nerdexam
Microsoft

SC-100 · Question #59

Your company has a Microsoft 365 E5 subscription. The company plans to deploy 45 mobile self-service kiosks that will run Windows 10. You need to provide recommendations to secure the kiosks. The…

The correct answer is D. Implement threat and vulnerability management in Microsoft Defender for Endpoint. E. Onboard the kiosks to Microsoft Intune and Microsoft Defender for Endpoint. Onboarding kiosks to Microsoft Intune and Microsoft Defender for Endpoint (E) is foundational: Intune enforces application control policies (e.g., Windows Defender Application Control or AppLocker) ensuring only authorized apps run, while Defender for Endpoint provides endpoint…

Design security solutions for infrastructure

Question

Your company has a Microsoft 365 E5 subscription. The company plans to deploy 45 mobile self-service kiosks that will run Windows 10. You need to provide recommendations to secure the kiosks. The solution must meet the following requirements:

  • Ensure that only authorized applications can run on the kiosks.
  • Regularly harden the kiosks against new threats.

Which two actions should you include in the recommendations? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AOnboard the kiosks to Azure Monitor.
  • BImplement Privileged Access Workstation (PAW) for the kiosks.
  • CImplement Automated Investigation and Remediation (AIR) in Microsoft Defender for Endpoint.
  • DImplement threat and vulnerability management in Microsoft Defender for Endpoint.
  • EOnboard the kiosks to Microsoft Intune and Microsoft Defender for Endpoint.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    25% (5)
  • C
    10% (2)
  • D
    60% (12)

Explanation

Onboarding kiosks to Microsoft Intune and Microsoft Defender for Endpoint (E) is foundational: Intune enforces application control policies (e.g., Windows Defender Application Control or AppLocker) ensuring only authorized apps run, while Defender for Endpoint provides endpoint protection and telemetry. Threat and Vulnerability Management (TVM) in Microsoft Defender for Endpoint (D) continuously assesses the kiosks for known vulnerabilities and misconfigurations, providing prioritized remediation guidance to regularly harden them against new threats. Azure Monitor (A) collects metrics and logs but doesn't harden devices or enforce app allow-listing. PAW (B) is a high-security workstation concept for privileged administrators, not self-service kiosks. Automated Investigation and Remediation (C) responds to detected threats after the fact but doesn't proactively harden devices against new vulnerabilities.

Topics

#Endpoint Security#Device Management#Application Control#Vulnerability Management

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice