Questions
To test your knowledge of protecting Windows clients and servers with Microsoft Defender for Endpoint, you can try answering the following questions. The answers can be found toward the end of this book:
- A developer is generating test versions of their new application and reports it is not launching successfully. You run
Get-MpPreference
and discover that itsCloudBlockLevel
is6
. What does this mean?- Block at first sight is in zero-tolerance mode
- Block at first sight is in high plus mode
- Block at first sight is in its default configuration
- A bad actor has local administrative rights to a Windows 11 device and is trying to evade defenses using PowerShell. You have enabled tamper protection on the device using Intune. Which of the following can the attacker not disable or evade? Choose all that apply.
- Real-time protection
- Cloud-delivered protection
- Default action based on threat ID
- Attack surface reduction rules
- You are migrating Windows Server 2016 from a well-known...