Courseiva

SC-200 Respond to security incidents Practice Question

A Microsoft Defender XDR incident involves a compromised endpoint. Your containment policy requires isolating the device from the network while still allowing you to run live response commands to collect evidence. You need to choose the appropriate device isolation type in Microsoft Defender for Endpoint. Which isolation type should you select?

⚠ Common exam trap

The trap here is assuming full isolation is always the safest choice, when it can remove the management path needed for live response evidence collection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Selective isolation, which blocks most network traffic but permits the Defender for Endpoint service and live response.

Selective isolation in Microsoft Defender for Endpoint cuts the device off from normal network communication while allowing the Defender for Endpoint service channel and live response. That preserves the analyst's ability to collect evidence through live response commands during containment. Full isolation, perimeter firewall rules, and hash-based indicators either over-restrict, fail to contain roaming devices, or address only a single artifact instead of the host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Selective isolation, which blocks most network traffic but permits the Defender for Endpoint service and live response.

    Why this is correct

    Selective isolation limits outbound and inbound communication to the Defender for Endpoint service channel and permits live response, so you can still run commands to gather forensic artifacts while the attacker is cut off from command-and-control and lateral movement. This matches the requirement to isolate the device yet retain live response capability. You can later release the device from isolation once remediation is verified.

  • ✗

    Device containment via a firewall rule that blocks the device's IP address at the perimeter.

    Why it's wrong here

    A perimeter firewall rule blocks traffic at the network edge but does nothing for a roaming or remote device and does not prevent the endpoint from communicating on the local subnet or over other networks. It also does not integrate with live response. This approach gives a false sense of containment and leaves the compromised host able to reach internal resources when it moves networks.

  • ✗

    Full isolation, which blocks all network traffic to and from the device.

    Why it's wrong here

    Full isolation restricts the device to only the Defender for Endpoint cloud service channel, which does technically permit live response, but it also blocks all other network communication including any management or remediation traffic you may still need. The scenario specifically wants evidence collection with live response while keeping the option to interact, and selective isolation is the documented choice that preserves that control path while limiting attacker movement.

  • ✗

    App execution restriction via an indicator that blocks the malicious process hash.

    Why it's wrong here

    Blocking a file hash through indicators prevents that specific binary from executing but does not stop the attacker from using other tools, scripts, or living-off-the-land binaries. It also leaves the device fully networked, so lateral movement and exfiltration remain possible. Indicator-based blocking is a surgical control, not a containment action, and does not satisfy the isolation requirement.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.