SC-200 Respond to security incidents Practice Question
A Microsoft Defender XDR incident involves a compromised endpoint. Your containment policy requires isolating the device from the network while still allowing you to run live response commands to collect evidence. You need to choose the appropriate device isolation type in Microsoft Defender for Endpoint. Which isolation type should you select?
⚠ Common exam trap
The trap here is assuming full isolation is always the safest choice, when it can remove the management path needed for live response evidence collection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Selective isolation, which blocks most network traffic but permits the Defender for Endpoint service and live response.
Selective isolation in Microsoft Defender for Endpoint cuts the device off from normal network communication while allowing the Defender for Endpoint service channel and live response. That preserves the analyst's ability to collect evidence through live response commands during containment. Full isolation, perimeter firewall rules, and hash-based indicators either over-restrict, fail to contain roaming devices, or address only a single artifact instead of the host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Selective isolation, which blocks most network traffic but permits the Defender for Endpoint service and live response.
Why this is correct
Selective isolation limits outbound and inbound communication to the Defender for Endpoint service channel and permits live response, so you can still run commands to gather forensic artifacts while the attacker is cut off from command-and-control and lateral movement. This matches the requirement to isolate the device yet retain live response capability. You can later release the device from isolation once remediation is verified.
- ✗
Device containment via a firewall rule that blocks the device's IP address at the perimeter.
Why it's wrong here
A perimeter firewall rule blocks traffic at the network edge but does nothing for a roaming or remote device and does not prevent the endpoint from communicating on the local subnet or over other networks. It also does not integrate with live response. This approach gives a false sense of containment and leaves the compromised host able to reach internal resources when it moves networks.
- ✗
Full isolation, which blocks all network traffic to and from the device.
Why it's wrong here
Full isolation restricts the device to only the Defender for Endpoint cloud service channel, which does technically permit live response, but it also blocks all other network communication including any management or remediation traffic you may still need. The scenario specifically wants evidence collection with live response while keeping the option to interact, and selective isolation is the documented choice that preserves that control path while limiting attacker movement.
- ✗
App execution restriction via an indicator that blocks the malicious process hash.
Why it's wrong here
Blocking a file hash through indicators prevents that specific binary from executing but does not stop the attacker from using other tools, scripts, or living-off-the-land binaries. It also leaves the device fully networked, so lateral movement and exfiltration remain possible. Indicator-based blocking is a surgical control, not a containment action, and does not satisfy the isolation requirement.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.