Microsoft Security Operations Analyst — Question 16

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.

You need to add threat indicators for all the IP addresses in a range of 171.23.34.32-171.23.34.63. The solution must minimize administrative effort.

What should you do in the Microsoft 365 Defender portal?

Answer options

Correct answer: A

Explanation

The correct answer is A because creating an import file with individual IP addresses allows for the specific range to be added without any ambiguity. Option B is incorrect as it uses a subnet notation that does not specifically list all desired addresses. Options C and D also do not utilize the import functionality and therefore would not minimize administrative effort.