MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator wants to prevent attackers from stealing credentials by blocking access to the Local Security Authority Subsystem Service (LSASS) from untrusted processes. Which Attack Surface Reduction (ASR) rule should the administrator enable to meet this requirement?
⚠ Common exam trap
Candidates often confuse the 'Block credential stealing from LSASS' rule with other ASR rules that address different attack vectors, such as blocking executable files or Office child processes, because they all fall under the same 'Attack Surface Reduction' umbrella but target distinct behaviors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block credential stealing from the Windows local security authority subsystem (lsass.exe).
The ASR rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) directly prevents untrusted processes from accessing LSASS memory, which is a common technique used by attackers to dump credentials via tools like Mimikatz. This rule blocks attempts to open lsass.exe with specific access rights (e.g., PROCESS_VM_READ) from non-trusted processes, thereby protecting credential material stored in LSASS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block credential stealing from the Windows local security authority subsystem (lsass.exe).
Why this is correct
LSASS is the Windows Local Security Authority Subsystem, which stores or caches credentials for single sign-on. Attackers use tools like Mimikatz or process injection to read the memory of lsass.exe and extract password hashes or plaintext credentials. The Block credential stealing from the Windows local security authority subsystem (lsass.exe) ASR rule prevents untrusted and non-signed processes from accessing lsass.exe, directly disrupting this credential-theft technique before it can succeed.
- ✗
Block executable files from running unless they meet a prevalence, age, or trusted list criterion.
Why it's wrong here
The ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' restricts execution of unknown or untrusted executables, which helps stop malicious binaries and ransomware payloads. However, it does not specifically protect lsass.exe because credential theft can be performed using built-in, signed Microsoft tools such as PowerShell or a remote administration utility that are already trusted. An attacker with local administrator rights can also use a driver or reflective DLL that bypasses this generic executable block, leaving LSASS memory exposed. This rule is a general anti-malware control, not a targeted countermeasure for credential theft.
- ✗
Block Office applications from creating child processes.
Why it's wrong here
Blocking Office applications from creating child processes is designed to prevent phishing attacks where malicious documents use macros to spawn PowerShell, cmd.exe, or other scripting engines. While this does stop one lateral-movement and payload-download chain, credential stealers do not rely on Office child processes to access LSASS. An attacker can directly call APIs such as NtOpenProcess and MiniDumpWriteDump on lsass.exe from a standalone process, or use a service like Local Security Authority (LSA) protection bypass, without launching any child from an Office app. Thus this rule addresses a different attack vector and does not mitigate LSASS credential theft.
- ✗
Block persistence through Windows Management Instrumentation (WMI) event subscription.
Why it's wrong here
The WMI event subscription rule blocks attackers from creating permanent WMI event consumers and filters to achieve persistence, which is a technique for surviving reboots and maintaining a foothold on the system. Credential theft from LSASS occurs in the 'credential access' phase of the attack chain, not the 'persistence' phase. An attacker on a compromised host may already have elevated privileges and can run Mimikatz or a custom tool directly, without needing any WMI subscription. Therefore, while this rule is valuable for defense-in-depth against persistence, it is unrelated to preventing the theft of credentials stored in lsass.exe.
Go deeper
Related to this question
Learn chapter
OneDrive Sharing Policies and External Access
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Attack surface reduction
Attack surface reduction is a set of security practices that minimizes the number of ways an attacker can access or exploit a system by removing unnecessary features, locking down configurations, and controlling software behavior.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.