SC-200 · Question #430
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2. The subscription contains 1,000 Windows 11 devices that run a third-party antivirus software and have Smart…
The correct answer is A. endpoint detection and response (EDR) in block mode. EDR in Block Mode in Microsoft Defender for Endpoint provides an essential layer of security when a third-party antivirus fails, automatically stopping and remediating a detected malicious artifact. While Smart App Control helps prevent unauthorized applications from running…
Question
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2. The subscription contains 1,000 Windows 11 devices that run a third-party antivirus software and have Smart App Control enabled. You need to ensure that if Defender for Endpoint detects a malicious artifact that was missed by the third-party software, it will remediate the artifact automatically. What should you configure?
Options
- Aendpoint detection and response (EDR) in block mode
- BAllow or block file
- CAutomatically resolve alerts
- Dtamper protection
How the community answered
(43 responses)- A84% (36)
- B5% (2)
- C2% (1)
- D9% (4)
Explanation
EDR in Block Mode in Microsoft Defender for Endpoint provides an essential layer of security when a third-party antivirus fails, automatically stopping and remediating a detected malicious artifact. While Smart App Control helps prevent unauthorized applications from running, EDR in Block Mode acts as a crucial backup by detecting and blocking advanced or overlooked threats, ensuring your system remains protected even if the primary antivirus misses something. https://learn.microsoft.com/en-us/defender-endpoint/edr-in-block-mode
Community Discussion
No community discussion yet for this question.