nerdexam
Microsoft

SC-200 · Question #16

You are investigating a potential attack that deploys a new ransomware strain. You plan to perform automated actions on a group of highly valuable machines that contain sensitive information. You…

The correct answer is A. Assign a tag to the device group. C. Add a tag to the machines. D. Create a new device group that has a rank of 1. To temporarily group specific high-value machines for automated response actions in Microsoft Defender for Endpoint, the correct workflow is: Add a tag to each target machine (C) - tags are the mechanism for dynamically identifying devices; Create a new device group with a rank…

Submitted by ravi_2018· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

You are investigating a potential attack that deploys a new ransomware strain. You plan to perform automated actions on a group of highly valuable machines that contain sensitive information. You have three custom device groups. You need to be able to temporarily group the machines to perform actions on the devices. Which three actions should you perform?Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AAssign a tag to the device group.
  • BAdd the device users to the admin role.
  • CAdd a tag to the machines.
  • DCreate a new device group that has a rank of 1.
  • ECreate a new admin role.
  • FCreate a new device group that has a rank of 4.

How the community answered

(30 responses)
  • A
    73% (22)
  • B
    17% (5)
  • E
    7% (2)
  • F
    3% (1)

Explanation

To temporarily group specific high-value machines for automated response actions in Microsoft Defender for Endpoint, the correct workflow is: Add a tag to each target machine (C) - tags are the mechanism for dynamically identifying devices; Create a new device group with a rank of 1 (D) - rank 1 gives the highest evaluation priority, ensuring these machines are matched to this group before any lower-ranked groups; and configure the device group to use that tag as its membership criterion (A). Rank 4 (F) would have lower priority and could be overridden by existing groups. Options B and E (creating admin roles and adding users to roles) are about access control, not device grouping. This approach is temporary and non-destructive to existing device group configurations.

Topics

#Device Management#Device Grouping#Device Tags#Automated Remediation

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice