Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security analyst is investigating a suspected phishing campaign targeting several users within the organization. The analyst has identified a malicious URL that was included in the phishing emails. To prevent further compromise, the analyst needs to quickly block access to this specific URL across all endpoints and email clients. Which Microsoft Defender XDR component should be used to create a custom indicator to block this malicious URL?

  1. AMicrosoft Defender for Endpoint
  2. BMicrosoft Defender for Identity
  3. CMicrosoft Defender for Cloud Apps
  4. DMicrosoft Defender for Office 365
Show answer & explanation

Correct answer: A. Microsoft Defender for Endpoint

While Defender for Office 365 handles email, to block a malicious URL *across all endpoints* and leverage the unified blocking capabilities that span devices and email, Microsoft Defender for Endpoint's custom Indicators of Compromise (IoC) for URLs/domains is the most effective. This allows for proactive blocking at the network protection layer on devices.

Why the other options are wrong

  • B. Defender for Identity focuses on identity-based threats, not URL blocking.
  • C. Defender for Cloud Apps provides controls for cloud application usage but is not the primary component for blocking specific malicious URLs across all endpoints.
  • D. Defender for Office 365 uses Safe Links to protect against malicious URLs in email, but to block a URL *across all endpoints* (including browser access outside of email links), Defender for Endpoint is needed.

MDE IoC - URL/Domain

Microsoft Defender for Endpoint allows security teams to create custom Indicators of Compromise (IoCs) for URLs and domains to block access to known malicious web resources.

  • Blocks access to specified URLs/domains at the endpoint level.
  • Works across browsers and applications.
  • Provides immediate containment for identified threats.

Memory trick: To block a bad URL everywhere, you need 'Endpoint' to enforce it at the device level.

More Mitigate threats using Microsoft Defender XDR questions