MS-102 Practice Question 3079
Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
You need to verify whether a suspicious hash is known across devices and block it tenant-wide from executing on any Defender for Endpoint machine. Where should you configure this indicator of compromise?
Answer Options
A
Settings > Endpoints > Indicators in the Microsoft Defender portal
B
Group Policy Management Console under Administrative Templates
C
Microsoft 365 Admin Center under Billing invoices
D
DNS zone file on your domain registrar
Correct Answer
A: Settings > Endpoints > Indicators in the Microsoft Defender portal
Explanation
In the Microsoft Defender portal under Settings > Endpoints > Indicators, administrators can add custom file hashes, IP addresses, and URLs with a Block and Remediate action.