Home › Forums › Azure › SC-200 Review test Set 2 – question 7 from “Manage Incident Response” category
-
SC-200 Review test Set 2 – question 7 from “Manage Incident Response” category
-
Hi ! 🖐🏻
Why could Defender not automatically isolate the device? 🤔
This is the third exam I am preparing with Tutorials Dojo and everything is great but for the first time I don’t understand at all the suggested answer 🤷🏻♂️
I tried to ask Claude but it doesn’t know better, even after checking the Microsoft Documentation.
Thank you in advance for your help 🙏🏻
Valentin
-
Hi Valentin,
Thanks for sharing your feedback. We completely understand the confusion here.
The correct answer is isolating the device because Microsoft Defender for Endpoint treats this as a manual action. Based on official Microsoft documentation, device isolation is considered a high-impact response since it disconnects the machine from the network and can disrupt operations.
Reference: https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts
Because of this, even with Automated Investigation and Response (AIR) enabled, Microsoft requires security analysts to trigger isolation manually instead of allowing it to run automatically.
In contrast, actions like quarantining emails, deleting messages, and running scans are low-impact and can be handled automatically.
We hope this clarifies your question. Please let us know if you have any follow-up questions.
Regards,
Lois @ Tutorials Dojo
-
Thank you Lois for the clarification 🙏🏻
So if I understand correctly, device isolation requires manual approval in AIR, which distinguishes between “low-impact” actions (running a scan, quarantining an email, etc.) and “high-impact” actions such as device.
➡️ However, is it true that automatic device isolation is still possible via a Sentinel Playbook or a Defender Custom Detection Rule?
Also, do you have any other example of high-impact actions that need manual validation in AIR? 👌🏻
-
Log in to reply.