SC-200 Respond to security incidents • Set 21
SC-200 Respond to security incidents Practice Test 21 — 15 questions with explanations. Free, no signup.
Your security team receives an alert from Microsoft Defender for Endpoint indicating a suspicious PowerShell command was executed on a device. The command attempted to download a payload from a known malicious IP. After confirming the alert is a true positive, what should be your first containment step?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.