exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 6 question 16 discussion

Actual exam question from Microsoft's SC-200
Question #: 16
Topic #: 6
[All SC-200 Questions]

You have a Microsoft 365 E5 subscription.

Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for Endpoint.

You have an incident involving a user that received malware-infected email messages on a managed device.

Which action requires manual remediation of the incident?

  • A. soft deleting the email message
  • B. hard deleting the email message
  • C. isolating the device
  • D. containing the device
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
laddu001
Highly Voted 10 months, 3 weeks ago
hard deleting the email message
upvoted 6 times
...
Onimole
Most Recent 1 month, 2 weeks ago
Selected Answer: C
Defender for Endpoint Plan 1 and Microsoft Defender for Business include only the following manual response actions: Run antivirus scan Isolate device Stop and quarantine a file Add an indicator to block or allow a file
upvoted 1 times
...
exams_certs
7 months ago
Corrent. AIR can soft or hard delete email. MDE don't do isolation as automate response - so this is correct. You can't contain device connected to MDE. You can check it here: https://learn.microsoft.com/en-us/defender-office-365/remediate-malicious-email-delivered-office-365 https://learn.microsoft.com/en-us/defender-endpoint/manage-auto-investigation#remediation-actions https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts
upvoted 4 times
talosDevbot
7 months ago
Agreed. You can only contain unmanaged devices
upvoted 2 times
...
...
scfitzp
9 months, 3 weeks ago
Selected Answer: C
https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts
upvoted 1 times
...
scfitzp
9 months, 3 weeks ago
https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts Important Defender for Endpoint Plan 1 includes only the following manual response actions: Run antivirus scan Isolate device Stop and quarantine a file Add an indicator to block or allow a file. Microsoft Defender for Business does not include the "Stop and quarantine a file" action at this time.
upvoted 3 times
...
Fren686478
10 months ago
https://learn.microsoft.com/en-us/defender-xdr/m365d-remediation-actions
upvoted 1 times
scfitzp
9 months, 3 weeks ago
This link is for XDR, not MDE. And if this were an accurate citing then the question would be rather terrible because the only thing not listed in that source is containing a device
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago