SC-200 Practice Question 3707
Exam: SC-200
Domain: Manage a security operations environment
Difficulty: medium
You need to ensure that an alert generated in Defender for Endpoint automatically isolates a machine when ransomware behavior is detected. What setting governs this autonomous action?
Answer Options
A
Automated Investigation and Response (AIR) in Full Automation mode
B
Semi-automated mode requiring manual email confirmation
C
Audit mode logging alerts without action
D
Disabled automation level
Correct Answer
A: Automated Investigation and Response (AIR) in Full Automation mode
Explanation
Automated Investigation and Response (AIR) configured with the "Full - remediate threats automatically" automation level executes remediation and containment without waiting for human approval.