Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO remediation actions are available in Microsoft Defender for Endpoint when responding to a malware infection?

⚠ Common exam trap

SC-200 often tests the boundary between endpoint remediation (MDE), identity actions (Entra ID), and CASB actions (Defender for Cloud Apps) — candidates must pick only the endpoint-native actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a full antivirus scan

Option A (Run a full antivirus scan) is correct because Microsoft Defender for Endpoint's device response actions include initiating a full Microsoft Defender Antivirus scan on the endpoint to detect and remediate residual malware artifacts beyond what was already found. Option E (Isolate the device from the network) is correct because device isolation is a core Defender for Endpoint live response action that cuts the endpoint off from the network (while optionally allowing Outlook/Teams communication) to contain the infection and prevent lateral movement. Option B is not a Defender for Endpoint remediation action; disabling user accounts is handled through identity services such as Active Directory or Entra ID, not the MDE device response console. Option C is not offered as an MDE response action; factory reset is a device-management operation (e.g., Intune), not a Defender for Endpoint remediation. Option D is incorrect because blocking an application in Defender for Cloud Apps is a Cloud App Security (CASB) control for cloud app sessions, not a Defender for Endpoint endpoint remediation action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run a full antivirus scan

    Why this is correct

    A full antivirus scan is a remediation action in Microsoft Defender for Endpoint, detecting and removing residual malware artefacts across the device after an infection. It satisfies the scenario by cleaning persistent threats that remain following initial detection and investigation.

  • ✗

    Disable the user account

    Why it's wrong here

    Disabling a user account is an identity remediation performed in Microsoft Entra ID, not an endpoint action available in Defender for Endpoint's device response. It tempts when compromised credentials caused the infection, where disabling sign-in is the correct containment step.

  • ✗

    Reset the device to factory settings

    Why it's wrong here

    Factory reset is a device-management action performed outside Defender for Endpoint's response console; the portal offers only live-response, isolation, and automated investigation remediation. It tempts as a last resort for persistently re-infected endpoints, but that is handled by reimaging via Intune.

  • ✗

    Block the application in Defender for Cloud Apps

    Why it's wrong here

    Defender for Cloud Apps governs SaaS and cloud app access, not endpoint malware artefacts, so blocking an application there cannot remove a threat on the device. It tempts when the infection arrives through a sanctioned cloud app, where CASB app control is the right layer.

  • ✓

    Isolate the device from the network

    Why this is correct

    Device isolation severs network connectivity while preserving Defender for Endpoint communication, containing the malware infection and preventing lateral movement or command-and-control traffic. This satisfies the remediation requirement by stopping active spread before further investigation and cleanup.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.