Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator wants to reduce the risk of credential dumping from LSASS on managed Windows endpoints. Which Attack Surface Reduction rule should be enabled?

⚠ Common exam trap

It's easy for candidates to confuse ASR rules with general malware prevention or USB controls, failing to recognize that the specific rule for LSASS credential protection is explicitly named and targeted at memory-based credential theft, not broader execution or download restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block credential stealing from the Windows Local Security Authority Subsystem

The 'Block credential stealing from the Windows Local Security Authority Subsystem' ASR rule (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) specifically prevents credential dumping from LSASS by blocking access to the process memory via common techniques like Mimikatz or direct API calls (e.g., OpenProcess, ReadProcessMemory). This directly reduces the risk of credential theft on managed Windows endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Block credential stealing from the Windows Local Security Authority Subsystem

    Why this is correct

    This ASR rule is specifically designed to block attempts to open and read the memory space of the Local Security Authority Subsystem Service (LSASS), the process in which Windows stores authentication credentials. By intercepting suspicious process calls to LSASS, it directly stops credential dumping tools such as Mimikatz from extracting plaintext passwords and NTLM hashes. When enabled in block mode, it logs and prevents these access attempts, making it the correct rule for reducing credential dumping on managed devices.

  • ✗

    Block executable files from running unless they meet prevalence, age, or trusted list criteria

    Why it's wrong here

    This rule evaluates executable files based on Microsoft's cloud reputation, using factors like prevalence, age, and trusted publisher lists, and blocks those that are unknown or low-reputation. While this helps prevent many malware samples from running, it does not monitor or restrict process calls to LSASS memory, so an attacker could still use a known, signed, or trusted binary to dump credentials. Credential dumping often leverages built-in Windows tools or malicious code injected into legitimate processes, both of which would bypass this reputation-based block.

  • ✗

    Block untrusted and unsigned processes that run from USB

    Why it's wrong here

    This ASR rule targets processes that are both untrusted and unsigned when they originate from removable USB media, thereby preventing USB-spread malware from executing on a system. It is irrelevant to credential dumping because an attacker's process could already be running from system memory, a network share, or a PowerShell in-memory payload, none of which involve USB execution. LSASS memory access is a local runtime action, not an execution-from-USB event, so this rule would not block a credential-dumping attack even if the tool had been previously dropped to disk by other means.

  • ✗

    Block JavaScript or VBScript from launching downloaded executable content

    Why it's wrong here

    This rule blocks JavaScript or VBScript files from launching executable content that was downloaded from the internet, which is a common infection chain used by script-based droppers. However, credential dumping from LSASS is performed by directly obtaining a handle to lsass.exe and reading its memory, which can be done via PowerShell Invoke-Mimikatz or a compiled native tool without any script launching a downloaded executable. This rule neither monitors LSASS access nor stops in-memory credential extraction, so it fails to address the specific technique described in the question.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.