Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization wants to use Microsoft Defender XDR automatic attack disruption to stop human-operated ransomware by immediately isolating any compromised endpoints. Before enabling the feature, which Microsoft Defender for Endpoint setting must you verify on the targeted devices so that Defender XDR can automatically contain them without requiring analyst approval?
Confirm that device discovery is configured for Standard discovery on the devices.
Create a suppression rule that hides ransomware alerts generated by these devices.
Place the devices in a Defender for Endpoint device group whose automation level is set to Full - remediate.
Enable Tamper Protection for each device in Microsoft Defender for Endpoint.
Automatic attack disruption isolates devices only when Microsoft Defender for Endpoint is deployed with device discovery set to Standard discovery. This setting allows Defender XDR to obtain the real-time device inventory signals required to execute containment actions automatically. Device-group automation levels, Tamper Protection, and alert suppression or notification rules do not influence the attack-disruption containment logic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is device discovery in Microsoft Defender for Endpoint?
Open an interactive chat with Bash
Why is Standard discovery required for automatic attack disruption?
Open an interactive chat with Bash
How does Microsoft Defender XDR isolate compromised endpoints?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .