MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security analyst has identified a new malware sample with SHA256 hash 'abc123...'. They need to immediately block this file from executing on any managed endpoint across the organization. Which Microsoft Defender for Endpoint capability should they use?
⚠ Common exam trap
Test-takers frequently confuse Indicators (IoC) with Attack Surface Reduction rules, mistakenly thinking ASR rules can block specific file hashes, when in fact ASR rules only block behavioral patterns and cannot target individual file hashes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Indicators (IoC)
Indicators of Compromise (IoC) in Microsoft Defender for Endpoint allow security analysts to create custom indicators (such as file hashes, IPs, or URLs) that are immediately enforced across all managed endpoints. This capability enables blocking execution of a specific SHA256 hash at the kernel level via the Microsoft Defender Antivirus driver, providing near-instant protection without requiring a signature update or policy change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attack surface reduction rules
Why it's wrong here
Attack surface reduction rules are heuristic rules in Microsoft Defender that target common attack techniques (e.g., blocking Office apps from creating child processes or preventing untrusted scripts from running). They do not match on a precise, newly discovered malware sample's SHA-256 hash; instead, they evaluate behavior patterns in real time. Since the analyst has identified a specific malware file hash, ASR rules cannot be used to selectively block just that sample without affecting broader categories of software behavior.
- ✓
Indicators (IoC)
Why this is correct
Indicators of compromise (IoC) in Microsoft 365 Defender for Endpoint let administrators explicitly define block actions for known malicious artifacts, including file SHA-256 hashes, IP addresses, URLs, and domains. After the analyst obtains the malware sample's exact hash, they can create a file indicator (with action 'Block and remediate') so that Defender blocks execution across managed endpoints. This is the only option here that directly provides granular, hash-based allow/block control rather than relying on behavioral heuristics or post-detection response.
- ✗
Automated investigation and response
Why it's wrong here
Automated investigation and response (AIR) is an incident-response capability that activates after a detection or alert is triggered; it automatically runs investigations, discovers scope, and takes remediation actions like quarantining files or isolating devices. It is reactive and depends on existing detections, so it cannot pre-emptively block a specific malware hash that is only identified as an indicator, before any alert fires. AIR is a response engine, not an IoC enforcement engine.
- ✗
Threat analytics
Why it's wrong here
Threat analytics in Microsoft 365 Defender is a threat-intelligence reporting module that provides detailed write-ups of active campaigns, affected platforms, and recommended mitigation steps (including the latest detection and protection status). It does not itself enforce blocking actions on a given file hash; it only surfaces information and guidance for the security team to act upon. Therefore, simply viewing the threat analytics report for this specific sample would not stop the malware from executing on endpoints.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.