Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security analyst has identified a new malware sample with SHA256 hash 'abc123...'. They need to immediately block this file from executing on any managed endpoint across the organization. Which Microsoft Defender for Endpoint capability should they use?

⚠ Common exam trap

Test-takers frequently confuse Indicators (IoC) with Attack Surface Reduction rules, mistakenly thinking ASR rules can block specific file hashes, when in fact ASR rules only block behavioral patterns and cannot target individual file hashes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Indicators (IoC)

Indicators of Compromise (IoC) in Microsoft Defender for Endpoint allow security analysts to create custom indicators (such as file hashes, IPs, or URLs) that are immediately enforced across all managed endpoints. This capability enables blocking execution of a specific SHA256 hash at the kernel level via the Microsoft Defender Antivirus driver, providing near-instant protection without requiring a signature update or policy change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Attack surface reduction rules

    Why it's wrong here

    Attack surface reduction rules are heuristic rules in Microsoft Defender that target common attack techniques (e.g., blocking Office apps from creating child processes or preventing untrusted scripts from running). They do not match on a precise, newly discovered malware sample's SHA-256 hash; instead, they evaluate behavior patterns in real time. Since the analyst has identified a specific malware file hash, ASR rules cannot be used to selectively block just that sample without affecting broader categories of software behavior.

  • Indicators (IoC)

    Why this is correct

    Indicators of compromise (IoC) in Microsoft 365 Defender for Endpoint let administrators explicitly define block actions for known malicious artifacts, including file SHA-256 hashes, IP addresses, URLs, and domains. After the analyst obtains the malware sample's exact hash, they can create a file indicator (with action 'Block and remediate') so that Defender blocks execution across managed endpoints. This is the only option here that directly provides granular, hash-based allow/block control rather than relying on behavioral heuristics or post-detection response.

  • Automated investigation and response

    Why it's wrong here

    Automated investigation and response (AIR) is an incident-response capability that activates after a detection or alert is triggered; it automatically runs investigations, discovers scope, and takes remediation actions like quarantining files or isolating devices. It is reactive and depends on existing detections, so it cannot pre-emptively block a specific malware hash that is only identified as an indicator, before any alert fires. AIR is a response engine, not an IoC enforcement engine.

  • Threat analytics

    Why it's wrong here

    Threat analytics in Microsoft 365 Defender is a threat-intelligence reporting module that provides detailed write-ups of active campaigns, affected platforms, and recommended mitigation steps (including the latest detection and protection status). It does not itself enforce blocking actions on a given file hash; it only surfaces information and guidance for the security team to act upon. Therefore, simply viewing the threat analytics report for this specific sample would not stop the malware from executing on endpoints.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.