Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

An organization wants to allow only specific company-approved USB devices (e.g., those with a specific hardware ID) on managed Windows devices. All other USB devices must be blocked. Which Microsoft 365 Defender feature should be configured?

⚠ Common exam trap

Test-takers frequently confuse Attack surface reduction rules with device control because both are part of Microsoft Defender for Endpoint, but ASR rules focus on process behaviors, not hardware device access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Endpoint device control

Microsoft Defender for Endpoint device control is the correct feature because it provides granular control over peripheral devices, including USB devices, based on hardware IDs. It allows administrators to create allow/block policies that enforce restrictions on managed Windows devices, ensuring only company-approved USB devices can be used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Attack surface reduction rules

    Why it's wrong here

    Attack surface reduction (ASR) rules are a component of Microsoft Defender Exploit Guard that target malicious behaviors and attack techniques, such as blocking executable content from email, Office processes, or script-based threats. While one ASR rule can block executables that are copied from USB drives, ASR rules operate on file execution behavior, not device enumeration. They have no concept of hardware IDs, device instance IDs, or USB vendor/device attributes, so they cannot be configured to allow only specific company-approved USB devices while denying all others.

  • Microsoft Defender for Endpoint device control

    Why this is correct

    Microsoft Defender for Endpoint device control is the correct capability because it is purpose-built to enforce flexible policies on peripheral devices, especially USB storage. Device control policies define rules based on device instance IDs, hardware IDs, or device classes, and support actions such as allow, deny, or audit. This allows an administrator to create a policy that permits only company-approved USB devices (matched by their hardware IDs) while blocking all other USB devices, meeting the stated requirement directly.

  • Microsoft Defender for Cloud Apps session policy

    Why it's wrong here

    Microsoft Defender for Cloud Apps session policies are enforced through the Conditional Access App Control reverse proxy and operate at the application or HTTP session layer. They evaluate signals like user, location, device tags, or app risk to control access to cloud services, and can apply actions like blocking download or requiring step-up authentication. Session policies have no visibility into, or ability to influence, the local operating system's USB device stack or peripheral drivers, so they cannot restrict which hardware devices are physically allowed to connect.

  • Conditional Access device compliance

    Why it's wrong here

    Conditional Access device compliance is an identity- and access-control layer that checks whether a device satisfies compliance policies—such as a required minimum OS version, disk encryption, or being enrolled in mobile device management—before allowing access to cloud resources. It is evaluated during authentication and cannot enforce real-time, granular hardware peripheral policies like USB device allowlisting. Compliance policies themselves are defined in Microsoft Intune and can set device health criteria, but the restriction of specific USB hardware IDs is handled by device configuration policies such as those in Microsoft Defender for Endpoint device control, not by Conditional Access.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.