Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and Microsoft 365 Defender. You have a playbook that automatically isolates a device when a malware incident is confirmed. The playbook uses the Microsoft Defender for Endpoint connector. During a recent incident, the playbook failed to isolate a device because the device was not found in Defender for Endpoint. Upon investigation, you find that the device is onboarded to Microsoft Defender for Endpoint but the playbook is using an incorrect device ID format. What should you do to ensure the playbook works correctly?

⚠ Common exam trap

SC-200 often tests the integration between Sentinel and Defender, where candidates might focus on onboarding or connector configuration instead of the correct use of incident entities for dynamic values.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the playbook to use the device ID from the incident's entities instead of a manually entered ID.

The playbook failed because it used an incorrect device ID format. The correct approach is to modify the playbook to dynamically retrieve the device ID from the incident's entities, which ensures the correct ID is used. This leverages the integration between Microsoft Sentinel and Microsoft 365 Defender, where incident entities include the proper device ID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensure the device is properly onboarded to Microsoft Defender for Endpoint by running the onboarding script again.

    Why it's wrong here

    Re-running the onboarding script addresses device registration, yet the stem confirms the device is already onboarded and the fault lies in the device ID format passed by the playbook. Onboarding scripts are the right remedy when a device is genuinely unenrolled, not when the identifier is malformed.

  • ✗

    Reconfigure the Microsoft Defender for Endpoint connector in Sentinel to use a different API version.

    Why it's wrong here

    Changing the connector's API version does not correct a malformed device ID, since the identifier is supplied by the playbook, not the connector configuration. API version changes are appropriate when an endpoint or schema is deprecated, not for input-format errors.

  • ✓

    Modify the playbook to use the device ID from the incident's entities instead of a manually entered ID.

    Why this is correct

    Using the incident entity's device ID guarantees the identifier matches Defender for Endpoint's onboarded record, because Sentinel incidents carry the exact machine ID surfaced by the connector. A manually entered ID risks format mismatches, such as Microsoft Entra ID object ID versus Defender machine ID, which caused the lookup failure.

  • ✗

    Use the device name instead of the device ID in the playbook.

    Why it's wrong here

    The Defender for Endpoint connector's isolate action requires the machine's device ID; substituting the device name does not satisfy that parameter and the call still fails. Device names suit human-readable lookups, but the API contract demands the identifier.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.