correlation rules. = No; Microsoft Sentinel integrates with Azure Logic Apps. = Yes. This hotspot question evaluates knowledge of Microsoft 365 threat protection solutions, specifically the capabilities of Microsoft Defender for Office 365, Microsoft Defender for Endpoint, and related security features.
Question
Exhibit
Answer Area
- Microsoft Sentinel only allows for built-in workbooks.No
- Microsoft Sentinel only allows for built-in correlation rules.No
- Microsoft Sentinel integrates with Azure Logic Apps.Yes
Explanation
This hotspot question evaluates knowledge of Microsoft 365 threat protection solutions, specifically the capabilities of Microsoft Defender for Office 365, Microsoft Defender for Endpoint, and related security features.
Approach. To answer hotspot questions about Microsoft 365 threat protection, you must understand the distinct roles of each solution: Microsoft Defender for Office 365 protects against email-based threats (phishing, malware in attachments/links via Safe Attachments and Safe Links), Microsoft Defender for Endpoint protects devices with EDR capabilities, and Microsoft Defender for Identity monitors on-premises Active Directory for identity-based attacks. Each statement should be evaluated against the specific feature set of the named solution - if the capability described matches what that product is designed to do, the answer is Yes; otherwise No. Common traps include confusing which Defender product handles which attack surface (email vs. endpoint vs. identity).
Concept tested. Microsoft 365 Defender threat protection portfolio - understanding the specific capabilities of Defender for Office 365 (Safe Links, Safe Attachments, anti-phishing), Defender for Endpoint (EDR, threat & vulnerability management), Defender for Identity (on-premises AD monitoring), and Microsoft Sentinel/Secure Score as part of the broader Microsoft security ecosystem.
Reference. Microsoft Learn: Microsoft 365 Defender overview - https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-365-defender
Topics
Community Discussion
No community discussion yet for this question.
