Courseiva

SC-200 Manage a security operations environment Practice Question

Your company uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You need to ensure that when a device is determined to be compromised, the device is automatically isolated from the network and a Sentinel incident is updated with the isolation status. What is the most efficient way to achieve this?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Intune compliance policies or conditional access with automated incident response actions, not realizing that only a Sentinel automation rule with a playbook can directly orchestrate both device isolation and incident update in a single, efficient workflow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Microsoft Sentinel automation rule with a playbook that isolates the device and updates the incident

It leverages Microsoft Sentinel's automation capabilities to respond to security incidents without manual intervention. By creating an automation rule that triggers a playbook (an Azure Logic Apps workflow), you can automatically isolate a compromised device via Microsoft Defender for Endpoint APIs and simultaneously update the Sentinel incident with the isolation status. This provides the most efficient, end-to-end automated response directly within the security operations workflow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Have the SOC analyst manually isolate the device from the MDE console and update the incident in Sentinel

    Why it's wrong here

    Manually isolating a device via the MDE console and then separately updating the Sentinel incident introduces operational latency and relies heavily on analyst judgment, so an active threat may continue to spread laterally before the action is taken. The two systems are never automatically synchronized, meaning the incident in Sentinel may remain stale or incomplete, and the process does not scale when multiple incidents occur simultaneously. A manual step also does not leave a consistent, auditable automation trail within Sentinel.

  • ✗

    Configure Microsoft Intune to automatically isolate the device when a compliance policy is violated

    Why it's wrong here

    Intune's compliance policies are designed to enforce device management and configuration baselines, not to act as a real-time response mechanism to security alerts from MDE. When a device falls out of compliance, Intune can mark it noncompliant and trigger Conditional Access policy, but it has no native capability to invoke the MDE device isolation action to quarantine the machine from the network. The signal for a compliance violation is also different from an active threat alert, so tying isolation to this event could either fail to respond to a genuine incident or over-isolate devices for trivial policy drift.

  • ✗

    Use Microsoft Defender XDR conditional access to block the device

    Why it's wrong here

    Microsoft Defender XDR Conditional Access is not an entity; Conditional Access in Microsoft Entra (Microsoft Entra ID) controls access to cloud applications through signals like user or device compliance, but it does not quarantine the device's network stack. Blocking a device with Conditional Access stops new cloud application sessions, yet the endpoint remains physically connected to the private network and can continue to communicate with other hosts or the attacker's command-and-control infrastructure. MDE's device isolation is an endpoint-level network quarantine that disables all non-MDE connectivity, which is a separate and more forceful control than access-blocking.

  • ✓

    Create a Microsoft Sentinel automation rule with a playbook that isolates the device and updates the incident

    Why this is correct

    A Sentinel automation rule can be configured to trigger on incident creation or update, and an associated playbook—an Azure Logic Apps workflow—calls the Microsoft Defender for Endpoint connector to perform a device isolation action while simultaneously updating the Sentinel incident with the isolation status and any analyst notes. This replaces manual steps with orchestration, enabling a consistent and auditable response that eliminates the delay separating detection from containment. The rule can be scoped by severity, entity type, or other conditions, and the playbook can also add a comment to the incident so the SOC can track that the isolation was executed automatically.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.