Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a series of alerts indicating suspicious activity originating from a specific IP address within the corporate network. The analyst needs to quickly block all communication to and from this IP address across all managed endpoints to contain the potential threat. Which Microsoft Defender for Endpoint capability should the analyst use to achieve this immediate network containment?
- ANetwork protection
- BIndicators of Compromise (IoC) - IP address
- CAttack Surface Reduction (ASR) rules
- DAutomated Investigation and Remediation (AIR)
Show answer & explanationAnswer & explanation
Correct answer: B. Indicators of Compromise (IoC) - IP address
Indicators of Compromise (IoC) allow security teams to define custom detection and prevention rules based on observed threat indicators. Adding the suspicious IP address as an IoC with a 'Block' or 'Block and Remediate' action will immediately prevent communication to/from that IP across all managed devices.
Why the other options are wrong
- A. Network protection prevents access to known malicious domains/IPs or phishing sites, but an IoC provides a way to custom-define and immediately block a *specific* observed suspicious IP.
- C. ASR rules prevent specific behaviors (e.g., executing obfuscated scripts), not direct blocking of IP addresses.
- D. AIR automates investigation and remediation workflows but doesn't directly configure network blocking rules for specific IPs.
MDE Indicators of Compromise (IoC)
Indicators of Compromise (IoCs) are artifacts observed on a network or in an operating system that reliably indicate a computer intrusion.
- Can be files, IPs, URLs, domains, certificates.
- Used for custom detection and prevention rules.
- Allows immediate blocking or alerting on specific threats.
Memory trick: To block a specific bad IP, you need to mark it as an 'IoC', like putting a 'wanted' poster on it.