Microsoft Security Operations Analyst Associate SC-200 Practice Question
You onboard Windows Server 2022 and Ubuntu Linux servers to Microsoft Defender for Endpoint (MDE). Only users in the SecOps Azure AD group must be able to view the servers in the Microsoft Defender portal, and automated investigation and remediation (AIR) for those servers must run in semi-automated mode. Workstation devices must remain unaffected. In the Defender portal, which action should you perform first?
Create an Azure AD dynamic device group that contains all servers and scope the SecOps role to that group.
Configure an alert notification rule that targets the SecOps Azure AD group.
Assign the SecOps Azure AD group to the built-in Security Administrator role in Microsoft Defender.
Create a new MDE device group that filters on the Windows Server and Linux operating-system platforms and set the group's Automation level to Semi-automated.
In MDE, role-based access control (RBAC) visibility and automation behavior are both applied at the device-group level. A device group can be populated by using filters such as operating-system platform, and every device group includes an Automation level setting that controls how AIR behaves (No automated response, Semi, Full). After the device group has been created, you can scope the SecOps RBAC role to that group so that only those users can see the servers. Creating the device group therefore must be done before you can configure either the RBAC scope or the automation level for the servers, making it the required first step. The other options either configure alert notifications, assign a role that is not scoped, or use Azure AD groups that do not control AIR settings inside MDE, so they do not satisfy the requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a device group in Microsoft Defender for Endpoint (MDE)?
Open an interactive chat with Bash
What does Semi-automated mode mean in automated investigation and remediation (AIR)?
Open an interactive chat with Bash
How does RBAC work in Microsoft Defender for Endpoint (MDE)?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .