Microsoft Security Operations Analyst Associate SC-200 Practice Question

You are a Security Operations Analyst for Contoso. In Microsoft Defender XDR, you see dozens of daily "Suspicious PowerShell command line" alerts triggered by an internal compliance-scanner script that runs from C:\Tools\Scan.ps1 on several servers. You have verified the activity is benign, but you still want Defender XDR to raise the same alert if any other script exhibits the behavior. Which action should you take to meet the requirement?

  • Create an alert suppression rule scoped to the alert type and the specific process command line that automatically closes matching alerts.

  • Configure an attack surface reduction (ASR) rule exception for applications launched from C:\Tools.

  • Create a custom detection rule that changes the alert severity to Informational when the scanner script runs.

  • Add the scanner script's folder to the Microsoft Defender Antivirus exclusion list on the affected servers.

Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot