Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security analyst at a company that uses Microsoft Defender XDR. You receive an alert about a potential ransomware activity on a workstation. The alert is generated by Microsoft Defender for Endpoint. You need to contain the threat by isolating the workstation from the network while allowing forensic analysis to proceed. You want to use Microsoft Defender XDR's built-in actions. What should you do?

⚠ Common exam trap

Many exam-takers confuse network isolation with other security controls (like blocking an IP in a CASB or unenrolling from MDM) and fail to recognize that Microsoft Defender XDR's 'Isolate device' is the only built-in action that both contains the threat and preserves forensic access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the 'Isolate device' action from the Microsoft Defender XDR portal.

The 'Isolate device' action in Microsoft Defender XDR (specifically from the Microsoft Defender for Endpoint component) disconnects the device from all network traffic except for the Defender for Endpoint service and a few authorized services (such as Windows Update and the Microsoft Update Service). This allows forensic analysis tools (like Live Response) to continue communicating with the device while preventing the ransomware from spreading laterally or communicating with command-and-control servers. This is the built-in, recommended containment action for such scenarios.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a firewall rule in Microsoft Defender for Cloud Apps to block the device's IP.

    Why it's wrong here

    Microsoft Defender for Cloud Apps operates as a cloud access security broker and can apply conditional access app control or block a user's access to sanctioned SaaS apps, but it does not provide host-level isolation for an onboarded Windows endpoint. Blocking the device's IP only affects traffic that traverses the CASB proxy for cloud apps; internal network traffic, lateral movement, and non-cloud destinations remain unimpeded. It is not a recognized containment action in the Microsoft Defender XDR incident response workflow.

  • ✓

    Use the 'Isolate device' action from the Microsoft Defender XDR portal.

    Why this is correct

    Use the 'Isolate device' action from the Microsoft Defender XDR portal, which invokes Defender for Endpoint's machine isolation and breaks the attack chain by severing all inbound and outbound network traffic, except traffic between the device and the MDE cloud service plus any forensic processes you explicitly allow. This preserves the agent's ability to receive future commands and send telemetry, enabling continued investigation while the threat actor loses connectivity. It is the direct, built-in containment action for an endpoint in an incident.

  • ✗

    Unenroll the device from Microsoft Intune.

    Why it's wrong here

    Unenrolling the device from Microsoft Intune is a management lifecycle operation, not a security containment step. It removes the MDM profile, compliance policies, and potentially the Defender for Endpoint configuration if co-management settings depend on Intune, so you would lose visibility and control exactly when the device is compromised. The device could even become less restricted, allowing the threat to persist or move laterally without management interference.

  • ✗

    Disable the network adapter on the workstation remotely.

    Why it's wrong here

    Microsoft 365 and Microsoft Defender XDR do not expose a native 'disable network adapter' action, so an analyst cannot perform this from the security portal. Attempting it would require separate remote management tools such as PowerShell/WMI or RMM agents, which may not be present, may be blocked by the attacker, and are not part of a sanctioned automated incident response. Even if executed, severing all network connectivity would also cut off the Defender sensor's telemetry and could prevent further remediation commands, unlike isolation which maintains a controlled channel.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.