Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

Your company deploys Microsoft Defender for Endpoint (Defender XDR) to all Windows devices. You need to create a custom detection rule that triggers an alert when a specific PowerShell script is executed on any device. Which action should you take in the Microsoft 365 Defender portal?

⚠ Common exam trap

It's easy for candidates to confuse Indicators of compromise (IoC) with custom detection rules, thinking a hash-based IoC can create a detection rule, but IoCs are for blocking or alerting on known files, not for writing custom KQL-based detection logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new custom detection rule based on an Advanced hunting query.

A is correct because custom detection rules in Microsoft 365 Defender are built from Advanced hunting queries (Kusto Query Language) that can detect specific script execution patterns, such as a PowerShell script with a known command line or hash. This allows you to trigger an alert when the exact script runs, meeting the requirement for a custom detection rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a new custom detection rule based on an Advanced hunting query.

    Why this is correct

    Custom detection rules run Advanced hunting KQL queries on a schedule and raise alerts when results match, so a query targeting PowerShell script execution events detects the script across all onboarded devices. This is the only mechanism in the Defender portal for query-based custom detections.

  • ✗

    Configure a Device control policy to block PowerShell.

    Why it's wrong here

    Device control policies govern removable media, printers and USB peripherals through attack surface reduction settings; they cannot block PowerShell execution. Blocking PowerShell outright is a separate ASR or AppLocker concern, and the stem requires alerting on a script, not preventing the interpreter.

  • ✗

    Add an Indicator of compromise for the script hash.

    Why it's wrong here

    An indicator of compromise for a file hash blocks or alerts on that known hash, but the requirement is detecting execution of a specific script, which may be modified or unsigned. Indicators suit known-bad artefacts, whereas custom detection rules query advanced hunting tables for behavioural conditions.

  • ✗

    Create a new attack simulation training campaign.

    Why it's wrong here

    Attack simulation training launches phishing and social-engineering simulations to measure user awareness; it cannot query device telemetry or raise alerts on PowerShell execution. It is the right choice when the goal is user education campaigns, not custom detection logic in advanced hunting.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.