Endpoint detection flags suspicious PowerShell activity on a licensing clerk's PC. Which Defender product is designed to detect and respond to that endpoint threat?
Select an answer to reveal the explanation.
Short Explanation
Weird PowerShell on a clerk PC is an endpoint alert, not a quiz or a hold. Defender for Endpoint watches and responds on the device. Forms, litigation hold, and Planner portfolios live elsewhere.
Full Explanation
Suspicious PowerShell and similar host behaviors are endpoint detection and response scenarios for Microsoft Defender for Endpoint. Forms, Exchange litigation hold, and Planner portfolios are not EDR sensors. Fundamentals candidates should associate endpoint behavioral detections with Defender for Endpoint.