MicrosoftMicrosoft
SC-200 · Question #390
SC-200 Question #390: Real Exam Question with Answer & Explanation
Sign in or unlock SC-200 to reveal the answer and full explanation for question #390. The question stem and answer options stay visible for context.
Submitted by certguy· Apr 18, 2026
Question
You have a Microsoft 365 E5 subscription. You need to ensure that an alert is generated in Microsoft Defender XDR when attackers attempt to connect to a specific device. The solution must minimize administrative effort. What should you do in the Microsoft Defender portal?
Options
- ACreate a deception rule that includes a decoy.
- BTag an existing device as a honeytoken entity.
- CCreate a deception rule that includes a lure.
- DTag an existing device as a sensitive entity.
Unlock SC-200 to see the answer
You've previewed enough free SC-200 questions. Unlock SC-200 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.