Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company uses Microsoft Defender for Endpoint. An alert indicates that a device is communicating with a known malicious IP address. The security team wants to automatically block the IP address on all devices. Which action should they configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Indicator of compromise (IoC)

An Indicator of compromise (IoC) in Microsoft Defender for Endpoint can be configured to automatically block a known malicious IP address across all devices. Option A (Custom detection rule) is wrong because custom detection rules are used for custom query-based detection, not for blocking. Option B (Automated investigation) is wrong because automated investigation can investigate and resolve alerts but does not directly block IP addresses. Option D (Threat analytics report) is wrong because it provides threat intelligence reports but does not take blocking actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Custom detection rule

    Why it's wrong here

    Custom detection rules in Microsoft Defender for Endpoint leverage Kusto Query Language (KQL) to proactively hunt for threats and suspicious activities across an organization's data. While these rules are powerful for identifying specific patterns or indicators, their primary function is to generate alerts when a match is found. They do not inherently provide direct blocking capabilities for network entities like IP addresses; instead, they inform security analysts who would then initiate blocking actions through other mechanisms.

  • Automated investigation

    Why it's wrong here

    Automated investigations in Microsoft Defender for Endpoint are designed to autonomously examine alerts, gather evidence, and determine if remediation is needed. These investigations can take actions like stopping processes, quarantining files, or blocking URLs, effectively resolving many common threats without human intervention. However, their scope is typically focused on remediating existing threats or suspicious activities identified by alerts, rather than proactively blocking a newly identified malicious IP address at a network or endpoint firewall level before an alert is fully processed.

  • Indicator of compromise (IoC)

    Why this is correct

    An Indicator of Compromise (IoC) is a piece of forensic data, such as an IP address, file hash, domain, or URL, that identifies malicious activity on a network or system. In Microsoft Defender for Endpoint, administrators can configure custom IoCs to explicitly allow, audit, or block specific entities across all managed devices. By adding a malicious IP address as a "Block" IoC, Defender for Endpoint will prevent communication with that IP, effectively stopping potential command-and-control or data exfiltration attempts.

  • Threat analytics report

    Why it's wrong here

    Threat analytics in Microsoft Defender for Endpoint provides expert-level threat intelligence and context regarding active threats and attack campaigns. It offers detailed reports, recommended actions, and insights into how an organization is exposed or resilient to specific threats. While invaluable for understanding the threat landscape and guiding security posture improvements, Threat analytics is an informational and guidance tool; it does not automatically implement blocking actions or directly configure security policies on endpoints.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.