easyMultiple ChoiceObjective-mapped
SC-200 Automated Investigation and Response (AIR) Practice Question
A security analyst is investigating an incident in Microsoft 365 Defender where a device is detected as infected with a trojan. The analyst wants to use automated investigation to contain the threat. Which action can be automatically taken on the affected device as part of a standard AIR playbook for endpoint detection and response?
⚠ Common exam trap
Many candidates confuse 'run a full antivirus scan' (a remediation action) with 'containment' (a first-step action), leading them to select Option B instead of recognizing that isolation is the primary automated containment action in the AIR playbook.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Initiate a device isolation.
In Microsoft Defender for Endpoint, the Automated Investigation and Response (AIR) playbook for endpoint detection and response includes the ability to isolate a device from the network. This action stops the device from communicating with other devices or the internet, containing the threat while allowing the investigation to continue. Option D is correct because device isolation is a standard containment action in the AIR playbook for trojan infections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the user account from the device.
Why it's wrong here
Removing the user account from the device is not an automated containment action in Microsoft 365 Defender AIR playbooks. Device compromise playbooks focus on halting attacker activity at the host and network level, whereas account deletion is an identity-resource remediation step typically reserved for compromised user accounts. Deleting the account would also destroy user-profile forensic evidence and complicate attribution, and it does not stop malware already executing on the device.
- ✗
Execute a full antivirus scan on the device.
Why it's wrong here
Executing a full antivirus scan is a post-containment investigation or remediation step, not a containment action. While an AIR playbook may eventually run a scan to identify and remove malware, the scan alone does not interrupt network communications or prevent the attacker from moving laterally. During the scan, the device remains fully connected to the network, so the threat can continue spreading, making isolation the prerequisite containment control.
- ✗
Disable the network adapter.
Why it's wrong here
Disabling the network adapter is not a standard automated action in Microsoft 365 Defender AIR. Although it would cut network connectivity, it also severs the management channel to Defender for Endpoint and other Microsoft 365 services, preventing live response, monitoring, and coordinated remediation. Device isolation is preferred because it applies a firewall-level restriction that blocks all traffic except allowed Defender service communications, preserving manageability while achieving containment.
- ✓
Initiate a device isolation.
Why this is correct
Initiating device isolation is the correct containment action for an impacted device in Microsoft 365 Defender AIR. Device isolation quarantines the endpoint by enforcing a firewall policy that drops all inbound and outbound traffic except communication with Defender for Endpoint services, which keeps the device manageable and allows AI and analysts to continue investigation or remediation. This action directly limits the attacker's ability to move laterally or exfiltrate data, and it is auditable and reversible when the investigation concludes.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.