SC-100 · Question #59
Your company has a Microsoft 365 E5 subscription. The company plans to deploy 45 mobile self-service kiosks that will run Windows 10. You need to provide recommendations to secure the kiosks. The…
The correct answer is D. Implement threat and vulnerability management in Microsoft Defender for Endpoint. E. Onboard the kiosks to Microsoft Intune and Microsoft Defender for Endpoint. Onboarding kiosks to Microsoft Intune and Microsoft Defender for Endpoint (E) is foundational: Intune enforces application control policies (e.g., Windows Defender Application Control or AppLocker) ensuring only authorized apps run, while Defender for Endpoint provides endpoint…
Question
Your company has a Microsoft 365 E5 subscription. The company plans to deploy 45 mobile self-service kiosks that will run Windows 10. You need to provide recommendations to secure the kiosks. The solution must meet the following requirements:
- Ensure that only authorized applications can run on the kiosks.
- Regularly harden the kiosks against new threats.
Which two actions should you include in the recommendations? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- AOnboard the kiosks to Azure Monitor.
- BImplement Privileged Access Workstation (PAW) for the kiosks.
- CImplement Automated Investigation and Remediation (AIR) in Microsoft Defender for Endpoint.
- DImplement threat and vulnerability management in Microsoft Defender for Endpoint.
- EOnboard the kiosks to Microsoft Intune and Microsoft Defender for Endpoint.
How the community answered
(20 responses)- A5% (1)
- B25% (5)
- C10% (2)
- D60% (12)
Explanation
Onboarding kiosks to Microsoft Intune and Microsoft Defender for Endpoint (E) is foundational: Intune enforces application control policies (e.g., Windows Defender Application Control or AppLocker) ensuring only authorized apps run, while Defender for Endpoint provides endpoint protection and telemetry. Threat and Vulnerability Management (TVM) in Microsoft Defender for Endpoint (D) continuously assesses the kiosks for known vulnerabilities and misconfigurations, providing prioritized remediation guidance to regularly harden them against new threats. Azure Monitor (A) collects metrics and logs but doesn't harden devices or enforce app allow-listing. PAW (B) is a high-security workstation concept for privileged administrators, not self-service kiosks. Automated Investigation and Remediation (C) responds to detected threats after the fact but doesn't proactively harden devices against new vulnerabilities.
Topics
Community Discussion
No community discussion yet for this question.