Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to automatically isolate a device when a high-severity incident is created. What is the most efficient way to achieve this?

⚠ Common exam trap

It's easy for candidates to confuse automation rules with direct script execution or assume that Defender XDR detection rules can natively perform response actions like isolation, when in fact isolation requires a playbook or automated response configuration outside the detection rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule in Microsoft Sentinel that triggers a playbook, which uses the Microsoft Defender for Endpoint connector to isolate the device.

It leverages Microsoft Sentinel's automation rules to trigger a playbook that uses the Microsoft Defender for Endpoint connector, enabling automated device isolation in response to a high-severity incident. This approach is the most efficient as it combines Sentinel's incident-driven automation with Defender for Endpoint's native isolation action, eliminating manual intervention and ensuring rapid response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually isolate the device from the Microsoft Defender for Endpoint console after the incident is created.

    Why it's wrong here

    Manually isolating the device from the Microsoft Defender for Endpoint console after the incident is created is not an automated response; it depends on an analyst noticing the incident and acting on it, which introduces significant delay and a chance of human error. Sentinel's automation rules are specifically designed to execute instant and consistent actions at incident creation, so a manual step fails the requirement for immediate, automatic isolation. Moreover, manual isolation does not scale when multiple incidents occur simultaneously.

  • ✗

    Create an automation rule in Microsoft Sentinel that runs a PowerShell script to isolate the device.

    Why it's wrong here

    Automation rules in Microsoft Sentinel cannot directly run PowerShell scripts; they natively trigger playbooks (Azure Logic Apps) or perform built-in actions like changing incident status or severity. To execute a script, you would need to embed it in a Logic Apps 'Run a PowerShell script' step, which is not a native integration and adds unnecessary complexity. Since the correct pattern is to call the Defender for Endpoint connector directly from a playbook, this option is technically invalid as stated.

  • ✗

    Create a custom detection rule in Microsoft Defender XDR that triggers device isolation.

    Why it's wrong here

    A custom detection rule in Microsoft Defender XDR can trigger automated actions such as device isolation, but it does so at the alert/device level before the correlated incident is created in Microsoft Sentinel. Because the requirement is to isolate the device after the Sentinel incident is created, this approach bypasses Sentinel's incident-triggered automation workflow. Additionally, it would not leverage Sentinel's automation rules or playbooks, and it would isolate the device regardless of the broader incident context.

  • ✓

    Create an automation rule in Microsoft Sentinel that triggers a playbook, which uses the Microsoft Defender for Endpoint connector to isolate the device.

    Why this is correct

    This is the correct approach because an automation rule in Microsoft Sentinel can be configured to trigger immediately upon incident creation and invoke a playbook. The playbook, built in Azure Logic Apps, uses the Microsoft Defender for Endpoint connector's 'Isolate machine' action to send an isolation command to the device. This provides a fully integrated, automated response that directly ties Sentinel's incident detection to the prescribed containment action, without manual intervention or custom script execution.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.