Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are deploying attack surface reduction (ASR) rules by using Microsoft Intune and Microsoft Defender for Endpoint Plan 2. Security leadership wants to prevent Office applications from dropping or writing executable content, but testers must be able to bypass the block after acknowledging a warning prompt. Which configuration should you apply in the Endpoint security > Attack surface reduction policy?
Enable the rule "Block Office communication application from creating child processes" and set its action to Block.
Enable the rule "Block Office applications from creating executable content" and set its action to Warn.
Create a custom indicator to block msiexec.exe when launched by any Office process.
Enable the rule "Block Office applications from creating executable content" and set its action to Block.
The ASR rule that prevents Office from creating or writing executable content is "Block Office applications from creating executable content." Setting the rule's action to Warn causes Defender for Endpoint to display a blocking toast notification but lets the user explicitly override the block and proceed, which satisfies the requirement for testers to bypass the restriction when necessary.
Choosing Block would silently or forcibly stop the action with no user override, while Audit only records events without preventing them. The rule that targets "Office communication application" is intended for applications like Outlook and does not address executable content creation. Indicators in Defender for Endpoint are used to allow or block specific files or hashes and do not fulfil the ASR scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are attack surface reduction (ASR) rules in Microsoft Defender for Endpoint?
Open an interactive chat with Bash
What is the 'Block Office applications from creating executable content' rule specifically designed to do?
Open an interactive chat with Bash
What is the difference between the actions 'Warn,' 'Block,' and 'Audit' in ASR rules?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .