Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization uses Microsoft Defender for Endpoint Plan 2. You must create an endpoint rule that stops a known malicious PowerShell script (SHA-256 hash is already available) from running on any onboarded device while still giving security analysts clear visibility each time a user attempts to launch the script. In the Microsoft 365 Defender portal, which action should you assign to the new file indicator so that the requirement is met?
For file indicators, Defender for Endpoint supports three possible actions: Allow, Alert only, and Block and remediate. Only Block and remediate both prevents the file from executing (block) and generates a security alert that analysts can review. Allow permits execution, and Alert only does not block execution. Therefore, choosing Block and remediate satisfies the need to prevent execution while preserving visibility through an alert.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a SHA-256 hash?
Open an interactive chat with Bash
How does 'Block and remediate' work in Microsoft Defender for Endpoint?
Open an interactive chat with Bash
What is Microsoft Defender for Endpoint Plan 2?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .