Configuring a critical asset rule so a database server appears on the Defender XDR attack surface map

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: B — A critical asset rule marks the server as a critical asset so it appears on the Defender XDR attack surface map.

You have a Microsoft 365 E5 subscription that contains a database server named DB1. DB1 is onboarded to Microsoft Defender XDR. You need to ensure that DB1 appears on the attack surface map. What should you configure?

  1. an asset rule
  2. a critical asset rule Correct Answer
  3. a sensitive entity tag
  4. a honeytoken entity tag

Community Votes

B
80%
C
20%

80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Critical asset rules in Defender XDR let you designate high-value devices (such as database servers) so they appear and are prioritized on the attack surface map, distinct from entity tags used for decoy/sensitivity classification.

To make an onboarded server appear on the Microsoft Defender XDR attack surface map as a prioritized asset, configure a critical asset rule, which tags the device as critical and surfaces it on the map for focused monitoring.

Choosing a sensitive or honeytoken entity tag — those classify discovered entities for decoy/sensitivity purposes, not for placing a real asset on the attack surface map; the critical asset rule is the correct mechanism.

Community Discussion (3 comments)

a_kto_to 👍 1 Selected: C
chatGTP is telling that C ✅ Final Answer: C. a sensitive entity tag
Blasty 👍 2 Selected: B
security.microsoft.com Settings > Microsoft Defender XDR > Rules > Critical asset management
MCWDSR 👍 2 Selected: B
To ensure that DB1 appears on the attack surface map in Microsoft Defender XDR, you should configure a critical asset rule. This will help prioritize DB1 as a critical asset, making it visible on the attack surface map and ensuring it is monitored appropriately. The correct answer is B. a critical asset rule.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Microsoft Defender XDR, critical asset management lets you configure critical asset rules that mark specific devices or identities as critical assets. A server configured this way appears on the attack surface map and is prioritized for monitoring and response, which is exactly what the scenario requires.

Why the Other Options Are Wrong

A sensitive entity tag (C) and a honeytoken entity tag (D) classify entities for sensitivity or decoy purposes and do not place a real asset on the attack surface map. A generic asset rule (A) is not the Defender XDR mechanism for critical-asset designation on the attack surface map.

Community Comment Notes

The community favors B (80 votes). Blasty and MCWDSR both point to Defender XDR Settings > Rules > Critical asset management as the place to configure this, noting it makes the asset visible on the attack surface map. a_kto_to's ChatGPT answer of C is incorrect.

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide