Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your company uses Microsoft Defender XDR to protect endpoints. The security team wants to implement automated response actions when a malicious file is detected on a device. Which Microsoft security feature should you configure to automatically isolate the affected device from the network?

⚠ Common exam trap

Many exam-takers confuse the proactive prevention capabilities of Attack surface reduction rules with the automated response capabilities of AIR, or they overestimate the real-time response abilities of Intune compliance policies, which are designed for configuration enforcement rather than incident response actions like network isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automated investigation and response (AIR) capabilities

Automated investigation and response (AIR) in Microsoft Defender XDR is the correct feature because it includes built-in playbooks that can automatically isolate a device from the network when a malicious file is detected. AIR leverages the Microsoft 365 Defender portal's automation capabilities to run investigation steps and execute response actions, such as device isolation, without manual intervention. This directly meets the requirement for automated response upon file detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Automated investigation and response (AIR) capabilities

    Why this is correct

    Automated investigation and response (AIR) is a built-in Microsoft Defender XDR engine that orchestrates detection, investigation, and remediation across endpoints. When malicious activity such as a suspected ransomware or credential theft is identified, AIR can automatically perform device isolation — a native action that severs the endpoint's network connections while preserving communication with Defender for Endpoint services. This isolation can be executed without human intervention or with approval depending on the automation level configured, making it the appropriate capability for this requirement.

  • Microsoft Sentinel automation rules

    Why it's wrong here

    Microsoft Sentinel automation rules operate within a cloud SIEM platform and are not native components of Defender XDR's endpoint response stack. They can trigger Azure Logic Apps playbooks that—if custom-built and properly authorized—call APIs like Microsoft Graph to initiate isolation, but this requires external orchestration, custom code, and additional permissions rather than being an intrinsic automated response. Consequently, Sentinel automation rules are incorrect for a requirement centered on Defender XDR's native endpoint isolation.

  • Attack surface reduction rules

    Why it's wrong here

    Attack surface reduction (ASR) rules are a preventive security control that blocks dangerous file types, scripts, or behaviors in real time to reduce how attackers can compromise a host—for example, blocking macros from Office or credential theft via WMI. They do not monitor for post-compromise execution chains or initiate network-level containment; their purpose is purely proactive hardening. Since the requirement demands isolating a device after detection, ASR rules fall short because they never execute response actions like device isolation.

  • Microsoft Intune compliance policies

    Why it's wrong here

    Intune compliance policies evaluate devices against configuration baselines (e.g., OS patch levels, a required Defender for Endpoint health status) and may mark a device as non-compliant, which Conditional Access uses to block cloud app access. However, non-compliance enforcement is limited to access control and does not quarantine the endpoint at the network level; in fact, an isolated device might still be marked compliant if its security configuration is otherwise healthy. Therefore, compliance policies cannot fulfill the explicit need for automated device isolation in response to detected threats.

About these practice questions

This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.