SC-200 Practice Question 3745
Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
A SOC analyst is investigating an active ransomware incident in Microsoft Defender XDR. The analyst needs to immediately sever network access to the compromised Windows 11 device while keeping the machine manageable in the cloud. Which action should the analyst select?
Answer Options
A
Execute the "Isolate device" response action
B
Delete the computer object from Microsoft Entra ID
C
Physically unplug the power supply from the machine
D
Reformat the hard drive immediately
Correct Answer
A: Execute the "Isolate device" response action
Explanation
The "Isolate device" response action cuts off all inbound and outbound network connectivity except for communication with the Microsoft Defender for Endpoint cloud service.