Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 5 pages
Exam (elaborations)

Microsoft SC-200 Study Guide Latest

Document preview thumbnail
Preview 2 out of 5 pages

Microsoft SC-200 Study Guide Latest Threat and vulnerability management - provides real-time visibility and helps identify ways to improve your security posture. attack surface reduction (ASR) - eliminates risky or unnecessary surface areas and restricts dangerous code from running. Advanced protection - uses machine learning and deep analysis to protect against file-based malware advanced persistent threats (APT) - Associated in high severity alerts uses continuous, clandestine, and sophisticated hacking techniques to gain access to a system and remain inside for a prolonged period of time, with potentially destructive consequences. High Severity Alert - credential theft tools activities, ransomware activities not associated with any group, tampering with security sensors, or any malicious activities indicative of a human adversary. Medium Severity Alert - observed behaviors typical of attack stages, anomalous registry change, execution of suspicious files Low Severity Alert - Alerts on threats associated with prevalent malware. hack-tools, non-malware hack tools, such as running exploration commands, clearing logs, isolated security tool by a user in organization. Informational (Grey) Alerts - might not be considered harmful to the network but can drive organizational security awareness on potential security issues. MDE vs MD AV Alert Severity - AV scope represents the absolute severity of the detected threat (malware) and is assigned based on the risk of the individual. MDE represent risk on device and risk to the organization. Incident Linking - You can create a new incident from the alert or link to an existing incident. Where can remediation actions be reviewed? - Action Center Automated investigation and remediation (AIR) - Full automation - (recommended) means remediation actions are taken automatically on artifacts determined to be malicious. Semi-automation - some remediation actions are taken automatically, but other remediation actions await approval before being taken What are the 7 pillars of MS ATP - Threat & Vulnerability management, Attack Surface Reduction, Next Generation AV, EDR, Auto investigation & Remediation, Microsoft Threat Experts, Management & APIs Hardware Isolation - Isolates untrusted websites and documents in a container Application Control - Allows only trusted applications to run Ransomware protection - Controlled Folder Access - Network Protection - Prevents any app from accessing dangerous locations Web Protection - Exploit Protection - Device control - Graph API - Where is attack surface reduction located? - MDE Endpoint Security Attack Surface reduction What is SmartScreen? - checks files that you download from the web against a list of reported malicious software sites and programs known to be unsafe Where is controlled folder access? - MDE Devices Configuration profiles Endpoint protection Request Remediation - creates an activity item which can be used to monitor the remediation progress of this recommendation Remediation Progress - is a real-time reflection of the endpoint patch state that is continuously assessed by the defender for Endpoint sensor What services does azure defender protect? - Servers, app services, Azure SQL DBs, Storage, Kubernetes, Container registries, key vault


Document information

Uploaded on
February 16, 2024
Number of pages
5
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers
$9.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Academicmines
4.1
(17)
Sold
94
Followers
55
Items
2689
Last sold
3 months ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions

Whoops! We can’t load your doc right now. Try again or contact support.