nerdexam
Microsoft

SC-200 · Question #154

You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line. You start by…

The correct answer is B. Isolate device. You can't issue either reboot, reinstall or reformat action. You can perform isolation devices. Depending on the severity of the attack and the sensitivity of the device, you might want to isolate the device from the network. This action can help prevent the attacker from…

Submitted by viktor_hu· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Endpoint

Question

You are a SOC Analyst of a company XYZ that has implemented Microsoft Defender for Endpoint. You are allocated an incident with alerts related to a doubtful PowerShell command line. You start by going through the incident and apprehend all the related alerts, devices, and evidence. You open the alert page to evaluate the Alert and choose to perform further analysis on the device. You open the Device page and decide that you require remote access to the device to collect more forensics information using a custom .ps1 script. Which one of the below is a Device action?

Options

  • AReformat device
  • BIsolate device
  • CReboot
  • DReinstall

How the community answered

(21 responses)
  • B
    90% (19)
  • C
    5% (1)
  • D
    5% (1)

Explanation

You can't issue either reboot, reinstall or reformat action. You can perform isolation devices. Depending on the severity of the attack and the sensitivity of the device, you might want to isolate the device from the network. This action can help prevent the attacker from controlling the compromised device and performing further activities such as data exfiltration and lateral https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-machine- alerts?view=o365-worldwide

Topics

#Microsoft Defender for Endpoint#Device actions#Incident response#Threat containment

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice