Security Flashcards

(17 cards)

1
Q

What is secure boot?

A

It is a feature of UEFI. It only allows trusted bootloaders/OS to run by checking the bootloader’s digital certificate.

This prevents rootkits and malware being loaded before the OS has booted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is TPM?

A

It is a chip on the motherboard that stores the disk encryption key.

It also checks secure boot, firmware and if the bootloader has been tampered with; if not it boots into the OS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What vulnerability do TPM and Secure Boot help secure?

A

The OS is most vulnerable when first booting because antivirus and other software is not running untill you boot the machine.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Microsoft Defender Application Control

A

It is a feature that allows you to control what apps are allowed on a machine and what apps can access files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Attack Surface reduction?

A

It is the protection of scripts, macros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is controlled folder access

A

Only allowing specifc apps to have access to folders
Only the local admin can also modify folders that the app have access to

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is exploit protection

A

Analogy - knights have suits that have little holes that need repairing - apps have small vulberabilities and need fixes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Application Guard?

A

It uses VBS to create a sandbox enviromnent for microsoft edge that tests for malware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Device Guard?

What Technology Does it use?

A

it combines Windows Defender application control with Hyper - V to protect the kernel from alicious code being injected - Device Guard does require addidtial hardware due to virtualisation

Uses TPM UEFI and secure boot

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is hardware based isolation?

A

Castle Anaolgy - Scans from the floors up and ensures no rooms, doors etc have been altered or changed

Ensures Hardware integrity by using secure boot

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does Windows Defender Exploit Guard Include?

A

ASR, Controlled Folder access, Netowrk Filtering and Exploit protection

Remeber the analogy - Expolit prtection is the magical reparing armour

Exploit Guard includes Explooit protection and three more features

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Windows Defender System Guard

A
  • Uses VBS to ensure integrity of System

Ensures signed drivers are loaded while booting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A company wants to edit the Antivirus settings for Intune. Where would they do this?

A

A) Endpoint Security > Antivirus
B) Device configuration > Device restrictions > Microsoft Defender Antivirus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Microsoft Defender Antivirus offline

A

Microsoft Defender Antivirus Offline mode scans the device before Windows fully loads, using kernel-based protection. This allows it to detect and remove rootkits and deeply embedded malware that may hide when the operating system is running.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

With least privilege in mind, what admin role should you apply a user that needs to change security defaults?

A) Security Admin
B) Conditional Access Admin
C) Intune Admin
D) Helpdesk Admin

A

B - Conditional Access Admin allows you to edit security defaults

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What Platforms are available for Microsoft Defender for Endpoint? Select 6

A) Linux
B) MacOS X
C) MacOS 12,13,14,16,26
D)Windows Server
E) Windows
F) iOS
G) Android
H) Linux Server

17
Q

What is a service principle?

A

Identity for Apps - Login account for apps