Microsoft Security Operations Analyst Associate SC-200 Practice Question

You manage Windows 10 and Windows 11 devices that are enrolled in Microsoft Intune and are already onboarded to Microsoft Defender for Endpoint. Before enforcing the rule with GUID D4F940AB-401B-4EFC-AADC-AD5F3C50688A ("Block executable files from running unless they meet a prevalence, age, or trusted list criterion"), you want to measure its impact without preventing any applications from starting. Which configuration should you deploy to the targeted devices?

  • Create an Endpoint security - Attack surface reduction rules policy in Intune and set the rule action to Audit.

  • Configure the rule through Group Policy and set its state to Block.

  • Create a Device control policy in Microsoft Defender for Endpoint and leave the enforcement level set to Not configured.

  • Run the PowerShell command Set-MpPreference -AttackSurfaceReductionOnlyExclusions "D4F940AB-401B-4EFC-AADC-AD5F3C50688A" on the devices.

Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot