Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A user reports that they cannot access a legitimate external website because Microsoft Defender for Endpoint is blocking it. The website is required for business. What should you do to allow access while maintaining security?

⚠ Common exam trap

The trap is choosing to disable network protection or exclude the device entirely, which are heavy-handed and reduce security, instead of using the targeted allow list feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the URL to the custom indicators allow list

Adding the URL to the custom indicators allow list in Microsoft Defender for Endpoint allows the specific URL while maintaining network protection for all other traffic. This is the granular approach to permit a legitimate business site without disabling security controls. The allow list overrides block actions for that indicator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exclude the device from the policy

    Why it's wrong here

    Excluding the device removes all Defender for Endpoint protection, not just the one blocked site, leaving the endpoint unprotected against every other threat. It is tempting because exclusions are the standard mechanism for suppressing false positives in Defender antivirus, so it would be correct for a misdetected file or process — not a web block.

  • ✗

    Disable network protection for the device

    Why it's wrong here

    Disabling network protection turns off malicious-domain and IP blocking across the whole device, so the business site loads but every other web threat is permitted too. It is tempting because network protection is the component generating the block, so disabling it would be correct only when the feature itself is faulty, not for one legitimate URL.

  • ✓

    Add the URL to the custom indicators allow list

    Why this is correct

    Custom indicators in Microsoft Defender for Endpoint let you define allow entries that override block decisions for specific URLs, files or certificates. Adding the business URL to the allow list permits access while the rest of the indicator and protection stack stays enforced, satisfying the requirement to unblock one legitimate site.

  • ✗

    Add the user to a custom group with lower security

    Why it's wrong here

    Group membership does not alter Defender for Endpoint's web filtering; network protection evaluates the URL, not the user's group. It is tempting because custom groups commonly scope Conditional Access and Intune assignments, so lowering a group's security posture would be the right lever for access policies — but not for blocking indicators.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.