MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your company has deployed Microsoft Defender for Endpoint on all Windows devices. You are investigating an alert for a suspicious PowerShell command that was blocked by Attack Surface Reduction (ASR) rules. The alert shows the command was executed from a script embedded in a Word document. You need to identify the ASR rule that blocked this activity. Which rule is most likely responsible?
⚠ Common exam trap
The trap is conflating ASR rules that all mention 'Office applications' — candidates must distinguish child-process creation from API calls, code injection, and executable content creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block Office applications from creating child processes
The ASR rule 'Block Office applications from creating child processes' is designed to stop Office apps (Word, Excel, PowerPoint) from spawning processes like powershell.exe, cmd.exe, or wscript.exe. A malicious macro in a Word document that launches PowerShell is the textbook trigger for this rule, which is why it is the most likely blocker.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block Office applications from creating child processes
Why this is correct
This ASR rule is specifically designed to block Office applications from spawning child processes, such as when Word launches PowerShell via a malicious macro. In this attack chain, the macro directly invokes PowerShell as a new process, so blocking child process creation breaks the execution chain at the critical point. Other ASR rules target different stages like API calls or code injection, but the core action here is the creation of the child process.
- ✗
Block Office applications from making Win32 API calls
Why it's wrong here
This ASR rule prevents Office macros from directly calling Win32 APIs, which is often used for low-level system interaction or evasion. However, it does not stop the creation of a child process because a macro can use alternative methods like COM objects, WMI, or the .NET framework to launch a process without making direct Win32 API calls. Therefore, while this rule might impede some techniques, it would not prevent Word from launching PowerShell in this scenario.
- ✗
Block Office applications from injecting code into other processes
Why it's wrong here
This ASR rule is designed to block code injection into other processes, a technique used for stealthy execution or privilege escalation. In the described attack, Word is not injecting code into an existing process; it is directly creating a new PowerShell process. Blocking code injection would leave the child process creation unhindered, so this rule does not address the specific action needed to stop the attack.
- ✗
Block Office applications from creating executable content
Why it's wrong here
This ASR rule focuses on preventing Office applications from writing executable files (e.g., .exe, .dll, .scr) to disk, which is a common payload-persistence step. However, in this scenario, the PowerShell payload is executed in memory via a command line, not dropped as a file on disk. Consequently, blocking executable content creation would not prevent PowerShell from being launched as a child process.
Go deeper
Related to this question
Learn chapter
Exchange Transport Rules and Mail Flow
Key term
Attack surface reduction
Attack surface reduction is a set of security practices that minimizes the number of ways an attacker can access or exploit a system by removing unnecessary features, locking down configurations, and controlling software behavior.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.