MS-102 Practice Question 3068
Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: easy
You need to deploy Defender for Endpoint Attack Surface Reduction (ASR) rules. You want to evaluate the impact of blocking credential stealing from LSASS without breaking applications. What rule mode should you configure first?
Answer Options
A
Audit mode
B
Block mode
C
Disabled mode
D
Enforced mode
Correct Answer
A: Audit mode
Explanation
Configuring ASR rules in "Audit mode" logs event telemetry to Windows Event Viewer and Advanced Hunting without blocking execution, allowing teams to evaluate application impact.