Microsoft SC-200 Question Answer
You have the following advanced hunting query in Microsoft 365 Defender.

You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
Microsoft SC-200 Summary
- Vendor: Microsoft
- Product: SC-200
- Update on: May 9, 2026
- Questions: 379

