nerdexam
Microsoft

SC-200 · Question #59

You receive a security bulletin about a potential attack that uses an image file. You need to create an indicator of compromise (IoC) in Microsoft Defender for Endpoint to prevent the attack. Which…

The correct answer is C. a file hash indicator that has Action set to Alert and block. The steps for to Create an indicator for files from the settings page 1. In the navigation pane, select Settings > Endpoints > Indicators (under Rules). 2. Select the File hashes tab. 3. Select Add indicator. 4. Specify the following details: 5. Indicator - Specify the entity…

Submitted by salim_om· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

You receive a security bulletin about a potential attack that uses an image file. You need to create an indicator of compromise (IoC) in Microsoft Defender for Endpoint to prevent the attack. Which indicator type should you use?

Options

  • Aa URL/domain indicator that has Action set to Alert only
  • Ba URL/domain indicator that has Action set to Alert and block
  • Ca file hash indicator that has Action set to Alert and block
  • Da certificate indicator that has Action set to Alert and block

How the community answered

(56 responses)
  • A
    5% (3)
  • B
    9% (5)
  • C
    71% (40)
  • D
    14% (8)

Explanation

The steps for to Create an indicator for files from the settings page 1. In the navigation pane, select Settings > Endpoints > Indicators (under Rules). 2. Select the File hashes tab. 3. Select Add indicator. 4. Specify the following details: 5. Indicator - Specify the entity details and define the expiration of the indicator. * Action - Specify the action to be taken and provide a description. * Scope - Define the scope of the device group. * Review the details in the Summary tab, then select Save. https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/indicator- file?view=o365-worldwide

Topics

#Indicator of Compromise#Microsoft Defender for Endpoint#File hash#Threat prevention

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice