Microsoft Security Operations Analyst Associate SC-200 Practice Question

You are deploying attack surface reduction (ASR) rules by using Microsoft Intune and Microsoft Defender for Endpoint Plan 2. Security leadership wants to prevent Office applications from dropping or writing executable content, but testers must be able to bypass the block after acknowledging a warning prompt. Which configuration should you apply in the Endpoint security > Attack surface reduction policy?

  • Enable the rule "Block Office communication application from creating child processes" and set its action to Block.

  • Enable the rule "Block Office applications from creating executable content" and set its action to Warn.

  • Create a custom indicator to block msiexec.exe when launched by any Office process.

  • Enable the rule "Block Office applications from creating executable content" and set its action to Block.

Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot