exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 2 question 35 discussion

Actual exam question from Microsoft's MS-100
Question #: 35
Topic #: 2
[All MS-100 Questions]

DRAG DROP -
You have a Microsoft 365 subscription.
You have the devices shown in the following table.

You need to onboard the devices to Windows Defender Advanced Threat Protection (ATP). The solution must avoid installing software on the devices whenever possible.
Which onboarding method should you use for each operating system? To answer, drag the appropriate methods to the correct operating systems. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1:
To onboard down-level Windows client endpoints to Microsoft Defender ATP, you'll need to:
Configure and update System Center Endpoint Protection clients.
Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender ATP
Box 2:
For Windows 10 clients, the following deployment tools and methods are supported:

Group Policy -
System Center Configuration Manager
Mobile Device Management (including Microsoft Intune)

Local script -
Box 3:
Windows Server 2016 can be onboarded by using Azure Security Centre. When you add servers in the Security Centre, the Microsoft Monitoring Agent is installed on the servers.
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat- protection

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 4 years, 11 months ago
Box 1: To onboard down-level Windows client endpoints to Microsoft Defender ATP, you'll need to: Configure and update System Center Endpoint Protection clients. Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender ATP Box 2: For Windows 10 clients, the following deployment tools and methods are supported: Group Policy System Center Configuration Manager Mobile Device Management (including Microsoft Intune) Local script. Box 3: Windows Server 2016 can be onboarded by using Azure Security Centre. When you add servers in the Security Centre, the Microsoft Monitoring Agent is installed on the servers.
upvoted 17 times
...
RNG60FR
Highly Voted 4 years, 5 months ago
This cannot be an MS-100 exam question.
upvoted 14 times
Turak64
3 years, 9 months ago
Correction, it *shouldn't* be a MS-100 question but this is Microsoft. I've done enough MS certs now, to know they are always adding in questions that are totally out of scope.
upvoted 10 times
...
...
suvittech
Most Recent 2 years, 5 months ago
1- Microsoft Monitoring Agent 2- Local Script 3- Local Script https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/onboard-windows-client?view=o365-worldwide
upvoted 5 times
...
H_ngM_n
2 years, 8 months ago
i agree
upvoted 1 times
H_ngM_n
2 years, 8 months ago
with windows server 2016 using local script
upvoted 1 times
...
...
mmraouf
2 years, 9 months ago
1-MMA 2-Local Script 3-Local Script https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/onboard-downlevel?view=o365-worldwide https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-server-endpoints?view=o365-worldwide#prerequisites-for-windows-server-2016
upvoted 10 times
...
aaron_roman
2 years, 11 months ago
Box 1 - MMA Box 2 &3 Local script to comply with the requirement "avoid installing software when possible"
upvoted 2 times
...
mikaiwhodakno
3 years ago
The "avoid installing software when possible", combined with local script available from 2012 R2-newer means local script for Win10 and 2016, and install MMA for Win8. The real question though is which version of the test do we get and which answer does the test actually accept as correct? Reference: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-endpoints?view=o365-worldwide
upvoted 1 times
...
TechMinerUK
3 years ago
I'm not sure I agree with this as from personal experience you do not need to install the Microsoft Monitoring Agent to onboard Server 2012 R2, Server 2016, Server 2019 or Server 2022 systems. In the past to onboard server systems we have used the same method as onboarding AD joined Windows systems which is creating a GPO that runs the onboarding script which would be an answer which meets the requirement of not installing any software. This is backed up by the documentation here: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-server-endpoints?view=o365-worldwide Note it says: The previous implementation of onboarding Windows Server 2012 R2 and Windows Server 2016 required the use of Microsoft Monitoring Agent (MMA). The new unified solution package makes it easier to onboard servers by removing dependencies and installation steps. Because of this I would say that Windows 8.1 needs the MMA however Server 2016 and Windows 10 do not from my experience
upvoted 3 times
...
neeewbi
3 years ago
What's right? https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-endpoints?view=o365-worldwide#endpoint-onboarding-tools
upvoted 2 times
...
forummj
3 years, 1 month ago
I don't agree with the answer or those suggesting using MMA more than once. https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-endpoints?view=o365-worldwide The above link clearly has Local Scripts for Server & 10 situations, and MMA for 8.1. In order to "avoid installing software" where possible, this would be the best solution for me.
upvoted 4 times
...
Wojer
3 years, 6 months ago
Now its possible to onboard win 2016 and 2012r2 with installation package and after that onboard package
upvoted 1 times
...
JAPo123
3 years, 10 months ago
in ms-100 exam last friday.
upvoted 7 times
...
JAPo123
3 years, 10 months ago
In exam last friday.
upvoted 2 times
...
melatocaroca
4 years ago
Windows 10 deployment supported tools and methods: • Group Policy • Microsoft Endpoint Configuration Manager • Mobile Device Management (including Microsoft Intune) • Local script https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-endpoints?view=o365-worldwide Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender for Endpoint • Windows 7 SP1 Enterprise • Windows 7 SP1 Pro • Windows 8.1 Pro • Windows 8.1 Enterprise Windows Defender ATP on legacy operating system requires installation of an agent https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/protecting-windows-server-with-windows-defender-atp/ba-p/267114 Windows 2016 Windows Defender Antivirus is built-in Windows Defender ATP on legacy operating system requires installation of an agent https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/protecting-windows-server-with-windows-defender-atp/ba-p/267114
upvoted 1 times
...
jroxas
4 years, 1 month ago
I saw this question on MS-101.
upvoted 5 times
...
Candice79
4 years, 2 months ago
This seems like a question for the MS 500 not the MS 100.
upvoted 5 times
...
Rstilekar
4 years, 5 months ago
Seems not a right question and any explainations either. Ques looks outdated
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...