Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security engineer is configuring a new Microsoft Defender for Endpoint deployment. The organization has several legacy applications that are known to perform actions (e.g., modifying specific registry keys or accessing certain network shares) that might be flagged as suspicious by Defender for Endpoint but are legitimate for these applications. To prevent excessive false positives, the engineer needs to ensure these specific actions are ignored by Defender for Endpoint while maintaining protection for all other activities. Which of the following should the engineer implement?

  1. AAdd exclusions for the specific processes and paths in Microsoft Defender Antivirus settings.
  2. BDefine a custom indicator of compromise (IoC) with an 'Allow' action for the legacy app behaviors.
  3. CConfigure a custom Automated Investigation and Remediation (AIR) automation level.
  4. DCreate a new Attack Surface Reduction (ASR) rule with an 'Audit' action for the legacy apps.
Show answer & explanation

Correct answer: A. Add exclusions for the specific processes and paths in Microsoft Defender Antivirus settings.

To prevent false positives from legitimate applications performing suspicious-looking actions, the most direct and effective method is to add exclusions within Microsoft Defender Antivirus settings. These exclusions can be configured for specific files, folders, processes, or file types, allowing the legacy applications to operate without being flagged, while the rest of the system remains protected.

Why the other options are wrong

  • B. IoCs are primarily for blocking or allowing specific known malicious or benign *files/IPs/URLs*, not for ignoring specific *behaviors* of legitimate applications. While 'Allow' IoCs exist, exclusions are more granular and appropriate for process/path-based behavioral allowances.
  • C. AIR automation levels determine how automated investigations and remediations are performed but do not prevent the initial detection of a legitimate activity as suspicious.
  • D. ASR rules target specific attack vectors, and while setting to 'Audit' would prevent blocking, it would still generate alerts, which the scenario aims to prevent. Exclusions are more appropriate for known legitimate behavior.

Microsoft Defender Antivirus Exclusions

Microsoft Defender Antivirus exclusions allow administrators to specify files, folders, file types, or processes that should be excluded from scans and real-time protection, often used to prevent conflicts with legitimate applications or reduce false positives.

  • Can be configured for files, folders, file types, and processes.
  • Reduces false positives for legitimate software.
  • Should be used cautiously to avoid creating security gaps.

Memory trick: Exclusions tell Defender, 'This app is a friend, not a foe, even if it looks a little weird.'

More Mitigate threats using Microsoft Defender XDR questions