nerdexam
Microsoft

SC-200 · Question #418

You have a Microsoft 365 E5 subscription that contains 500 Windows 11 devices. You have a Microsoft Defender for Endpoint deployment that has the following settings: - Discovery mode: Basic - Live…

The correct answer is D. Set Enable EDR in block mode to On. EDR in block mode should be enabled or in passive mode for it to function correctly with the full automated remediation capabilities of Microsoft Defender XDR. EDR in block mode provides a crucial layer of protection for Microsoft Defender Antivirus, and while it's most…

Submitted by skyler.x· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription that contains 500 Windows 11 devices. You have a Microsoft Defender for Endpoint deployment that has the following settings:

  • Discovery mode: Basic
  • Live Response: Disabled
  • Enable EDR in block mode: Off
  • Tamper Protection: Off

You need to implement automatic attack disruption in Microsoft Defender XDR. What should you do?

Options

  • AChange Discovery mode to Standard discovery.
  • BSet Live Response to On.
  • CSet Tamper Protection to On.
  • DSet Enable EDR in block mode to On.

How the community answered

(52 responses)
  • A
    6% (3)
  • B
    15% (8)
  • C
    4% (2)
  • D
    75% (39)

Explanation

EDR in block mode should be enabled or in passive mode for it to function correctly with the full automated remediation capabilities of Microsoft Defender XDR. EDR in block mode provides a crucial layer of protection for Microsoft Defender Antivirus, and while it's most beneficial when MDE is running in passive mode, it is necessary for automatic attack disruption to work https://learn.microsoft.com/en-us/defender-xdr/configure-attack-disruption

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice