Courseiva
Question 74 of 1,250

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company wants to reduce the attack surface on its Windows devices by blocking common techniques used by malware, such as preventing Office applications from creating child processes or blocking executable files from running from the %TEMP% folder. Which Microsoft Defender for Endpoint feature should be configured?

⚠ Common exam trap

A common mix-up: candidates confuse Attack surface reduction rules with Microsoft Defender Antivirus or Controlled folder access, assuming that any 'blocking' feature is part of the antivirus or that folder protection covers execution, when in fact ASR rules are the only feature that enforces behavior-based policies on process creation and execution from specific locations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Attack surface reduction rules

Attack surface reduction (ASR) rules are a feature of Microsoft Defender for Endpoint that specifically target common malware behaviors, such as blocking Office applications from creating child processes and preventing executable files from running from the %TEMP% folder. These rules are designed to reduce the attack surface by enforcing policies that stop suspicious or malicious actions at the process level, without relying solely on signature-based detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender Antivirus

    Why it's wrong here

    Microsoft Defender Antivirus primarily operates by detecting, quarantining, and removing known malware based on signatures, heuristics, and machine learning models. Its core strength lies in identifying and neutralizing malicious files and processes that match established threat intelligence. However, it does not inherently block legitimate applications, such as Microsoft Office, from performing actions like creating child processes or executing files from common temporary folders, unless those specific actions are part of a detected malicious payload or a known malicious file signature.

    When this WOULD be correct

    A question asking which Microsoft Defender for Endpoint component provides real-time antivirus scanning, signature-based detection, and remediation of known malware on Windows devices would have Microsoft Defender Antivirus as the correct answer.

  • Attack surface reduction rules

    Why this is correct

    Attack surface reduction (ASR) rules are a core component of Microsoft Defender for Endpoint, specifically designed to prevent common malware and ransomware techniques by blocking suspicious behaviors at the endpoint. These rules operate by preventing specific actions, such as Office applications creating executable child processes or scripts executing from temporary folders, which are frequently exploited by attackers. By proactively blocking these known exploit techniques, ASR rules significantly reduce the attack surface, enhancing endpoint security beyond traditional signature-based detection.

  • Network protection

    Why it's wrong here

    Network protection, a feature within Microsoft Defender for Endpoint, primarily functions at the network layer to prevent devices from connecting to known malicious IP addresses, domains, and URLs. Its purpose is to block access to phishing sites, command-and-control servers, and other threat sources by inspecting network traffic. However, network protection does not govern or block local process behaviors, such as an Office application spawning a child process or an executable running from a temporary directory, as its scope is network communication, not internal process execution.

    When this WOULD be correct

    A question asking for a feature that blocks outbound connections to malicious URLs or IP addresses, such as preventing a device from contacting a known command-and-control server.

  • Controlled folder access

    Why it's wrong here

    Controlled folder access is a security feature within Microsoft Defender for Endpoint focused on protecting sensitive data by preventing unauthorized applications from making changes to files within designated protected folders. It primarily safeguards against ransomware and other malicious attempts to encrypt or modify user documents and system files. While crucial for data integrity, this feature does not block specific process behaviors like an Office application creating a child process or an executable running from a temporary folder, as its scope is file modification control, not general process execution behavior.

    When this WOULD be correct

    A question asks: 'Which Microsoft Defender for Endpoint feature should be configured to prevent unauthorized applications from modifying files in protected folders, such as Documents and Pictures?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Attack surface reduction rulesCorrect answer

Why this is correct

Attack surface reduction (ASR) rules are a core component of Microsoft Defender for Endpoint, specifically designed to prevent common malware and ransomware techniques by blocking suspicious behaviors at the endpoint. These rules operate by preventing specific actions, such as Office applications creating executable child processes or scripts executing from temporary folders, which are frequently exploited by attackers. By proactively blocking these known exploit techniques, ASR rules significantly reduce the attack surface, enhancing endpoint security beyond traditional signature-based detection.

Microsoft Defender AntivirusWrong answer — click to see why

Why this is wrong here

Microsoft Defender Antivirus provides real-time protection against malware by scanning files and processes, but it does not specifically block behaviors like Office apps creating child processes or executables running from %TEMP%. Those are behavioral restrictions enforced by Attack Surface Reduction (ASR) rules.

★ When this WOULD be the correct answer

A question asking which Microsoft Defender for Endpoint component provides real-time antivirus scanning, signature-based detection, and remediation of known malware on Windows devices would have Microsoft Defender Antivirus as the correct answer.

Why candidates choose this

Candidates may think antivirus is the primary tool to block malware techniques, not realizing that ASR rules are specifically designed to reduce attack surface by blocking common malware behaviors beyond traditional signature-based detection.

Network protectionWrong answer — click to see why

Why this is wrong here

Network protection prevents connections to malicious IPs/domains, not local process behaviors like Office apps creating child processes or executables running from %TEMP%.

★ When this WOULD be the correct answer

A question asking for a feature that blocks outbound connections to malicious URLs or IP addresses, such as preventing a device from contacting a known command-and-control server.

Why candidates choose this

Candidates may confuse network-level blocking with endpoint behavioral controls, assuming 'network protection' covers all malware-related restrictions.

Controlled folder accessWrong answer — click to see why

Why this is wrong here

Controlled folder access protects files in specific folders from unauthorized changes by ransomware and other threats, but it does not block Office apps from creating child processes or prevent executables from running from the %TEMP% folder.

★ When this WOULD be the correct answer

A question asks: 'Which Microsoft Defender for Endpoint feature should be configured to prevent unauthorized applications from modifying files in protected folders, such as Documents and Pictures?'

Why candidates choose this

Candidates may confuse controlled folder access with general attack surface reduction because both aim to block malicious behaviors, but controlled folder access focuses on file protection rather than process and execution restrictions.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.