Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

An organization is experiencing frequent ransomware attacks targeting its endpoints. The security team has deployed Microsoft Defender for Endpoint and wants to implement proactive measures to prevent the execution of malicious code, particularly from untrusted sources or common attack vectors like email attachments and USB drives. Which Defender for Endpoint feature should be configured to directly address this requirement?

  1. AAutomated investigation and remediation (AIR)
  2. BAttack Surface Reduction (ASR) rules
  3. CEndpoint detection and response (EDR)
  4. DThreat and Vulnerability Management (TVM)
Show answer & explanation

Correct answer: B. Attack Surface Reduction (ASR) rules

Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint are specifically designed to prevent behaviors commonly associated with malware, such as executing obfuscated scripts, launching executables from email, or running unsigned scripts, thereby proactively addressing ransomware vectors.

Why the other options are wrong

  • A. AIR automates the response to detected alerts, which is reactive rather than proactive prevention of execution.
  • C. EDR focuses on detecting and responding to active threats, not proactively preventing their execution before they cause harm.
  • D. TVM identifies and prioritizes vulnerabilities and misconfigurations, which is a proactive measure but does not directly prevent malware execution like ASR rules.

Attack Surface Reduction (ASR) Rules

A set of capabilities in Microsoft Defender for Endpoint that target specific behaviors and software functions commonly abused by malware, such as ransomware, to prevent attacks.

  • Blocks actions like launching executables from email clients or untrusted locations.
  • Reduces the attack surface of devices.
  • Configurable with audit, block, or warn modes.

Memory trick: To prevent ransomware, build strong walls and reduce entry points.

More Mitigate threats using Microsoft Defender XDR questions