nerdexam
Microsoft

SC-200 · Question #296

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains 500 Windows devices. You plan to create a Microsoft Defender XDR custom deception rule. You need…

The correct answer is D. Assign a tag to the devices. To apply a Microsoft Defender XDR custom deception rule to only 10 specific devices, you should first assign a tag to those devices.

Submitted by wei.xz· Apr 18, 2026

Question

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint Plan 2 and contains 500 Windows devices. You plan to create a Microsoft Defender XDR custom deception rule. You need to ensure that the rule will be applied to only 10 specific devices. What should you do first?

Options

  • AAdd custom lures to the rule.
  • BAdd the IP address of each device to the list of decoy accounts and hosts of the rule.
  • CAdd the devices to a group.
  • DAssign a tag to the devices.

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    13% (2)
  • C
    6% (1)
  • D
    75% (12)

Why each option

To apply a Microsoft Defender XDR custom deception rule to only 10 specific devices, you should first assign a tag to those devices.

AAdd custom lures to the rule.

Adding custom lures is part of defining the deception rule's content, but it does not control which devices the rule applies to.

BAdd the IP address of each device to the list of decoy accounts and hosts of the rule.

Adding IP addresses to a decoy list is about configuring the deception itself (what appears as a decoy), not about targeting the rule's application to specific devices.

CAdd the devices to a group.

While grouping devices is a logical step, Defender for Endpoint primarily uses device tags for dynamic grouping and policy targeting for this kind of scenario, rather than a separate 'group' object for rule application.

DAssign a tag to the devices.Correct

In Microsoft Defender for Endpoint, device tags are used to create logical groupings of devices, which can then be used to scope policies, rules, or alerts to specific subsets of devices, making them the primary method for targeting custom deception rules to a limited number of machines. By assigning a unique tag to the 10 devices, you can configure the deception rule to apply exclusively to devices with that tag.

Concept tested: Device tagging for Defender for Endpoint rule targeting

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-device-tags

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice