Identifying the incident remediation action that requires manual action despite full automation
You have a Microsoft 365 E5 subscription. Automated investigation and response (AIR) is enabled in Microsoft Defender for Office 365 and devices use full automation in Microsoft Defender for Endpoint. You have an incident involving a user that received malware-infected email messages on a managed device. Which action requires manual remediation of the incident?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Defender for Endpoint's automated investigation can remediate files and some device actions, but device isolation is a manual response action an analyst must initiate, so isolating the device requires manual remediation even under full automation.
With AIR in Defender for Office 365 and full automation in Defender for Endpoint, email remediation (soft/hard delete) and many device actions are automated, but isolating the device is not performed automatically and requires manual remediation.
Assuming full automation isolates devices automatically — device isolation is a manual action; automated investigation does not isolate a managed device on its own.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for Endpoint automated investigation and response can take many remediation actions automatically, but isolating a device is a manual response action that an analyst must initiate; even with full automation, the system does not automatically isolate the device. Therefore isolating the device is the action that requires manual remediation.Why the Other Options Are Wrong
Soft deleting (A) and hard deleting (B) email messages are remediation actions Defender for Office 365 AIR can perform automatically. Containing the device (D) via Defender for Endpoint is also handled by automated response, whereas isolation specifically remains a manual step.Community Comment Notes
The community favors C (100 votes). exams_certs explains that AIR can soft/hard delete email and that Defender for Endpoint does not automate device isolation, and Onimole and scfitzp cite the manual response actions list, confirming isolate device is manual.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →