Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization uses Microsoft Defender for Endpoint (MDE) with Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to evaluate the effect of enabling the attack surface reduction (ASR) rule named Block Office macro code from creating child processes across all managed devices without preventing users from completing their work. The evaluation must generate security events that are sent to Microsoft Defender XDR so analysts can review the potential impact.
In the Endpoint security blade of the Microsoft Intune admin center, which action value should you assign to this ASR rule to meet the requirement?
Configure the rule in Audit mode. Audit mode allows the potentially risky action but records an event (for example, Windows Security event ID 1122) that is forwarded to Microsoft Defender for Endpoint and surfaces in Microsoft Defender XDR. This lets security teams understand how frequently the rule would have triggered and adjust exclusions before enforcing it. Using Block would immediately stop the action, Warn would interrupt users with a prompt, and Disabled would neither enforce the rule nor collect data. Therefore, Audit meets the requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Audit mode in the context of Microsoft Defender for Endpoint?
Open an interactive chat with Bash
What are attack surface reduction (ASR) rules, and why are they important?
Open an interactive chat with Bash
How does Microsoft Defender XDR use security events sent from Microsoft Intune-managed devices?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .