Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A Microsoft 365 administrator is configuring Microsoft Defender for Endpoint for a large enterprise with thousands of devices. The organization has a strict policy that prevents users from downloading and executing unsigned scripts from the internet. The administrator needs to ensure that all unapproved or unsigned applications and scripts are automatically blocked from running on endpoints. Which Defender for Endpoint capability should be implemented to achieve this?

  1. ANetwork protection
  2. BAttack Surface Reduction rules
  3. CControlled folder access
  4. DExploit protection
Show answer & explanation

Correct answer: B. Attack Surface Reduction rules

Attack Surface Reduction (ASR) rules include specific rules to block the execution of unsigned scripts and other potentially malicious software, directly addressing the requirement to prevent unapproved applications and scripts from running.

Why the other options are wrong

  • A. Network protection primarily prevents access to malicious domains and IP addresses, and does not control script execution.
  • C. Controlled folder access protects specific folders from unauthorized changes by untrusted applications, but it doesn't block unsigned scripts from running generally.
  • D. Exploit protection focuses on mitigating exploits against vulnerabilities in applications and the OS, not primarily on blocking unsigned scripts.

Defender for Endpoint Attack Surface Reduction (ASR) Rules

Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint target common attack vectors used by malware, such as unsigned scripts, executable content, and credential theft, to prevent them from executing.

  • Reduces the attack surface of devices.
  • Includes rules like 'Block execution of potentially obfuscated scripts' and 'Block untrusted and unsigned processes'.
  • Can be configured in audit, block, or warn mode.
  • Helps prevent zero-day attacks and sophisticated threats.

Memory trick: To REDUCE your ATTACK SURFACE from scripts, use ASR rules.

More Implement and manage Microsoft Defender XDR questions