Microsoft Security Operations Analyst Associate SC-200 Practice Question

Your organization uses Microsoft Defender for Endpoint (MDE) with Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to evaluate the effect of enabling the attack surface reduction (ASR) rule named Block Office macro code from creating child processes across all managed devices without preventing users from completing their work. The evaluation must generate security events that are sent to Microsoft Defender XDR so analysts can review the potential impact.

In the Endpoint security blade of the Microsoft Intune admin center, which action value should you assign to this ASR rule to meet the requirement?

  • Audit

  • Warn

  • Disabled

  • Block

Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot