A security architect is enabling automatic attack disruption in Microsoft Defender XDR so that, on a high-confidence human-operated ransomware detection, the platform can autonomously isolate an affected onboarded Windows device before any analyst intervenes. Endpoint signals are onboarded and automated investigation is running. Which TWO conditions must be satisfied so that the device-isolation disruption action is actually applied to a targeted device? Select TWO.
- AThe targeted device must be actively onboarded to Microsoft Defender for Endpoint with its sensor reporting, so disruption has a managed agent through which to enforce the isolation. Correct
- BA Microsoft Sentinel scheduled analytics rule must be authored to detect the ransomware pattern and call the isolation as its automated response action.
- CThe device group's Microsoft Defender for Endpoint automation level must not be set to no automated response, so automated containment is permitted on that device. Correct
- DA Microsoft Defender XDR custom detection rule with a device-isolation response action must be created and scheduled before disruption can isolate the device.
Why A is correct: Correct: attack disruption isolates a device through the Microsoft Defender for Endpoint sensor, so the device must be onboarded and actively reporting for the action to be enforced.
Why B is wrong: Tempting because Sentinel rules can trigger response automation, but attack disruption is a built-in Microsoft Defender XDR capability that needs no analytics rule, so this is not a prerequisite.
Why C is correct: Correct: if the device group is set to no automated response, automated actions including disruption isolation are blocked, so the automation level must permit automated containment.
Why D is wrong: Tempting because custom detection rules can carry an isolate-device action, but disruption acts on its own high-confidence signals and does not depend on a custom detection rule, so this is incorrect.