SC-200 - Manage a Security Operations Environment - Section 1.2

Configure Microsoft Defender for Endpoint advanced features, rules, custom data collection, attack surface reduction, and device groups.

Enable and configure Microsoft Defender for Endpoint advanced features, including custom data collection via data collection rules, and deploy attack surface reduction (ASR) rules to block common attack vectors. Organise devices into device groups and assign automation levels that control how aggressively automated investigation and response acts on each group.

Microsoft Defender for Endpoint advanced featuresrules settingscustom data collectionattack surface reduction (ASR) rulesdevice groups, permissions, and automation levels

Practice question for this objective

Free sampleManage a Security Operations Environmenthard

A security architect is enabling automatic attack disruption in Microsoft Defender XDR so that, on a high-confidence human-operated ransomware detection, the platform can autonomously isolate an affected onboarded Windows device before any analyst intervenes. Endpoint signals are onboarded and automated investigation is running. Which TWO conditions must be satisfied so that the device-isolation disruption action is actually applied to a targeted device? Select TWO.

  • AThe targeted device must be actively onboarded to Microsoft Defender for Endpoint with its sensor reporting, so disruption has a managed agent through which to enforce the isolation. Correct
  • BA Microsoft Sentinel scheduled analytics rule must be authored to detect the ransomware pattern and call the isolation as its automated response action.
  • CThe device group's Microsoft Defender for Endpoint automation level must not be set to no automated response, so automated containment is permitted on that device. Correct
  • DA Microsoft Defender XDR custom detection rule with a device-isolation response action must be created and scheduled before disruption can isolate the device.
Automatic attack disruption isolates a device through the active Microsoft Defender for Endpoint sensor and only when the device group's automation level permits automated response. Disruption enforces device isolation via the Microsoft Defender for Endpoint sensor, so the device must be onboarded and reporting, and the device group's automation level must not be set to no automated response, otherwise the platform is prevented from applying any automated containment action.

Why A is correct: Correct: attack disruption isolates a device through the Microsoft Defender for Endpoint sensor, so the device must be onboarded and actively reporting for the action to be enforced.

Why B is wrong: Tempting because Sentinel rules can trigger response automation, but attack disruption is a built-in Microsoft Defender XDR capability that needs no analytics rule, so this is not a prerequisite.

Why C is correct: Correct: if the device group is set to no automated response, automated actions including disruption isolation are blocked, so the automation level must permit automated containment.

Why D is wrong: Tempting because custom detection rules can carry an isolate-device action, but disruption acts on its own high-confidence signals and does not depend on a custom detection rule, so this is incorrect.

See more SC-200 practice questions, answers explained.

More in this domain

Back to all Manage a Security Operations Environment objectives, or the SC-200 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.