Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 endpoints integrated with Microsoft Defender for Endpoint. To prepare for enforcing stricter script controls, you must collect telemetry any time users attempt to run potentially obfuscated scripts, but you must not prevent execution during the pilot. Which attack surface reduction (ASR) configuration should you deploy?
Enable the ASR rule "Block all Office applications from creating child processes" and set the action to Warn
Enable the ASR rule "Block execution of potentially obfuscated scripts" and set the action to Block
Enable the ASR rule "Block execution of potentially obfuscated scripts" and set the action to Audit
Enable the ASR rule "Block JavaScript or VBScript from launching downloaded executable content" and set the action to Audit
The ASR rule "Block execution of potentially obfuscated scripts" targets PowerShell, JavaScript, and VBScript files whose content suggests obfuscation or other suspicious characteristics. Setting the rule's action to Audit causes Microsoft Defender for Endpoint to record an event each time the script is run without blocking the execution, letting the security team evaluate impact before moving to enforcement. Choosing a different rule would audit or block a different behavior, while setting the action to Block or Warn would prevent or interrupt execution, which does not meet the requirement to allow scripts to run during the pilot.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Attack Surface Reduction (ASR) rule?
Open an interactive chat with Bash
What does 'Audit' mode in ASR rules do?
Open an interactive chat with Bash
What is script obfuscation and why is it considered suspicious?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .