nerdexam
MicrosoftMicrosoft

SC-200 · Question #172

SC-200 Question #172: Real Exam Question with Answer & Explanation

The correct answer is A: Create an import file that contains the individual IP addresses in the range. Select Import and. This approach is necessary because Microsoft Defender for Endpoint does not support Classless Inter-Domain Routing (CIDR) notation for IP addresses. Therefore, specifying the range as 171.23.34.32/27 or using a range format like 171.23.34.32-171.23.34.63 directly is not supported

Submitted by jaden.t· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. You need to add threat indicators for all the IP addresses in a range of 171.23.34.32- 171.23.34.63. The solution must minimize administrative effort. What should you do in the Microsoft 365 Defender portal?

Options

  • ACreate an import file that contains the individual IP addresses in the range. Select Import and
  • BCreate an import file that contains the IP address of 171.23.34.32/27. Select Import and import
  • CSelect Add indicator and set the IP address to 171.23.34.32 - 171.23.34.63.
  • DSelect Add indicator and set the IP address to 171.23.34.32/27.

Explanation

This approach is necessary because Microsoft Defender for Endpoint does not support Classless Inter-Domain Routing (CIDR) notation for IP addresses. Therefore, specifying the range as 171.23.34.32/27 or using a range format like 171.23.34.32-171.23.34.63 directly is not supported. Instead, you need to list each IP address individually in an import file and then import this file into the Microsoft 365 Defender portal. https://learn.microsoft.com/en-us/defender-endpoint/indicator-manage

Topics

#Microsoft Defender for Endpoint#Threat Indicators#IP Address#Bulk Import

Community Discussion

No community discussion yet for this question.

Full SC-200 PracticeBrowse All SC-200 Questions