nerdexam
Microsoft

SC-200 · Question #290

You have 500 on-premises devices. You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You onboard 100 devices to Microsoft Defender 365. You need to identify any unmanaged…

The correct answer is C. Set Discovery mode to Basic. In Microsoft Defender XDR Device Discovery, setting the mode to Basic enables passive discovery - onboarded devices monitor network traffic they naturally observe without actively probing the network. This is the prerequisite first step before you can configure which specific…

Submitted by weili_xi· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

You have 500 on-premises devices. You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You onboard 100 devices to Microsoft Defender 365. You need to identify any unmanaged on-premises devices. The solution must ensure that only specific onboarded devices perform the discovery. What should you do first?

Options

  • ACreate a device group.
  • BCreate an exclusion.
  • CSet Discovery mode to Basic.
  • DCreate a tag.

How the community answered

(53 responses)
  • A
    11% (6)
  • B
    6% (3)
  • C
    79% (42)
  • D
    4% (2)

Explanation

In Microsoft Defender XDR Device Discovery, setting the mode to Basic enables passive discovery - onboarded devices monitor network traffic they naturally observe without actively probing the network. This is the prerequisite first step before you can configure which specific onboarded devices act as discovery agents. Basic mode scopes discovery activity to only the onboarded endpoints, preventing uncontrolled active probing across the network. Creating a device group (A) and tags (D) are subsequent steps used to designate specific devices, but you must first establish the correct discovery mode. Creating exclusions (B) is used to exclude known devices from discovery results, not to control which devices perform discovery.

Topics

#Microsoft Defender for Endpoint#Device Discovery#Unmanaged devices#Security configuration

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice