Courseiva

SC-200 Manage a security operations environment Practice Question

You are managing Microsoft Defender for Endpoint. Which TWO actions can be taken directly from the Microsoft 365 Defender portal to respond to a compromised device?

⚠ Common exam trap

It's easy for candidates to confuse identity-based remediation (like blocking sign-in) with endpoint-based remediation, assuming all security actions are available from the same portal, when in fact Microsoft 365 Defender focuses on device-level responses while identity actions remain in Microsoft Entra ID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a full antivirus scan on the device.

The Microsoft 365 Defender portal allows security operators to initiate a full antivirus scan on a compromised device directly from the device's action menu. This leverages Microsoft Defender Antivirus to detect and remediate threats without requiring local user interaction, providing an immediate response capability within the unified security operations interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run a full antivirus scan on the device.

    Why this is correct

    Running a full antivirus scan is a supported response action in Microsoft Defender for Endpoint. It invokes Microsoft Defender Antivirus to scan the entire device for malware, including persistent threats that may survive a quick scan, and automatically remediates detected threats. This action is initiated from the device's page in the Microsoft 365 Defender portal.

  • ✗

    Block the user's sign-in from Microsoft Entra ID.

    Why it's wrong here

    Blocking a user's sign-in is an identity-level control performed in Microsoft Entra ID, not a device response action in Defender for Endpoint. Defender for Endpoint's response actions operate on the device itself, such as isolating or scanning, while sign-in blocking relies on conditional access policies and user risk assessments in Entra ID. Even if the device is compromised, this action would not remove the threat or contain the device.

  • ✗

    Remotely wipe the device.

    Why it's wrong here

    Remote wipe is an Intune (Microsoft Endpoint Manager) device management action used to erase a device's data, typically for lost or stolen devices, and is not part of Defender for Endpoint's threat response toolkit. Defender for Endpoint focuses on containing and remediating active threats on the device, not full data destruction. Wiping the device would also eliminate forensic evidence needed for investigation.

  • ✓

    Isolate the device from the network.

    Why this is correct

    Isolating the device from the network is a supported Defender for Endpoint response action that blocks all inbound and outbound communication, including network shares, to prevent lateral movement while allowing continued communication with the Defender for Endpoint cloud service. This containment measure is critical for stopping an attacker from spreading to other devices until the threat is fully remediated. It can be applied per-device with a toggle for allowing limited outbound communication if needed.

  • ✗

    Reset the device's local administrator password.

    Why it's wrong here

    Resetting the device's local administrator password is not a response action available in Defender for Endpoint. Local password resets are handled through identity or device management services such as Microsoft Entra ID for hybrid-joined devices or Intune for policy-based management. Defender for Endpoint's scope is threat detection and response, which does not include credential management or password rotation for local accounts.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO actions can be taken directly from the Microsoft Defender XDR incident queue? (Select TWO.)

easy
  • ✓ A.Isolate a device involved in the incident
  • B.Modify a data connector's log collection
  • ✓ C.Change the incident status to 'In progress'
  • D.Create a new analytics rule
  • E.Create an automation rule

Why A: The Microsoft Defender XDR incident queue provides direct actions, including device isolation, to contain threats without navigating to separate device management consoles. This capability is built into the incident investigation pane, allowing security analysts to quickly isolate a device involved in an incident from the unified queue.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.