Microsoft Security Operations Analyst Associate SC-200 Practice Question
Within Microsoft Defender for Endpoint, RBAC is enabled. You already have a device group named Servers that uses the Full remediation automation level. You create a new device group named Tier0Servers that targets devices with the Tag value "Tier0" and sets automation to Semi (require approval). One day later, a Tier0-tagged server is still remediated automatically. What is the most likely reason?
Automatic remediation levels are configured only at the tenant level, so device-group settings cannot override the existing Full automation level.
Device group membership is refreshed every 72 hours, so the server has not yet moved to the new group.
Tags cannot be used as membership filters when RBAC is enabled, preventing the server from ever matching the Tier0Servers group.
The Tier0Servers group is positioned below the Servers group in the device-group list, so Tier0 servers are assigned to the Servers group and keep the Full automation level.
A device can belong to only one Microsoft Defender for Endpoint device group. When RBAC is enabled, devices are evaluated against the list of device groups from top to bottom; the first group whose criteria are met wins. Because the Tier0Servers group sits below the existing Servers group, Tier0-tagged servers match the Servers group first and inherit its Full automation level, so remediation still runs automatically. The other options are incorrect: automation levels are scoped per device group, not tenant-wide; membership is refreshed roughly every 24 hours, not 72; and tags are valid criteria even when RBAC is turned on.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does RBAC mean in Microsoft Defender for Endpoint?
Open an interactive chat with Bash
How are device groups evaluated when RBAC is enabled?
Open an interactive chat with Bash
What happens to automation settings in a device group?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .