exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 1 question 35 discussion

Actual exam question from Microsoft's SC-200
Question #: 35
Topic #: 1
[All SC-200 Questions]

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.

You need to add threat indicators for all the IP addresses in a range of 171.23.34.32-171.23.34.63. The solution must minimize administrative effort.

What should you do in the Microsoft 365 Defender portal?

  • A. Create an import file that contains the individual IP addresses in the range. Select Import and import the file.
  • B. Create an import file that contains the IP address of 171.23.34.32/27. Select Import and import the file.
  • C. Select Add indicator and set the IP address to 171.23.34.32-171.23.34.63.
  • D. Select Add indicator and set the IP address to 171.23.34.32/27.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RobertDuval
Highly Voted 2 years ago
In Exam today (21 April 2023)
upvoted 15 times
Bit_Shady
1 month ago
Still recent, in exam today (25 mar 2025)
upvoted 1 times
...
...
Valunchai
Highly Voted 2 years, 2 months ago
Selected Answer: A
Test on lab
upvoted 14 times
...
HAjouz
Most Recent 4 weeks, 1 day ago
Selected Answer: D
A is correct but not least admin work
upvoted 1 times
...
dejo
6 months ago
A is corrected, tested!
upvoted 2 times
...
Nikki0222
6 months, 1 week ago
A correct
upvoted 3 times
...
2b0cac4
6 months, 3 weeks ago
Selected Answer: D
Select Add indicator and set the IP address to 171.23.34.32/27. The question asks what is going to save the admin time, entering IPs one at a time as suggested by A isn't the correct option.
upvoted 4 times
1375514
4 months, 3 weeks ago
CIDR is not supported, so listing them out then uploading the file is correct.
upvoted 4 times
...
...
1a144a0
8 months, 1 week ago
Selected Answer: A
Classless Inter-Domain Routing (CIDR) notation for IP addresses is not supported https://learn.microsoft.com/en-us/defender-endpoint/indicator-manage
upvoted 2 times
...
Str4int
9 months, 4 weeks ago
answer A. lassless Inter-Domain Routing (CIDR) notation for IP addresses isn't supported.
upvoted 1 times
...
emartiy
10 months, 4 weeks ago
Selected Answer: C
What Microsoft Copilot AI answers for this question: To add threat indicators for all the IP addresses in the range of 171.23.34.32-171.23.34.63 in Microsoft 365 Defender, follow these steps: Navigate to the Indicators setting: In the Microsoft 365 Defender portal, go to Settings. Choose Cloud Apps. Under System, select IP address ranges. Add the IP address range: Select Add IP address range. Specify the following details: Name: Give a name to your IP range (used for management purposes). IP Address Range: Enter the range as 171.23.34.32-171.23.34.63. C is the correct answer
upvoted 1 times
sergioandreslq
7 months ago
1. Copilot anwered wrong, the question is for MDE, In Copilot answer you are refering to MDCA which is E5. MDE is a feature for Business Premium and E3 license. 2. Wrong B: CIDR is not supported, you need to add ip one-by-one 3. Wrong C, you will need to create one-by-one ip which is a high administrative task. 4. Wrong D: CIDR is not supported, you need to add ip one-by-one The correct answer is A. upload a file with all the ips.
upvoted 2 times
...
emartiy
10 months, 4 weeks ago
D. Select Add indicator and set the IP address to 171.23.34.32/27. (current addition options support this)
upvoted 1 times
sergioandreslq
7 months ago
Wrong D. Reason: Classless Inter-Domain Routing (CIDR) notation for IP addresses is NOT supported https://learn.microsoft.com/en-us/defender-endpoint/indicator-manage
upvoted 1 times
...
...
...
Ramye
1 year, 2 months ago
Selected Answer: A
C and D are not supported. Tested and the system does not allow using the giving range format on these options. Since D is not supported hence, B is not supported either.
upvoted 1 times
...
GermanGerman
1 year, 4 months ago
Selected Answer: B
This approach is the most efficient because: The IP address range 171.23.34.32-171.23.34.63 can be represented using the CIDR (Classless Inter-Domain Routing) notation as 171.23.34.32/27. This notation efficiently covers all the IPs in the specified range. By creating an import file with this CIDR notation and importing it, you can add all the IP addresses in the range at once, significantly reducing the administrative effort compared to adding each IP address individually.
upvoted 2 times
...
kabooze
1 year, 5 months ago
Selected Answer: A
it doesn't recognize ranges or cidr notation
upvoted 1 times
...
chepeerick
1 year, 6 months ago
correct
upvoted 2 times
...
Yaya
1 year, 6 months ago
in exam 20/10/2023.
upvoted 1 times
Dracula666
1 year, 6 months ago
Hope you passed the exam? Was the question in this topic relevant? I have gone through the material from the learning path once and I am completely relying on this questions. Please advice
upvoted 1 times
...
...
Gurulee
1 year, 6 months ago
Selected Answer: A
CIDR not supported
upvoted 1 times
...
jamclash
1 year, 7 months ago
in exam 9/20/23
upvoted 1 times
...
mali1969
1 year, 7 months ago
Selected Answer: D
To add threat indicators for all the IP addresses in a range in Microsoft Defender for Endpoint, you need to use the CIDR notation to specify the subnet that covers the range. The CIDR notation is a compact representation of an IP address and its associated routing prefix. It consists of an IP address followed by a slash and the number of bits in the prefix1. The IP address range of 171.23.34.32-171.23.34.63 can be represented by the CIDR notation of 171.23.34.32/27, which means that the first 27 bits of the IP address are fixed and the remaining 5 bits can vary2. This covers 32 possible IP addresses, from 171.23.34.32 to 171.23.34.63. Therefore, the correct answer is D. Select Add indicator and set the IP address to 171.23.34.32/27
upvoted 1 times
mali1969
1 year, 7 months ago
I changed my answer and correct answer is A
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago