Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to design a solution that investigates and responds to a ransomware incident. Which three actions should you take? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate affected devices using Microsoft Defender for Endpoint.

Option A is correct because isolating affected devices via Microsoft Defender for Endpoint (using the live response 'isolate device' action) immediately contains the ransomware and prevents lateral spread while investigation continues. Option B is correct because the unified incident timeline in Microsoft Defender XDR correlates alerts, evidence, and entities across endpoints, identities, email, and cloud apps, giving the analyst the full attack story needed to scope and respond to the incident. Option E is correct because running a hunting query (KQL) in Microsoft Sentinel lets you search ingested logs across connected data sources to identify additional affected devices and indicators beyond those already alerted on. Option C is not required for investigation or response; workbooks are for visualization and reporting, not incident triage. Option D is wrong because deleting log data destroys forensic evidence and violates retention requirements, and it does nothing to improve incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Isolate affected devices using Microsoft Defender for Endpoint.

    Why this is correct

    Isolating affected devices with Microsoft Defender for Endpoint is the immediate containment step. Device isolation severs network connections, including inbound and outbound traffic, preventing ransomware from spreading laterally while still allowing the security team to collect forensics via the MDE sensor. The error message displayed to the user can be customized, but the action itself blocks SMB, RDP, and other communication channels.

  • ✓

    Review the incident timeline in Microsoft Defender XDR.

    Why this is correct

    Reviewing the incident timeline in Microsoft Defender XDR provides a unified, chronological view of alerts, entities, and raw events across email, identity, and endpoint signals. This timeline is critical for reconstructing the attack chain, identifying the initial access vector, and understanding how the adversary moved laterally before containment. It aggregates data from both MDE and Microsoft 365 Defender, giving investigators the complete story without switching consoles.

  • ✗

    Create a new workbook to visualize the incident.

    Why it's wrong here

    Creating a new workbook in Microsoft Sentinel constructs a visualization of telemetry data, but it is a passive, dashboarding action with no direct impact on the active incident. Workbooks are designed for ongoing monitoring, reporting, and trend analysis, not for time-sensitive response tasks such as containment or scoping. Since this is a live ransomware event, spending time building a custom visualization delays the immediate steps that would stop the spread and preserve evidence.

  • ✗

    Delete all log data older than 24 hours to improve performance.

    Why it's wrong here

    Deleting log data older than 24 hours is a destructive action that removes forensic evidence essential for investigating the full attack path, which may have started days or weeks earlier as a dwell time. Microsoft Sentinel retains logs on a configurable retention policy, but shortening it for performance would violate data retention best practices and blur the chain of custody. Performance issues in Sentinel are typically addressed through query optimization, not by purging historical data during an active incident.

  • ✓

    Run a hunting query in Microsoft Sentinel to identify affected devices.

    Why this is correct

    Running a hunting query in Microsoft Sentinel, using KQL to correlate events from endpoints, identities, and network devices, helps determine the full scope of the ransomware infection. This is a recommended investigative technique to discover other affected devices beyond those already flagged in the XDR incident. However, it is not the immediate first action because containing the known affected devices must happen first to stop additional spread; hunting is best performed in parallel or immediately after isolation.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.