Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your company has deployed Microsoft Defender for Endpoint on all Windows devices. You are investigating an alert for a suspicious PowerShell command that was blocked by Attack Surface Reduction (ASR) rules. The alert shows the command was executed from a script embedded in a Word document. You need to identify the ASR rule that blocked this activity. Which rule is most likely responsible?

⚠ Common exam trap

The trap is conflating ASR rules that all mention 'Office applications' — candidates must distinguish child-process creation from API calls, code injection, and executable content creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block Office applications from creating child processes

The ASR rule 'Block Office applications from creating child processes' is designed to stop Office apps (Word, Excel, PowerPoint) from spawning processes like powershell.exe, cmd.exe, or wscript.exe. A malicious macro in a Word document that launches PowerShell is the textbook trigger for this rule, which is why it is the most likely blocker.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Block Office applications from creating child processes

    Why this is correct

    This ASR rule is specifically designed to block Office applications from spawning child processes, such as when Word launches PowerShell via a malicious macro. In this attack chain, the macro directly invokes PowerShell as a new process, so blocking child process creation breaks the execution chain at the critical point. Other ASR rules target different stages like API calls or code injection, but the core action here is the creation of the child process.

  • ✗

    Block Office applications from making Win32 API calls

    Why it's wrong here

    This ASR rule prevents Office macros from directly calling Win32 APIs, which is often used for low-level system interaction or evasion. However, it does not stop the creation of a child process because a macro can use alternative methods like COM objects, WMI, or the .NET framework to launch a process without making direct Win32 API calls. Therefore, while this rule might impede some techniques, it would not prevent Word from launching PowerShell in this scenario.

  • ✗

    Block Office applications from injecting code into other processes

    Why it's wrong here

    This ASR rule is designed to block code injection into other processes, a technique used for stealthy execution or privilege escalation. In the described attack, Word is not injecting code into an existing process; it is directly creating a new PowerShell process. Blocking code injection would leave the child process creation unhindered, so this rule does not address the specific action needed to stop the attack.

  • ✗

    Block Office applications from creating executable content

    Why it's wrong here

    This ASR rule focuses on preventing Office applications from writing executable files (e.g., .exe, .dll, .scr) to disk, which is a common payload-persistence step. However, in this scenario, the PowerShell payload is executed in memory via a command line, not dropped as a file on disk. Consequently, blocking executable content creation would not prevent PowerShell from being launched as a child process.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.