You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to implement deception rules. The solution must ensure that you can limit the scope of the rules.
What should you create first? A. device groups
Correct Answer: A
In Microsoft Defender XDR , deception rules (part of the Defender for Endpoint Deception capability) allow security teams to deploy decoys and honeytokens to lure attackers. When configuring deception rules, scope management is essential to control which devices the rule applies to.
According to Microsoft's Defender XDR documentation:
"Deception rules can be targeted to specific devices or sets of devices by assigning them to device groups .
Device groups allow you to manage and scope rules, configurations, and alerts efficiently." Therefore, before creating a deception rule that must apply only to a specific subset of devices, you first create device groups - then assign the deception rule to those groups.
# Final answer: A. device groups