Ms-102 Implement Threat Intelligence in Microsoft Defender Flashcards

(16 cards)

1
Q

To get to the Alerts Queue in Defender

A

In the navigation pane, you must select the Incidents & alerts group to expand it, and then select Alerts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The manage alert pane allows you to

A

view or specify:

The alert status (New, Resolved, In progress).

The user account which Microsoft Defender XDR assigned to the alert.

The alert’s classification:

Not set. This option is the default setting.

True positive. Use this classification for alerts that accurately indicate a real threat. Specifying the threat type helps your security team see threat patterns and act to defend your organization from them.

Informational, expected activity. Use the options in this category to classify alerts. For example, for security tests, red team activity, and expected unusual behavior from trusted apps and users.

False positive. Use this classification for the type of alerts related to nonmalicious activity. Classifying alerts as false positive helps Microsoft Defender XDR improve its detection quality.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

(AIR)

A

Automated investigation and response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

to select an item in the Action center

A

Go to the Microsoft Defender portal and sign in.
In the navigation pane, select Actions & submissions, and then select Action center.
On the Action center pane, the Pending tab is displayed by default. Select either the Pending or History tab and then select an item. The system displays a detail pane for the selected item.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

which of the following items triggers the start of an automated investigation?

A

An incident, in turn, can start an automated investigation. The automated investigation results in a verdict for each piece of evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How many days of raw data can you explore up to in an advanced threat hunting query?

A

30 days of raw data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

To access Threat Analytics

A

Threat Intelligence –> Threat Analytics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security)

A

identifies and combats cyberthreats across all your Microsoft and third-party cloud services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Cloud Discovery

A

uses an organization’s traffic logs to dynamically discover and analyze the cloud apps that it’s using.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Cloud app catalog

A

growing catalog of over 25,000 cloud apps. Microsoft ranked and scored the apps based on industry standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

App connectors

A

facilitate the integration between the Cloud App Security service and cloud applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Policy control

A

detect risky behavior, violations, or suspicious data points and activities in an organization’s cloud environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Access the Defender for Cloud Apps portal

A

in the Microsoft Defender portal, the Cloud Apps section in the left-hand navigation pane provides links to the Microsoft Defender for Cloud Apps features. Select Settings to navigate to the Settings page.

On the Settings page, select Cloud Apps to navigate to the Settings page for Cloud Apps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Create a new file policy

A

On the Microsoft Defender for Cloud Apps portal, select Control in the navigation pane, and then select Policies.

On the Policies page, the All policies tab is displayed by default. Select the Information protection tab.

In the Information protection tab, select +Create policy on the menu bar. In the drop-down menu that appears, select File policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Monitor alerts

A

n the Microsoft Defender portal, in the left-hand navigation pane, select Incidents & alerts to expand the group, and then select Alerts.
On the Alerts page, select Add filter on the menu bar.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly