Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium
A security operations center (SOC) analyst is investigating a suspicious activity detected by Microsoft Defender for Endpoint. The alert indicates that a PowerShell script executed on a workstation attempted to communicate with a known malicious IP address. The analyst needs to quickly block all future communication from this workstation to that specific IP address across the entire organization. Which action should the analyst take within Microsoft Defender for Endpoint?
- AAdd indicator to block IP address
- BCollect investigation package
- CRestrict app execution
- DIsolate device
Show answer & explanationAnswer & explanation
Correct answer: A. Add indicator to block IP address
Adding an indicator to block the IP address in Microsoft Defender for Endpoint will apply this blocking rule across all devices in the organization, preventing future communication to that malicious IP, which directly addresses the requirement.
Why the other options are wrong
- B. Collecting an investigation package gathers forensic data from the device but does not block network communication.
- C. Restricting app execution limits what applications can run on a device but does not block specific IP communication.
- D. Isolating the device disconnects it from the network (except for Defender services) but is a temporary, device-specific action, not an organization-wide block of a specific IP.
Defender for Endpoint Indicators
Indicators in Microsoft Defender for Endpoint allow security teams to define custom detection, prevention, and exclusion rules based on file hashes, IP addresses, URLs/domains, or certificates.
- Can be set to 'Allow', 'Audit', or 'Block'.
- Applied globally across all onboarded devices.
- Effective for blocking known malicious entities like IP addresses or files.
- Supports various indicator types: file hash, IP address, URL/domain, certificate.
Memory trick: To BLOCK a specific IP ACROSS the org, use an INDICATOR.