exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 5 question 6 discussion

Actual exam question from Microsoft's SC-200
Question #: 6
Topic #: 5
[All SC-200 Questions]

You have 500 on-premises devices.

You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365.

You onboard 100 devices to Microsoft Defender 365.

You need to identify any unmanaged on-premises devices. The solution must ensure that only specific onboarded devices perform the discovery.

What should you do first?

  • A. Create a device group.
  • B. Create an exclusion.
  • C. Set Discovery mode to Basic.
  • D. Create a tag.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DChilds
Highly Voted 1 year ago
Selected Answer: C
C https://learn.microsoft.com/en-us/defender-endpoint/device-discovery?view=o365-worldwide
upvoted 7 times
sebas12345
10 months, 1 week ago
Basic discovery: In this mode, endpoints passively collect events in your network and extract device information from them. Basic discovery uses the SenseNDR.exe binary for passive network data collection and no network traffic is initiated. Endpoints extract data from all network traffic seen by an onboarded device. With basic discovery, you only gain limited visibility of unmanaged endpoints in your network.
upvoted 1 times
...
...
Optimizor_IT
Most Recent 1 month, 1 week ago
Selected Answer: A
First, create a device group to include only the specific onboarded devices you want as discovery agents (e.g., 10 of the 100). Then, in Settings > Endpoints > Device discovery, set “Devices that will perform discovery” to “Only devices in specified device groups” and select your group. A device group (A) or tag (D) can do this, but A is the stronger starting point because: Groups are purpose-built for policy assignment in Defender. Groups support dynamic membership (e.g., based on attributes), unlike tags (manual). Post-group creation, you can configure discovery settings to use only that group.
upvoted 1 times
...
Tamataya
2 months, 1 week ago
Selected Answer: C
It is C according to ChatGPT
upvoted 1 times
...
HAjouz
2 months, 2 weeks ago
Selected Answer: C
C. Set Discovery mode to Basic.
upvoted 1 times
...
Tuitor01
5 months, 1 week ago
Selected Answer: D
Can I control which devices perform Standard discovery? You can customize the list of devices that are used to perform Standard discovery. You can either enable Standard discovery on all the onboarded devices that also support this capability (currently Windows 10 or later and Windows Server 2019 or later devices only) or select a subset or subsets of your devices by specifying their device tags. In this case, all other devices are configured to run Basic discovery only. The configuration is available in the device discovery settings page.
upvoted 2 times
...
sapphire
6 months ago
Selected Answer: D
Select tags https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery-faq
upvoted 1 times
Sparkletoss
6 months ago
The answer is C based on this link With basic discovery, you only gain limited visibility of unmanaged endpoints in your network. https://learn.microsoft.com/en-us/defender-endpoint/device-discovery?view=o365-worldwide
upvoted 1 times
...
...
VeiN
6 months, 2 weeks ago
Selected Answer: D
You need to create a tag. By default Standard discovery is already turned on. Only when its turned on you can specify what onboarded devices will do Standard discovery. - ALL devices - only the ones which have specific tag So if you create first a tag and select the tag in this setting only those specified devices will do the discovery.
upvoted 2 times
sapphire
6 months ago
Correct, I checked in Microsoft Defender. Discovery Setup >> Select which devices to use for Standard discovery: Select tags.
upvoted 1 times
...
...
talosDevbot
7 months, 1 week ago
Selected Answer: D
Important point in the question: "The solution must ensure that only specific onboarded devices perform the discovery" Standard discovery is the default and recommended mode. It'll provide results than Basic discovery so you don't need to set it to Basic. You can configure the Standard discovery scan to be performed by all onboarded devices or by a subset of devices. This is configured by specifying their device tag.
upvoted 1 times
...
g_man_rap
8 months, 4 weeks ago
The requirement is to ensure that only specific onboarded devices perform the discovery. Simply setting the discovery mode to Basic does not address the need to limit discovery to specific devices. Instead, it changes the scope and intensity of the discovery but applies this setting globally, not selectively to specific devices.
upvoted 2 times
...
g_man_rap
8 months, 4 weeks ago
Selected Answer: A
The first step should be to create a device group. By doing so, you can group the specific onboarded devices that you want to perform the unmanaged device discovery. Once the group is created, you can configure discovery settings or apply policies that only affect that group, ensuring that only those specific devices handle the discovery task.
upvoted 1 times
...
ddmitric
9 months, 2 weeks ago
Selected Answer: D
On first look I thought C, but after reading question again and documentation, I would say D is right. "To set up device discovery, take the following configuration steps in Microsoft Defender portal: Navigate to Settings > Device discovery If you want to configure Basic as the discovery mode to use on your onboarded devices, select Basic and then select Save If you've selected to use Standard discovery, select which devices to use for active probing: all devices or on a subset by specifying their device tags, and then select Save"
upvoted 1 times
LOMCLOTRMC
9 months ago
The question asks, "What should I do first?" You've already said that. The answer is C.
upvoted 1 times
...
...
threshclo
9 months, 2 weeks ago
Selected Answer: D
standard scan is needed to specify which devices can perform discovery, so the answer to this question is D.
upvoted 1 times
...
laddu001
1 year ago
Set Discovery mode to Basic. T
upvoted 2 times
...
wheeldj
1 year ago
Selected Answer: D
Answer D - Create a device tag. https://learn.microsoft.com/en-us/defender-endpoint/device-discovery-faq#can-i-control-which-devices-perform-standard-discovery A- Device groups are not used to specify which device perform discovery scans B- Exclusions are used to exclude specific devices from being scanned, no control which devices perform the scane C- setting discovery mode to basic just controls the type of scan that's performed it doesn't limit scans to only be run from a specific list of devices. D- as per the above article Devices tags can be used to ensure Standard Discovery scans are only performed by specific devices with the assigned tag. All other managed devices are limited to basic scans only. this doesn't quite meet the requirement in the question which infers ALL scans must be limited to specific devices but it is all that MS support and therefore answer D is the closest to meeting this requirement.
upvoted 4 times
4b097e5
10 months, 1 week ago
I think D is correct as we will need to create a Tag for the devices and than tag these devices which can discover unmanaged devices. Even though the keyword is first, creating a tag should be the first step.
upvoted 2 times
...
kukuliquid
1 year ago
The keyword is first. The first think you should do is setup the discovery to basic. Then you can filter which devices can do the scan. It is during that second step that you will specify a tag,
upvoted 2 times
4b097e5
10 months, 1 week ago
I don't think you can setup a tag to a device if the discovery is set to Basic. The option to to choose 'Select Tag's grey's out in the portal.
upvoted 4 times
...
...
...
ServerBrain
1 year ago
Selected Answer: C
Set Discovery Mode to Basic: Configure the Discovery mode for your onboarded devices. Choose Basic discovery mode to passively collect events in your network and extract device information from them. Basic discovery uses the SenseNDR.exe binary for passive network data collection, and no network traffic is initiated. Endpoints extract data from all network traffic seen by an onboarded device. Note that with basic discovery, you gain limited visibility of unmanaged endpoints in your network
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago