SC-200 Respond to security incidents • Set 17
SC-200 Respond to security incidents Practice Test 17 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Defender for Endpoint. A user reports that their device is running slowly and exhibiting unusual network activity. You run a live response session and find a suspicious process running. Which action should you take first to contain the threat?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.