Microsoft 365 Administrator Expert MS-102 Practice Question

You manage Windows 10 Enterprise 21H2 devices that are protected by a third-party antivirus solution and have been onboarded to Microsoft Defender for Endpoint (MDE). Security leadership wants Defender to stop or quarantine malicious artifacts that its endpoint detection and response (EDR) component identifies, but they do not want to replace the existing antivirus.

Which MDE capability should you enable on the devices to meet the requirement while keeping the third-party antivirus as the primary antimalware engine?

  • Switch Microsoft Defender Antivirus to active mode and disable the third-party antivirus.

  • Enable Controlled folder access.

  • Configure Attack Surface Reduction (ASR) rules in block mode.

  • Enable EDR in block mode on the devices.

Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot