Configure automation for Microsoft Defender XDR and Microsoft Sentinel
11 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
Limiting Microsoft Defender device discovery to specific onboarded devices by creating a device tag first
You must identify unmanaged on-premises devices but ensure only specific onboarded devices perform the discovery; the first step is to create a device
Blocking suspected malware by file hash indicators in Defender for Endpoint — only PE files are supported
You must block suspected malware files (.sys, .pdf, .docx, .xlsx) by hash in Defender for Endpoint Plan 2; file hash indicators support portable execu
Scoping a Defender XDR custom deception rule to 10 specific devices by assigning device tags first
You plan a Defender XDR custom deception rule that must apply to only 10 specific devices; the first step is to assign a tag to those devices, because
Granting Defender XDR Unified RBAC permission to send alert email notifications under least privilege
With Defender XDR Unified RBAC enabled for Endpoints, User1 must configure alerts that email a Microsoft 365 group; the 'Manage security settings' per
Assigning Security Administrator so a user can manage Defender XDR custom detection rules and Endpoint security policies
User1 must manage Microsoft Defender XDR custom detection rules and Endpoint security policies under least privilege; the Security Administrator role
Scoping Microsoft Defender XDR deception rules to specific devices with device tags
You must implement Defender XDR deception rules and limit their scope to specific devices; the first thing to create is device tags, because deception
Using Sentinel automation rules and playbooks to minimize incident response effort
To minimize the administrative effort of responding to and remediating Sentinel incidents, use Microsoft Sentinel automation rules (which triage and a
Using the SeenBy() function to map discovered network devices to the onboarded device that saw them
In a Defender for Endpoint advanced hunting query for network device discovery, the SeenBy() function returns the onboarded device that discovered eac
Enabling the Microsoft 365 connector and app governance so Defender for Cloud Apps feeds automatic attack disruption
To let Microsoft Defender XDR automatic attack disruption use signals from Defender for Cloud Apps, you must enable the Microsoft 365 connector and tu
Configuring a critical asset rule so a database server appears on the Defender XDR attack surface map
To make an onboarded server appear on the Microsoft Defender XDR attack surface map as a prioritized asset, configure a critical asset rule, which tag
Using EDR in block mode to remediate artifacts missed by a third-party antivirus in passive mode
With 1,000 Windows devices running a third-party AV as primary and Microsoft Defender Antivirus in passive mode, enabling Endpoint Detection and Respo