Using EDR in block mode to remediate artifacts missed by a third-party antivirus in passive mode
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 subscription. You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode. You need to ensure that the devices are protected from malicious artifacts that were undetected by the third-party antivirus product. Solution: You configure endpoint detection and response (EDR) in block mode. Does this meet the goal?
Community Votes
75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
EDR in block mode gives Defender for Endpoint the ability to actively block/remediate threats using its own engine even while Defender Antivirus stays passive, closing the gap left by the third-party product.
With 1,000 Windows devices running a third-party AV as primary and Microsoft Defender Antivirus in passive mode, enabling Endpoint Detection and Response (EDR) in block mode lets Defender for Endpoint block and remediate malicious artifacts the primary AV missed, so the solution meets the goal (Yes).
Thinking EDR in block mode is purely reactive and therefore insufficient — it does act post-detection, but that is exactly how it catches artifacts the primary AV failed to flag, which is the stated goal.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
EDR in block mode is a Microsoft Defender for Endpoint capability designed for exactly this scenario: a non-Microsoft antivirus is the primary protection while Defender Antivirus runs in passive mode. EDR in block mode lets Defender for Endpoint automatically block and remediate malicious artifacts that the primary AV did not detect, so the solution meets the goal.Why the Other Option Is Wrong
Answering No (B) misreads EDR in block mode as incapable of addressing missed artifacts; in fact, acting on Defender for Endpoint's own telemetry to block/remediate is its purpose in a passive-mode deployment.Community Comment Notes
Shingie and a_kto_to both confirm A, explaining that EDR in block mode blocks and remediates threats even when Defender Antivirus is passive. HAjouz argues B on the grounds that EDR is reactive, but the goal is precisely to remediate artifacts the primary AV missed, which EDR in block mode does.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →