Attack surface rules policies Flashcards

(14 cards)

1
Q

What is the purpose of attack surface reduction (ASR) policies?

A

To reduce the attack surface of devices by minimizing vulnerabilities to cyberthreats and attacks.

ASR policies help organizations enhance their security posture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 2 prerequisites for Attack surface reduction profiles?

A
  • Devices must run Windows 10 or Windows 11
  • Defender antivirus must be the primary antivirus on the device.

These prerequisites ensure compatibility and effectiveness of ASR policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which 3 systems support Attack surface reduction when using Security Management for Microsoft Defender for Endpoint?

A
  • Windows 10,
  • Windows 11
  • Windows Server

This applies to devices onboarded to Defender without enrollment with Intune.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What must be set up for Configuration Manager clients to support Attack surface reduction?

A

Tenant attach for Configuration Manager devices.

This allows integration with Microsoft Defender for Endpoint.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are Attack Surface Reduction Rules?

A

Settings that target behaviors commonly used by malware and malicious apps to infect computers, including:
* Executable files and scripts in Office apps or web mail
* Obfuscated or suspicious scripts
* Unusual app behaviors during normal work

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does Device Control settings configure?

A

It configures devices for a layered approach to secure removable media and provides monitoring and control features to prevent threats from unauthorized peripherals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the purpose of App and Browser Isolation?

A

It manages settings for Windows Defender Application Guard to prevent attacks and isolate untrusted sites while defining trusted sites, cloud resources, and internal networks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does Application Control help mitigate?

A

It helps mitigate security threats by restricting applications that users can run and the code that runs in the System Core (kernel), including blocking unsigned scripts and MSIs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Exploit Protection?

A

Settings that help protect against malware using exploits to infect devices and spread, consisting of many mitigations applicable to the operating system or individual apps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does Web Protection in Microsoft Edge Legacy manage?

A

It configures network protection to secure machines against web threats, including:
* Network protection
* SmartScreen
* Blocking access to malicious sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What devices can be managed by Defender for Endpoint without Intune?

A

Devices running Windows 10, Windows 11, and Windows Server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which profiles are supported for devices managed by Defender that aren’t enrolled with Intune?

A

Attack Surface Reduction Rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

List the profiles available for devices managed by Configuration Manager.

A
  • App and Browser Isolation
  • Attack Surface Reduction Rules
  • Exploit Protection
  • Web Protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the 4 steps to create an ASR rule ?

A
  1. Navigate to Endpoint security > Attack surface reduction
  2. Platform : Windows
  3. Profile: select one of the following and click Create:
    ■ App and Browser Isolation
    ■ Attack Surface Reduction Rules
    ■ Device Control
    ■ Exploit Protection
    ■ Web protection (Microsoft Edge Legacy)
    ■ Application control
  4. Configuration settings Depending on the option you choose displays different options.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly