Blocking suspected malware by file hash indicators in Defender for Endpoint — only PE files are supported

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: A — Defender for Endpoint file hash indicators support portable executable (PE) files only, so only the .sys file can be blocked.

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains 500 Windows devices. As part of an incident investigation, you identify the following suspected malware files: • sys • pdf • docx • xlsx You need to create indicator hashes to block users from downloading the files to the devices. Which files can you block by using the indicator hashes?

  1. File1.sys only Correct Answer
  2. File1.sys and File3.docx only
  3. File1.sys, File3.docx, and File4.xlsx only
  4. File2.pdf, File3.docx, and File4.xlsx only
  5. File1.sys, File2.pdf, File3.docx, and File4.xlsx

Community Votes

E
59%
A
41%

59% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Defender for Endpoint file indicators work only on portable executable (PE) files; .sys (a driver PE file) can be blocked, whereas .pdf, .docx, and .xlsx are not PE files and cannot be blocked by file hash indicators.

You must block suspected malware files (.sys, .pdf, .docx, .xlsx) by hash in Defender for Endpoint Plan 2; file hash indicators support portable executable (PE) files such as .exe, .dll, and .sys only.

Assuming any file type can be blocked by its hash — the indicator mechanism is limited to PE files, so only the .sys file among the listed candidates qualifies.

Community Discussion (14 comments)

liveup2it 👍 17 Selected: E
Based on File hashes, you should be able to block each and every file with this hash, regardless the name of the file.
g_man_rap 👍 5 Selected: A
Key Points: Executable Files: Microsoft Defender for Endpoint can block executable files such as .exe, .dll, .sys, and other similar types. Non-Executable Files: Generally, Microsoft Defender for Endpoint does not allow blocking of non-executable files (e.g., .pdf, .docx, .xlsx) by file hash using the same indicator mechanism designed for executables.
RonWonkers 👍 1 Selected: E
You make get a hash for every file and block it.
Avaris 👍 1 Selected: E
I am gonna go with a whim and select E for one reason, I remember blocking all types of files including pdfs we block with hashes I think
arturro007 👍 1 Selected: E
Question is about hashes. You can add any hash to Defender and it will be blocked.
1375514 👍 2 Selected: A
https://learn.microsoft.com/en-us/defender-endpoint/indicator-file From Microsoft: "File indicators support portable executable (PE) files, including .exe and .dll files only." Only the .sys is a PE file, therefore it is the only file that can be blocked via file indicator.
talosDevbot 👍 3 Selected: A
File indicators only support Portable Execution (PE) files like exe, dll, sys
talosDevbot 👍 2
File indicators only support Portable Execution (PE) files like exe, dll, sys
b9cf0e5 👍 2
Answer is D: Blocking .sys files could affect system functionality, and thus Defender for Endpoint does not allow blocking system-critical files.
smanzana 👍 1
E https://learn.microsoft.com/en-us/defender-endpoint/indicator-file
Rodwhite 👍 1 Selected: E
I took the hash from (.pdf, sys, doc,) and each file and was able to upload successfully. Therefore, the answer is E.
Hawklx 👍 5 Selected: A
This feature is designed to prevent suspected malware (or potentially malicious files) from being downloaded from the web. It currently supports portable executable (PE) files, including .exe and .dll files. Ref: https://learn.microsoft.com/en-us/defender-endpoint/indicator-file
phoenix5 👍 3
Answer - C (.sys , .docx, .xlsx as per this explanation by Copilot - You can create indicator hashes to block executable files with the following extensions: .exe, .dll, and .sys. Additionally, Office files like .docx and .xlsx can also be blocked using indicator hashes. However, PDF files cannot be blocked using indicator hashes in Microsoft Defender for Endpoint1.
ada26b1 👍 1 Selected: E
Surely you can block all of them

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for Endpoint file indicators (IOC hashes) support portable executable (PE) files, including.exe,.dll, and.sys files only. Among the four listed files, File1.sys is the only PE file, so it is the only one that can be blocked by a file hash indicator.

Why the Other Options Are Wrong

The.pdf,.docx, and.xlsx files are not PE files, so none of them can be blocked through the file hash indicator mechanism, which rules out options B, C, D, and E. Choosing any option that includes non-PE files rests on the incorrect belief that any file type can be blocked by hash.

Community Comment Notes

The community leans E (block all four, 59 votes), but the more documented answers cite https://learn.microsoft.com/en-us/defender-endpoint/indicator-file, which states file indicators support PE files only. Hawklx, talosDevbot, and 1375514 all confirm only PE files (.exe/.dll/.sys) are supported, making File1.sys the sole blockable file.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide