Configure automation for Microsoft Defender XDR and Microsoft Sentinel

11 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.

SC-200 S-grade

Limiting Microsoft Defender device discovery to specific onboarded devices by creating a device tag first

You must identify unmanaged on-premises devices but ensure only specific onboarded devices perform the discovery; the first step is to create a device

15 comments
SC-200 S-grade

Blocking suspected malware by file hash indicators in Defender for Endpoint — only PE files are supported

You must block suspected malware files (.sys, .pdf, .docx, .xlsx) by hash in Defender for Endpoint Plan 2; file hash indicators support portable execu

14 comments
SC-200 S-grade

Scoping a Defender XDR custom deception rule to 10 specific devices by assigning device tags first

You plan a Defender XDR custom deception rule that must apply to only 10 specific devices; the first step is to assign a tag to those devices, because

9 comments
SC-200 S-grade

Granting Defender XDR Unified RBAC permission to send alert email notifications under least privilege

With Defender XDR Unified RBAC enabled for Endpoints, User1 must configure alerts that email a Microsoft 365 group; the 'Manage security settings' per

9 comments
SC-200 S-grade

Assigning Security Administrator so a user can manage Defender XDR custom detection rules and Endpoint security policies

User1 must manage Microsoft Defender XDR custom detection rules and Endpoint security policies under least privilege; the Security Administrator role

8 comments
SC-200 S-grade

Scoping Microsoft Defender XDR deception rules to specific devices with device tags

You must implement Defender XDR deception rules and limit their scope to specific devices; the first thing to create is device tags, because deception

6 comments
SC-200 A-grade

Using Sentinel automation rules and playbooks to minimize incident response effort

To minimize the administrative effort of responding to and remediating Sentinel incidents, use Microsoft Sentinel automation rules (which triage and a

4 comments
SC-200 A-grade

Using the SeenBy() function to map discovered network devices to the onboarded device that saw them

In a Defender for Endpoint advanced hunting query for network device discovery, the SeenBy() function returns the onboarded device that discovered eac

3 comments
SC-200 A-grade

Enabling the Microsoft 365 connector and app governance so Defender for Cloud Apps feeds automatic attack disruption

To let Microsoft Defender XDR automatic attack disruption use signals from Defender for Cloud Apps, you must enable the Microsoft 365 connector and tu

3 comments
SC-200 A-grade

Configuring a critical asset rule so a database server appears on the Defender XDR attack surface map

To make an onboarded server appear on the Microsoft Defender XDR attack surface map as a prioritized asset, configure a critical asset rule, which tag

3 comments
SC-200 A-grade

Using EDR in block mode to remediate artifacts missed by a third-party antivirus in passive mode

With 1,000 Windows devices running a third-party AV as primary and Microsoft Defender Antivirus in passive mode, enabling Endpoint Detection and Respo

3 comments