Microsoft MS-102 Defender For Endpoint Onboarding And Endpoint Settings Practice Test

 

MS-102 skills 3.3 | 26 original questions

This MS-102 practice set focuses on defender for endpoint onboarding and endpoint settings through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

The operations team at Litware Financial needs to resolve an issue without granting broader permissions than necessary. A post-incident action item requires the tenant to enroll managed endpoints into Defender for Endpoint at scale using a method appropriate to the environment. The service desk has 51 related tickets from 17 business units, so the team wants a targeted fix. The change must be repeatable and supportable after the project team leaves. Which option best satisfies the requirement?

  1. Prioritize remediation by exposure and business context rather than score alone
  2. Use the supported Defender for Endpoint onboarding method for the device-management platform
  3. Use Microsoft Defender Threat Intelligence for threat actor and indicator context
  4. Use Threat Explorer or Real-time detections to investigate the malicious message campaign
  5. Create and track a remediation activity from the vulnerability recommendation

Correct answer: B

Why: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

Option review:

A: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

C: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q001: Use the supported Defender for Endpoint onboarding method for the device-management platform – Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification.

Question 2

The messaging administrator at Adventure Works is designing the next phase of the Microsoft 365 rollout. The current workaround is too manual. The replacement should confirm that endpoint telemetry is reaching the Defender service. The team will validate the change with 7 pilot groups before expanding it to 68 users. The change must be repeatable and supportable after the project team leaves. Which approach most directly addresses the requirement?

  1. Secure the compromised account before removing the sending restriction
  2. Validate the app connector status and granted permissions
  3. Verify the device appears in Defender for Endpoint device inventory after onboarding
  4. Review the discovered app risk score and usage before sanctioning or unsanctioning it
  5. Prioritize remediation by exposure and business context rather than score alone

Correct answer: C

Why: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

Option review:

A: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

D: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q002: Verify the device appears in Defender for Endpoint device inventory after onboarding – Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed.

Question 3

A quarterly control review at Fourth Coffee identifies a gap that must be corrected before the next audit. The support team has reproduced the issue and narrowed it to this requirement: enroll managed endpoints into Defender for Endpoint at scale using a method appropriate to the environment. The service desk has 85 related tickets from 20 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Review Microsoft Secure Score improvement actions
  2. Use Microsoft Defender XDR reports for trend and coverage analysis
  3. Create a Microsoft Defender for Office 365 alert policy
  4. Use the supported Defender for Endpoint onboarding method for the device-management platform
  5. Secure the compromised account before removing the sending restriction

Correct answer: D

Why: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

Option review:

A: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

E: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q003: Use the supported Defender for Endpoint onboarding method for the device-management platform – Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification.

Question 4

Fourth Coffee has completed a pilot and must now choose the production administration approach. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to confirm that endpoint telemetry is reaching the Defender service. The affected scope contains 11 users across 10 administrative groups. The change must be repeatable and supportable after the project team leaves. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Review simulation results to identify users or techniques that need additional training
  2. Use threat and exploit context when prioritizing two vulnerabilities with similar severity
  3. Use Cloud App Discovery data from supported endpoint or network traffic sources
  4. Review Microsoft Secure Score improvement actions
  5. Verify the device appears in Defender for Endpoint device inventory after onboarding

Correct answer: E

Why: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

Option review:

A: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

Learning point: MS102-T16-Q004: Verify the device appears in Defender for Endpoint device inventory after onboarding – Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed.

Question 5

City Power & Light is migrating a business process to Microsoft 365 and wants the narrowest supported solution. An internal assessment finds the control technically functional but unable to enroll managed endpoints into Defender for Endpoint at scale using a method appropriate to the environment. The control owner requires a review after 28 days and evidence from 23 representative cases. The administrator must avoid granting unrelated tenant-wide privilege. Which action should the administrator take?

  1. Use the supported Defender for Endpoint onboarding method for the device-management platform
  2. Configure Defender for Endpoint settings in the Microsoft Defender portal
  3. Investigate the incident in the Microsoft Defender portal
  4. Configure a Safe Attachments policy
  5. Review simulation results to identify users or techniques that need additional training

Correct answer: A

Why: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

Option review:

A: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

B: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q005: Use the supported Defender for Endpoint onboarding method for the device-management platform – Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification.

Question 6

An incident review at Wide World Importers produces a single administrative requirement for the tenant administrator. A post-incident action item requires the tenant to confirm that endpoint telemetry is reaching the Defender service. The team will validate the change with 13 pilot groups before expanding it to 45 users. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which approach most directly addresses the requirement?

  1. Use quarantine and remediation actions for confirmed malicious messages
  2. Verify the device appears in Defender for Endpoint device inventory after onboarding
  3. Review exposed devices for the recommendation before scheduling the fix
  4. Filter the Defender for Cloud Apps activity log by user, IP address, activity, or application
  5. Configure Defender for Endpoint settings in the Microsoft Defender portal

Correct answer: B

Why: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

Option review:

A: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

C: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q006: Verify the device appears in Defender for Endpoint device inventory after onboarding – Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed.

Question 7

During a tenant review at Southridge Video, the tenant administrator identifies one unresolved requirement. A production change is approved only if it can enroll managed endpoints into Defender for Endpoint at scale using a method appropriate to the environment. The solution should use a native Microsoft control that matches the stated requirement. The service desk has 62 related tickets from 3 business units, so the team wants a targeted fix. Which action should the administrator take?

  1. Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate
  2. Assign and track improvement work from the Secure Score recommendation context
  3. Use the supported Defender for Endpoint onboarding method for the device-management platform
  4. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  5. Use quarantine and remediation actions for confirmed malicious messages

Correct answer: C

Why: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

Option review:

A: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

D: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q007: Use the supported Defender for Endpoint onboarding method for the device-management platform – Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification.

Question 8

An incident review at Litware Financial produces a single administrative requirement for the governance lead. The next migration wave is blocked until the team can confirm that endpoint telemetry is reaching the Defender service. The design should minimize manual per-user administration where a scoped central control exists. The team will validate the change with 16 pilot groups before expanding it to 79 users. Which administrative choice should be recommended?

  1. Tune alert policy thresholds or recipients instead of weakening threat protection
  2. Prioritize the vulnerability recommendation with the highest risk and exposure impact
  3. Create an activity policy in Defender for Cloud Apps with an alert
  4. Verify the device appears in Defender for Endpoint device inventory after onboarding
  5. Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate

Correct answer: D

Why: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

Option review:

A: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

E: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q008: Verify the device appears in Defender for Endpoint device inventory after onboarding – Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed.

Question 9

Coho Winery is standardizing administration after several teams used inconsistent procedures. The existing configuration works for normal operations but fails the new requirement to enroll managed endpoints into Defender for Endpoint at scale using a method appropriate to the environment. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The service desk has 5 related tickets from 6 business units, so the team wants a targeted fix. Which action should the administrator take?

  1. Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source
  2. Use Microsoft Security Exposure Management to investigate exposure paths and initiatives
  3. Drill from a Defender XDR report finding into the underlying security data
  4. Tune alert policy thresholds or recipients instead of weakening threat protection
  5. Use the supported Defender for Endpoint onboarding method for the device-management platform

Correct answer: E

Why: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

Option review:

A: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

Learning point: MS102-T16-Q009: Use the supported Defender for Endpoint onboarding method for the device-management platform – Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification.

Question 10

The operations team at Alpine Ski House needs to resolve an issue without granting broader permissions than necessary. An internal assessment finds the control technically functional but unable to confirm that endpoint telemetry is reaching the Defender service. The service desk has 22 related tickets from 19 business units, so the team wants a targeted fix. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which control should the team use?

  1. Verify the device appears in Defender for Endpoint device inventory after onboarding
  2. Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement
  3. Review the restricted entities page for the blocked user
  4. Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector
  5. Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source

Correct answer: A

Why: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

Option review:

A: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

B: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q010: Verify the device appears in Defender for Endpoint device inventory after onboarding – Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed.

Question 11

VanArsdel Media is standardizing administration after several teams used inconsistent procedures. The service owner wants a supportable design that will enroll managed endpoints into Defender for Endpoint at scale using a method appropriate to the environment. The change must be repeatable and supportable after the project team leaves. The initial rollout covers 9 locations and approximately 390 managed identities or devices. Which option best satisfies the requirement?

  1. Pivot from a suspicious activity-log event to the related user or app context
  2. Use the supported Defender for Endpoint onboarding method for the device-management platform
  3. Use device groups or supported scoped settings when different endpoint populations require different treatment
  4. Use advanced hunting with KQL
  5. Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement

Correct answer: B

Why: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

Option review:

A: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

C: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q011: Use the supported Defender for Endpoint onboarding method for the device-management platform – Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification.

Question 12

Datum Dynamics is migrating a business process to Microsoft 365 and wants the narrowest supported solution. Security and operations teams agree on the target state: confirm that endpoint telemetry is reaching the Defender service. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The service desk has 56 related tickets from 22 business units, so the team wants a targeted fix. What is the most appropriate next step?

  1. Configure a Safe Links policy
  2. Create an Attack Simulation Training campaign
  3. Verify the device appears in Defender for Endpoint device inventory after onboarding
  4. Reassess the recommendation after remediation to verify exposure decreased
  5. Pivot from a suspicious activity-log event to the related user or app context

Correct answer: C

Why: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

Option review:

A: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. It directly addresses the stated requirement.

D: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q012: Verify the device appears in Defender for Endpoint device inventory after onboarding – Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed.

Question 13

Northwind Traders is preparing a change requested by the security administrator. The administrator is comparing native Microsoft controls after documenting a requirement to enroll managed endpoints into Defender for Endpoint at scale using a method appropriate to the environment. The affected scope contains 73 users across 12 administrative groups. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use an anomaly detection or app discovery policy when the requirement is behavior- or discovery-driven
  2. Verify the device appears in Defender for Endpoint device inventory after onboarding
  3. Use exposure initiatives to measure progress toward a defined security objective
  4. Use the supported Defender for Endpoint onboarding method for the device-management platform
  5. Configure a Safe Links policy

Correct answer: D

Why: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

Option review:

A: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. It directly addresses the stated requirement.

E: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q013: Use the supported Defender for Endpoint onboarding method for the device-management platform – Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification.

Question 14

Lucerne Publishing is standardizing administration after several teams used inconsistent procedures. A post-incident action item requires the tenant to control endpoint security service behavior centrally for the supported tenant features. The team will validate the change with 2 pilot groups before expanding it to 90 users. The design should minimize manual per-user administration where a scoped central control exists. Which control should the team use?

  1. Use Microsoft Defender Threat Intelligence for threat actor and indicator context
  2. Use Threat Explorer or Real-time detections to investigate the malicious message campaign
  3. Create and track a remediation activity from the vulnerability recommendation
  4. Use an anomaly detection or app discovery policy when the requirement is behavior- or discovery-driven
  5. Configure Defender for Endpoint settings in the Microsoft Defender portal

Correct answer: E

Why: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Option review:

A: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Learning point: MS102-T16-Q014: Configure Defender for Endpoint settings in the Microsoft Defender portal – Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability.

Question 15

An incident review at Northwind Traders produces a single administrative requirement for the security administrator. The implementation review is focused on one outcome: apply endpoint security administration according to device scope instead of changing every endpoint identically. The team will validate the change with 15 pilot groups before expanding it to 16 users. The team does not want to redesign unrelated workloads. What is the most appropriate next step?

  1. Use device groups or supported scoped settings when different endpoint populations require different treatment
  2. Validate the app connector status and granted permissions
  3. Review the discovered app risk score and usage before sanctioning or unsanctioning it
  4. Prioritize remediation by exposure and business context rather than score alone
  5. Use Microsoft Defender Threat Intelligence for threat actor and indicator context

Correct answer: A

Why: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

Option review:

A: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

B: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q015: Use device groups or supported scoped settings when different endpoint populations require different treatment – Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities.

Question 16

During a tenant review at Graphic Design Institute, the security operations analyst identifies one unresolved requirement. A controlled pilot must demonstrate how to control endpoint security service behavior centrally for the supported tenant features. The change must be repeatable and supportable after the project team leaves. The team will validate the change with 5 pilot groups before expanding it to 33 users. Which approach most directly addresses the requirement?

  1. Use Microsoft Defender XDR reports for trend and coverage analysis
  2. Configure Defender for Endpoint settings in the Microsoft Defender portal
  3. Create a Microsoft Defender for Office 365 alert policy
  4. Secure the compromised account before removing the sending restriction
  5. Validate the app connector status and granted permissions

Correct answer: B

Why: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Option review:

A: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

C: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q016: Configure Defender for Endpoint settings in the Microsoft Defender portal – Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability.

Question 17

An incident review at Litware Financial produces a single administrative requirement for the compliance administrator. The implementation review is focused on one outcome: apply endpoint security administration according to device scope instead of changing every endpoint identically. The control owner requires a review after 50 days and evidence from 18 representative cases. The team does not want to redesign unrelated workloads. Which option best satisfies the requirement?

  1. Use threat and exploit context when prioritizing two vulnerabilities with similar severity
  2. Use Cloud App Discovery data from supported endpoint or network traffic sources
  3. Use device groups or supported scoped settings when different endpoint populations require different treatment
  4. Review Microsoft Secure Score improvement actions
  5. Use Microsoft Defender XDR reports for trend and coverage analysis

Correct answer: C

Why: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

Option review:

A: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

D: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q017: Use device groups or supported scoped settings when different endpoint populations require different treatment – Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities.

Question 18

Proseware Logistics is preparing a change requested by the governance lead. The implementation review is focused on one outcome: control endpoint security service behavior centrally for the supported tenant features. The affected scope contains 67 users across 8 administrative groups. The team does not want to redesign unrelated workloads. Which control should the team use?

  1. Investigate the incident in the Microsoft Defender portal
  2. Configure a Safe Attachments policy
  3. Review simulation results to identify users or techniques that need additional training
  4. Configure Defender for Endpoint settings in the Microsoft Defender portal
  5. Use threat and exploit context when prioritizing two vulnerabilities with similar severity

Correct answer: D

Why: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Option review:

A: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

E: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q018: Configure Defender for Endpoint settings in the Microsoft Defender portal – Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability.

Question 19

Humongous Insurance is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A controlled pilot must demonstrate how to apply endpoint security administration according to device scope instead of changing every endpoint identically. The team must preserve a clear audit trail for the administrative decision. The affected scope contains 84 users across 21 administrative groups. What should the administrator configure first?

  1. Review exposed devices for the recommendation before scheduling the fix
  2. Filter the Defender for Cloud Apps activity log by user, IP address, activity, or application
  3. Verify the device appears in Defender for Endpoint device inventory after onboarding
  4. Investigate the incident in the Microsoft Defender portal
  5. Use device groups or supported scoped settings when different endpoint populations require different treatment

Correct answer: E

Why: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

Option review:

A: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

Learning point: MS102-T16-Q019: Use device groups or supported scoped settings when different endpoint populations require different treatment – Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities.

Question 20

The messaging administrator at Woodgrove Bank is designing the next phase of the Microsoft 365 rollout. A post-incident action item requires the tenant to control endpoint security service behavior centrally for the supported tenant features. The initial rollout covers 11 locations and approximately 100 managed identities or devices. The change must be repeatable and supportable after the project team leaves. What should the administrator configure first?

  1. Configure Defender for Endpoint settings in the Microsoft Defender portal
  2. Assign and track improvement work from the Secure Score recommendation context
  3. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  4. Use quarantine and remediation actions for confirmed malicious messages
  5. Review exposed devices for the recommendation before scheduling the fix

Correct answer: A

Why: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Option review:

A: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

B: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q020: Configure Defender for Endpoint settings in the Microsoft Defender portal – Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability.

Question 21

A quarterly control review at Wingtip Services identifies a gap that must be corrected before the next audit. The support team has reproduced the issue and narrowed it to this requirement: apply endpoint security administration according to device scope instead of changing every endpoint identically. The team will validate the change with 24 pilot groups before expanding it to 27 users. The administrator must avoid granting unrelated tenant-wide privilege. Which control should the team use?

  1. Prioritize the vulnerability recommendation with the highest risk and exposure impact
  2. Use device groups or supported scoped settings when different endpoint populations require different treatment
  3. Create an activity policy in Defender for Cloud Apps with an alert
  4. Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate
  5. Assign and track improvement work from the Secure Score recommendation context

Correct answer: B

Why: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

Option review:

A: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

C: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q021: Use device groups or supported scoped settings when different endpoint populations require different treatment – Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities.

Question 22

During a tenant review at VanArsdel Media, the governance lead identifies one unresolved requirement. Security and operations teams agree on the target state: control endpoint security service behavior centrally for the supported tenant features. The change must be repeatable and supportable after the project team leaves. The control owner requires a review after 44 days and evidence from 14 representative cases. Which approach most directly addresses the requirement?

  1. Use Microsoft Security Exposure Management to investigate exposure paths and initiatives
  2. Drill from a Defender XDR report finding into the underlying security data
  3. Configure Defender for Endpoint settings in the Microsoft Defender portal
  4. Tune alert policy thresholds or recipients instead of weakening threat protection
  5. Prioritize the vulnerability recommendation with the highest risk and exposure impact

Correct answer: C

Why: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Option review:

A: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

D: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q022: Configure Defender for Endpoint settings in the Microsoft Defender portal – Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability.

Question 23

Margie Travel is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to apply endpoint security administration according to device scope instead of changing every endpoint identically. The change must be repeatable and supportable after the project team leaves. The control owner requires a review after 61 days and evidence from 4 representative cases. Which action should the administrator take?

  1. Review the restricted entities page for the blocked user
  2. Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector
  3. Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source
  4. Use device groups or supported scoped settings when different endpoint populations require different treatment
  5. Use Microsoft Security Exposure Management to investigate exposure paths and initiatives

Correct answer: D

Why: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

Option review:

A: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

E: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q023: Use device groups or supported scoped settings when different endpoint populations require different treatment – Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities.

Question 24

The operations team at Contoso Retail needs to resolve an issue without granting broader permissions than necessary. A production change is approved only if it can control endpoint security service behavior centrally for the supported tenant features. The architecture board will reject a choice that solves a different problem from the one stated. The team will validate the change with 17 pilot groups before expanding it to 78 users. Which administrative choice should be recommended?

  1. Use device groups or supported scoped settings when different endpoint populations require different treatment
  2. Use advanced hunting with KQL
  3. Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement
  4. Review the restricted entities page for the blocked user
  5. Configure Defender for Endpoint settings in the Microsoft Defender portal

Correct answer: E

Why: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Option review:

A: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Learning point: MS102-T16-Q024: Configure Defender for Endpoint settings in the Microsoft Defender portal – Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability.

Question 25

Wingtip Services is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The current workaround is too manual. The replacement should apply endpoint security administration according to device scope instead of changing every endpoint identically. The service desk has 95 related tickets from 7 business units, so the team wants a targeted fix. The solution should use a native Microsoft control that matches the stated requirement. What should the administrator configure first?

  1. Use device groups or supported scoped settings when different endpoint populations require different treatment
  2. Create an Attack Simulation Training campaign
  3. Reassess the recommendation after remediation to verify exposure decreased
  4. Pivot from a suspicious activity-log event to the related user or app context
  5. Configure Defender for Endpoint settings in the Microsoft Defender portal

Correct answer: A

Why: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

Option review:

A: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. It directly addresses the stated requirement.

B: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q025: Use device groups or supported scoped settings when different endpoint populations require different treatment – Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities.

Question 26

An incident review at Fourth Coffee produces a single administrative requirement for the Microsoft 365 administrator. Administrators have confirmed the present design does not control endpoint security service behavior centrally for the supported tenant features. The initial rollout covers 20 locations and approximately 210 managed identities or devices. The architecture board will reject a choice that solves a different problem from the one stated. Which option best satisfies the requirement?

  1. Use the supported Defender for Endpoint onboarding method for the device-management platform
  2. Configure Defender for Endpoint settings in the Microsoft Defender portal
  3. Use exposure initiatives to measure progress toward a defined security objective
  4. Configure a Safe Links policy
  5. Create an Attack Simulation Training campaign

Correct answer: B

Why: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

Option review:

A: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. It directly addresses the stated requirement.

C: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T16-Q026: Configure Defender for Endpoint settings in the Microsoft Defender portal – Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability.

img