Your organization uses Microsoft Defender XDR. You receive an alert about a potentially unwanted application (PUA) being installed on a device. The PUA is not blocked by your current policy. You need to prevent future installations of this PUA without affecting other software. What should you do?
Creating a custom indicator of compromise (IoC) for the specific file hash, with the action set to Block and remediate, is the precise and recommended response. This indicator is propagated to all devices through Microsoft Defender XDR, preventing the file from executing and automatically triggering remediation of existing copies on any onboarded endpoint. Because the block is scoped solely to that file hash, legitimate applications are preserved, avoiding false positives, and the defense persists for future attempts to execute or download the file.
Why this answer
Creating a custom indicator of compromise (IoC) with the specific file hash allows you to block only that exact PUA file without affecting other software. This leverages Microsoft Defender for Endpoint's custom IoC capability to override the default PUA detection policy, targeting the specific file hash rather than enabling a broad block on all PUAs.
Exam trap
The trap here is that candidates may choose Option A, thinking that enabling PUA blocking is the simplest solution, but they overlook the requirement to avoid affecting other software, which makes the broad policy change inappropriate.
How to eliminate wrong answers
Option A is wrong because enabling blocking of all potentially unwanted applications would affect other software that may be legitimate or needed, violating the requirement to not affect other software. Option B is wrong because resetting the device to factory settings is an extreme, disruptive action that does not prevent future installations of the PUA and is not a targeted solution. Option D is wrong because running a full scan removes the existing PUA but does not prevent future installations of the same file.