Courseiva

SC-200 Full isolation Practice Question

Your company uses Microsoft Defender XDR. During a ransomware incident, you need to isolate a compromised Windows 10 device from the network while allowing connectivity to the Microsoft Defender for Endpoint service. Which action should you take?

⚠ Common exam trap

SC-200 often tests the difference between full and selective isolation; the trap is choosing selective isolation thinking it blocks external threats while allowing internal management, when ransomware containment requires full isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate a Full isolation from the device's action menu.

Full isolation from the device's action menu is correct because in Microsoft Defender XDR, full isolation blocks all network traffic to and from the device except for the Defender for Endpoint service communication channel. This allows the security team to contain ransomware spread while still managing the device and running remediation actions through the Defender portal. Selective isolation, by contrast, only blocks external connections and permits internal ones, which is insufficient for ransomware containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Initiate a Full isolation from the device's action menu.

    Why this is correct

    Initiating Full isolation from the device's action menu in Microsoft Defender XDR is the correct response because it immediately blocks all network traffic to and from the compromised device except for communication with the Defender for Endpoint service. This keeps the sensor and cloud command channel alive, allowing remediation actions like antivirus scans and collected forensic packages to be delivered. It is a policy-driven, reversible action that prevents ransomware from spreading laterally or reaching command-and-control while preserving your ability to investigate and respond.

  • ✗

    Contain the device from the Microsoft Defender XDR portal.

    Why it's wrong here

    Containing the device from the Microsoft Defender XDR portal is not an isolation method because containment leverages conditional access and risk policies to restrict the device's ability to reach other resources over the network, but it does not block the device's own outbound or internal network traffic. The ransomware can still communicate with its C2 server or encrypt files on mapped drives, and the device's network stack remains fully functional. Unlike full isolation, containment is designed to limit lateral movement through authentication controls, not to sever network communications, so it cannot stop the active attack in progress.

  • ✗

    Apply a firewall rule to block all outbound traffic.

    Why it's wrong here

    Applying a firewall rule to block all outbound traffic is an inadequate and potentially harmful manual workaround because it would also block communication with Microsoft Defender for Endpoint services, breaking the telemetry channel and preventing the portal from sending response commands. A local firewall rule is unaware of Defender's own allowed service endpoints, so the device becomes unmanageable and the incident response is effectively blind. Additionally, this approach does not stop inbound lateral movement from other compromised hosts and is prone to misconfiguration, making it far less reliable than the built-in isolation action which is centrally managed and audited.

  • ✗

    Run a selective isolation to block only external connections.

    Why it's wrong here

    Selective isolation is not a feature in Microsoft Defender XDR's manual device response actions—the only network isolation option available is Full isolation, which blocks all network traffic except to Defender services. 'Blocking only external connections' would require a custom firewall setup, not a native Defender action, and would still leave the device exposed to lateral movement from compromised internal hosts. Since this option represents a nonexistent action, it cannot provide the required containment and would delay the correct response of full isolation.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.