Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Endpoint. You need to configure a device group that automatically assigns devices to the group based on their domain membership. Devices joined to 'contoso.com' should be in the 'Corporate' group, and all others in 'Non-Corporate'. What should you use?

⚠ Common exam trap

Test-takers frequently assume the domain field can be used directly in device group rules, but Defender for Endpoint does not expose the domain attribute for rule creation; instead, you must use tags applied via GPO or other management tools to achieve domain-based grouping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device group with a rule using the device tag 'Contoso' and assign tags via GPO.

Microsoft Defender for Endpoint device groups can use device tags to automatically assign devices based on domain membership. By creating a device group with a rule that matches the device tag 'Contoso' and assigning that tag to domain-joined machines via Group Policy Object (GPO), you ensure that devices joined to 'contoso.com' are placed in the 'Corporate' group, while all others fall into the default 'Non-Corporate' group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a custom detection rule to move devices based on risk level.

    Why it's wrong here

    Custom detection rules operate on the Microsoft 365 Defender detection pipeline to surface threats and trigger automated response actions; they do not have the ability to modify device group membership or assign devices to a specific group. Risk level is a computed attribute from a device's risk score that can inform policies and conditional access, but you cannot use a custom detection rule to 'move' devices into a device group. Device group membership is determined through group rules or manual assignment in the portal, not through detection logic.

  • ✓

    Create a device group with a rule using the device tag 'Contoso' and assign tags via GPO.

    Why this is correct

    This is the correct approach because Microsoft Defender for Endpoint device groups support rule criteria based on device tags, and device tags can be assigned centrally via Group Policy or Intune. By tagging all Contoso devices with the same device tag and creating a device group rule that matches that tag, you automatically assign the correct devices and keep the group in sync as new devices are onboarded. This is dynamic and scalable, avoiding manual, one-off reconfiguration.

  • ✗

    Create two device groups and manually move devices.

    Why it's wrong here

    Manually creating two device groups and dragging devices into them is possible for a small pilot, but it does not scale for an enterprise and is highly error-prone because every new device requires a manual step to join the right group. Device groups are designed to be dynamic, using rules to automatically include or exclude devices based on attributes such as tag, name, or OS version. Manual assignment also breaks if a device changes its name or is reimaged, since the assignment may be lost.

  • ✗

    Create a device group with a rule using the domain field 'contoso.com'.

    Why it's wrong here

    Device group rules in Microsoft Defender for Endpoint support matching on attributes such as device name, tag, and OS version, but 'domain' is not a valid, selectable rule criterion in the device group rule builder. While domain-joined devices have an Active Directory domain, that field is not exposed for device group rule matching, so a rule using the domain field will not function as intended. To group by domain, you would need to reflect that domain in a device tag and use a tag rule as in the correct approach.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.