Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender XDR. You receive an automated investigation that found a malicious file on a device. The investigation recommends 'Block the file'. What does this action do?

⚠ Common exam trap

SC-200 often tests the distinction between different response actions in Defender XDR, such as blocking a file versus isolating a device or running a scan. Candidates may confuse 'Block the file' with deleting the file or isolating the device, but blocking specifically adds the hash to the block list to prevent execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adds the file hash to the block list in Microsoft Defender for Endpoint.

In Microsoft Defender XDR, when an automated investigation finds a malicious file and recommends 'Block the file', the action adds the file's hash to the block list in Microsoft Defender for Endpoint. This prevents the file from executing on any device in the organization by leveraging the indicator of compromise (IoC) system. It does not isolate devices, initiate scans, or delete files; it simply blocks future execution based on the hash.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Adds the file hash to the block list in Microsoft Defender for Endpoint.

    Why this is correct

    The 'Block file' action in Microsoft Defender for Endpoint (MDE) adds the file's SHA-256 hash to the organization's custom threat intelligence indicators, which are enforced by the MDE cloud block list. This preventive control immediately prevents the file from executing on any device onboarded to MDE, including future instances of the same hash. It is a tenant-wide action and does not require the original device to remain connected, as the block is propagated through the cloud.

  • ✗

    Isolates the device where the file was found.

    Why it's wrong here

    Isolating a device is a separate containment action that severs the device's network connectivity from the rest of the network while maintaining a management channel to MDE. This is performed to contain an active attack on a specific endpoint, not to prevent a known file from running. The 'Block file' action does not isolate the originating device; it blocks execution of the file across all endpoints, leaving devices otherwise operational and connected.

  • ✗

    Initiates a full antivirus scan on all devices.

    Why it's wrong here

    Initiating a full antivirus scan is an independent remediation action that triggers Microsoft Defender Antivirus to scan all files and folders for malware on selected devices. This is a reactive, periodic or on-demand operation, whereas blocking a file hash is a proactive, immediate prevention mechanism. The 'Block file' action does not schedule or run any scans; it only adds the hash to a block list that is checked before any process execution.

  • ✗

    Deletes the file from all devices in the organization.

    Why it's wrong here

    Deleting a file is a separate response action that removes the file from the disk on affected endpoints, often after a scan identifies it as malicious. However, the 'Block file' action is purely preventive; it stops the file from executing but does not delete existing copies from any device. Blocking a hash is safer in environments where automatic deletion could break legitimate workflows, and it does not require locating every instance of the file beforehand.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.