You are onboarding Windows Server 2019 and 2012 R2 machines to Microsoft Defender for Endpoint using Microsoft Defender for Cloud. A third‑party antivirus remains the primary AV. You must enable EDR in block mode to remediate post‑breach activity. What should you do? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Microsoft Defender for Servers with MDE integration auto‑provisioning to onboard the servers; ensure Microsoft Defender Antivirus is installed and set to Passive mode on the servers, then enable EDR in block mode in the Microsoft Defender portal..
Why this is the answer
To enable EDR in block mode while a third-party antivirus is present, you must first onboard the servers to Microsoft Defender for Endpoint. This is achieved by enabling Microsoft Defender for Servers with MDE integration auto-provisioning. For EDR in block mode to function correctly alongside a third-party antivirus, Microsoft Defender Antivirus must be installed and configured in Passive mode. Passive mode allows Defender Antivirus to perform scans and receive updates without interfering with the primary antivirus. Once these prerequisites are met, EDR in block mode can be enabled in the Microsoft Defender portal. Uninstalling the third-party antivirus is not necessary if Defender Antivirus is in passive mode. Enabling EDR in block mode via Group Policy alone is insufficient without the proper onboarding and Defender Antivirus configuration. Qualys is a vulnerability management solution, not an EDR in block mode provider. Cloud-delivered protection is a component of Defender Antivirus but does not automatically enable EDR in block mode.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed