Courseiva

SC-200 Respond to security incidents Practice Question

During an incident response, your team identifies a suspicious PowerShell command executed on multiple devices. Which Microsoft Defender XDR feature should you use to block the command across all endpoints immediately?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Indicators of compromise (IoC)

Microsoft Defender XDR's Indicators of compromise (IoC) allow creating custom indicators to block file hashes, IPs, URLs, or commands across endpoints. Option A is wrong because Potentially Unwanted Application (PUA) protection targets unwanted software, not specific commands. Option C is wrong because Attack Surface Reduction (ASR) rules are designed to block common attack patterns, not ad-hoc commands. Option D is wrong because Device Control policies manage peripheral devices like USB drives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Potentially Unwanted Application (PUA) protection

    Why it's wrong here

    PUA protection blocks low-reputation software based on reputation classification, not arbitrary command lines, so it cannot block a specific PowerShell command. It is the correct control when unwanted applications such as adware or bundled installers must be prevented from running.

  • ✓

    Indicators of compromise (IoC)

    Why this is correct

    Indicators of compromise in Microsoft Defender XDR let you define file hashes, IPs, URLs or commands that block or remediate across onboarded endpoints. Creating a command indicator enforces immediate blocking fleet-wide, satisfying the requirement to stop the PowerShell command on all devices.

  • ✗

    Attack Surface Reduction (ASR) rules

    Why it's wrong here

    ASR rules constrain behaviours such as script execution by Office applications, but they cannot target a specific observed command line across the estate on demand. They are designed for pre-emptive hardening, so they would be the right choice when proactively reducing script-based attack surface rather than responding to a live incident.

  • ✗

    Device Control policies

    Why it's wrong here

    Device Control governs removable media, USB peripherals and printer access through policy, and has no mechanism for blocking command execution. It would be the right choice when restricting which external devices may connect to managed endpoints.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.