SC-200 Respond to security incidents Practice Question
During an incident, an analyst wants to use Microsoft Defender XDR's automatic attack disruption to contain an ongoing attack. What prerequisite must be met?
⚠ Common exam trap
Many candidates confuse the broader Microsoft security ecosystem (Purview, Sentinel, Microsoft Entra ID P2) as prerequisites for Defender XDR's automated response, when in fact the core requirement is simply having devices onboarded to Microsoft Defender for Endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Devices must be onboarded to Microsoft Defender for Endpoint.
Microsoft Defender XDR's automatic attack disruption relies on Microsoft Defender for Endpoint (MDE) signals to automatically contain compromised devices or user accounts. Devices must be onboarded to MDE so that the high-confidence alerts (e.g., from ransomware or lateral movement) can trigger automated containment actions like device isolation or blocking an IP. Without MDE onboarding, the attack disruption engine has no endpoint telemetry or remediation capability to act upon.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Devices must be onboarded to Microsoft Defender for Endpoint.
Why this is correct
Automatic attack disruption in Microsoft Defender XDR executes active containment responses—such as isolating devices or blocking indicators—based on real-time endpoint signals. These signals only exist when devices are onboarded to Microsoft Defender for Endpoint, which deploys the sensor and enables EDR in active mode. Without onboarded endpoints, the service has no telemetry to trigger or apply disruption actions.
- ✗
Microsoft Purview compliance portal must be configured.
Why it's wrong here
The Microsoft Purview compliance portal governs data lifecycle, records management, and regulatory compliance, but it does not supply any endpoint telemetry or orchestration to Defender XDR. Attack disruption is a security response feature that relies on Defender for Endpoint's sensor and threat intelligence, not on compliance configurations. While Purview might alert on sensitivity labels or data loss prevention rules, it cannot execute the automated device isolation or process blocking used during an incident.
- ✗
Users must have Microsoft Entra ID P2 licenses.
Why it's wrong here
Microsoft Entra ID P2 licenses provide Identity Protection features like risk-based conditional access and privileged identity management, but they are not a licensing dependency for automatic attack disruption. Endpoint attack disruption requires Microsoft Defender for Endpoint and Microsoft Defender XDR, not a specific Microsoft Entra ID tier. An organization could have no Microsoft Entra ID P2 users and still use Defender for Endpoint to isolate compromised machines automatically.
- ✗
Microsoft Sentinel must be enabled and connected to Defender XDR.
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM that ingests and correlates alerts across sources, but it is not required for automatic attack disruption, which runs natively within Defender XDR at the endpoint layer. Although Sentinel can receive rich incident data from Defender XDR and create automated playbooks, the disruption itself executes on Defender for Endpoint devices independently of Sentinel's connector status. Disabling or omitting Sentinel would have no effect on the core attack disruption workflow.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.