Microsoft Security Operations Analyst Associate SC-200 Practice Question

You manage Windows 10 devices that are onboarded to Microsoft Defender for Endpoint and enrolled in Intune. Two endpoint security profiles target the same devices. Profile A sets the attack surface reduction rule "Block Office applications from creating child processes" to Audit, whereas Profile B sets the same rule to Block. Both profiles apply successfully. After policy processing, which enforcement mode will the rule use on the devices?

  • The rule alternates between Audit and Block depending on which policy applies last.

  • The rule is disabled because the conflicting settings cancel each other.

  • The rule runs in Block mode on the devices.

  • The rule runs in Audit mode on the devices.

Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot