nerdexam
Microsoft

SC-200 · Question #322

You have a Microsoft 365 E5 subscription. Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for…

The correct answer is C. isolating the device. Despite full automation being enabled for devices, isolating a device in Microsoft Defender for Endpoint, which severely impacts user operations by cutting off network connectivity, is typically an action that requires manual approval or remediation due to its high impact.

Submitted by mateo_ar· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription. Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for Endpoint. You have an incident involving a user that received malware-infected email messages on a managed device. Which action requires manual remediation of the incident?

Options

  • Asoft deleting the email message
  • Bhard deleting the email message
  • Cisolating the device
  • Dcontaining the device

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    82% (31)
  • D
    11% (4)

Why each option

Despite full automation being enabled for devices, isolating a device in Microsoft Defender for Endpoint, which severely impacts user operations by cutting off network connectivity, is typically an action that requires manual approval or remediation due to its high impact.

Asoft deleting the email message
Bhard deleting the email message
Cisolating the deviceCorrect

Isolating a device in Microsoft Defender for Endpoint, which severs all network connections except to Defender services, is a highly disruptive action. While it can be automated with specific advanced settings, it often requires manual approval or remediation due to its significant impact on business operations, even when other automated investigation and response actions are fully enabled.

Dcontaining the device

The term 'containing the device' typically refers to an automated response action, such as limiting the device's communication to prevent further spread of malware, which is generally handled by the full automation capabilities of Microsoft Defender for Endpoint.

Concept tested: Defender for Endpoint automated response limitations

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-automated-investigation-remediation?view=o365-worldwide

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice