Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization has already onboarded all Windows 11 client PCs to Microsoft Defender for Endpoint (MDE). You now enable the built-in device discovery feature and leave the settings unchanged, which keeps the feature in its default mode.
How will MDE detect Windows computers that are still connected to the corporate network but not yet onboarded to MDE?
The Defender for Endpoint cloud service cross-references Azure AD sign-in logs and flags computer names that have never sent security data.
Each onboarded Windows PC passively listens to local broadcast traffic (for example, ARP and DHCP) to identify nearby hosts that are not sending signals to MDE, and lists them as unmanaged.
An Azure Arc agent is automatically deployed to each subnet to report machines that are not onboarded to MDE.
Every onboarded Windows PC performs an active ICMP ping sweep and TCP port scan of its subnet to locate hosts that are not protected.
When device discovery is enabled and left in its default Basic mode, the SenseNDR component on each onboarded Windows device passively captures local network traffic such as ARP, DHCP, DNS, and NetBIOS broadcasts. From this broadcast traffic it infers the presence of other hosts on the same subnet. Any host that appears in the traffic but does not report itself to the MDE service is added to the device inventory as an unmanaged device. Basic mode never initiates active ICMP ping sweeps or TCP port scans. Those active probes are performed only when an administrator explicitly switches discovery to Standard mode. No additional agents such as Azure Arc are required for either mode because the existing Defender for Endpoint sensor performs the discovery work.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the SenseNDR component in Microsoft Defender for Endpoint?
Open an interactive chat with Bash
What is the difference between Basic mode and Standard mode in MDE's device discovery?
Open an interactive chat with Bash
Why doesn't device discovery in MDE require additional agents like Azure Arc?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .