Instiq

4Defender for Endpoint and Cloud Apps

Practice questions →Glossary →
  • 4.1Defender for Endpoint

    Understand onboarding devices to Microsoft Defender for Endpoint, endpoint settings (attack surface reduction ASR, EDR block mode, tamper protection), and Microsoft Defender Vulnerability Management for surfacing and remediating vulnerabilities.

  • 4.2Defender for Cloud Apps

    Understand Microsoft Defender for Cloud Apps: connecting via the Microsoft 365 app connector, policies (activity/file policies that trigger alerts), Cloud App Discovery for shadow IT, and interpreting/responding to the activity log.