SC-200 Practice Question 3771
Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
In Microsoft Defender for Endpoint, what does the "Stop and Quarantine file" action execute when targeted against a detected malicious binary?
Answer Options
A
Terminates running process and moves binary to an isolated encrypted quarantine
B
Deletes the entire C:\Windows directory
C
Emails the binary file to all corporate employees
D
Renames the file to .txt and leaves it on the desktop
Correct Answer
A: Terminates running process and moves binary to an isolated encrypted quarantine
Explanation
It terminates the running process instance of the malicious executable and moves the binary to an isolated encrypted quarantine store on the endpoint.