Microsoft 365 Administrator Expert MS-102 Practice Question
You manage Windows 10 Enterprise 21H2 devices that are protected by a third-party antivirus solution and have been onboarded to Microsoft Defender for Endpoint (MDE). Security leadership wants Defender to stop or quarantine malicious artifacts that its endpoint detection and response (EDR) component identifies, but they do not want to replace the existing antivirus.
Which MDE capability should you enable on the devices to meet the requirement while keeping the third-party antivirus as the primary antimalware engine?
Switch Microsoft Defender Antivirus to active mode and disable the third-party antivirus.
Enable Controlled folder access.
Configure Attack Surface Reduction (ASR) rules in block mode.
EDR in block mode allows Microsoft Defender for Endpoint to take blocking or containment actions on malicious behaviors detected by its EDR sensor even when Microsoft Defender Antivirus is running in passive mode because another antivirus product is active. When EDR in block mode is turned on, Defender acts only after a detection; it does not replace or disable the existing antivirus.
Attack Surface Reduction rules or Controlled folder access are separate hardening features that do not rely on EDR detections, and switching Microsoft Defender Antivirus to active mode would conflict with the requirement to retain the third-party antivirus.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is EDR in block mode?
Open an interactive chat with Bash
Why does EDR in block mode work when Defender is in passive mode?
Open an interactive chat with Bash
How is EDR different from Attack Surface Reduction (ASR) rules?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .