Microsoft 365 Administrator Expert MS-102 Practice Question
Your SOC monitors Microsoft Defender XDR. Yesterday Microsoft Threat Intelligence Center published intelligence on a phishing campaign that uses the domain update-contoso.biz and a specific SHA-256 file hash. You must rapidly determine whether any assets in your tenant have interacted with the campaign and ensure that future traffic to the domain is blocked. Which Defender XDR capability should you use first to obtain tenant-specific exposure insights, and which immediate follow-up action will meet the blocking requirement?
Inspect Vulnerability management recommendations and add the domain to an attack surface reduction blocklist.
Run an Advanced hunting query for the domain and hash, then save the query as a custom detection rule.
Review Microsoft Secure Score improvement actions and enable the recommended preset security policies in Exchange Online.
Open the relevant Threat analytics report and then add a URL/domain indicator to block update-contoso.biz.
Threat analytics contains curated reports from Microsoft threat intelligence and automatically shows whether the indicators referenced in a report (such as a malicious domain or file hash) have been observed in your tenant, giving an instant view of exposure. From the report-or from the Indicators page-you can create a URL/domain indicator that instructs Microsoft Defender XDR to block any future communication with the specified domain across supported workloads. Advanced hunting or Secure Score can provide useful data, but they neither surface campaign-specific exposure automatically nor create an enforced block on the domain. Editing baselines or applying mail-flow rules likewise will not deliver tenant-wide blocking in Defender XDR.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Defender XDR?
Open an interactive chat with Bash
How does Threat analytics identify exposure in Microsoft Defender XDR?
Open an interactive chat with Bash
What does a URL/domain indicator do in Microsoft Defender XDR?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .