SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company uses Microsoft Defender for Endpoint. An alert indicates that a device is communicating with a known malicious IP address. The security team wants to automatically block the IP address on all devices. Which action should they configure?
⚠ Common exam trap
SC-900 often tests the confusion between detection features (custom detection rules, threat analytics) and enforcement features (IoC blocking) — candidates pick detection when the question asks for automatic blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Indicator of compromise (IoC)
An Indicator of Compromise (IoC) in Microsoft Defender for Endpoint lets security teams define a known malicious IP address, URL, domain, or file hash and configure an action such as 'Block' or 'Alert and block'. Once created, the IoC is enforced across all onboarded devices, automatically blocking communication with the malicious IP. This is the correct feature for automated, organization-wide blocking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Custom detection rule
Why it's wrong here
Custom detection rules in Microsoft Defender for Endpoint leverage Kusto Query Language (KQL) to proactively hunt for threats and suspicious activities across an organization's data. While these rules are powerful for identifying specific patterns or indicators, their primary function is to generate alerts when a match is found. They do not inherently provide direct blocking capabilities for network entities like IP addresses; instead, they inform security analysts who would then initiate blocking actions through other mechanisms.
- ✗
Automated investigation
Why it's wrong here
Automated investigations in Microsoft Defender for Endpoint are designed to autonomously examine alerts, gather evidence, and determine if remediation is needed. These investigations can take actions like stopping processes, quarantining files, or blocking URLs, effectively resolving many common threats without human intervention. However, their scope is typically focused on remediating existing threats or suspicious activities identified by alerts, rather than proactively blocking a newly identified malicious IP address at a network or endpoint firewall level before an alert is fully processed.
- ✓
Indicator of compromise (IoC)
Why this is correct
An Indicator of Compromise (IoC) is a piece of forensic data, such as an IP address, file hash, domain, or URL, that identifies malicious activity on a network or system. In Microsoft Defender for Endpoint, administrators can configure custom IoCs to explicitly allow, audit, or block specific entities across all managed devices. By adding a malicious IP address as a "Block" IoC, Defender for Endpoint will prevent communication with that IP, effectively stopping potential command-and-control or data exfiltration attempts.
- ✗
Threat analytics report
Why it's wrong here
Threat analytics in Microsoft Defender for Endpoint provides expert-level threat intelligence and context regarding active threats and attack campaigns. It offers detailed reports, recommended actions, and insights into how an organization is exposed or resilient to specific threats. While invaluable for understanding the threat landscape and guiding security posture improvements, Threat analytics is an informational and guidance tool; it does not automatically implement blocking actions or directly configure security policies on endpoints.
Go deeper
Related to this question
Learn chapter
Session and Access Policies in Defender for Cloud Apps
Key term
IOC
IOC stands for Indicator of Compromise, which is forensic evidence that a system has been breached or infected by malware.
Key term
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise-grade security platform that protects devices, servers, and networks from advanced cyber threats by combining antivirus, endpoint detection and response, and automated investigation and remediation.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.