SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender XDR for threat detection and response. The security team wants to automatically isolate a compromised device when a specific malware alert is triggered, but only if the device is not a critical server. What is the most efficient way to achieve this?
⚠ Common exam trap
Candidates often confuse automation rules (native to Defender XDR) with playbooks (which require external orchestration like Logic Apps), leading them to choose PowerShell or custom detection rules instead of the simpler built-in automation rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an automation rule in Microsoft Defender XDR
Automation rules in Microsoft Defender XDR allow you to define conditions (e.g., malware alert triggered) and actions (e.g., isolate device) with scoping filters (e.g., exclude devices tagged as 'critical server'). This provides a no-code, built-in mechanism that runs automatically without manual intervention or external scripting, making it the most efficient approach for conditional automated response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use advanced hunting to find devices and then manually isolate
Why it's wrong here
Advanced hunting is a Kusto Query Language (KQL)-based threat hunting tool for querying raw telemetry across tables such as DeviceInfo, DeviceProcessEvents, and DeviceNetworkInfo. While it can enumerate potentially compromised devices, it is a read-only investigation interface and has no action engine to execute containment steps; isolating a device from a hunting result would require a separate manual action in Microsoft Defender for Endpoint, which is slow and inconsistent. For automated, policy-driven response, you need an automation rule or playbook that acts on alert triggers, not a hunting query.
- ✗
Use PowerShell scripts in a playbook
Why it's wrong here
A Microsoft Sentinel playbook built on Azure Logic Apps can run PowerShell scripts via the log analytics connector, but this introduces significant overhead: you must integrate Defender XDR with Sentinel, create and monitor the logic app, and ensure the service principal has appropriate permissions to call isolation APIs. Playbooks also execute asynchronously after an incident is created, adding latency and potential failure points, and they are not a native Defender XDR capability. Automation rules are purpose-built for this scenario, providing immediate, reliable response without the need to orchestrate external compute via PowerShell.
- ✓
Configure an automation rule in Microsoft Defender XDR
Why this is correct
Configuring an automation rule in Microsoft Defender XDR is the correct approach because automation rules are native, event-driven response engines that evaluate criteria such as alert title, severity, device group, and incident tags, then automatically perform actions like isolating a device or running an antivirus scan. They are managed centrally, support order of execution for multiple rules, and do not require external services or scripting. This enables an immediate, policy-based containment action precisely when a qualifying alert fires, which is directly aligned with the requirement for automated device isolation.
- ✗
Create a custom detection rule
Why it's wrong here
Custom detection rules in Microsoft 365 Defender are KQL-based scheduled queries that generate alerts when they find matches in the raw event data; they are part of the detection layer and do not include any remediation actions. While a custom detection could surface a suspicious device, it has no capability to isolate that device or run antivirus on it, so it would only add another alert for a human to triage. The actual response—isolation—must be implemented separately, making this option insufficient for automated containment.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.