Using EDR in block mode to remediate artifacts missed by a third-party antivirus in passive mode

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: A — EDR in block mode lets Defender for Endpoint block and remediate artifacts the passive-mode primary AV missed, so the goal is met.

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 subscription. You have 1,000 Windows devices that have a third-party antivirus product installed and Microsoft Defender Antivirus in passive mode. You need to ensure that the devices are protected from malicious artifacts that were undetected by the third-party antivirus product. Solution: You configure endpoint detection and response (EDR) in block mode. Does this meet the goal?

  1. Yes Correct Answer
  2. No

Community Votes

A
75%
B
25%

75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

EDR in block mode gives Defender for Endpoint the ability to actively block/remediate threats using its own engine even while Defender Antivirus stays passive, closing the gap left by the third-party product.

With 1,000 Windows devices running a third-party AV as primary and Microsoft Defender Antivirus in passive mode, enabling Endpoint Detection and Response (EDR) in block mode lets Defender for Endpoint block and remediate malicious artifacts the primary AV missed, so the solution meets the goal (Yes).

Thinking EDR in block mode is purely reactive and therefore insufficient — it does act post-detection, but that is exactly how it catches artifacts the primary AV failed to flag, which is the stated goal.

Community Discussion (3 comments)

a_kto_to 👍 1 Selected: A
ChetGTP: ✅ Yes, the solution meets the goal. 🛡️ Explanation: EDR in block mode allows Microsoft Defender for Endpoint to block and remediate threats, even when Microsoft Defender Antivirus is in passive mode. So, even though a third-party antivirus is the primary AV, EDR in block mode will: Detect threats using Defender for Endpoint's telemetry. Automatically block or remediate threats that the third-party AV missed. Provide real-time protection against malicious artifacts.
HAjouz 👍 1 Selected: B
B. No. EDR in block mode is a reactive measure. It acts after malicious activity is detected. The goal is to protect against malicious artifacts undetected by the third-party antivirus. EDR won't necessarily detect a file that the antivirus missed unless that file is executed and exhibits suspicious behavior. The scenario requires a proactive approach to find these undetected artifacts.
Shingie 👍 2 Selected: A
Answer: A. Yes Configuring Endpoint Detection and Response (EDR) in block mode meets the goal. EDR in block mode allows Microsoft Defender for Endpoint to detect and remediate malicious artifacts even when Microsoft Defender Antivirus is in passive mode due to the presence of a third-party antivirus. This ensures that threats missed by the third-party antivirus can still be addressed by Microsoft Defender for Endpoint's advanced detection and response capabilities. Thus, enabling EDR in block mode effectively provides the required protection in this scenario.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

EDR in block mode is a Microsoft Defender for Endpoint capability designed for exactly this scenario: a non-Microsoft antivirus is the primary protection while Defender Antivirus runs in passive mode. EDR in block mode lets Defender for Endpoint automatically block and remediate malicious artifacts that the primary AV did not detect, so the solution meets the goal.

Why the Other Option Is Wrong

Answering No (B) misreads EDR in block mode as incapable of addressing missed artifacts; in fact, acting on Defender for Endpoint's own telemetry to block/remediate is its purpose in a passive-mode deployment.

Community Comment Notes

Shingie and a_kto_to both confirm A, explaining that EDR in block mode blocks and remediates threats even when Defender Antivirus is passive. HAjouz argues B on the grounds that EDR is reactive, but the goal is precisely to remediate artifacts the primary AV missed, which EDR in block mode does.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide