Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst in Microsoft Sentinel receives an incident with a high severity alert from Microsoft Defender for Identity. The incident description mentions a suspected lateral movement pass-the-hash attack. What should the analyst do first?

⚠ Common exam trap

It's easy for candidates to choose password reset (Option A) thinking it immediately revokes access, but they overlook that the cached NTLM hash on the compromised device remains usable for lateral movement until the device is isolated or the hash is cleared.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the affected device from the network.

The immediate priority in a suspected lateral movement pass-the-hash attack is to contain the threat by isolating the affected device from the network. This prevents the attacker from using the compromised account's NTLM hash to authenticate to other systems, stopping the lateral spread while preserving forensic evidence for further investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reset the password of the compromised account.

    Why it's wrong here

    Resetting the password may invalidate the account's plaintext credentials and eventually force re-authentication, but an attacker who already compromises the host can continue using cached NTLM hashes, Kerberos tickets, or other session tokens. This action is not immediate containment because the lateral movement is already in progress via pass-the-hash, and password changes do not retroactively kill existing authenticated sessions. Thus, while useful as a follow-up, it does not stop the active attack.

  • ✗

    Review the Microsoft Defender for Cloud Apps logs.

    Why it's wrong here

    Microsoft Defender for Cloud Apps is designed to monitor and govern user activity in cloud applications, not the on-premises SMB and NTLM traffic used in pass-the-hash attacks. Since the alert specifically indicates lateral movement across on-premises hosts, reviewing cloud app logs will not reveal or halt the attacker's remote authentication attempts. This action is investigative in the cloud domain and therefore does not serve as a containment measure for the on-premises compromise.

  • ✓

    Isolate the affected device from the network.

    Why this is correct

    Isolating the affected device from the network breaks the attacker's ability to use the compromised host to authenticate to other systems via pass-the-hash, effectively containing the lateral movement at the source. This is an immediate containment action that limits the blast radius while preserving process memory and network evidence for forensic analysis. In Microsoft Defender for Endpoint, 'Isolate device' blocks all inbound/outbound traffic except to the Defender service.

  • ✗

    Create a new analytics rule to detect pass-the-hash attacks.

    Why it's wrong here

    Creating a new analytics rule to detect pass-the-hash attacks is a preventive/detective control that will only generate alerts for future occurrences, not stop the current incident. It is a long-term engineering task, and the investigation timing means the attacker continues moving laterally through the environment during rule creation. Containment must be an operational action taken now, not a permanent detection improvement.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.