Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A security operations team is investigating a potential phishing campaign targeting users within their organization. They have identified a malicious URL that was embedded in several emails. They need to quickly block access to this URL across all monitored endpoints using Microsoft Defender for Endpoint. Which of the following is the MOST efficient method to achieve this?
- ACreate a custom detection rule in Advanced Hunting to alert on access to the URL.
- BAdd the URL as an Indicator of Compromise (IoC) to Microsoft Defender for Endpoint.
- CConfigure a network protection policy in Microsoft Intune to block the URL.
- DManually update the hosts file on each affected endpoint to redirect the URL.
Show answer & explanationAnswer & explanation
Correct answer: B. Add the URL as an Indicator of Compromise (IoC) to Microsoft Defender for Endpoint.
Adding the malicious URL as an Indicator of Compromise (IoC) directly into Microsoft Defender for Endpoint allows for immediate and automated blocking across all managed devices. This is designed for rapid response to identified threats.
Why the other options are wrong
- A. This would only generate an alert, not actively block access, and would require further manual intervention.
- C. While Intune can manage network protection policies, adding an IoC directly in Defender for Endpoint is a more direct and often quicker method for specific threat blocking.
- D. This is a manual, time-consuming, and impractical method for a large organization, lacking centralized management and rapid deployment.
MDE Indicator of Compromise (IoC)
An IoC in Microsoft Defender for Endpoint is an artifact observed on a network or in an operating system that reliably indicates a computer intrusion. MDE can ingest IoCs like URLs, domains, IPs, file hashes, and certificates to detect and block threats.
- Used for rapid detection and blocking of known threats.
- Supports various types: files, IP addresses, URLs/domains, certificates.
- Configured in the Microsoft 365 Defender portal under Settings > Endpoints > Indicators.
Memory trick: Indicators of Compromise are the fastest way to STOP bad links.