Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft Exam SC-200 Topic 2 Question 59 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 59
Topic #: 2
[All SC-200 Questions]

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to implement deception rules. The solution must ensure that you can limit the scope of the rules.

What should you create first?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Lilli
6 days ago
Hmm, device groups seem like the logical choice here. I mean, how else are you going to limit the scope of those deception rules? It's like trying to catch a fly with a baseball bat.
upvoted 0 times
...
My
21 days ago
I'm not sure, maybe we should consider device tags as well to better organize the devices.
upvoted 0 times
...
Gail
23 days ago
I agree with Jaclyn, honeytoken entity tags would help limit the scope of the deception rules.
upvoted 0 times
...
Jaclyn
24 days ago
I think we should create honeytoken entity tags first.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77