MS-102 M365 Security Management Flashcards

(16 cards)

1
Q

What is Microsoft Defender for Office 365?

A

a suite of cybersecurity solutions offered by Microsoft, encompassing antivirus software, cloud-based security services, and endpoint protection for devices and networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two main plans of Microsoft Defender for Office 365?

A

Plan 1: Includes Safe Attachments, Safe Links, and Anti-Phishing protection

Plan 2: Includes all Plan 1 features plus Threat Explorer, Real-time detections, Automated Investigation and Response (AIR), and Campaign Views

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Safe Attachments feature in Defender for Office 365?

A

A feature that protects against malicious attachments by opening them in a virtual environment before delivery to check for malicious behavior. It can be configured to block emails with malicious attachments, deliver the email without the attachment, or delay delivery until scanning is complete.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the Safe Links feature in Defender for Office 365?

A

A feature that protects users when they click on links in emails and Office documents by checking the URL at time of click against a list of known malicious sites and URLs. If malicious, users are prevented from accessing the site.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Anti-Phishing protection in Defender for Office 365?

A

Protection that uses machine learning models to detect phishing attempts. It can be configured to protect specific users, custom domains, and includes impersonation protection for specified VIPs or domains.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Microsoft Defender for Endpoint?

A

An enterprise endpoint security platform designed to prevent, detect, investigate, and respond to advanced threats. It uses behavioral sensors, cloud security analytics, and threat intelligence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Attack Surface Reduction (ASR) in Defender for Endpoint?

A

A set of rules that reduce vulnerabilities in applications, helping to block malware, ransomware, and other threats. Rules can be set to block or audit mode and include controls for preventing macros, executable content, and script-based attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is EDR in Defender for Endpoint?

A

Endpoint Detection and Response - capabilities that provide advanced attack detection, automated investigation, and response. It includes behavioral analytics and machine learning to detect attacks and zero-day exploits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How does Threat & Vulnerability Management in Defender for Endpoint work?

A

An integrated component that continuously scans endpoints for vulnerabilities, misconfigurations, and provides risk-based recommendations for remediation, helping organizations prioritize security issues based on threat landscape and business contex

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Microsoft Defender for Cloud Apps?

A

A Cloud Access Security Broker (CASB) that provides visibility, control over data travel, and sophisticated analytics to identify and combat cyberthreats across Microsoft and third-party cloud services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the key components of Microsoft Defender for Cloud Apps?

A

Cloud Discovery
Sanctioning and unsanctioning apps
App connectors
Conditional Access App Control
Policy controls and templates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the main sections of the Microsoft 365 Defender portal?

A

-Home (dashboard with threat analytics)
-Incidents & alerts
-Hunting
-Threat analytics
-Secure Score
-Vulnerability management
-Endpoint management
-Email & collaboration
-Reports
-Settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are Security Baselines in Microsoft 365?

A

Pre-configured groups of settings that represent best practices and recommendations from Microsoft security teams to help organizations establish a secure starting point for managing their environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What factors affect Microsoft Secure Score

A

-Configuration status of security features
-Security-related actions taken
-Adoption of Microsoft security solutions
-Implementation of third-party security solutions
-Addressing of security recommendations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the Baseline policy approach in Conditional Access?

A

A set of recommended essential security policies that provide basic protection, including:

-Requiring MFA for admins
-End-user protection (MFA when needed)
-Blocking legacy authentication
-Requiring device compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly