exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 5 question 6 discussion

Actual exam question from Microsoft's SC-200
Question #: 6
Topic #: 5
[All SC-200 Questions]

You have 500 on-premises devices.

You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365.

You onboard 100 devices to Microsoft Defender 365.

You need to identify any unmanaged on-premises devices. The solution must ensure that only specific onboarded devices perform the discovery.

What should you do first?

  • A. Create a device group.
  • B. Create an exclusion.
  • C. Set Discovery mode to Basic.
  • D. Create a tag.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DChilds
Highly Voted 1 year, 2 months ago
Selected Answer: C
C https://learn.microsoft.com/en-us/defender-endpoint/device-discovery?view=o365-worldwide
upvoted 7 times
sebas12345
1 year ago
Basic discovery: In this mode, endpoints passively collect events in your network and extract device information from them. Basic discovery uses the SenseNDR.exe binary for passive network data collection and no network traffic is initiated. Endpoints extract data from all network traffic seen by an onboarded device. With basic discovery, you only gain limited visibility of unmanaged endpoints in your network.
upvoted 2 times
OneplusOne
1 month, 3 weeks ago
Basic is like passive, no network traffic is initiated. With standard, there will be an active discovery run on the network. So definitely not C.
upvoted 1 times
...
...
...
Optimizor_IT
Most Recent 3 months, 2 weeks ago
Selected Answer: A
First, create a device group to include only the specific onboarded devices you want as discovery agents (e.g., 10 of the 100). Then, in Settings > Endpoints > Device discovery, set “Devices that will perform discovery” to “Only devices in specified device groups” and select your group. A device group (A) or tag (D) can do this, but A is the stronger starting point because: Groups are purpose-built for policy assignment in Defender. Groups support dynamic membership (e.g., based on attributes), unlike tags (manual). Post-group creation, you can configure discovery settings to use only that group.
upvoted 2 times
...
Tamataya
4 months, 2 weeks ago
Selected Answer: C
It is C according to ChatGPT
upvoted 1 times
...
HAjouz
4 months, 3 weeks ago
Selected Answer: C
C. Set Discovery mode to Basic.
upvoted 1 times
...
Tuitor01
7 months, 2 weeks ago
Selected Answer: D
Can I control which devices perform Standard discovery? You can customize the list of devices that are used to perform Standard discovery. You can either enable Standard discovery on all the onboarded devices that also support this capability (currently Windows 10 or later and Windows Server 2019 or later devices only) or select a subset or subsets of your devices by specifying their device tags. In this case, all other devices are configured to run Basic discovery only. The configuration is available in the device discovery settings page.
upvoted 3 times
...
sapphire
8 months, 1 week ago
Selected Answer: D
Select tags https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery-faq
upvoted 2 times
Sparkletoss
8 months ago
The answer is C based on this link With basic discovery, you only gain limited visibility of unmanaged endpoints in your network. https://learn.microsoft.com/en-us/defender-endpoint/device-discovery?view=o365-worldwide
upvoted 1 times
...
...
VeiN
8 months, 3 weeks ago
Selected Answer: D
You need to create a tag. By default Standard discovery is already turned on. Only when its turned on you can specify what onboarded devices will do Standard discovery. - ALL devices - only the ones which have specific tag So if you create first a tag and select the tag in this setting only those specified devices will do the discovery.
upvoted 2 times
sapphire
8 months, 1 week ago
Correct, I checked in Microsoft Defender. Discovery Setup >> Select which devices to use for Standard discovery: Select tags.
upvoted 1 times
...
...
talosDevbot
9 months, 2 weeks ago
Selected Answer: D
Important point in the question: "The solution must ensure that only specific onboarded devices perform the discovery" Standard discovery is the default and recommended mode. It'll provide results than Basic discovery so you don't need to set it to Basic. You can configure the Standard discovery scan to be performed by all onboarded devices or by a subset of devices. This is configured by specifying their device tag.
upvoted 1 times
...
g_man_rap
11 months ago
The requirement is to ensure that only specific onboarded devices perform the discovery. Simply setting the discovery mode to Basic does not address the need to limit discovery to specific devices. Instead, it changes the scope and intensity of the discovery but applies this setting globally, not selectively to specific devices.
upvoted 2 times
...
g_man_rap
11 months ago
Selected Answer: A
The first step should be to create a device group. By doing so, you can group the specific onboarded devices that you want to perform the unmanaged device discovery. Once the group is created, you can configure discovery settings or apply policies that only affect that group, ensuring that only those specific devices handle the discovery task.
upvoted 1 times
...
ddmitric
11 months, 2 weeks ago
Selected Answer: D
On first look I thought C, but after reading question again and documentation, I would say D is right. "To set up device discovery, take the following configuration steps in Microsoft Defender portal: Navigate to Settings > Device discovery If you want to configure Basic as the discovery mode to use on your onboarded devices, select Basic and then select Save If you've selected to use Standard discovery, select which devices to use for active probing: all devices or on a subset by specifying their device tags, and then select Save"
upvoted 1 times
LOMCLOTRMC
11 months ago
The question asks, "What should I do first?" You've already said that. The answer is C.
upvoted 1 times
...
...
threshclo
11 months, 3 weeks ago
Selected Answer: D
standard scan is needed to specify which devices can perform discovery, so the answer to this question is D.
upvoted 1 times
...
laddu001
1 year, 2 months ago
Set Discovery mode to Basic. T
upvoted 2 times
...
wheeldj
1 year, 2 months ago
Selected Answer: D
Answer D - Create a device tag. https://learn.microsoft.com/en-us/defender-endpoint/device-discovery-faq#can-i-control-which-devices-perform-standard-discovery A- Device groups are not used to specify which device perform discovery scans B- Exclusions are used to exclude specific devices from being scanned, no control which devices perform the scane C- setting discovery mode to basic just controls the type of scan that's performed it doesn't limit scans to only be run from a specific list of devices. D- as per the above article Devices tags can be used to ensure Standard Discovery scans are only performed by specific devices with the assigned tag. All other managed devices are limited to basic scans only. this doesn't quite meet the requirement in the question which infers ALL scans must be limited to specific devices but it is all that MS support and therefore answer D is the closest to meeting this requirement.
upvoted 4 times
4b097e5
1 year ago
I think D is correct as we will need to create a Tag for the devices and than tag these devices which can discover unmanaged devices. Even though the keyword is first, creating a tag should be the first step.
upvoted 2 times
...
kukuliquid
1 year, 2 months ago
The keyword is first. The first think you should do is setup the discovery to basic. Then you can filter which devices can do the scan. It is during that second step that you will specify a tag,
upvoted 2 times
4b097e5
1 year ago
I don't think you can setup a tag to a device if the discovery is set to Basic. The option to to choose 'Select Tag's grey's out in the portal.
upvoted 4 times
...
...
...
ServerBrain
1 year, 2 months ago
Selected Answer: C
Set Discovery Mode to Basic: Configure the Discovery mode for your onboarded devices. Choose Basic discovery mode to passively collect events in your network and extract device information from them. Basic discovery uses the SenseNDR.exe binary for passive network data collection, and no network traffic is initiated. Endpoints extract data from all network traffic seen by an onboarded device. Note that with basic discovery, you gain limited visibility of unmanaged endpoints in your network
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...