SC-200 - Manage a Security Operations Environment (41% of the exam) - Section 1.2

Configure Microsoft Defender for Endpoint advanced features, rules, custom data collection, attack surface reduction, and device groups.

Enable and configure Microsoft Defender for Endpoint advanced features, including custom data collection via data collection rules, and deploy attack surface reduction (ASR) rules to block common attack vectors. Organise devices into device groups and assign automation levels that control how aggressively automated investigation and response acts on each group.

Microsoft Defender for Endpoint advanced featuresrules settingscustom data collectionattack surface reduction (ASR) rulesdevice groups, permissions, and automation levels

Practice question for this objective

Free sampleManage a Security Operations Environmenthard

A security architect is enabling automatic attack disruption in Microsoft Defender XDR so that, on a high-confidence human-operated ransomware detection, the platform can autonomously isolate an affected onboarded Windows device before any analyst intervenes. Endpoint signals are onboarded and automated investigation is running. Which TWO conditions must be satisfied so that the device-isolation disruption action is actually applied to a targeted device? Select TWO.

  • AThe targeted device must be actively onboarded to Microsoft Defender for Endpoint with its sensor reporting, so disruption has a managed agent through which to enforce the isolation. Correct
  • BA Microsoft Sentinel scheduled analytics rule must be authored to detect the ransomware pattern and call the isolation as its automated response action.
  • CThe device group's Microsoft Defender for Endpoint automation level must not be set to no automated response, so automated containment is permitted on that device. Correct
  • DA Microsoft Defender XDR custom detection rule with a device-isolation response action must be created and scheduled before disruption can isolate the device.
Automatic attack disruption isolates a device through the active Microsoft Defender for Endpoint sensor and only when the device group's automation level permits automated response. Disruption enforces device isolation via the Microsoft Defender for Endpoint sensor, so the device must be onboarded and reporting, and the device group's automation level must not be set to no automated response, otherwise the platform is prevented from applying any automated containment action.

Why A is correct: Correct: attack disruption isolates a device through the Microsoft Defender for Endpoint sensor, so the device must be onboarded and actively reporting for the action to be enforced.

Why B is wrong: Tempting because Sentinel rules can trigger response automation, but attack disruption is a built-in Microsoft Defender XDR capability that needs no analytics rule, so this is not a prerequisite.

Why C is correct: Correct: if the device group is set to no automated response, automated actions including disruption isolation are blocked, so the automation level must permit automated containment.

Why D is wrong: Tempting because custom detection rules can carry an isolate-device action, but disruption acts on its own high-confidence signals and does not depend on a custom detection rule, so this is incorrect.

See more SC-200 practice questions, answers explained.

Exam traps in Manage a Security Operations Environment

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • View data - security operations, because this permission lets the holder open the security operations data and is the permission that authorises taking response actions such as device isolation against a confirmed alert.

    Why it is wrong: View data - security operations grants read-only visibility of security operations data, which is tempting because the analyst needs to see alerts, but it confers no power to investigate or to run any containment action.

  • Semi - require approval for any remediation, so every action that automated investigation proposes is queued in the Action centre until an analyst reviews and approves the verdict for the branch servers.

    Why it is wrong: Semi - require approval for any remediation does run automated investigation, but it holds every action pending analyst sign-off, which directly conflicts with the requirement to remediate immediately at a site with no reliable analyst coverage.

  • The server is placed in the device group whose membership rule was created earliest, because device group precedence follows the chronological creation order of the groups regardless of the rank assigned to each one.

    Why it is wrong: Creation order is not the tie-breaker; if it were, an administrator could not deterministically control which group wins. Precedence is driven by the explicit rank value, not by when each group was defined.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.