SC-200 Respond to security incidents Practice Question
Which TWO remediation actions are available in Microsoft Defender for Endpoint when responding to a malware infection?
⚠ Common exam trap
SC-200 often tests the boundary between endpoint remediation (MDE), identity actions (Entra ID), and CASB actions (Defender for Cloud Apps) — candidates must pick only the endpoint-native actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a full antivirus scan
Option A (Run a full antivirus scan) is correct because Microsoft Defender for Endpoint's device response actions include initiating a full Microsoft Defender Antivirus scan on the endpoint to detect and remediate residual malware artifacts beyond what was already found. Option E (Isolate the device from the network) is correct because device isolation is a core Defender for Endpoint live response action that cuts the endpoint off from the network (while optionally allowing Outlook/Teams communication) to contain the infection and prevent lateral movement. Option B is not a Defender for Endpoint remediation action; disabling user accounts is handled through identity services such as Active Directory or Entra ID, not the MDE device response console. Option C is not offered as an MDE response action; factory reset is a device-management operation (e.g., Intune), not a Defender for Endpoint remediation. Option D is incorrect because blocking an application in Defender for Cloud Apps is a Cloud App Security (CASB) control for cloud app sessions, not a Defender for Endpoint endpoint remediation action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run a full antivirus scan
Why this is correct
A full antivirus scan is a remediation action in Microsoft Defender for Endpoint, detecting and removing residual malware artefacts across the device after an infection. It satisfies the scenario by cleaning persistent threats that remain following initial detection and investigation.
- ✗
Disable the user account
Why it's wrong here
Disabling a user account is an identity remediation performed in Microsoft Entra ID, not an endpoint action available in Defender for Endpoint's device response. It tempts when compromised credentials caused the infection, where disabling sign-in is the correct containment step.
- ✗
Reset the device to factory settings
Why it's wrong here
Factory reset is a device-management action performed outside Defender for Endpoint's response console; the portal offers only live-response, isolation, and automated investigation remediation. It tempts as a last resort for persistently re-infected endpoints, but that is handled by reimaging via Intune.
- ✗
Block the application in Defender for Cloud Apps
Why it's wrong here
Defender for Cloud Apps governs SaaS and cloud app access, not endpoint malware artefacts, so blocking an application there cannot remove a threat on the device. It tempts when the infection arrives through a sanctioned cloud app, where CASB app control is the right layer.
- ✓
Isolate the device from the network
Why this is correct
Device isolation severs network connectivity while preserving Defender for Endpoint communication, containing the malware infection and preventing lateral movement or command-and-control traffic. This satisfies the remediation requirement by stopping active spread before further investigation and cleanup.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.