MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to ensure that when a file is detected as malware by Microsoft Defender for Endpoint, the file is automatically blocked and added to the indicator list across all devices in the organization. What should you configure?
⚠ Common exam trap
It's easy for candidates to confuse automated response actions or cloud protection features with the explicit indicator list, which is the only way to persistently block a file across all devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom indicator in Microsoft Defender for Endpoint with the action 'Block and remediate' and scope it to all devices.
Custom indicators in Microsoft Defender for Endpoint are the correct way to block files organization-wide. By creating an indicator with the action 'Block and remediate' and setting the scope to all devices, the file is blocked and remediated on any device. Other options either do not add to the indicator list or are not scoped organization-wide.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the 'Block at first sight' feature in Microsoft Defender for Endpoint.
Why it's wrong here
'Block at first sight' uses cloud protection to block new malware quickly, but it does not create a persistent indicator list entry. It is a real-time protection feature, not a method to manually add a file to the block list across all devices.
- ✗
Configure an automated investigation and response (AIR) playbook to block the file when malware is detected.
Why it's wrong here
AIR playbooks can take response actions, but they do not automatically add files to the indicator list. They can block files on affected devices, but not organization-wide as a persistent indicator. The requirement is to add to the indicator list, which is done via custom indicators.
- ✗
Set up a Microsoft Defender for Cloud Apps file policy to block the file.
Why it's wrong here
Defender for Cloud Apps policies apply to cloud app activities, not directly to endpoint file blocks. They can govern cloud storage but do not add file indicators to Defender for Endpoint. This would not meet the endpoint blocking requirement.
- ✓
Create a custom indicator in Microsoft Defender for Endpoint with the action 'Block and remediate' and scope it to all devices.
Why this is correct
Custom indicators in Defender for Endpoint allow you to define file hashes or certificates to block or allow. By setting the action to 'Block and remediate' and scoping to all devices, you ensure the file is blocked organization-wide. This directly meets the requirement.
Go deeper
Related to this question
Learn chapter
Custom Domain Management in Microsoft 365
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.