Courseiva
Manage a security operations environmenteasyMultiple ChoiceObjective-mapped

SC-200 Manage a security operations environment Practice Question

Your company is deploying Microsoft Defender for Endpoint. You need to ensure that all devices report their security baseline compliance to Microsoft Intune. Which configuration should you use?

⚠ Common exam trap

Many candidates confuse a generic device configuration profile (Option A) with a Security Baseline policy, not realizing that only the latter provides built-in compliance evaluation and reporting for security baselines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assign a Security Baseline policy in Microsoft Intune to the device groups

Security Baseline policies in Microsoft Intune define a set of pre-configured security settings recommended by Microsoft to harden devices. When assigned to device groups, these policies automatically evaluate and report compliance status for each device, ensuring all devices meet the required security baseline. This directly fulfills the requirement to report security baseline compliance to Intune.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure a device configuration profile in Microsoft Intune

    Why it's wrong here

    A device configuration profile in Microsoft Intune lets you define and deploy custom settings (e.g., device restrictions, endpoint protection policies) to devices, but it does not inherently deliver a compliance assessment against a predefined security baseline. While you can manually configure individual security settings, a profile lacks the versioned, industry-recommended default values and the built-in compliance reporting capabilities that a security baseline policy provides. Without that baseline evaluation, you cannot generate a straightforward compliance report showing which settings deviate from Microsoft's recommended configuration.

  • Deploy Windows Update for Business reports

    Why it's wrong here

    Windows Update for Business reports focuses specifically on the deployment status and compliance of Windows updates (e.g., which devices have installed required updates or need a reboot). It does not assess the broader security baseline settings such as BitLocker configuration, firewall rules, user account control, or administrative template policies. Even if a device is fully patched, it can still be noncompliant with security baseline recommendations, so this service is not a substitute for baseline compliance reporting.

  • Assign a Security Baseline policy in Microsoft Intune to the device groups

    Why this is correct

    Assigning a Security Baseline policy in Microsoft Intune to the device groups is the correct mechanism because security baselines are pre-defined collections of recommended security settings (e.g., from Microsoft's security baseline for Windows) that Intune applies and then evaluates against each device. The Intune console provides a 'Security Baselines' node that shows per-device compliance status, listing every setting that deviates from the baseline version you assigned. This gives you the exact report of compliance against a security baseline, including the ability to compare against different baseline versions.

  • Enable Microsoft Defender for Cloud Apps session controls

    Why it's wrong here

    Microsoft Defender for Cloud Apps session controls are a conditional access capability that acts as a reverse proxy to monitor and control user sessions on cloud apps (e.g., blocking uploads or downloads in SaaS applications). These controls do not assess or report on the local security configuration of managed endpoints, nor do they interact with Intune device baselines. Therefore, enabling session controls is irrelevant to the task of reporting compliance against a security baseline for endpoints.

About these practice questions

Courseiva writes every SC-200 question from scratch — 673 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.