Design solutions that align with security best practices and priorities →mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your company uses Microsoft Defender XDR to protect endpoints. The security team wants to implement automated response actions when a malicious file is detected on a device. Which Microsoft security feature should you configure to automatically isolate the affected device from the network?
⚠ Common exam trap
Many exam-takers confuse the proactive prevention capabilities of Attack surface reduction rules with the automated response capabilities of AIR, or they overestimate the real-time response abilities of Intune compliance policies, which are designed for configuration enforcement rather than incident response actions like network isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and response (AIR) capabilities
Automated investigation and response (AIR) in Microsoft Defender XDR is the correct feature because it includes built-in playbooks that can automatically isolate a device from the network when a malicious file is detected. AIR leverages the Microsoft 365 Defender portal's automation capabilities to run investigation steps and execute response actions, such as device isolation, without manual intervention. This directly meets the requirement for automated response upon file detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated investigation and response (AIR) capabilities
Why this is correct
Automated investigation and response (AIR) is a built-in Microsoft Defender XDR engine that orchestrates detection, investigation, and remediation across endpoints. When malicious activity such as a suspected ransomware or credential theft is identified, AIR can automatically perform device isolation — a native action that severs the endpoint's network connections while preserving communication with Defender for Endpoint services. This isolation can be executed without human intervention or with approval depending on the automation level configured, making it the appropriate capability for this requirement.
- ✗
Microsoft Sentinel automation rules
Why it's wrong here
Microsoft Sentinel automation rules operate within a cloud SIEM platform and are not native components of Defender XDR's endpoint response stack. They can trigger Azure Logic Apps playbooks that—if custom-built and properly authorized—call APIs like Microsoft Graph to initiate isolation, but this requires external orchestration, custom code, and additional permissions rather than being an intrinsic automated response. Consequently, Sentinel automation rules are incorrect for a requirement centered on Defender XDR's native endpoint isolation.
- ✗
Attack surface reduction rules
Why it's wrong here
Attack surface reduction (ASR) rules are a preventive security control that blocks dangerous file types, scripts, or behaviors in real time to reduce how attackers can compromise a host—for example, blocking macros from Office or credential theft via WMI. They do not monitor for post-compromise execution chains or initiate network-level containment; their purpose is purely proactive hardening. Since the requirement demands isolating a device after detection, ASR rules fall short because they never execute response actions like device isolation.
- ✗
Microsoft Intune compliance policies
Why it's wrong here
Intune compliance policies evaluate devices against configuration baselines (e.g., OS patch levels, a required Defender for Endpoint health status) and may mark a device as non-compliant, which Conditional Access uses to block cloud app access. However, non-compliance enforcement is limited to access control and does not quarantine the endpoint at the network level; in fact, an isolated device might still be marked compliant if its security configuration is otherwise healthy. Therefore, compliance policies cannot fulfill the explicit need for automated device isolation in response to detected threats.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.