Courseiva
Protect devicesmediumMultiple ChoiceObjective-mapped

MD-102 Protect devices Practice Question

Your company deploys Microsoft Defender for Endpoint (Defender XDR) to all Windows devices. You need to create a custom detection rule that triggers an alert when a specific PowerShell script is executed on any device. Which action should you take in the Microsoft 365 Defender portal?

⚠ Common exam trap

It's easy for candidates to confuse Indicators of compromise (IoC) with custom detection rules, thinking a hash-based IoC can create a detection rule, but IoCs are for blocking or alerting on known files, not for writing custom KQL-based detection logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a new custom detection rule based on an Advanced hunting query.

A is correct because custom detection rules in Microsoft 365 Defender are built from Advanced hunting queries (Kusto Query Language) that can detect specific script execution patterns, such as a PowerShell script with a known command line or hash. This allows you to trigger an alert when the exact script runs, meeting the requirement for a custom detection rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a new custom detection rule based on an Advanced hunting query.

    Why this is correct

    Custom detection rules allow you to define custom alerts based on advanced hunting queries.

  • Configure a Device control policy to block PowerShell.

    Why it's wrong here

    Device control policies restrict hardware, not create detection rules.

  • Add an Indicator of compromise for the script hash.

    Why it's wrong here

    Indicators are for block/allow actions, not custom detection rules.

  • Create a new attack simulation training campaign.

    Why it's wrong here

    Attack simulation training is for phishing simulations, not custom detections.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.