SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender XDR. A security administrator reports that a user's device is showing high severity alerts for 'Tampering with Microsoft Defender Antivirus' but the device is not isolated. You need to ensure that when such alerts occur, the device is automatically isolated in Microsoft Defender for Endpoint. What should you do?
⚠ Common exam trap
A common mix-up: candidates confuse automation rules in Microsoft Sentinel (which handle incidents) with custom detection rules in Defender XDR (which handle raw alerts and can trigger direct automated actions), leading them to choose Option A despite Sentinel not being the native tool for this specific Defender-for-Endpoint isolation requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom detection rule in Microsoft Defender XDR
Microsoft Defender XDR's custom detection rules allow you to create automated actions based on specific alert triggers, such as 'Tampering with Microsoft Defender Antivirus'. By configuring a custom detection rule with an automated response action (e.g., 'Isolate device'), you can ensure the device is automatically isolated in Microsoft Defender for Endpoint when the alert occurs, without requiring manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an automation rule in Microsoft Sentinel
Why it's wrong here
Automation rules in Microsoft Sentinel are incident-centric: they run against security incidents (e.g., to assign severity, change status, or invoke a playbook) and have no built-in action to isolate an endpoint. Any device isolation from Sentinel would require a separate Logic Apps playbook that calls the Microsoft Defender for Endpoint API, making it an indirect, multi-step integration rather than a native automatic response on the device itself.
- ✗
Create an endpoint detection and response policy in Microsoft Intune
Why it's wrong here
An endpoint detection and response policy in Microsoft Intune is a configuration profile used to onboard devices to Microsoft Defender for Endpoint and to manage settings such as sample collection, automatic investigation, or EDR telemetry. It does not define threat-specific detection logic nor does it provide automatic response actions like device isolation; those decisions belong to the Defender for Endpoint/Defender XDR detection engine, not to Intune's policy-based device management.
- ✓
Create a custom detection rule in Microsoft Defender XDR
Why this is correct
Custom detection rules in Microsoft Defender XDR are built with KQL queries over the advanced hunting schema (such as DeviceProcessEvents or DeviceNetworkEvents) and allow you to set automatic response actions directly, including 'Isolate device' as a triggered action. When the query matches a device, the rule natively instructs the Defender for Endpoint sensor to isolate that machine immediately, which is exactly the capability the scenario requires. This is the only option that both detects a suspicious behavior and executes a device-level containment action without relying on external automation.
- ✗
Configure an attack surface reduction rule
Why it's wrong here
Attack surface reduction (ASR) rules are predefined, scenario-based policies that prevent specific behaviors—such as launching executable content from email or blocking Office apps from creating child processes—before they happen. They are a prevention mechanism and do not include any response action like device isolation; they either block or audit an activity, but they cannot retroactively isolate an endpoint after a detection. Thus, ASR rules focus on shrinking the attack surface rather than automatically responding to an alert with containment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.