SC-200 Practice Question 3745

Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
A SOC analyst is investigating an active ransomware incident in Microsoft Defender XDR. The analyst needs to immediately sever network access to the compromised Windows 11 device while keeping the machine manageable in the cloud. Which action should the analyst select?

Answer Options

A
Execute the "Isolate device" response action
B
Delete the computer object from Microsoft Entra ID
C
Physically unplug the power supply from the machine
D
Reformat the hard drive immediately

Correct Answer

A: Execute the "Isolate device" response action

Explanation

The "Isolate device" response action cuts off all inbound and outbound network connectivity except for communication with the Microsoft Defender for Endpoint cloud service.