Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your company uses Microsoft 365 Defender (XDR) for endpoint detection and response. You need to design a solution to automatically remediate malware infections on Windows 10 devices. The solution should isolate the device from the network, run a full antivirus scan, and reset the device if the infection cannot be cleaned. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automated investigation and remediation in Microsoft Defender for Endpoint with action settings: isolate, run AV, and reset.

Enabling automated investigation and remediation in Microsoft Defender for Endpoint with action settings for isolate, run AV, and reset. This directly satisfies the scenario because Defender for Endpoint's AIR capabilities can automatically isolate a compromised Windows 10 device, trigger a full antivirus scan, and reset the device when remediation cannot clean the infection. Option A is manual and does not provide automatic remediation, while option C introduces a third-party tool that is unnecessary and not specified as available. Option D only marks devices non-compliant and requires user action, so it does not isolate, scan, or reset the device automatically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a manual incident response process where analysts remotely connect and run scripts.

    Why it's wrong here

    Manual analyst intervention cannot deliver automatic remediation, and remote script execution lacks Defender's device isolation and reset primitives. It is tempting where automation is untrusted or for bespoke forensic triage, but the scenario demands unattended isolation, scanning and reset, which only automated investigation and remediation provides.

  • ✓

    Enable automated investigation and remediation in Microsoft Defender for Endpoint with action settings: isolate, run AV, and reset.

    Why this is correct

    Automated investigation and remediation in Microsoft Defender for Endpoint executes response actions automatically. Configuring the action settings to isolate the device, run a full antivirus scan, and reset it when cleaning fails satisfies all three remediation requirements without manual intervention.

  • ✗

    Deploy a third-party EDR tool that integrates with Microsoft Sentinel.

    Why it's wrong here

    Third-party EDR integration with Microsoft Sentinel provides detection and orchestration, but Sentinel playbooks cannot natively trigger Defender's isolate device, full scan, or reset actions without the built-in automated investigation and remediation engine. It suits cross-platform correlation and custom response workflows, not native Defender XDR remediation.

  • ✗

    Configure Intune compliance policies to mark infected devices as non-compliant and require user action.

    Why it's wrong here

    Intune compliance policies evaluate device state and flag non-compliance, prompting user remediation rather than executing isolation, scanning or reset actions. It is tempting because it addresses infected endpoints, but automated response requires automated investigation and remediation playbooks in Microsoft 365 Defender.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.