StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 2: Respond to security incidents

Defender for Endpoint response: isolate device, restrict app execution, run antivirus scan, collect investigation package, live response, stop and quarantine file, file indicators, device timeline

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

When an endpoint is involved in an incident, Microsoft Defender for Endpoint (MDE) gives you response actions on the device page and on file pages. Knowing which one fits the situation is a core SC-200 skill, because each action trades containment against disruption to the user. Device actions appear in the top-right menu of the device page; file actions appear on the file page you reach from an alert, the device timeline or a search.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan