MS-102 · Question #125
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. From Microsoft Defender for Endpoint, you turn on the Allow or block file advanced feature. You need to block…
The correct answer is B. an indicator. To block users from downloading a specific file using Microsoft Defender for Endpoint, after enabling the 'Allow or block file' advanced feature, you should use an indicator.
Question
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint. From Microsoft Defender for Endpoint, you turn on the Allow or block file advanced feature. You need to block users from downloading a file named File1.exe. What should you use?
Options
- Aa suppression rule
- Ban indicator
- Ca device configuration profile
How the community answered
(44 responses)- A9% (4)
- B86% (38)
- C5% (2)
Why each option
To block users from downloading a specific file using Microsoft Defender for Endpoint, after enabling the 'Allow or block file' advanced feature, you should use an indicator.
A suppression rule is used to automatically resolve or hide alerts based on specific criteria, not to block the execution or download of a file.
In Microsoft Defender for Endpoint, after enabling the 'Allow or block file' feature, you can create an indicator of compromise (IoC) with a 'Block' action for the hash of File1.exe, which will prevent its download or execution on managed devices.
A device configuration profile, managed through Microsoft Intune, is used for broader device settings and security configurations but is not the specific mechanism within Defender for Endpoint for blocking an individual file by its hash.
Concept tested: Microsoft Defender for Endpoint file blocking with indicators
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/indicator-file?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.