SC-200 · Question #296
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains 500 Windows devices. You plan to create a Microsoft Defender XDR custom deception rule. You need…
The correct answer is D. Assign a tag to the devices. To apply a Microsoft Defender XDR custom deception rule to only 10 specific devices, you should first assign a tag to those devices.
Question
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains 500 Windows devices. You plan to create a Microsoft Defender XDR custom deception rule. You need to ensure that the rule will be applied to only 10 specific devices. What should you do first?
Options
- AAdd custom lures to the rule.
- BAdd the IP address of each device to the list of decoy accounts and hosts of the rule.
- CAdd the devices to a group.
- DAssign a tag to the devices.
How the community answered
(16 responses)- A6% (1)
- B13% (2)
- C6% (1)
- D75% (12)
Why each option
To apply a Microsoft Defender XDR custom deception rule to only 10 specific devices, you should first assign a tag to those devices.
Adding custom lures is part of defining the deception rule's content, but it does not control which devices the rule applies to.
Adding IP addresses to a decoy list is about configuring the deception itself (what appears as a decoy), not about targeting the rule's application to specific devices.
While grouping devices is a logical step, Defender for Endpoint primarily uses device tags for dynamic grouping and policy targeting for this kind of scenario, rather than a separate 'group' object for rule application.
In Microsoft Defender for Endpoint, device tags are used to create logical groupings of devices, which can then be used to scope policies, rules, or alerts to specific subsets of devices, making them the primary method for targeting custom deception rules to a limited number of machines. By assigning a unique tag to the 10 devices, you can configure the deception rule to apply exclusively to devices with that tag.
Concept tested: Device tagging for Defender for Endpoint rule targeting
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-device-tags
Community Discussion
No community discussion yet for this question.