Microsoft Security Operations Analyst Associate SC-200 Practice Question

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 endpoints integrated with Microsoft Defender for Endpoint. To prepare for enforcing stricter script controls, you must collect telemetry any time users attempt to run potentially obfuscated scripts, but you must not prevent execution during the pilot. Which attack surface reduction (ASR) configuration should you deploy?

  • Enable the ASR rule "Block all Office applications from creating child processes" and set the action to Warn

  • Enable the ASR rule "Block execution of potentially obfuscated scripts" and set the action to Block

  • Enable the ASR rule "Block execution of potentially obfuscated scripts" and set the action to Audit

  • Enable the ASR rule "Block JavaScript or VBScript from launching downloaded executable content" and set the action to Audit

Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot