MS-900 · Question #458
Hotspot Question A company plans to implement Microsoft Defender XDR. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is…
This hotspot question tests knowledge of Microsoft Defender XDR capabilities, including its components, integration points, and core functionality for unified security operations.
Question
Exhibit
Answer Area
- Conditional Access App Control integrates Microsoft and third-party cloud apps to enforce policies, detect threats, and provide governance actions to resolve issues.
- Microsoft Secure Score provides real-time visibility and control over access and activities within cloud apps.
- The Cloud Access Security Broker monitors user activities for anomalous behaviors and controls access to resources through access controls.
Explanation
This hotspot question tests knowledge of Microsoft Defender XDR capabilities, including its components, integration points, and core functionality for unified security operations.
Approach. To answer hotspot questions about Microsoft Defender XDR, you must understand that it is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints (Defender for Endpoint), identities (Defender for Identity), email (Defender for Office 365), cloud apps (Defender for Cloud Apps), and more. Key facts: Defender XDR correlates signals across these workloads into unified incidents, supports automated investigation and remediation (AIR), integrates with Microsoft Sentinel as an SIEM layer, provides a unified portal at security.microsoft.com, and uses AI/ML to reduce alert fatigue. Statements that align with these capabilities should be marked Yes; those that misrepresent scope, integration, or functionality should be marked No.
Concept tested. Microsoft Defender XDR architecture, component integration (Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps), unified incident management, automated investigation and response (AIR), and the scope of cross-domain threat protection.
Topics
Community Discussion
No community discussion yet for this question.
