Scoping a Defender XDR custom deception rule to 10 specific devices by assigning device tags first

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: D — Deception rules are scoped by device tags, so you assign a tag to the 10 devices first, then scope the rule to those tagged devices.

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains 500 Windows devices. You plan to create a Microsoft Defender XDR custom deception rule. You need to ensure that the rule will be applied to only 10 specific devices. What should you do first?

  1. Add custom lures to the rule.
  2. Add the IP address of each device to the list of decoy accounts and hosts of the rule.
  3. Add the devices to a group.
  4. Assign a tag to the devices. Correct Answer

Community Votes

D
80%
A
20%

80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Deception rule scoping offers only 'all Windows client devices' or 'devices with specific tags'; there is no device-group option, so tagging the 10 target devices is the prerequisite that limits the rule's scope.

You plan a Defender XDR custom deception rule that must apply to only 10 specific devices; the first step is to assign a tag to those devices, because deception rules are scoped in the rule wizard by device tags, not by device groups.

Choosing device groups because groups are familiar from other Defender features — the deception rule wizard does not support device groups for scoping, only device tags.

Community Discussion (9 comments)

don_binak 👍 6 Selected: D
Identify the devices where you intend to plant the lures in the scope section. You can select to plant lures in all Windows client devices or in clients with specific tags. The deception feature currently covers Windows clients. https://learn.microsoft.com/en-us/defender-xdr/configure-deception
Optimizor_IT 👍 1 Selected: D
First, tag the 10 devices (e.g., Security.microsoft.com > Devices > select 10 devices > Manage tags > “DeceptionTargets”). Then, create the deception rule and scope it to “Devices with specific tags,” selecting “DeceptionTargets.”
HAjouz 👍 1 Selected: D
You're right to question that! While device groups are generally useful for managing devices in Defender for Endpoint, they are not the primary way to target specific devices for custom deception rules.
sapphire 👍 1 Selected: D
correct answer >> Microsoft Defender >> Rules Managmenet > Apply a tag in Choose which actions to apply to this rule.
g_man_rap 👍 1
ChatGpt4 answer: Option C: Add the devices to a group. Correct. In Microsoft 365 and Defender for Endpoint, devices are often managed in groups (known as device groups or device collections). By adding the specific devices to a group, you can then configure the rule to apply only to that group. This ensures that the rule is only applied to the 10 devices you intend to target. Option D: Assign a tag to the devices. Incorrect. Assigning a tag to devices can help with organization and management within Microsoft Defender for Endpoint, but it doesn’t directly control rule application. Tags are useful for filtering and reporting but not for determining rule scope.
Rodwhite 👍 1 Selected: D
with Deception rules scope you only get the option to (1) All Windows Client devices or (2) Devices with specific Tags. Therefore, "D".
Sekpluz 👍 2 Selected: D
It's (D) first [tag 10 devices], and then when you create the rule, you chose the lure (A), and then you chose the decoys ( the 10 devices you tagged ) https://learn.microsoft.com/en-us/defender-xdr/configure-deception
rsanx42 👍 3 Selected: A
A: Add custom lures to the rule "In the rule creation pane, add a rule name, description, and select what lure types to create. You can select both" https://learn.microsoft.com/en-us/defender-xdr/configure-deception
laddu001 👍 3
Add the devices to a group.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In the deception rule creation wizard, the scope section lets you plant lures on all Windows client devices or only on clients that carry specific device tags. To target exactly 10 devices, you first assign a tag to those 10 devices and then scope the rule to 'devices with specific tags.'

Why the Other Options Are Wrong

Adding custom lures (A) is a later step inside the rule and does not determine which devices receive them. Adding IP addresses to decoy accounts/hosts (B) populates decoy entities, not the device scope. Adding devices to a group (C) is not a supported scoping mechanism in the deception rule wizard.

Community Comment Notes

don_binak (6 likes) and Rodwhite both cite https://learn.microsoft.com/en-us/defender-xdr/configure-deception and confirm the scope offers only 'all Windows clients' or 'devices with specific tags', so D is the answer. Sekpluz describes the order: tag the 10 devices first, then add the lure, then select the tagged devices as decoys.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide