Courseiva
easyMultiple ChoiceObjective-mapped

SC-200 Automated Investigation and Response (AIR) Practice Question

A security analyst is investigating an incident in Microsoft 365 Defender where a device is detected as infected with a trojan. The analyst wants to use automated investigation to contain the threat. Which action can be automatically taken on the affected device as part of a standard AIR playbook for endpoint detection and response?

⚠ Common exam trap

Many candidates confuse 'run a full antivirus scan' (a remediation action) with 'containment' (a first-step action), leading them to select Option B instead of recognizing that isolation is the primary automated containment action in the AIR playbook.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Initiate a device isolation.

In Microsoft Defender for Endpoint, the Automated Investigation and Response (AIR) playbook for endpoint detection and response includes the ability to isolate a device from the network. This action stops the device from communicating with other devices or the internet, containing the threat while allowing the investigation to continue. Option D is correct because device isolation is a standard containment action in the AIR playbook for trojan infections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Remove the user account from the device.

    Why it's wrong here

    Removing the user account from the device is not an automated containment action in Microsoft 365 Defender AIR playbooks. Device compromise playbooks focus on halting attacker activity at the host and network level, whereas account deletion is an identity-resource remediation step typically reserved for compromised user accounts. Deleting the account would also destroy user-profile forensic evidence and complicate attribution, and it does not stop malware already executing on the device.

  • Execute a full antivirus scan on the device.

    Why it's wrong here

    Executing a full antivirus scan is a post-containment investigation or remediation step, not a containment action. While an AIR playbook may eventually run a scan to identify and remove malware, the scan alone does not interrupt network communications or prevent the attacker from moving laterally. During the scan, the device remains fully connected to the network, so the threat can continue spreading, making isolation the prerequisite containment control.

  • Disable the network adapter.

    Why it's wrong here

    Disabling the network adapter is not a standard automated action in Microsoft 365 Defender AIR. Although it would cut network connectivity, it also severs the management channel to Defender for Endpoint and other Microsoft 365 services, preventing live response, monitoring, and coordinated remediation. Device isolation is preferred because it applies a firewall-level restriction that blocks all traffic except allowed Defender service communications, preserving manageability while achieving containment.

  • Initiate a device isolation.

    Why this is correct

    Initiating device isolation is the correct containment action for an impacted device in Microsoft 365 Defender AIR. Device isolation quarantines the endpoint by enforcing a firewall policy that drops all inbound and outbound traffic except communication with Defender for Endpoint services, which keeps the device manageable and allows AI and analysts to continue investigation or remediation. This action directly limits the attacker's ability to move laterally or exfiltrate data, and it is auditable and reversible when the investigation concludes.

About these practice questions

This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.