Your organization uses Microsoft Defender XDR and you are configuring attack surface reduction (ASR) rules. You need to implement a rule that blocks executable files from running unless they meet a prevalence, age, or trusted list criterion. Which ASR rule should you enable?
This is the correct ASR rule: it uses Microsoft's cloud-based threat intelligence to compute a risk score for each executable file. An executable is allowed to run only if it is widely prevalent, has been observed for a sufficiently long time, or is explicitly listed in a trusted list; otherwise, execution is blocked. This directly matches the requirement to block executable files from running unless they meet a prevalence, age, or trusted list criterion, making it the appropriate choice.
Why this answer
The ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) is specifically designed to prevent executable files (e.g., .exe, .dll, .scr) from running unless they have been seen in the organization (prevalence), are old enough (age), or are on a trusted list. This rule uses cloud-delivered protection and Microsoft's reputation-based intelligence to evaluate files before execution, directly matching the requirement described in the question.
Exam trap
The trap here is that candidates often confuse this ASR rule with the 'Block untrusted and unsigned processes that run from USB' rule, mistakenly thinking that 'untrusted' means the same as 'not meeting prevalence/age/trusted list criteria,' but the USB rule only applies to removable drives, not all executable files from any location.
How to eliminate wrong answers
Option A is wrong because 'Block untrusted and unsigned processes that run from USB' (GUID: b2b3f03d-6a4c-4b7e-8f6f-0c7f8f8e8f8f) only blocks processes launched from USB removable drives, not all executable files regardless of source. Option B is wrong because 'Block Office applications from creating executable content' (GUID: 3b576869-a4ec-4529-8536-b80a7769e899) specifically targets Office apps (Word, Excel, etc.) creating executable content, not all executable files from any source. Option C is wrong because 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' (GUID: 9e6c4e1f-7d60-472f-b1a0-3f2d6d7e8f9a) is an ASR rule that protects LSASS from credential dumping attacks, not a rule that evaluates executable files based on prevalence, age, or trusted list criteria.