exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 9 question 1 discussion

Actual exam question from Microsoft's MS-500
Question #: 1
Topic #: 9
[All MS-500 Questions]

You need to enable and configure Microsoft Defender for Endpoint to meet the security requirements. What should you do?

  • A. Configure port mirroring
  • B. Create the ForceDefenderPassiveMode registry setting
  • C. Download and install the Microsoft Monitoring Agent
  • D. Run WindowsDefenderATPLocalOnboardingScript.cmd
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AmplifiedStitches
2 years, 3 months ago
Selected Answer: C
Correct answer is C. "WindowsDefenderATPOnboardingScript.cmd" is the actual name of the script that the erroneous answer is referring to, however, this script is only for onboarding after defender is already installed. Microsoft does provide a script to install defender on Github but it's separate from the one the answer is talking about. references: - https://github.com/microsoft/mdefordownlevelserver
upvoted 1 times
...
Avaris
2 years, 6 months ago
The reason why the answer is Microsoft Monitoring Agent is because there is nothing called windows defender local onboarding script.cmd it is called (windowsdefenderatponboardingscript.cmd)https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-server-endpoints?view=o365-worldwide
upvoted 2 times
...
goape
2 years, 7 months ago
Selected Answer: D
The previous implementation (before April of 2022) of onboarding Windows Server 2012 R2 and Windows Server 2016 required the use of Microsoft Monitoring Agent (MMA).
upvoted 1 times
...
Broesweelies
2 years, 9 months ago
Selected Answer: D
You need to enable and configure Microsoft Defender for Endpoint to meet the security requirements. What should you do? -Windows server 2016, which means you can do it via GPO, via script or via packages. In this case, the only option available is the script. See documentation below that proves it. EXAMPLE: .\install.ps1 -RemoveMMA <YOUR_WORKSPACE_ID> -OnboardingScript ".\WindowsDefenderATPOnboardingScript.cmd" https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/server-migration?view=o365-worldwide#installer-script
upvoted 4 times
...
RVR
2 years, 9 months ago
Selected Answer: D
Believe the Answer is D: "installation and onboarding packages" is the new way to onboard and WindowsDefenderATPOnboardingScript.cmd - contains the onboarding script https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-endpoints-script?view=o365-worldwide
upvoted 3 times
JimboJones99
2 years, 9 months ago
The requirement is: "Configure domain-joined servers to ensure that they report sensor data to Microsoft Defender for Endpoint". The servers are WS2016 so the agent can be installed on them. The script method of installation is for WS2019+
upvoted 5 times
...
...
kiketxu
4 years, 3 months ago
given answer is correct. This is not asking for events forwarding, which requires port forwarding https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...