SC-200 · Question #322
You have a Microsoft 365 E5 subscription. Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for…
The correct answer is C. isolating the device. Despite full automation being enabled for devices, isolating a device in Microsoft Defender for Endpoint, which severely impacts user operations by cutting off network connectivity, is typically an action that requires manual approval or remediation due to its high impact.
Question
You have a Microsoft 365 E5 subscription. Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for Endpoint. You have an incident involving a user that received malware-infected email messages on a managed device. Which action requires manual remediation of the incident?
Options
- Asoft deleting the email message
- Bhard deleting the email message
- Cisolating the device
- Dcontaining the device
How the community answered
(38 responses)- A3% (1)
- B5% (2)
- C82% (31)
- D11% (4)
Why each option
Despite full automation being enabled for devices, isolating a device in Microsoft Defender for Endpoint, which severely impacts user operations by cutting off network connectivity, is typically an action that requires manual approval or remediation due to its high impact.
Isolating a device in Microsoft Defender for Endpoint, which severs all network connections except to Defender services, is a highly disruptive action. While it can be automated with specific advanced settings, it often requires manual approval or remediation due to its significant impact on business operations, even when other automated investigation and response actions are fully enabled.
The term 'containing the device' typically refers to an automated response action, such as limiting the device's communication to prevent further spread of malware, which is generally handled by the full automation capabilities of Microsoft Defender for Endpoint.
Concept tested: Defender for Endpoint automated response limitations
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-automated-investigation-remediation?view=o365-worldwide
Community Discussion
No community discussion yet for this question.