exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 1 question 27 discussion

Actual exam question from Microsoft's SC-200
Question #: 27
Topic #: 1
[All SC-200 Questions]

HOTSPOT -
You have a Microsoft 365 E5 subscription that contains 200 Windows 10 devices enrolled in Microsoft Defender for Endpoint.
You need to ensure that users can access the devices by using a remote shell connection directly from the Microsoft 365 Defender portal. The solution must use the principle of least privilege.
What should you do in the Microsoft 365 Defender portal? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Turn on Live Response -
Live response is a capability that gives you instantaneous access to a device by using a remote shell connection. This gives you the power to do in-depth investigative work and take immediate response actions.

Box: 2 -
Network assessment jobs allow you to choose network devices to be scanned regularly and added to the device inventory.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-machine-alerts?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-devices?view=o365-worldwide

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Lion007
Highly Voted 2 years, 10 months ago
The first answer is correct, but the second answer is wrong. The network assessment job has nothing to do with the question. It is a feature to scan networks and discover network devices for vulnerability management. The correct answer should be "Automation in Full mode", because it is the only correct answer since the last provided answer is to set Automation to "Not automated" which is not correct as per Microsoft docs on Live Response, check it out here "Ensure that the device has an Automation Remediation level assigned to it." https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/live-response?view=o365-worldwide
upvoted 64 times
Nikki0222
6 months, 1 week ago
Correct
upvoted 3 times
...
CatoFong
2 years, 9 months ago
Lion007 is correct. Turn on Live Response >> Automation level to Full
upvoted 9 times
urisoft
2 years, 3 months ago
I subscribe to the above: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/automation-levels?view=o365-worldwide#levels-of-automation
upvoted 1 times
...
...
...
rdy4u
Highly Voted 3 years ago
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/live-response?view=o365-worldwide Ensure that the device has an Automation Remediation level assigned to it. You'll need to enable, at least, the minimum Remediation Level for a given Device Group. Otherwise you won't be able to establish a Live Response session to a member of that group.
upvoted 11 times
...
Adam7777
Most Recent 6 months, 4 weeks ago
1. Turn on Liv response 2. Create a device group that contains the devices and set Automation level to No automated response, because setting "no automated response" ensures that Defender for Endpoint will not automatically take any actions on devices, but users can still use Live Response. This adheres to the principle of least privilege, as users are not granted unnecessary automated control over devices.
upvoted 3 times
...
chepeerick
1 year, 6 months ago
Turn On Live response and full level
upvoted 3 times
...
donathon
1 year, 7 months ago
Turn on Live reponse and Full automation
upvoted 1 times
...
jamclash
1 year, 7 months ago
in exam 9/20/23
upvoted 2 times
...
Marchiano
1 year, 9 months ago
Box 1: Turn on Live Response Fact: Live response requires Automated investigation to be turned on before you can enable it in the advanced settings section in the Microsoft Defender for Endpoint portal. - this also gives the answer to Box 2 Box 2: Create a device group that contains the devices and set Automation level to Full "With no automation, automated investigation doesn't run on your organization's devices." no automation = automated investigation is off, not on, and it needs to be on (Full Remediation) for Live Response to work.
upvoted 2 times
...
ct1984
2 years ago
The second answer is obviosuly wrong. Why isnt this page updated?
upvoted 9 times
...
doch
2 years, 2 months ago
1. Turn On Live Response 2. Automation Level should be full. Ensure that the device has an Automation Remediation level assigned to it. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/live-response?source=recommendations&view=o365-worldwide
upvoted 2 times
...
Fukacz
2 years, 7 months ago
Second need to be full. Whole concept of REMEDIATION during live connect is based on Remediation assigned. If its off, then Live connect wont start.
upvoted 3 times
...
DumbBobJohnson
3 years ago
The second answer should be the last one. It has to have a minimum Remediation level https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/live-response?view=o365-worldwide
upvoted 4 times
vincenttoolate
2 years, 10 months ago
no, the last one is "no automated response", which means "no automation". "Create a device group that contains the devices and set Automation level to full" is the only answer have automation remediation enabled.
upvoted 2 times
avr
2 years, 10 months ago
it says "no automated response" but still is a Remediation Level and the question says "least privileges" so, the second answer should be the last one
upvoted 2 times
...
...
...
abdulwaheed525
3 years ago
The second answer for the creation of a network assessment job is confusing. Could someone explain?
upvoted 1 times
StaxJaxson
2 years, 11 months ago
Its a red herring - its wrong - nothing to do with AIR/LR.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago