Question 74 of 1,250
SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company wants to reduce the attack surface on its Windows devices by blocking common techniques used by malware, such as preventing Office applications from creating child processes or blocking executable files from running from the %TEMP% folder. Which Microsoft Defender for Endpoint feature should be configured?
⚠ Common exam trap
A common mix-up: candidates confuse Attack surface reduction rules with Microsoft Defender Antivirus or Controlled folder access, assuming that any 'blocking' feature is part of the antivirus or that folder protection covers execution, when in fact ASR rules are the only feature that enforces behavior-based policies on process creation and execution from specific locations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attack surface reduction rules
Attack surface reduction (ASR) rules are a feature of Microsoft Defender for Endpoint that specifically target common malware behaviors, such as blocking Office applications from creating child processes and preventing executable files from running from the %TEMP% folder. These rules are designed to reduce the attack surface by enforcing policies that stop suspicious or malicious actions at the process level, without relying solely on signature-based detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender Antivirus
Why it's wrong here
Microsoft Defender Antivirus primarily operates by detecting, quarantining, and removing known malware based on signatures, heuristics, and machine learning models. Its core strength lies in identifying and neutralizing malicious files and processes that match established threat intelligence. However, it does not inherently block legitimate applications, such as Microsoft Office, from performing actions like creating child processes or executing files from common temporary folders, unless those specific actions are part of a detected malicious payload or a known malicious file signature.
When this WOULD be correct
A question asking which Microsoft Defender for Endpoint component provides real-time antivirus scanning, signature-based detection, and remediation of known malware on Windows devices would have Microsoft Defender Antivirus as the correct answer.
- ✓
Attack surface reduction rules
Why this is correct
Attack surface reduction (ASR) rules are a core component of Microsoft Defender for Endpoint, specifically designed to prevent common malware and ransomware techniques by blocking suspicious behaviors at the endpoint. These rules operate by preventing specific actions, such as Office applications creating executable child processes or scripts executing from temporary folders, which are frequently exploited by attackers. By proactively blocking these known exploit techniques, ASR rules significantly reduce the attack surface, enhancing endpoint security beyond traditional signature-based detection.
- ✗
Network protection
Why it's wrong here
Network protection, a feature within Microsoft Defender for Endpoint, primarily functions at the network layer to prevent devices from connecting to known malicious IP addresses, domains, and URLs. Its purpose is to block access to phishing sites, command-and-control servers, and other threat sources by inspecting network traffic. However, network protection does not govern or block local process behaviors, such as an Office application spawning a child process or an executable running from a temporary directory, as its scope is network communication, not internal process execution.
When this WOULD be correct
A question asking for a feature that blocks outbound connections to malicious URLs or IP addresses, such as preventing a device from contacting a known command-and-control server.
- ✗
Controlled folder access
Why it's wrong here
Controlled folder access is a security feature within Microsoft Defender for Endpoint focused on protecting sensitive data by preventing unauthorized applications from making changes to files within designated protected folders. It primarily safeguards against ransomware and other malicious attempts to encrypt or modify user documents and system files. While crucial for data integrity, this feature does not block specific process behaviors like an Office application creating a child process or an executable running from a temporary folder, as its scope is file modification control, not general process execution behavior.
When this WOULD be correct
A question asks: 'Which Microsoft Defender for Endpoint feature should be configured to prevent unauthorized applications from modifying files in protected folders, such as Documents and Pictures?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Attack surface reduction rulesCorrect answer▾
Why this is correct
Attack surface reduction (ASR) rules are a core component of Microsoft Defender for Endpoint, specifically designed to prevent common malware and ransomware techniques by blocking suspicious behaviors at the endpoint. These rules operate by preventing specific actions, such as Office applications creating executable child processes or scripts executing from temporary folders, which are frequently exploited by attackers. By proactively blocking these known exploit techniques, ASR rules significantly reduce the attack surface, enhancing endpoint security beyond traditional signature-based detection.
✗Microsoft Defender AntivirusWrong answer — click to see why▾
Why this is wrong here
Microsoft Defender Antivirus provides real-time protection against malware by scanning files and processes, but it does not specifically block behaviors like Office apps creating child processes or executables running from %TEMP%. Those are behavioral restrictions enforced by Attack Surface Reduction (ASR) rules.
★ When this WOULD be the correct answer
A question asking which Microsoft Defender for Endpoint component provides real-time antivirus scanning, signature-based detection, and remediation of known malware on Windows devices would have Microsoft Defender Antivirus as the correct answer.
Why candidates choose this
Candidates may think antivirus is the primary tool to block malware techniques, not realizing that ASR rules are specifically designed to reduce attack surface by blocking common malware behaviors beyond traditional signature-based detection.
✗Network protectionWrong answer — click to see why▾
Why this is wrong here
Network protection prevents connections to malicious IPs/domains, not local process behaviors like Office apps creating child processes or executables running from %TEMP%.
★ When this WOULD be the correct answer
A question asking for a feature that blocks outbound connections to malicious URLs or IP addresses, such as preventing a device from contacting a known command-and-control server.
Why candidates choose this
Candidates may confuse network-level blocking with endpoint behavioral controls, assuming 'network protection' covers all malware-related restrictions.
✗Controlled folder accessWrong answer — click to see why▾
Why this is wrong here
Controlled folder access protects files in specific folders from unauthorized changes by ransomware and other threats, but it does not block Office apps from creating child processes or prevent executables from running from the %TEMP% folder.
★ When this WOULD be the correct answer
A question asks: 'Which Microsoft Defender for Endpoint feature should be configured to prevent unauthorized applications from modifying files in protected folders, such as Documents and Pictures?'
Why candidates choose this
Candidates may confuse controlled folder access with general attack surface reduction because both aim to block malicious behaviors, but controlled folder access focuses on file protection rather than process and execution restrictions.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.