Microsoft SC-200 Automatic Attack Disruption Device Groups Permissions And Automation Levels Practice Test

 

Skills 1.1 • 30 original questions

This Microsoft SC-200 Security Operations Analyst practice test focuses on automatic attack disruption device groups permissions and automation levels through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a cloud-workload incident at Litware Manufacturing, the incident responder must automatically contain an eligible active attack by using correlated Defender XDR signals. Which action most directly satisfies the requirement for the night shift, response wave 1? The design priority is to retain evidence for follow-up analysis.

  1. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: A

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 2

Woodgrove Bank is revising its SOC runbook after a multi-cloud monitoring rollout. Analysts need to scope endpoint permissions and automated remediation behavior to the correct device population. Which implementation should the security operations analyst select for the EMEA SOC, response wave 1 while trying to avoid unnecessary alert noise?

  1. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  2. Configure Defender for Endpoint device groups with the required permissions and automation level
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow

Correct answer: B

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 3

A ticket escalated to the Defender administrator at Fourth Coffee states one non-negotiable goal: automatically contain an eligible active attack by using correlated Defender XDR signals. Which choice is the strongest fit for the high-value-assets group, response wave 2? The team also wants to avoid unnecessary alert noise.

  1. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  2. Configure the appropriate email notification rule in Microsoft Defender XDR
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: C

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 4

For the privileged-users group, response wave 2 at A. Datum, a endpoint containment exercise can proceed only if the team can scope endpoint permissions and automated remediation behavior to the correct device population. What should the incident responder configure first if the operational goal is to preserve least privilege?

  1. Configure Defender for Endpoint device groups with the required permissions and automation level
  2. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  3. Configure the appropriate email notification rule in Microsoft Defender XDR
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal

Correct answer: A

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 5

The security architecture review at Fabrikam Retail focuses on this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals. Which Microsoft security action is most appropriate for the remote-user fleet, response wave 3, given the need to preserve least privilege?

  1. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  4. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  5. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal

Correct answer: B

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 6

A change advisory board at Adventure Works asks how to scope endpoint permissions and automated remediation behavior to the correct device population during a threat-hunting campaign. Which proposed action should the Defender administrator approve for the production subscription, response wave 3? The change should reduce mean time to respond.

  1. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  2. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: C

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 7

Alpine Ski House has ruled out a manual one-off workaround. For the regulated workload segment, response wave 4, the remaining requirement is to automatically contain an eligible active attack by using correlated Defender XDR signals. Which choice best addresses it and helps reduce mean time to respond?

  1. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: C

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 8

During post-incident review at Wide World Importers, the SOC analyst identifies a gap: the SOC still needs to scope endpoint permissions and automated remediation behavior to the correct device population. Which action should be added for the Tier 1 queue, response wave 4 before the next incident, with an emphasis on trying to scope the change to the affected security domain?

  1. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  2. Configure Defender for Endpoint device groups with the required permissions and automation level
  3. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  4. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: B

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 9

The Tier 2 analyst at Lucerne Publishing is comparing several Microsoft security options for a SOC handoff review. Which one directly enables the team to automatically contain an eligible active attack by using correlated Defender XDR signals for the identity-response team, response wave 5 while helping scope the change to the affected security domain?

  1. Configure the appropriate email notification rule in Microsoft Defender XDR
  2. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: E

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 10

A security-operations workshop at Northwind Traders defines the desired outcome as follows: scope endpoint permissions and automated remediation behavior to the correct device population. Which implementation should be chosen for the endpoint-response team, response wave 5? The team wants to keep the workflow auditable.

  1. Configure Defender for Endpoint device groups with the required permissions and automation level
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  4. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: A

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 11

Which Microsoft security action best matches this technical purpose for the messaging-security team, response wave 6: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. The SOC is trying to keep the workflow auditable.

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal

Correct answer: C

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 12

An analyst at Blue Yonder Airlines describes the needed capability this way: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. Which option should be associated with that requirement for the night shift, response wave 6 while the team tries to avoid changing an unrelated control plane?

  1. Configure the appropriate email notification rule in Microsoft Defender XDR
  2. Configure Defender for Endpoint device groups with the required permissions and automation level
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: B

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 13

During a design validation for the Americas SOC, response wave 7, A. Datum documents the following behavior: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. Which Microsoft security feature or action is being described? The objective is to avoid changing an unrelated control plane.

  1. Configure the appropriate email notification rule in Microsoft Defender XDR
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: E

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 14

The security engineer must identify the Microsoft security capability that provides this function for the high-value-assets group, response wave 7: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. Which choice is correct if the SOC also needs to improve detection coverage?

  1. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: C

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 15

A runbook for the server fleet, response wave 8 contains this description: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. Which implementation belongs in that runbook during a lateral-movement investigation? The process should improve detection coverage.

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: E

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 16

Proseware Services is troubleshooting a cloud-workload incident. Evidence shows that the decisive requirement is to scope endpoint permissions and automated remediation behavior to the correct device population. Which action should the Sentinel administrator investigate first for the remote-user fleet, response wave 8, without losing the ability to support repeatable response?

  1. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  2. Configure Defender for Endpoint device groups with the required permissions and automation level
  3. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  4. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  5. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal

Correct answer: B

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 17

After eliminating network and licensing causes, the incident responder at Wide World Importers determines that success depends on the ability to automatically contain an eligible active attack by using correlated Defender XDR signals. Which security action should be checked next for the research subscription, response wave 9? The team must support repeatable response.

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: D

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 18

A service-desk escalation during a identity compromise review has been narrowed to one security-operations requirement: scope endpoint permissions and automated remediation behavior to the correct device population. Which configuration is the most relevant starting point for the regulated workload segment, response wave 9 if the SOC wants to separate collection from detection logic?

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: C

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 19

The failure pattern at Northwind Traders affects the Tier 2 queue, response wave 10. Before making unrelated policy changes, the Defender administrator needs a solution that will automatically contain an eligible active attack by using correlated Defender XDR signals. Which action is most directly relevant and helps separate collection from detection logic?

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Correct answer: B

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 20

While investigating a ransomware response, Tailspin Toys confirms the environment must scope endpoint permissions and automated remediation behavior to the correct device population. Which Microsoft security capability should be validated for the identity-response team, response wave 10? The investigation should preserve investigation context.

  1. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  2. Configure the appropriate email notification rule in Microsoft Defender XDR
  3. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  4. Configure Defender for Endpoint device groups with the required permissions and automation level
  5. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action

Correct answer: D

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 21

Two teams at Blue Yonder Airlines propose different approaches for the cloud-security team, response wave 11. The selection criterion is simple: the chosen approach must automatically contain an eligible active attack by using correlated Defender XDR signals. Which option should win the technical comparison if the SOC also wants to preserve investigation context?

  1. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  5. Configure the appropriate email notification rule in Microsoft Defender XDR

Correct answer: A

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 22

For the messaging-security team, response wave 11, Trey Research wants the least indirect solution to this goal: scope endpoint permissions and automated remediation behavior to the correct device population. Which action aligns most closely with that requirement and the need to minimize manual analyst steps?

  1. Configure Defender for Endpoint device groups with the required permissions and automation level
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: A

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 23

A modernization plan at Contoso Health includes a threat-hunting campaign. The threat hunter is asked to choose the control that specifically helps the organization automatically contain an eligible active attack by using correlated Defender XDR signals. Which choice fits best for the EMEA SOC, response wave 12 while supporting the goal to minimize manual analyst steps?

  1. Configure Defender for Endpoint device groups with the required permissions and automation level
  2. Configure the appropriate email notification rule in Microsoft Defender XDR
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: D

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 24

The Americas SOC, response wave 12 is moving into a controlled rollout at Litware Manufacturing. Which action should be included when the stated security objective is to scope endpoint permissions and automated remediation behavior to the correct device population? The operational standard is to retain evidence for follow-up analysis.

  1. Configure the appropriate email notification rule in Microsoft Defender XDR
  2. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  3. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  4. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: E

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 25

Proseware Services is replacing an ad hoc process during a post-incident review. The replacement must reliably automatically contain an eligible active attack by using correlated Defender XDR signals. Which security-operations approach should the Tier 2 analyst implement for the privileged-users group, response wave 13 if the team also wants to retain evidence for follow-up analysis?

  1. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  2. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration

Correct answer: C

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 26

An audit finding for the server fleet, response wave 13 says the current process does not consistently scope endpoint permissions and automated remediation behavior to the correct device population. Which Microsoft security action most directly closes that gap while helping the SOC avoid unnecessary alert noise?

  1. Configure Defender for Endpoint device groups with the required permissions and automation level
  2. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow

Correct answer: A

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 27

The security engineer at Wingtip Toys needs a repeatable configuration for the production subscription, response wave 14. It must automatically contain an eligible active attack by using correlated Defender XDR signals. Which choice should be implemented instead of relying on manual incident work if the goal is to avoid unnecessary alert noise?

  1. Configure Defender for Endpoint device groups with the required permissions and automation level
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: B

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 28

During readiness testing at Fabrikam Retail, the research subscription, response wave 14 fails a business requirement because analysts cannot yet scope endpoint permissions and automated remediation behavior to the correct device population. Which action should be implemented before rollout continues? The SOC also needs to preserve least privilege.

  1. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  2. Configure Defender for Endpoint device groups with the required permissions and automation level
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  5. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Correct answer: B

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Question 29

A governance review asks the Sentinel administrator to justify the control selected for the Tier 1 queue, response wave 15. The requirement is to automatically contain an eligible active attack by using correlated Defender XDR signals. Which action has the clearest technical alignment while supporting the goal to preserve least privilege?

  1. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  2. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  3. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  4. Configure Defender for Endpoint device groups with the required permissions and automation level
  5. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation

Correct answer: C

Why: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Option review:

A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

C: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. This directly addresses the requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

E: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: automatically contain an eligible active attack by using correlated Defender XDR signals.

Learning point: Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Question 30

For a lateral-movement investigation, Alpine Ski House needs a Microsoft security capability with this effect: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. Which option most accurately provides that capability for the Tier 2 queue, response wave 15? The process should reduce mean time to respond.

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  3. Configure Defender for Endpoint device groups with the required permissions and automation level
  4. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  5. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Correct answer: C

Why: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

B: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

C: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. This directly addresses the requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

D: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: scope endpoint permissions and automated remediation behavior to the correct device population.

Learning point: Configure Defender for Endpoint device groups with the required permissions and automation level

Popular posts

img