SC-200 Manage a security operations environment Practice Question
Which TWO actions can be taken directly from the Microsoft Defender XDR incident queue? (Select TWO.)
⚠ Common exam trap
A common mix-up: candidates confuse the Defender XDR incident queue with the broader Microsoft Sentinel workspace, assuming all security operations tasks (like creating rules or modifying data connectors) are available from the incident queue, when in fact only incident-specific response actions are permitted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate a device involved in the incident
The Microsoft Defender XDR incident queue provides direct actions, including device isolation, to contain threats without navigating to separate device management consoles. This capability is built into the incident investigation pane, allowing security analysts to quickly isolate a device involved in an incident from the unified queue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate a device involved in the incident
Why this is correct
From the Microsoft Defender XDR incident queue, you can directly initiate isolation of a device involved in the incident, provided the device is onboarded to Microsoft Defender for Endpoint. This action is available through the device details pane or 'Take actions' menu, allowing an analyst to contain a compromised endpoint immediately. This capability is part of Defender's integrated response tools and does not require Sentinel.
- ✗
Modify a data connector's log collection
Why it's wrong here
Modifying a data connector's log collection cannot be done from Microsoft Defender XDR's incident queue; this configuration belongs to Microsoft Sentinel's data management. Data connector settings control which log sources are ingested and are defined in Sentinel under 'Data connectors', not in the Defender incident interface. Altering log collection would require a separate administrative workflow in the Sentinel workspace.
- ✓
Change the incident status to 'In progress'
Why this is correct
In Microsoft Defender XDR, incidents are triaged directly from the queue. The status field can be updated to 'In progress' without leaving the incident list, enabling security operations teams to immediately reflect that an analyst is actively working the case. This is a core incident management action available in the Defender interface, distinct from Sentinel's incident configuration.
- ✗
Create a new analytics rule
Why it's wrong here
Creating a new analytics rule is not an action you can take directly from a Microsoft Defender XDR incident. Analytics rules are authored in Microsoft Sentinel, where they define detection logic that queries data and triggers alerts and incidents. In Defender XDR, you work with existing incidents that are generated by built-in detections or rules already sent from Sentinel, but rule creation is out of scope for the incident queue.
- ✗
Create an automation rule
Why it's wrong here
Automation rules in the context of incident management are created in Microsoft Sentinel, not directly from the Microsoft Defender XDR incident queue. These rules automate responses, such as assigning owners or running playbooks when incidents meet certain conditions. While Defender XDR has its own automated investigation and response capabilities, the specific 'automation rule' construct is a Sentinel feature and is not available in the Defender incident UI.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.