SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company uses Microsoft Defender for Endpoint. An alert indicates that a device is communicating with a known malicious IP address. The security team wants to automatically block the IP address on all devices. Which action should they configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Indicator of compromise (IoC)
An Indicator of compromise (IoC) in Microsoft Defender for Endpoint can be configured to automatically block a known malicious IP address across all devices. Option A (Custom detection rule) is wrong because custom detection rules are used for custom query-based detection, not for blocking. Option B (Automated investigation) is wrong because automated investigation can investigate and resolve alerts but does not directly block IP addresses. Option D (Threat analytics report) is wrong because it provides threat intelligence reports but does not take blocking actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Custom detection rule
Why it's wrong here
Custom detection rules in Microsoft Defender for Endpoint leverage Kusto Query Language (KQL) to proactively hunt for threats and suspicious activities across an organization's data. While these rules are powerful for identifying specific patterns or indicators, their primary function is to generate alerts when a match is found. They do not inherently provide direct blocking capabilities for network entities like IP addresses; instead, they inform security analysts who would then initiate blocking actions through other mechanisms.
- ✗
Automated investigation
Why it's wrong here
Automated investigations in Microsoft Defender for Endpoint are designed to autonomously examine alerts, gather evidence, and determine if remediation is needed. These investigations can take actions like stopping processes, quarantining files, or blocking URLs, effectively resolving many common threats without human intervention. However, their scope is typically focused on remediating existing threats or suspicious activities identified by alerts, rather than proactively blocking a newly identified malicious IP address at a network or endpoint firewall level before an alert is fully processed.
- ✓
Indicator of compromise (IoC)
Why this is correct
An Indicator of Compromise (IoC) is a piece of forensic data, such as an IP address, file hash, domain, or URL, that identifies malicious activity on a network or system. In Microsoft Defender for Endpoint, administrators can configure custom IoCs to explicitly allow, audit, or block specific entities across all managed devices. By adding a malicious IP address as a "Block" IoC, Defender for Endpoint will prevent communication with that IP, effectively stopping potential command-and-control or data exfiltration attempts.
- ✗
Threat analytics report
Why it's wrong here
Threat analytics in Microsoft Defender for Endpoint provides expert-level threat intelligence and context regarding active threats and attack campaigns. It offers detailed reports, recommended actions, and insights into how an organization is exposed or resilient to specific threats. While invaluable for understanding the threat landscape and guiding security posture improvements, Threat analytics is an informational and guidance tool; it does not automatically implement blocking actions or directly configure security policies on endpoints.
Visual reference
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise-grade security platform that protects devices, servers, and networks from advanced cyber threats by combining antivirus, endpoint detection and response, and automated investigation and remediation.
Key term
Indicator of compromise
An indicator of compromise is a piece of digital evidence—such as a suspicious file hash, IP address, or unusual network pattern—that suggests a system may have been breached by an attacker.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.