exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 125 discussion

Actual exam question from Microsoft's MS-102
Question #: 125
Topic #: 1
[All MS-102 Questions]

Your company has a Microsoft 365 E5 subscription.

You onboard a device on the company's network to Microsoft Defender for Endpoint.

In the Microsoft 365 Defender portal, you notice that the device inventory displays many devices that have an Onboarding status of Can be onboarded.

You need to ensure that onboarded devices are prevented from polling the network for device discovery but can still discover devices with which they communicate directly.

What should you configure in the Microsoft 365 Defender portal?

  • A. standard discovery
  • B. device discovery exclusions
  • C. basic discovery
  • D. a network assessment job
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
netbw
Highly Voted 1 year, 7 months ago
Selected Answer: C
C. Basic discovery https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery?view=o365-worldwide#discovery-methods
upvoted 16 times
...
Cfernandes
Highly Voted 1 year, 6 months ago
Selected Answer: C
C esta correta.
upvoted 5 times
...
jarattdavis
Most Recent 8 months, 2 weeks ago
Selected Answer: B
B. device discovery exclusions Here's why: Standard discovery and basic discovery are both discovery methods that allow devices to poll the network for other devices. This is not what you want to prevent. A network assessment job is used to assess the security posture of your network. It doesn't directly address the issue of preventing onboarded devices from polling the network. Device discovery exclusions allow you to specify devices that should be excluded from network-wide device discovery. By excluding onboarded devices from this discovery method, you can prevent them from polling the network for other devices while still allowing them to discover devices with which they communicate directly.
upvoted 1 times
...
XylosSW
9 months, 2 weeks ago
Selected Answer: C
"In the Device Discovery settings, select Basic Device Discovery mode. This mode restricts the devices from polling the network to discover other devices. Instead, it allows devices to discover only those with which they directly communicate." Explanation: Standard Discovery: This mode might allow for broader network polling which doesn’t meet the requirement of limiting discovery to direct communications only. Device Discovery Exclusions: These settings are typically used to exclude specific devices or IP ranges from being discovered but don't inherently restrict onboarded devices from polling the network for discovery. ChatGPT 4-o says C
upvoted 3 times
...
BossLG
1 year, 1 month ago
I agree its C For further clarification read the FAQ https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery-faq?view=o365-worldwide
upvoted 1 times
...
Iccen
1 year, 2 months ago
To achieve the desired outcome of preventing onboarded devices from polling the network for device discovery while still allowing them to discover devices with which they communicate directly in the Microsoft 365 Defender portal, you should: B. Device discovery exclusions Explanation: By configuring device discovery exclusions, you can specify certain devices or ranges of IP addresses that should be excluded from the device discovery process. This allows you to prevent onboarded devices from indiscriminately polling the network for device discovery while still enabling them to discover devices with which they communicate directly. This approach provides a targeted solution to meet the specific requirements outlined in the scenario.
upvoted 4 times
...
Amir1909
1 year, 2 months ago
C is correct
upvoted 1 times
...
Vaerox
1 year, 3 months ago
Selected Answer: D
I believe it's D. A basic or standard discovery will still scan for the entire network, the scan will just either be passive (less information, less network usage) or active (more information, more network usage). Please read the article below: https://techcommunity.microsoft.com/t5/microsoft-defender-vulnerability/network-device-discovery-and-vulnerability-assessments/ba-p/2267548
upvoted 1 times
...
RJTW070
1 year, 3 months ago
Selected Answer: A
AI says A: To prevent onboarded devices from polling the network for device discovery but still discover devices with which they communicate directly, you should configure the Standard discovery mode in the Microsoft Defender for Endpoint portal1. This mode allows endpoints to actively find devices in your network to enrich collected data and discover more devices - helping you build a reliable and coherent device inventory. In addition to devices that were observed using the passive method, standard mode also leverages common discovery protocols that use multicast queries in the network to find even more devices1. Summary: To prevent onboarded devices from polling the network for device discovery but still discover devices with which they communicate directly, you should configure the Standard discovery mode in the Microsoft Defender for Endpoint portal.
upvoted 1 times
...
TheMCT
1 year, 3 months ago
Selected Answer: A
Standard discovery (recommended): This mode allows endpoints to actively find devices in your network to enrich collected data and discover more devices - helping you build a reliable and coherent device inventory. When Standard mode is enabled, minimal, and negligible network activity generated by the discovery sensor might be observed by network monitoring tools in your organization.
upvoted 1 times
...
Sesbri
1 year, 3 months ago
For me it is B. See here for reference: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-device-discovery?view=o365-worldwide#exclude-devices-from-being-actively-probed-in-standard-discovery
upvoted 1 times
...
Festus365
1 year, 5 months ago
It could be D; A network assessment job
upvoted 2 times
...
jt2214
1 year, 6 months ago
Selected Answer: C
It's C https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery?view=o365-worldwide#discovery-methods
upvoted 3 times
...
Sas2003
1 year, 7 months ago
Selected Answer: B
I believe the correct answer is B. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery?view=o365-worldwide#discovery-methods
upvoted 1 times
Sas2003
1 year, 7 months ago
Oops I meant C
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago