nerdexam
Microsoft

MS-102 · Question #125

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. From Microsoft Defender for Endpoint, you turn on the Allow or block file advanced feature. You need to block…

The correct answer is B. an indicator. To block users from downloading a specific file using Microsoft Defender for Endpoint, after enabling the 'Allow or block file' advanced feature, you should use an indicator.

Submitted by jaden.t· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. From Microsoft Defender for Endpoint, you turn on the Allow or block file advanced feature. You need to block users from downloading a file named File1.exe. What should you use?

Options

  • Aa suppression rule
  • Ban indicator
  • Ca device configuration profile

How the community answered

(44 responses)
  • A
    9% (4)
  • B
    86% (38)
  • C
    5% (2)

Why each option

To block users from downloading a specific file using Microsoft Defender for Endpoint, after enabling the 'Allow or block file' advanced feature, you should use an indicator.

Aa suppression rule

A suppression rule is used to automatically resolve or hide alerts based on specific criteria, not to block the execution or download of a file.

Ban indicatorCorrect

In Microsoft Defender for Endpoint, after enabling the 'Allow or block file' feature, you can create an indicator of compromise (IoC) with a 'Block' action for the hash of File1.exe, which will prevent its download or execution on managed devices.

Ca device configuration profile

A device configuration profile, managed through Microsoft Intune, is used for broader device settings and security configurations but is not the specific mechanism within Defender for Endpoint for blocking an individual file by its hash.

Concept tested: Microsoft Defender for Endpoint file blocking with indicators

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/indicator-file?view=o365-worldwide

Topics

#Microsoft Defender for Endpoint#File blocking#Indicators of Compromise (IoC)#Threat management

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice