SC-200 · Question #348
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets…
The correct answer is A. Yes. Configuring Endpoint Detection and Response (EDR) in block mode meets the goal. EDR in block mode allows Microsoft Defender for Endpoint to detect and remediate malicious artifacts even when Microsoft Defender Antivirus is in passive mode due to the presence of a third-party…
Question
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 subscription. You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode. You need to ensure that the devices are protected from malicious artifacts that were undetected by the third-party antivirus product. Solution: You configure endpoint detection and response (EDR) in block mode. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(56 responses)- A80% (45)
- B20% (11)
Explanation
Configuring Endpoint Detection and Response (EDR) in block mode meets the goal. EDR in block mode allows Microsoft Defender for Endpoint to detect and remediate malicious artifacts even when Microsoft Defender Antivirus is in passive mode due to the presence of a third-party antivirus. This ensures that threats missed by the third-party antivirus can still be addressed by Microsoft Defender for Endpoint's advanced detection and response capabilities. Thus, enabling EDR in block mode effectively provides the required protection in this scenario.
Community Discussion
No community discussion yet for this question.