Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. During an incident investigation, you find that a device is exfiltrating data to an external IP. You need to isolate the device from the network using automated response. Which action should you configure in an automation rule?

⚠ Common exam trap

A common mix-up: candidates confuse 'disabling a device' in Entra ID (which only revokes authentication) with true network isolation, or they may think a DLP policy can stop active network-level exfiltration, when in fact only a Defender for Endpoint isolation action blocks all network traffic at the host level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a playbook that triggers a Microsoft Defender for Endpoint 'Isolate device' action.

The scenario requires network isolation of a device that is actively exfiltrating data. Microsoft Defender for Endpoint provides a built-in 'Isolate device' action that can be triggered via a playbook from a Microsoft Sentinel automation rule. This action immediately blocks all inbound and outbound network traffic to and from the device, except for communication with the Defender for Endpoint service, effectively containing the threat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trigger a Microsoft Purview data loss prevention policy.

    Why it's wrong here

    Microsoft Purview DLP policies are designed to inspect and protect sensitive data by applying rules such as blocking uploads or encrypting files, but they lack any capability to disconnect a device from the network. DLP operates at the data plane, not the network plane, so it cannot contain an adversary who is already exfiltrating via an active network session. Consequently, while DLP is a valuable preventive control, it is not a containment action and does not satisfy the requirement to isolate the compromised endpoint.

  • ✗

    Run a Microsoft Entra ID playbook to disable the device.

    Why it's wrong here

    Disabling a device in Microsoft Entra ID revokes its cloud authentication tokens and blocks interactive sign-in, but it does not alter the device's network connectivity or kill existing sessions and cached credentials. An isolated adversary who already has a foothold can continue transmitting data over the LAN, because Entra ID has no visibility or enforcement at the Layer 2/3 network level. Therefore, an Entra ID playbook can at best accelerate re-authentication failures, but it cannot cut off the exfiltration path that MDE's isolation would sever.

  • ✓

    Run a playbook that triggers a Microsoft Defender for Endpoint 'Isolate device' action.

    Why this is correct

    Running a playbook that invokes the Microsoft Defender for Endpoint 'Isolate device' action is the correct containment response because it actively disconnects the endpoint from the corporate network while preserving a connection to the MDE cloud service for management and forensics. This action terminates all network traffic to and from the device (except low-level MDE communication), immediately stopping data exfiltration and command-and-control traffic. In Sentinel, this playbook can be triggered automatically or manually and is the only listed option that provides a network-level isolation layer.

  • ✗

    Create an automation rule in Microsoft Intune to wipe the device.

    Why it's wrong here

    An Intune automation rule that wipes the device is a destructive recovery action that erases all data and settings, but it does not, by itself, sever the device from the network quickly enough to prevent ongoing exfiltration. Wiping may take time to deploy, can fail if the device is offline or already disconnected, and it removes forensic evidence needed for an incident investigation. Furthermore, Intune's remote wipe is not a supported containment technique in Sentinel response playbooks — Defender for Endpoint's isolate is the recommended immediate containment action.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.