SC-200 Practice Question 3707

Exam: SC-200
Domain: Manage a security operations environment
Difficulty: medium
You need to ensure that an alert generated in Defender for Endpoint automatically isolates a machine when ransomware behavior is detected. What setting governs this autonomous action?

Answer Options

A
Automated Investigation and Response (AIR) in Full Automation mode
B
Semi-automated mode requiring manual email confirmation
C
Audit mode logging alerts without action
D
Disabled automation level

Correct Answer

A: Automated Investigation and Response (AIR) in Full Automation mode

Explanation

Automated Investigation and Response (AIR) configured with the "Full - remediate threats automatically" automation level executes remediation and containment without waiting for human approval.