SC-200 Respond to security incidents Practice Question
A security analyst in Microsoft Sentinel receives an incident with a high severity alert from Microsoft Defender for Identity. The incident description mentions a suspected lateral movement pass-the-hash attack. What should the analyst do first?
⚠ Common exam trap
It's easy for candidates to choose password reset (Option A) thinking it immediately revokes access, but they overlook that the cached NTLM hash on the compromised device remains usable for lateral movement until the device is isolated or the hash is cleared.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the affected device from the network.
The immediate priority in a suspected lateral movement pass-the-hash attack is to contain the threat by isolating the affected device from the network. This prevents the attacker from using the compromised account's NTLM hash to authenticate to other systems, stopping the lateral spread while preserving forensic evidence for further investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset the password of the compromised account.
Why it's wrong here
Resetting the password may invalidate the account's plaintext credentials and eventually force re-authentication, but an attacker who already compromises the host can continue using cached NTLM hashes, Kerberos tickets, or other session tokens. This action is not immediate containment because the lateral movement is already in progress via pass-the-hash, and password changes do not retroactively kill existing authenticated sessions. Thus, while useful as a follow-up, it does not stop the active attack.
- ✗
Review the Microsoft Defender for Cloud Apps logs.
Why it's wrong here
Microsoft Defender for Cloud Apps is designed to monitor and govern user activity in cloud applications, not the on-premises SMB and NTLM traffic used in pass-the-hash attacks. Since the alert specifically indicates lateral movement across on-premises hosts, reviewing cloud app logs will not reveal or halt the attacker's remote authentication attempts. This action is investigative in the cloud domain and therefore does not serve as a containment measure for the on-premises compromise.
- ✓
Isolate the affected device from the network.
Why this is correct
Isolating the affected device from the network breaks the attacker's ability to use the compromised host to authenticate to other systems via pass-the-hash, effectively containing the lateral movement at the source. This is an immediate containment action that limits the blast radius while preserving process memory and network evidence for forensic analysis. In Microsoft Defender for Endpoint, 'Isolate device' blocks all inbound/outbound traffic except to the Defender service.
- ✗
Create a new analytics rule to detect pass-the-hash attacks.
Why it's wrong here
Creating a new analytics rule to detect pass-the-hash attacks is a preventive/detective control that will only generate alerts for future occurrences, not stop the current incident. It is a long-term engineering task, and the investigation timing means the attacker continues moving laterally through the environment during rule creation. Containment must be an operational action taken now, not a permanent detection improvement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.