Microsoft Security Operations Analyst Associate SC-200 Practice Question

You onboard Windows Server 2022 and Ubuntu Linux servers to Microsoft Defender for Endpoint (MDE). Only users in the SecOps Azure AD group must be able to view the servers in the Microsoft Defender portal, and automated investigation and remediation (AIR) for those servers must run in semi-automated mode. Workstation devices must remain unaffected. In the Defender portal, which action should you perform first?

  • Create an Azure AD dynamic device group that contains all servers and scope the SecOps role to that group.

  • Configure an alert notification rule that targets the SecOps Azure AD group.

  • Assign the SecOps Azure AD group to the built-in Security Administrator role in Microsoft Defender.

  • Create a new MDE device group that filters on the Windows Server and Linux operating-system platforms and set the group's Automation level to Semi-automated.

Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot