Microsoft MD-102 Microsoft Defender For Endpoint EDR Onboarding And App Control Practice Test

 

Skills 3.1 • 30 original questions

This Microsoft MD-102 Endpoint Administrator practice test focuses on microsoft defender for endpoint edr onboarding and app control through original scenario-based questions aligned to the skills measured as of July 24, 2026. Use the full ExamSnap MD-102 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft MD-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a security hardening project at Northwind Traders, the Intune administrator must use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action most directly satisfies the requirement? The affected devices are in the executive-device cohort, rollout wave 1.

  1. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  2. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  3. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  4. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  5. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security

Correct answer: B

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 2

Tailspin Toys is revising endpoint operations for a tenant consolidation. Administrators need to bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which implementation should the Microsoft 365 administrator select for the remote-user cohort, rollout wave 1?

  1. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  2. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  3. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  4. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  5. Create and assign Microsoft Defender Firewall policy through Intune endpoint security

Correct answer: D

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Option review:

A: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

B: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 3

A ticket escalated to the endpoint administrator at Alpine Ski House states one non-negotiable goal: restrict code execution to applications and binaries that satisfy the organization’s trust policy. Which choice is the strongest fit for the shared-device cohort, rollout wave 1?

  1. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  2. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  3. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  4. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  5. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges

Correct answer: C

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Option review:

A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 4

For the field-device cohort, rollout wave 2 at Wide World Importers, a compliance initiative can proceed only if the team can use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. What should the endpoint administrator configure?

  1. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  2. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  3. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  4. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  5. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance

Correct answer: C

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 5

The endpoint architecture review at Northwind Traders focuses on this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which Microsoft management action is most appropriate for the developer cohort, rollout wave 2?

  1. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  2. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  3. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  4. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  5. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Correct answer: E

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Option review:

A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

E: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 6

A change advisory board at Tailspin Toys asks how to restrict code execution to applications and binaries that satisfy the organization’s trust policy during a BYOD program. Which proposed action should the security administrator approve for the frontline-user cohort, rollout wave 2?

  1. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  2. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  3. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  4. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  5. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security

Correct answer: B

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Option review:

A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

B: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 7

Alpine Ski House has already ruled out manual per-device administration. For the kiosk cohort, rollout wave 3, the remaining requirement is to use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which choice best addresses it?

  1. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  2. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  3. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  4. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  5. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security

Correct answer: C

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 8

During post-pilot review at Wide World Importers, the Microsoft 365 administrator identifies a gap: the organization still needs to bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which action should be added before the new-hire cohort, rollout wave 3 moves to production?

  1. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  2. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  3. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  4. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  5. Plan and assign an Intune security baseline, then review conflicts with other configuration sources

Correct answer: D

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Option review:

A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 9

The endpoint administrator at Northwind Traders is comparing several cloud-management options for a branch migration. Which one directly enables the team to restrict code execution to applications and binaries that satisfy the organization’s trust policy for the contractor cohort, rollout wave 3?

  1. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  2. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  3. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  4. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  5. Create and assign Microsoft Defender Firewall policy through Intune endpoint security

Correct answer: C

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Option review:

A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 10

A security and operations workshop at Tailspin Toys defines the desired outcome as follows: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which implementation should be chosen for the lab-device cohort, rollout wave 4?

  1. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  2. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  3. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  4. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  5. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Correct answer: E

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 11

Which action best matches this technical purpose for the pilot ring, rollout wave 4: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service.

  1. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  2. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  3. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  4. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  5. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Correct answer: C

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

Option review:

A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

C: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

E: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 12

An administrator at Wide World Importers describes the needed capability this way: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. Which option should be associated with that requirement for the production ring, rollout wave 4?

  1. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  2. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  3. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  4. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  5. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Correct answer: E

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

Option review:

A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 13

During a design validation for the executive-device cohort, rollout wave 5, Northwind Traders documents the following behavior: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. Which endpoint-management feature or action is being described?

  1. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  2. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  3. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  4. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  5. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security

Correct answer: C

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..

Option review:

A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..

B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..

C: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..

D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..

E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities..

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 14

The Microsoft 365 administrator must identify the Microsoft endpoint-management capability that provides this function for the remote-user cohort, rollout wave 5: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. Which choice is correct?

  1. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  2. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  3. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  4. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  5. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Correct answer: E

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

Option review:

A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

B: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

E: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service..

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 15

A runbook for the shared-device cohort, rollout wave 5 contains this description: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. Which implementation belongs in that runbook?

  1. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  2. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  3. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  4. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  5. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Correct answer: E

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

Option review:

A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 16

Wide World Importers is troubleshooting a compliance initiative. Evidence shows that the decisive requirement is to use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action should the service desk lead investigate first for the field-device cohort, rollout wave 6?

  1. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  2. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  3. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  4. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  5. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Correct answer: A

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 17

After eliminating network and licensing causes, the desktop engineer at Northwind Traders determines that success depends on the ability to bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which endpoint-management action should be checked next for the developer cohort, rollout wave 6?

  1. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  2. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  3. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  4. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  5. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges

Correct answer: C

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Option review:

A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

C: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 18

A service-desk escalation during a BYOD program has been narrowed to one management requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy. Which configuration is the most relevant starting point for the frontline-user cohort, rollout wave 6?

  1. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  2. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  3. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  4. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  5. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Correct answer: A

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Option review:

A: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

E: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 19

The failure pattern at Alpine Ski House affects the kiosk cohort, rollout wave 7. Before making unrelated policy changes, the Intune administrator needs a solution that will use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action is most directly relevant?

  1. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  2. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  3. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  4. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  5. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges

Correct answer: A

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 20

While investigating a tenant consolidation, Wide World Importers confirms the environment must bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which Microsoft endpoint-management capability should be validated for the new-hire cohort, rollout wave 7?

  1. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  2. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  3. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  4. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  5. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance

Correct answer: D

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Option review:

A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

C: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 21

Two teams at Northwind Traders propose different approaches for the contractor cohort, rollout wave 7. The selection criterion is simple: the chosen approach must restrict code execution to applications and binaries that satisfy the organization’s trust policy. Which option should win the technical comparison?

  1. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  2. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  3. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  4. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  5. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Correct answer: E

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Option review:

A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 22

For the lab-device cohort, rollout wave 8, Tailspin Toys wants the least indirect solution to this goal: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action aligns most closely with that requirement?

  1. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  2. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  3. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  4. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  5. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges

Correct answer: D

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 23

A modernization plan at Alpine Ski House includes a Windows 11 rollout. The desktop engineer is asked to choose the control that specifically helps the organization bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which choice fits best for the pilot ring, rollout wave 8?

  1. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  2. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  3. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  4. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  5. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Correct answer: E

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Option review:

A: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

B: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

D: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

E: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 24

The production ring, rollout wave 8 is moving into a controlled rollout at Wide World Importers. Which action should be included when the stated management objective is to restrict code execution to applications and binaries that satisfy the organization’s trust policy?

  1. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  2. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  3. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  4. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  5. Create and assign Microsoft Defender Firewall policy through Intune endpoint security

Correct answer: B

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Option review:

A: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

B: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 25

Northwind Traders is replacing an ad hoc process during a security hardening project. The replacement must reliably use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which endpoint-management approach should the Intune administrator implement for the executive-device cohort, rollout wave 9?

  1. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  2. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  3. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  4. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  5. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Correct answer: D

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 26

An audit finding for the remote-user cohort, rollout wave 9 says the current process does not consistently bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which Microsoft endpoint-management action most directly closes that gap?

  1. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  2. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  3. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  4. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  5. Plan and assign an Intune security baseline, then review conflicts with other configuration sources

Correct answer: B

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Option review:

A: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 27

The endpoint administrator at Alpine Ski House needs a repeatable configuration for the shared-device cohort, rollout wave 9. It must restrict code execution to applications and binaries that satisfy the organization’s trust policy. Which choice should be implemented instead of relying on manual endpoint work?

  1. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
  2. Create and assign Microsoft Defender Firewall policy through Intune endpoint security
  3. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  4. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  5. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Correct answer: E

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Option review:

A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: restrict code execution to applications and binaries that satisfy the organization’s trust policy.

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Question 28

During readiness testing at Wide World Importers, the field-device cohort, rollout wave 10 fails a business requirement because administrators cannot yet use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls. Which action should be implemented before rollout continues?

  1. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  2. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  3. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  4. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  5. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Correct answer: E

Why: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Option review:

A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

C: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

E: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. This directly addresses the requirement: use Defender for Endpoint risk and EDR telemetry together with Intune to investigate endpoint threats and support conditional controls.

Learning point: Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation

Question 29

A governance review asks the desktop engineer to justify the control selected for the developer cohort, rollout wave 10. The requirement is to bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting. Which action has the clearest technical alignment?

  1. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  2. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  3. Plan and assign an Intune security baseline, then review conflicts with other configuration sources
  4. Integrate Intune with Microsoft Defender for Endpoint and configure EDR policy so endpoint risk, detections, and incidents can inform management and investigation
  5. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Correct answer: B

Why: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Option review:

A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

B: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. This directly addresses the requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

D: The Intune-Defender integration connects endpoint security management and risk signals, while EDR onboarding/policy provides behavioral detection and response capabilities. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

E: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: bring managed endpoints under Microsoft Defender for Endpoint protection and EDR reporting.

Learning point: Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy

Question 30

For a BYOD program, Tailspin Toys needs an endpoint-management capability with this effect: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. Which option most accurately provides that capability for the frontline-user cohort, rollout wave 10?

  1. Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run
  2. Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
  3. Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
  4. Onboard supported endpoints to Microsoft Defender for Endpoint using the organization’s selected onboarding method or Intune EDR policy
  5. Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance

Correct answer: A

Why: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

Option review:

A: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code. This directly addresses the requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

D: Devices must be onboarded to Defender for Endpoint before they can fully report endpoint detection and response telemetry to the service. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: App Control for Business enforces application-control trust policy and can reduce the execution of unapproved code..

Learning point: Create and deploy App Control for Business policy through Intune to define which trusted applications, scripts, and binaries are allowed to run

Popular posts

img