Microsoft Security Operations Analyst Associate SC-200 Practice Question
You manage Windows 10 and Windows 11 devices that are enrolled in Microsoft Intune and are already onboarded to Microsoft Defender for Endpoint. Before enforcing the rule with GUID D4F940AB-401B-4EFC-AADC-AD5F3C50688A ("Block executable files from running unless they meet a prevalence, age, or trusted list criterion"), you want to measure its impact without preventing any applications from starting. Which configuration should you deploy to the targeted devices?
Run the PowerShell command Set-MpPreference -AttackSurfaceReductionOnlyExclusions "D4F940AB-401B-4EFC-AADC-AD5F3C50688A" on the devices.
Configure the rule through Group Policy and set its state to Block.
Create a Device control policy in Microsoft Defender for Endpoint and leave the enforcement level set to Not configured.
Create an Endpoint security - Attack surface reduction rules policy in Intune and set the rule action to Audit.
The safest way to understand the operational impact of an attack surface reduction (ASR) rule is to run it in Audit mode. Intune exposes ASR configuration through Endpoint security > Attack surface reduction rules. When you create a Windows 10 or later Attack surface reduction policy and set the rule action to Audit, Defender for Endpoint logs detections to the Windows event log and the Defender portal but does not block execution. Group Policy or PowerShell could also configure ASR; however, enabling the rule with Block immediately prevents execution, and using the Disabled action records nothing. Device control policies are unrelated to ASR.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of Audit mode in ASR rules?
Open an interactive chat with Bash
How does Intune integrate with Microsoft Defender for Endpoint for ASR rules?
Open an interactive chat with Bash
What does GUID D4F940AB-401B-4EFC-AADC-AD5F3C50688A represent in ASR rules?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .