Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization has a device group named CriticalServers in Microsoft Defender XDR. You must ensure that the SOC receives an email each time an alert with a severity of High or above is raised on any device in that group, while suppressing notifications for Medium and Low alerts. Which configuration should you create to meet the requirement?
Create an incident notification rule with a minimum incident severity of High and no additional filters.
Create a vulnerability notification rule that filters on CVSS severity High and targets the CriticalServers device group.
Build a scheduled hunting query in Microsoft Sentinel that looks for High-severity alerts on CriticalServers and sends an action-group email.
Create an alert notification rule scoped to the CriticalServers device group with a minimum alert severity of High.
Alert notification rules are designed to send email messages whenever an alert that meets the rule's criteria is generated. When creating the rule you can scope it to one or more device groups and set a minimum alert severity. Selecting the CriticalServers device group and setting the minimum severity to High guarantees that only High- and Critical-severity alerts originating from those devices trigger an email. Vulnerability notification rules focus on CVEs and exposure rather than alert events, incident notification rules have no device-group filter and could notify on unrelated resources, and a Sentinel hunting query is unnecessary overhead when Defender XDR already provides purpose-built alert notifications.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Defender XDR?
Open an interactive chat with Bash
How do alert notification rules work in Microsoft Defender XDR?
Open an interactive chat with Bash
What’s the difference between alert notification rules and vulnerability notification rules in Defender XDR?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .