Identifying the incident remediation action that requires manual action despite full automation

Respond to alerts and incidents in Microsoft Defender XDR
Answer Correct answer: C — Device isolation is a manual response action and is not performed automatically, even under full automation.

You have a Microsoft 365 E5 subscription. Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for Endpoint. You have an incident involving a user that received malware-infected email messages on a managed device. Which action requires manual remediation of the incident?

  1. soft deleting the email message
  2. hard deleting the email message
  3. isolating the device Correct Answer
  4. containing the device

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Defender for Endpoint's automated investigation can remediate files and some device actions, but device isolation is a manual response action an analyst must initiate, so isolating the device requires manual remediation even under full automation.

With AIR in Defender for Office 365 and full automation in Defender for Endpoint, email remediation (soft/hard delete) and many device actions are automated, but isolating the device is not performed automatically and requires manual remediation.

Assuming full automation isolates devices automatically — device isolation is a manual action; automated investigation does not isolate a managed device on its own.

Community Discussion (6 comments)

laddu001 👍 6
hard deleting the email message
Onimole 👍 1 Selected: C
Defender for Endpoint Plan 1 and Microsoft Defender for Business include only the following manual response actions: Run antivirus scan Isolate device Stop and quarantine a file Add an indicator to block or allow a file
exams_certs 👍 3
Corrent. AIR can soft or hard delete email. MDE don't do isolation as automate response - so this is correct. You can't contain device connected to MDE. You can check it here: https://learn.microsoft.com/en-us/defender-office-365/remediate-malicious-email-delivered-office-365 https://learn.microsoft.com/en-us/defender-endpoint/manage-auto-investigation#remediation-actions https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts
scfitzp 👍 1 Selected: C
https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts
scfitzp 👍 3
https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts Important Defender for Endpoint Plan 1 includes only the following manual response actions: Run antivirus scan Isolate device Stop and quarantine a file Add an indicator to block or allow a file. Microsoft Defender for Business does not include the "Stop and quarantine a file" action at this time.
Fren686478 👍 1
https://learn.microsoft.com/en-us/defender-xdr/m365d-remediation-actions

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for Endpoint automated investigation and response can take many remediation actions automatically, but isolating a device is a manual response action that an analyst must initiate; even with full automation, the system does not automatically isolate the device. Therefore isolating the device is the action that requires manual remediation.

Why the Other Options Are Wrong

Soft deleting (A) and hard deleting (B) email messages are remediation actions Defender for Office 365 AIR can perform automatically. Containing the device (D) via Defender for Endpoint is also handled by automated response, whereas isolation specifically remains a manual step.

Community Comment Notes

The community favors C (100 votes). exams_certs explains that AIR can soft/hard delete email and that Defender for Endpoint does not automate device isolation, and Onimole and scfitzp cite the manual response actions list, confirming isolate device is manual.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide