Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security operations center (SOC) team uses Microsoft Defender XDR. They have identified a sophisticated phishing campaign that uses a newly registered domain ('malicious-domain.com') to host credential harvesting pages. To immediately block all network connections to this domain across all endpoints, regardless of the application attempting the connection, which Microsoft Defender for Endpoint capability should the SOC team configure?
- AAttack Surface Reduction (ASR) rules
- BIndicators of Compromise (IoC) - URL/Domain
- CCustom detection rules (Advanced Hunting)
- DDevice control policies
Show answer & explanationAnswer & explanation
Correct answer: B. Indicators of Compromise (IoC) - URL/Domain
Indicators of Compromise (IoCs) allow security teams to define specific entities (like domains, URLs, file hashes) as malicious and configure Defender for Endpoint to automatically block or alert on any interaction with them. Adding 'malicious-domain.com' as a 'URL/Domain' IoC with a 'Block' action will achieve immediate network blocking across all endpoints.
Why the other options are wrong
- A. ASR rules prevent specific behaviors (e.g., executing scripts from email), not blocking access to a specific domain.
- C. Custom detection rules generate alerts for specific activities but do not universally block network connections to a domain.
- D. Device control policies manage access to peripherals (e.g., USB drives), not network connections to domains.
MDE IoC (URL/Domain)
Microsoft Defender for Endpoint's Indicators of Compromise feature allows defining specific URLs or domain names as malicious, enabling automatic blocking or auditing of network connections to them across all managed endpoints.
- Provides immediate, proactive blocking.
- Applies to all managed endpoints.
- Supports 'Block' and 'Audit' actions.
Memory trick: IoC is the 'No Entry' sign for known bad guys, like a domain.