Scoping Microsoft Defender XDR deception rules to specific devices with device tags

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: B — Deception rules in Defender XDR are scoped by device tags, so you create the device tags first to limit the rule's scope.

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to implement deception rules. The solution must ensure that you can limit the scope of the rules. What should you create first?

  1. device groups
  2. device tags Correct Answer
  3. honeytoken entity tags
  4. sensitive entity tags

Community Votes

B
75%
A
25%

75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Deception rules in Defender XDR target devices through device tags, not device groups; tagging the intended machines first lets you scope the rule to exactly those devices while keeping the configuration simple.

You must implement Defender XDR deception rules and limit their scope to specific devices; the first thing to create is device tags, because deception rules scope their lures to devices by tag rather than by device group.

Choosing device groups because they are familiar from other Defender features — the deception rule scoping control offers device tags, not device groups, so a group cannot limit the rule's scope.

Community Discussion (6 comments)

HAjouz 👍 1 Selected: B
B is the right answer
ExamSC200 👍 1 Selected: B
Device groups are useful for organizing devices but aren't specifically designed to limit the scope of deception rules. Device tags offer more granular control.
RonWonkers 👍 3 Selected: B
B, first you tag a device based on characterics for instance the title, then you group based on tags.
Dogfather 👍 3 Selected: B
I agree, B is correct, When configuring a deception role there's no option to use a device group, only device tags. Source: https://learn.microsoft.com/en-us/defender-xdr/configure-deception
WinstonN 👍 1 Selected: B
B is correct. Check the scoping. its Device Tags. https://learn.microsoft.com/en-us/defender-xdr/configure-deception
ctshepard 👍 3 Selected: A
A is correct because once the devices are grouped, they can then be tagged.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Deception rules in Microsoft Defender XDR are scoped in the rule's scope section, where you choose to plant lures on all Windows client devices or only on clients that carry specific device tags. Creating the device tags first is therefore the prerequisite step that lets you limit the rule to the intended machines.

Why the Other Options Are Wrong

Device groups (A) are used elsewhere in Defender for Endpoint but are not offered as a scoping mechanism inside the deception rule wizard, so they cannot limit the rule's scope. Honeytoken entity tags (C) and sensitive entity tags (D) are classifications you apply to discovered entities (users, devices, secrets) to flag them as decoys or high-value, not the mechanism that scopes where lures are planted.

Community Comment Notes

Dogfather and WinstonN both cite https://learn.microsoft.com/en-us/defender-xdr/configure-deception and note there is no device-group option when configuring a deception rule, only device tags. ExamSC200 adds that device tags give more granular control than device groups for this purpose.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide