Courseiva

SC-200 Respond to security incidents Practice Question

During a security incident, you need to isolate a compromised Windows device from the network while allowing communication with Microsoft Defender for Endpoint services. Which Microsoft Defender for Endpoint action should you use?

⚠ Common exam trap

Test-takers frequently confuse 'Restrict app execution' with network isolation, not realizing that restricting apps only controls what software can run locally, not the device's ability to communicate over the network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate device

The correct action is 'Isolate device' because it disconnects the compromised Windows device from the network while maintaining a dedicated communication channel to Microsoft Defender for Endpoint (MDE) services. This ensures the device cannot be used to spread laterally or exfiltrate data, yet MDE can still receive telemetry and apply remediation commands. The isolation is enforced via a Windows Filtering Platform (WFP) firewall rule that blocks all inbound and outbound traffic except for MDE-related endpoints (e.g., *.events.data.microsoft.com).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run antivirus scan

    Why it's wrong here

    Running an antivirus scan is a detection and remediation action that looks for known malicious files, but it does nothing to sever the compromised device's network connectivity. While the scan runs, the host can still reach command-and-control servers and other internal systems, so lateral movement or data exfiltration can continue. Malware can also evade a scan using rootkits or fileless techniques, making this ineffective as an isolation measure.

  • ✓

    Isolate device

    Why this is correct

    Device isolation in Defender for Endpoint places the machine in a state where all inbound and outbound network traffic is blocked, except for traffic to the Defender for Endpoint cloud service. This preserves the management channel, allowing security operations to issue further commands, receive telemetry, and complete remediation while the host is quarantined from the network. It directly prevents the attacker from continuing their C2 and lateral movement, making it the correct containment action.

  • ✗

    Collect investigation package

    Why it's wrong here

    Collecting an investigation package bundles forensic artifacts such as event logs, registry hives, memory, and prefetch files into a single archive for offline analysis. This is purely a data-gathering operation and has no effect on the host's network configuration, running processes, or open connections. The attacker's access and any active communications remain fully intact, so this action cannot contain or isolate the compromise.

  • ✗

    Restrict app execution

    Why it's wrong here

    Restricting application execution, for example through AppLocker or Windows Defender Application Control, limits which binaries and scripts are allowed to run, but it does not close any existing network sockets or block traffic. An attacker who already has code running, such as a PowerShell process or a service, can continue operating and communicating even after the policy is applied. It is a hardening measure, not a network containment control, so it fails to isolate the compromised device.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.