Microsoft MD-102 Microsoft Defender For Endpoint EDR Onboarding And App Control Practice Test
Skills 3.1 • 30 original questions
This Microsoft MD-102 Endpoint Administrator practice test focuses on microsoft defender for endpoint edr onboarding and app control through original scenario-based questions aligned to the skills measured as of July 24, 2026. Use the full ExamSnap MD-102 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft MD-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a security hardening project at Northwind Traders, the Intune administrator must use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action most directly satisfies the requirement? The affected devices are in the executive-device cohort, rollout wave 1.
Correct answer: B
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
Tailspin Toys is revising endpoint operations for a tenant consolidation. Administrators need to bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which implementation should the Microsoft 365 administrator select for the remote-user cohort, rollout wave 1?
Correct answer: D
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Option review:
A: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
B: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
A ticket escalated to the endpoint administrator at Alpine Ski House states one non-negotiable goal: restrict code execution to applications and binaries that satisfy the organization’s trust policy. Which choice is the strongest fit for the shared-device cohort, rollout wave 1?
Correct answer: C
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
For the field-device cohort, rollout wave 2 at Wide World Importers, a compliance initiative can proceed only if the team can use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. What should the endpoint administrator configure?
Correct answer: C
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
The endpoint architecture review at Northwind Traders focuses on this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which Microsoft management action is most appropriate for the developer cohort, rollout wave 2?
Correct answer: E
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
E: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
A change advisory board at Tailspin Toys asks how to restrict code execution to applications and binaries that satisfy the organization’s trust policy during a BYOD program. Which proposed action should the security administrator approve for the frontline-user cohort, rollout wave 2?
Correct answer: B
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
B: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
Alpine Ski House has already ruled out manual per-device administration. For the kiosk cohort, rollout wave 3, the remaining requirement is to use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which choice best addresses it?
Correct answer: C
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
During post-pilot review at Wide World Importers, the Microsoft 365 administrator identifies a gap: the organization still needs to bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which action should be added before the new-hire cohort, rollout wave 3 moves to production?
Correct answer: D
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
The endpoint administrator at Northwind Traders is comparing several cloud-management options for a branch migration. Which one directly enables the team to restrict code execution to applications and binaries that satisfy the organization’s trust policy for the contractor cohort, rollout wave 3?
Correct answer: C
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
A security and operations workshop at Tailspin Toys defines the desired outcome as follows: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which implementation should be chosen for the lab-device cohort, rollout wave 4?
Correct answer: E
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
Which action best matches this technical purpose for the pilot ring, rollout wave 4: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service.
Correct answer: C
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
C: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
E: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
An administrator at Wide World Importers describes the needed capability this way: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. Which option should be associated with that requirement for the production ring, rollout wave 4?
Correct answer: E
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
During a design validation for the executive-device cohort, rollout wave 5, Northwind Traders documents the following behavior: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. Which endpoint-management feature or action is being described?
Correct answer: C
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..
B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..
C: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..
E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
The Microsoft 365 administrator must identify the Microsoft endpoint-management capability that provides this function for the remote-user cohort, rollout wave 5: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. Which choice is correct?
Correct answer: E
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
B: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
E: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
A runbook for the shared-device cohort, rollout wave 5 contains this description: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. Which implementation belongs in that runbook?
Correct answer: E
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
Wide World Importers is troubleshooting a compliance initiative. Evidence shows that the decisive requirement is to use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action should the service desk lead investigate first for the field-device cohort, rollout wave 6?
Correct answer: A
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
After eliminating network and licensing causes, the desktop engineer at Northwind Traders determines that success depends on the ability to bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which endpoint-management action should be checked next for the developer cohort, rollout wave 6?
Correct answer: C
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
C: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
A service-desk escalation during a BYOD program has been narrowed to one management requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy. Which configuration is the most relevant starting point for the frontline-user cohort, rollout wave 6?
Correct answer: A
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Option review:
A: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
E: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
The failure pattern at Alpine Ski House affects the kiosk cohort, rollout wave 7. Before making unrelated policy changes, the Intune administrator needs a solution that will use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action is most directly relevant?
Correct answer: A
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
While investigating a tenant consolidation, Wide World Importers confirms the environment must bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which Microsoft endpoint-management capability should be validated for the new-hire cohort, rollout wave 7?
Correct answer: D
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
C: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
Two teams at Northwind Traders propose different approaches for the contractor cohort, rollout wave 7. The selection criterion is simple: the chosen approach must restrict code execution to applications and binaries that satisfy the organization’s trust policy. Which option should win the technical comparison?
Correct answer: E
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
For the lab-device cohort, rollout wave 8, Tailspin Toys wants the least indirect solution to this goal: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action aligns most closely with that requirement?
Correct answer: D
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
A modernization plan at Alpine Ski House includes a Windows 11 rollout. The desktop engineer is asked to choose the control that specifically helps the organization bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which choice fits best for the pilot ring, rollout wave 8?
Correct answer: E
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Option review:
A: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
B: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
D: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
E: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
The production ring, rollout wave 8 is moving into a controlled rollout at Wide World Importers. Which action should be included when the stated management objective is to restrict code execution to applications and binaries that satisfy the organization’s trust policy?
Correct answer: B
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Option review:
A: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
B: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
Northwind Traders is replacing an ad hoc process during a security hardening project. The replacement must reliably use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which endpoint-management approach should the Intune administrator implement for the executive-device cohort, rollout wave 9?
Correct answer: D
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
An audit finding for the remote-user cohort, rollout wave 9 says the current process does not consistently bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which Microsoft endpoint-management action most directly closes that gap?
Correct answer: B
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Option review:
A: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
The endpoint administrator at Alpine Ski House needs a repeatable configuration for the shared-device cohort, rollout wave 9. It must restrict code execution to applications and binaries that satisfy the organization’s trust policy. Which choice should be implemented instead of relying on manual endpoint work?
Correct answer: E
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
During readiness testing at Wide World Importers, the field-device cohort, rollout wave 10 fails a business requirement because administrators cannot yet use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action should be implemented before rollout continues?
Correct answer: E
Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Option review:
A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
E: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.
Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
A governance review asks the desktop engineer to justify the control selected for the developer cohort, rollout wave 10. The requirement is to bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which action has the clearest technical alignment?
Correct answer: B
Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.
Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
For a BYOD program, Tailspin Toys needs an endpoint-management capability with this effect: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. Which option most accurately provides that capability for the frontline-user cohort, rollout wave 10?
Correct answer: A
Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
Option review:
A: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..
Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
Popular posts
Recent Posts
