mediumMultiple ChoiceObjective-mapped
SC-200 Microsoft 365 Defender Practice Question
An organization uses Microsoft 365 Defender. An automated investigation on a device identifies a malicious file and blocks it. The analyst now wants to allow a specific trusted application that was incorrectly blocked, while keeping other malicious files blocked. Which action should the analyst take from the device's entity page?
⚠ Common exam trap
Test-takers frequently confuse the 'Add indicator' feature with manual file deletion or changing global investigation settings, not realizing that a custom IOC with an Allow action is the precise mechanism to override a block for a specific trusted file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'Add indicator' feature to create a custom IOC for the file hash with action 'Allow'.
The 'Add indicator' feature in Microsoft Defender XDR allows analysts to create custom indicators of compromise (IOCs) based on file hashes, IPs, or domains. By setting the action to 'Allow' for the specific file hash, the analyst can override the automated block for that trusted application while keeping other malicious files blocked. This is the correct approach because it provides granular control without affecting the overall automated investigation settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Initiate a live response session and delete the file manually.
Why it's wrong here
Initiating a live response session to delete the file is counterproductive because the objective is to permit the file, not remove it. Even if the file is deleted from an endpoint, the automated investigation's verdict remains 'blocked', and the file will continue to be blocked on other devices. Live response actions do not create an allow decision or override the threat intelligence verdict; only an indicator with an 'Allow' action can explicitly authorize the file hash.
- ✓
Use the 'Add indicator' feature to create a custom IOC for the file hash with action 'Allow'.
Why this is correct
Creating a custom indicator for the file hash with the 'Allow' action instructs Microsoft Defender for Endpoint (and connected Microsoft 365 Defender services) to treat the file as trusted, overriding the automated investigation's block. This indicator is a tenant-level override that applies to all monitored devices and allows the file to run without triggering future alerts. After adding the indicator, the file is permitted and the automated investigation's block is effectively removed.
- ✗
Change the automated investigation settings to 'No action' and rerun investigation.
Why it's wrong here
Modifying the automated investigation settings to 'No action' only alters how future automated investigations respond; it does not retroactively affect the current block. Rerunning the investigation would still assess the file as malicious and may re-block it, because no allow decision has been recorded for that file hash. The correct way to override an existing verdict is to add an allow indicator, not to change global automation settings.
- ✗
Collect the file for analysis; the allow decision must be made by Microsoft after analysis.
Why it's wrong here
Submitting the file for analysis is a way to request a Microsoft verdict, but it is asynchronous and does not provide an immediate allow for the currently blocked file. The organization's own analysts have the authority to create an 'Allow' indicator for the file hash in Microsoft 365 Defender without waiting for Microsoft's analysis. Relying solely on analysis submission leaves the file blocked until a third-party decision is made, whereas an indicator gives immediate, tenant-wide control.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization uses Microsoft 365 Defender. An automated investigation on a device has determined that a file is malicious and has been blocked. The analyst wants to verify that the file was blocked and see the action taken (e.g., block, allow). Which entity page provides this information?
medium- ✓ A.File entity page
- B.Device entity page
- C.User entity page
- D.Email entity page
Why A: The File entity page in Microsoft Defender XDR provides a centralized view of a file's reputation, detection details, and the specific actions taken (e.g., blocked, allowed, quarantined) during automated investigations. Since the analyst needs to confirm the block action on a specific malicious file, this page directly displays the investigation result and the applied remediation action.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.