Microsoft Security Operations Analyst Associate SC-200 Practice Question
You must receive an email whenever Microsoft Defender XDR detects a newly discovered CVE rated Critical on any server. Requirements: trigger only for Critical severity, scope to the Default device group, send immediately. Which rule type should you create in the Microsoft Defender portal, and which option lets you enforce both the severity and device-scope filters?
Configure a Data retention policy with a Critical severity filter for the Default device group.
Create an Alert notification rule and set Severity to Critical and Device group to Default.
Create a Vulnerability notification rule and set the Severity filter to Critical and the Device group filter to Default.
Configure an Automated investigation exclusion scoped to the Default device group and critical severity.
A Vulnerability notification rule is the only rule type that can monitor new CVEs reported by Microsoft Defender Vulnerability Management. When you create the rule, you can specify both the Severity filter (set to Critical) and the Device group filter (set to the built-in Default group). Alert notification rules cover security alerts, not CVE discoveries, while automated investigation exclusions and data-retention policies do not generate vulnerability emails. Therefore, selecting Vulnerability notification and configuring the two filters meets every requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a CVE, and why is it important in vulnerability management?
Open an interactive chat with Bash
How does a Vulnerability notification rule differ from an Alert notification rule?
Open an interactive chat with Bash
What is the significance of a Device group in Microsoft Defender vulnerability notifications?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .