Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A security operations team is implementing Microsoft Defender for Endpoint. They need to ensure that specific applications, such as internal diagnostic tools, are not flagged as malicious by the antivirus engine, even if their behavior might otherwise appear suspicious. These applications are known to be safe within the organization's environment. Which feature should the team configure to achieve this?

  1. AAttack Surface Reduction (ASR) rules
  2. BIndicators of Compromise (IoC)
  3. CExclusions for Microsoft Defender Antivirus
  4. DAutomated Investigation and Remediation (AIR)
Show answer & explanation

Correct answer: C. Exclusions for Microsoft Defender Antivirus

To prevent legitimate internal tools from being incorrectly flagged by Microsoft Defender Antivirus, specific exclusions should be configured. This allows the antivirus engine to ignore the specified files, folders, or processes.

Why the other options are wrong

  • A. ASR rules prevent common attack techniques, but are not designed for whitelisting specific applications.
  • B. IoCs are used to detect and block known threats, not to whitelist trusted applications.
  • D. AIR automatically investigates and remediates threats, but does not prevent legitimate applications from being detected in the first place.

Microsoft Defender Antivirus Exclusions

A setting in Microsoft Defender Antivirus that allows administrators to specify files, folders, processes, or file types that should not be scanned or detected as threats.

  • Used to prevent false positives for legitimate applications.
  • Can be configured for files, folders, file types, and processes.
  • Should be used cautiously to avoid creating security blind spots.

Memory trick: Exclude the good, catch the bad.

More Mitigate threats using Microsoft Defender XDR questions