Microsoft SC-200 Automatic Attack Disruption Device Groups Permissions And Automation Levels Practice Test
Skills 1.1 • 30 original questions
This Microsoft SC-200 Security Operations Analyst practice test focuses on automatic attack disruption device groups permissions and automation levels through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a cloud-workload incident at Litware Manufacturing, the incident responder must automatically contain an eligible active attack by using correlated Defender XDR signals. Which action most directly satisfies the requirement for the night shift, response wave 1? The design priority is to retain evidence for follow-up analysis.
Correct answer: A
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
Woodgrove Bank is revising its SOC runbook after a multi-cloud monitoring rollout. Analysts need to scope endpoint permissions and automated remediation behavior to the correct device population. Which implementation should the security operations analyst select for the EMEA SOC, response wave 1 while trying to avoid unnecessary alert noise?
Correct answer: B
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
A ticket escalated to the Defender administrator at Fourth Coffee states one non-negotiable goal: automatically contain an eligible active attack by using correlated Defender XDR signals. Which choice is the strongest fit for the high-value-assets group, response wave 2? The team also wants to avoid unnecessary alert noise.
Correct answer: C
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
For the privileged-users group, response wave 2 at A. Datum, a endpoint containment exercise can proceed only if the team can scope endpoint permissions and automated remediation behavior to the correct device population. What should the incident responder configure first if the operational goal is to preserve least privilege?
Correct answer: A
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
The security architecture review at Fabrikam Retail focuses on this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals. Which Microsoft security action is most appropriate for the remote-user fleet, response wave 3, given the need to preserve least privilege?
Correct answer: B
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
A change advisory board at Adventure Works asks how to scope endpoint permissions and automated remediation behavior to the correct device population during a threat-hunting campaign. Which proposed action should the Defender administrator approve for the production subscription, response wave 3? The change should reduce mean time to respond.
Correct answer: C
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
Alpine Ski House has ruled out a manual one-off workaround. For the regulated workload segment, response wave 4, the remaining requirement is to automatically contain an eligible active attack by using correlated Defender XDR signals. Which choice best addresses it and helps reduce mean time to respond?
Correct answer: C
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
During post-incident review at Wide World Importers, the SOC analyst identifies a gap: the SOC still needs to scope endpoint permissions and automated remediation behavior to the correct device population. Which action should be added for the Tier 1 queue, response wave 4 before the next incident, with an emphasis on trying to scope the change to the affected security domain?
Correct answer: B
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
The Tier 2 analyst at Lucerne Publishing is comparing several Microsoft security options for a SOC handoff review. Which one directly enables the team to automatically contain an eligible active attack by using correlated Defender XDR signals for the identity-response team, response wave 5 while helping scope the change to the affected security domain?
Correct answer: E
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
A security-operations workshop at Northwind Traders defines the desired outcome as follows: scope endpoint permissions and automated remediation behavior to the correct device population. Which implementation should be chosen for the endpoint-response team, response wave 5? The team wants to keep the workflow auditable.
Correct answer: A
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
Which Microsoft security action best matches this technical purpose for the messaging-security team, response wave 6: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. The SOC is trying to keep the workflow auditable.
Correct answer: C
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
An analyst at Blue Yonder Airlines describes the needed capability this way: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. Which option should be associated with that requirement for the night shift, response wave 6 while the team tries to avoid changing an unrelated control plane?
Correct answer: B
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
During a design validation for the Americas SOC, response wave 7, A. Datum documents the following behavior: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. Which Microsoft security feature or action is being described? The objective is to avoid changing an unrelated control plane.
Correct answer: E
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
The security engineer must identify the Microsoft security capability that provides this function for the high-value-assets group, response wave 7: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. Which choice is correct if the SOC also needs to improve detection coverage?
Correct answer: C
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
A runbook for the server fleet, response wave 8 contains this description: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. Which implementation belongs in that runbook during a lateral-movement investigation? The process should improve detection coverage.
Correct answer: E
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
Proseware Services is troubleshooting a cloud-workload incident. Evidence shows that the decisive requirement is to scope endpoint permissions and automated remediation behavior to the correct device population. Which action should the Sentinel administrator investigate first for the remote-user fleet, response wave 8, without losing the ability to support repeatable response?
Correct answer: B
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
After eliminating network and licensing causes, the incident responder at Wide World Importers determines that success depends on the ability to automatically contain an eligible active attack by using correlated Defender XDR signals. Which security action should be checked next for the research subscription, response wave 9? The team must support repeatable response.
Correct answer: D
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
A service-desk escalation during a identity compromise review has been narrowed to one security-operations requirement: scope endpoint permissions and automated remediation behavior to the correct device population. Which configuration is the most relevant starting point for the regulated workload segment, response wave 9 if the SOC wants to separate collection from detection logic?
Correct answer: C
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
The failure pattern at Northwind Traders affects the Tier 2 queue, response wave 10. Before making unrelated policy changes, the Defender administrator needs a solution that will automatically contain an eligible active attack by using correlated Defender XDR signals. Which action is most directly relevant and helps separate collection from detection logic?
Correct answer: B
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
While investigating a ransomware response, Tailspin Toys confirms the environment must scope endpoint permissions and automated remediation behavior to the correct device population. Which Microsoft security capability should be validated for the identity-response team, response wave 10? The investigation should preserve investigation context.
Correct answer: D
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
Two teams at Blue Yonder Airlines propose different approaches for the cloud-security team, response wave 11. The selection criterion is simple: the chosen approach must automatically contain an eligible active attack by using correlated Defender XDR signals. Which option should win the technical comparison if the SOC also wants to preserve investigation context?
Correct answer: A
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
For the messaging-security team, response wave 11, Trey Research wants the least indirect solution to this goal: scope endpoint permissions and automated remediation behavior to the correct device population. Which action aligns most closely with that requirement and the need to minimize manual analyst steps?
Correct answer: A
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
A modernization plan at Contoso Health includes a threat-hunting campaign. The threat hunter is asked to choose the control that specifically helps the organization automatically contain an eligible active attack by using correlated Defender XDR signals. Which choice fits best for the EMEA SOC, response wave 12 while supporting the goal to minimize manual analyst steps?
Correct answer: D
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
The Americas SOC, response wave 12 is moving into a controlled rollout at Litware Manufacturing. Which action should be included when the stated security objective is to scope endpoint permissions and automated remediation behavior to the correct device population? The operational standard is to retain evidence for follow-up analysis.
Correct answer: E
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
Proseware Services is replacing an ad hoc process during a post-incident review. The replacement must reliably automatically contain an eligible active attack by using correlated Defender XDR signals. Which security-operations approach should the Tier 2 analyst implement for the privileged-users group, response wave 13 if the team also wants to retain evidence for follow-up analysis?
Correct answer: C
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
An audit finding for the server fleet, response wave 13 says the current process does not consistently scope endpoint permissions and automated remediation behavior to the correct device population. Which Microsoft security action most directly closes that gap while helping the SOC avoid unnecessary alert noise?
Correct answer: A
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
The security engineer at Wingtip Toys needs a repeatable configuration for the production subscription, response wave 14. It must automatically contain an eligible active attack by using correlated Defender XDR signals. Which choice should be implemented instead of relying on manual incident work if the goal is to avoid unnecessary alert noise?
Correct answer: B
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
During readiness testing at Fabrikam Retail, the research subscription, response wave 14 fails a business requirement because analysts cannot yet scope endpoint permissions and automated remediation behavior to the correct device population. Which action should be implemented before rollout continues? The SOC also needs to preserve least privilege.
Correct answer: B
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
A governance review asks the Sentinel administrator to justify the control selected for the Tier 1 queue, response wave 15. The requirement is to automatically contain an eligible active attack by using correlated Defender XDR signals. Which action has the clearest technical alignment while supporting the goal to preserve least privilege?
Correct answer: C
Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Option review:
A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.
Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
For a lateral-movement investigation, Alpine Ski House needs a Microsoft security capability with this effect: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. Which option most accurately provides that capability for the Tier 2 queue, response wave 15? The process should reduce mean time to respond.
Correct answer: C
Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Option review:
A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.
Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level
Popular posts
Recent Posts
