MS-102 Practice Question 3079

Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
You need to verify whether a suspicious hash is known across devices and block it tenant-wide from executing on any Defender for Endpoint machine. Where should you configure this indicator of compromise?

Answer Options

A
Settings > Endpoints > Indicators in the Microsoft Defender portal
B
Group Policy Management Console under Administrative Templates
C
Microsoft 365 Admin Center under Billing invoices
D
DNS zone file on your domain registrar

Correct Answer

A: Settings > Endpoints > Indicators in the Microsoft Defender portal

Explanation

In the Microsoft Defender portal under Settings > Endpoints > Indicators, administrators can add custom file hashes, IP addresses, and URLs with a Block and Remediate action.