Find answers, ask questions, and connect with our
community around the world.

Home Forums Azure SC-200 Review test Set 2 – question 7 from “Manage Incident Response” category

  • SC-200 Review test Set 2 – question 7 from “Manage Incident Response” category

     vnapoli updated 2 months, 3 weeks ago 2 Members · 3 Posts
  • vnapoli

    Member
    April 13, 2026 at 10:36 pm

    Hi ! 🖐🏻

    Why could Defender not automatically isolate the device? 🤔

    This is the third exam I am preparing with Tutorials Dojo and everything is great but for the first time I don’t understand at all the suggested answer 🤷🏻‍♂️

    I tried to ask Claude but it doesn’t know better, even after checking the Microsoft Documentation.

    Thank you in advance for your help 🙏🏻

    Valentin

  • Lois-TutorialsDojo

    Administrator
    April 14, 2026 at 1:52 pm

    Hi Valentin,

    Thanks for sharing your feedback. We completely understand the confusion here.

    The correct answer is isolating the device because Microsoft Defender for Endpoint treats this as a manual action. Based on official Microsoft documentation, device isolation is considered a high-impact response since it disconnects the machine from the network and can disrupt operations.

    Reference: https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts

    Because of this, even with Automated Investigation and Response (AIR) enabled, Microsoft requires security analysts to trigger isolation manually instead of allowing it to run automatically.

    In contrast, actions like quarantining emails, deleting messages, and running scans are low-impact and can be handled automatically.

    We hope this clarifies your question. Please let us know if you have any follow-up questions.

    Regards,

    Lois @ Tutorials Dojo

    • vnapoli

      Member
      April 14, 2026 at 6:05 pm

      Thank you Lois for the clarification 🙏🏻

      So if I understand correctly, device isolation requires manual approval in AIR, which distinguishes between “low-impact” actions (running a scan, quarantining an email, etc.) and “high-impact” actions such as device.

      ➡️ However, is it true that automatic device isolation is still possible via a Sentinel Playbook or a Defender Custom Detection Rule?

      Also, do you have any other example of high-impact actions that need manual validation in AIR? 👌🏻

Viewing 1 - 2 of 2 replies

Log in to reply.

Original Post
0 of 0 posts June 2018
Now
Skip to content