Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC uses Microsoft Sentinel and Microsoft Defender XDR. An incident is created from a Defender for Endpoint alert about a malware detection on a device. The incident has low priority, but you want to automatically isolate the device from the network if the alert is confirmed as a true positive by the SOC. What is the recommended approach?

⚠ Common exam trap

Many exam-takers confuse automated response capabilities (like immediate isolation in Defender for Endpoint) with the need for human approval in a SOC workflow, leading them to choose Option C without considering the 'confirmed as a true positive' requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule in Microsoft Sentinel that triggers a playbook with an approval step before executing device isolation.

It aligns with the recommended SOC workflow: an automation rule in Microsoft Sentinel triggers a playbook that includes an approval step, ensuring that device isolation only occurs after the SOC confirms the alert as a true positive. This approach maintains human oversight for low-priority incidents while leveraging automation for the response action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a separate analytics rule that triggers on the same alert and uses a playbook to isolate the device.

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are responsible for ingesting signals and generating incidents via alert grouping; they do not natively execute playbooks or contain a direct 'trigger playbook' action. A separate analytics rule firing on the same underlying alert would duplicate incident creation, create alert-suppression conflicts, and still require an automation rule to actually invoke the Logic App. Since the existing alert already produces an incident, the correct path is to attach an approval-gated playbook through an automation rule rather than adding a second rule.

  • ✗

    Use automatic attack disruption in Microsoft Defender XDR to isolate the device automatically.

    Why it's wrong here

    Automatic attack disruption in Microsoft Defender XDR continuously monitors multiple signals and can take autonomous response actions—including isolating a device—when it detects an in-progress, high-confidence attack. These actions are deliberately rapid and do not wait for or require SOC approval, which is exactly the missing human confirmation in this scenario. Although effective for advanced attacks, it is not invoked from Sentinel's incident workflow and cannot provide the controlled, approval-first response the SOC asked for.

  • ✗

    Configure an automated response in Defender for Endpoint to isolate the device immediately when an alert is generated.

    Why it's wrong here

    Defender for Endpoint allows you to create automated response actions such as device isolation that run immediately when an alert is generated. Applying that at alert-trigger time means every alert—regardless of false-positive likelihood or business impact—triggers a disruptive containment action. This unconditional automation lacks the severity assessment, context, and analyst judgment that an approval workflow provides and can quickly lead to unnecessary isolation of healthy or business-critical devices, so it does not satisfy the requirement for SOC confirmation.

  • ✓

    Create an automation rule in Microsoft Sentinel that triggers a playbook with an approval step before executing device isolation.

    Why this is correct

    An automation rule in Microsoft Sentinel runs when an incident is created or updated and can trigger a playbook that includes an approval action—for example, a Microsoft Teams adaptive card or Outlook email requiring a SOC analyst to click Approve. Only after that approval is received does the Logic App continue to the Defender for Endpoint device-isolation step, ensuring a human has actively confirmed the containment decision. This approach also records every action in the playbook's run history and complies with the SOC's requirement to confirm before isolating.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.