Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO actions can you perform in Microsoft Defender XDR as part of incident response?

⚠ Common exam trap

Candidates often confuse actions available in Microsoft Defender XDR with those in other Microsoft security services like Microsoft Sentinel or Azure Data Explorer, leading them to select options that are valid in those separate tools but not within Defender XDR's incident response workflow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Collect an investigation package from a device

Option D is correct because Microsoft Defender XDR's device response actions include collecting an investigation package, which gathers forensic artifacts (such as running processes, network connections, and event logs) from an endpoint for offline analysis. Option E is correct because isolating a device from the network is a core Defender XDR live response action that cuts off an endpoint's network connectivity (while optionally allowing Defender communications) to contain a compromised host during incident response. The other options fall outside Defender XDR's native incident response capabilities: Microsoft Sentinel workbooks (A) are authored in Microsoft Sentinel, modifying an Entra ID conditional access policy (B) is done in the Microsoft Entra admin center, and running a KQL query in Azure Data Explorer (C) is an Azure Data Explorer operation, not a Defender XDR response action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Microsoft Sentinel workbook

    Why it's wrong here

    Creating a Microsoft Sentinel workbook is not a Defender XDR response action because workbooks are interactive reports built on Azure Monitor and are a visualization feature of Sentinel, not part of the Microsoft 365 Defender portal. While Sentinel can ingest XDR data, the workbook creation workflow lives in the Sentinel environment to aggregate and present logs from multiple sources. Defender XDR focuses on incident response actions directly on devices, mailboxes, and identities rather than on creating custom dashboards.

  • ✗

    Modify a Microsoft Entra ID conditional access policy

    Why it's wrong here

    Modifying a Microsoft Entra ID conditional access policy is outside the scope of Microsoft Defender XDR response actions because such policies are administered in the Entra ID service and control authentication and access decisions, not post-breach mitigation on an already-compromised device. Defender XDR can surface alerts about suspicious sign-ins that might trigger a CA policy, but it does not have a native action to create or edit CA policies directly from its incident response workflow. This action belongs to identity administrators and requires privileged role permissions distinct from the Defender role-based access controls.

  • ✗

    Run a KQL query in Azure Data Explorer

    Why it's wrong here

    Running a KQL query in Azure Data Explorer is not a Defender XDR response action because ADX is a separate PaaS service for data analytics and does not directly interact with Defender's live response capabilities. While KQL is also used in Defender's advanced hunting, that query interface is embedded in the Microsoft 365 Defender portal and targets the unified XDR data schema, not an external ADX cluster. More importantly, running a query is a hunting or investigative step, not a remediation or containment action that alters the state of a threat.

  • ✓

    Collect an investigation package from a device

    Why this is correct

    Collecting an investigation package from a device is a legitimate Defender for Endpoint response action that bundles the device's relevant forensic artifacts—such as the registry, running processes, network connections, and memory information—into a zip file for offline analysis. It is initiated through the device's action menu, and the package is stored in secure storage for the analyst to download. This action is complementary to isolation and is used to gather evidence without requiring a live remote-command channel to the device.

  • ✓

    Isolate a device from the network

    Why this is correct

    Device isolation in Microsoft Defender for Endpoint is a valid response action that severs the device's connections to the external network while maintaining the management channel to the Defender backend, allowing continued monitoring and forensic collection. It is initiated from the device's entity page or the action center, and you can choose whether to allow outbound communication on a case-by-case basis. This action is critical for containing an active breach without losing visibility.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.