SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender XDR. You receive an automated investigation that found a malicious file on a device. The investigation recommends 'Block the file'. What does this action do?
⚠ Common exam trap
SC-200 often tests the distinction between different response actions in Defender XDR, such as blocking a file versus isolating a device or running a scan. Candidates may confuse 'Block the file' with deleting the file or isolating the device, but blocking specifically adds the hash to the block list to prevent execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adds the file hash to the block list in Microsoft Defender for Endpoint.
In Microsoft Defender XDR, when an automated investigation finds a malicious file and recommends 'Block the file', the action adds the file's hash to the block list in Microsoft Defender for Endpoint. This prevents the file from executing on any device in the organization by leveraging the indicator of compromise (IoC) system. It does not isolate devices, initiate scans, or delete files; it simply blocks future execution based on the hash.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Adds the file hash to the block list in Microsoft Defender for Endpoint.
Why this is correct
The 'Block file' action in Microsoft Defender for Endpoint (MDE) adds the file's SHA-256 hash to the organization's custom threat intelligence indicators, which are enforced by the MDE cloud block list. This preventive control immediately prevents the file from executing on any device onboarded to MDE, including future instances of the same hash. It is a tenant-wide action and does not require the original device to remain connected, as the block is propagated through the cloud.
- ✗
Isolates the device where the file was found.
Why it's wrong here
Isolating a device is a separate containment action that severs the device's network connectivity from the rest of the network while maintaining a management channel to MDE. This is performed to contain an active attack on a specific endpoint, not to prevent a known file from running. The 'Block file' action does not isolate the originating device; it blocks execution of the file across all endpoints, leaving devices otherwise operational and connected.
- ✗
Initiates a full antivirus scan on all devices.
Why it's wrong here
Initiating a full antivirus scan is an independent remediation action that triggers Microsoft Defender Antivirus to scan all files and folders for malware on selected devices. This is a reactive, periodic or on-demand operation, whereas blocking a file hash is a proactive, immediate prevention mechanism. The 'Block file' action does not schedule or run any scans; it only adds the hash to a block list that is checked before any process execution.
- ✗
Deletes the file from all devices in the organization.
Why it's wrong here
Deleting a file is a separate response action that removes the file from the disk on affected endpoints, often after a scan identifies it as malicious. However, the 'Block file' action is purely preventive; it stops the file from executing but does not delete existing copies from any device. Blocking a hash is safer in environments where automatic deletion could break legitimate workflows, and it does not require locating every instance of the file beforehand.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.