Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst is investigating a potential ransomware incident in Microsoft Defender XDR. The analyst needs to confirm the scope of the attack and halt further propagation. Which TWO actions should the analyst take first?

⚠ Common exam trap

The SC-200 exam often tests the distinction between containment-first vs. investigation-first; the trap here is that candidates may choose 'collect forensic evidence' (C) thinking it is necessary before isolation, but in a ransomware scenario, stopping propagation is the immediate priority, and forensic collection can be done after isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate automated investigation on the affected devices

Initiating automated investigation on affected devices (A) is correct because Microsoft Defender XDR's automated investigation uses built-in playbooks to automatically analyze alerts, determine the scope of compromise, and suggest remediation actions without manual intervention. This is the fastest way to confirm the attack scope while simultaneously halting propagation. Isolating affected devices (D) is correct because network isolation immediately cuts off communication between the compromised device and other systems, preventing lateral movement and further encryption of network shares. Both actions are first-response steps in a ransomware incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Initiate automated investigation on the affected devices

    Why this is correct

    Microsoft Defender for Endpoint's automated investigation leverages behavioral analytics and threat intelligence to immediately scope a ransomware incident, identifying all affected files, processes, and user accounts in parallel while containing the threat. Because it executes investigation playbooks automatically and can trigger containment actions such as device isolation or indicator blocking, it is faster than manual triage and preserves forensic context for the incident graph. Initiating automated investigation is the recommended first step in Defender for Endpoint because it converts a suspected outbreak into a scoped, machine-readable set of evidence.

  • ✗

    Reset passwords for all users in the organization

    Why it's wrong here

    Organization-wide password resets address the risk of credential theft but do nothing to stop ransomware that is actively running on compromised endpoints, since the malware process will continue encrypting local and remote files until it is contained. A mass reset can also cause account lockouts and disrupt legitimate users, particularly if the attacker has manipulated authentication policies, which can slow down the incident response itself. Password resets belong in the recovery and eradication phase, after devices are isolated and persistence mechanisms are removed, rather than as an immediate response action.

  • ✗

    Collect forensic evidence from affected systems

    Why it's wrong here

    Forensic evidence collection, such as memory dumps or disk images, is necessary for root-cause analysis and potential prosecution, but capturing that evidence before containment gives the ransomware more time to propagate and encrypt network shares. In a live incident, taking the affected host offline for forensic imaging may actually destroy volatile data and interrupts the ability to observe attacker behavior in real time. The proper sequence is to isolate the device first, then collect forensics from the isolated copy or via Defender's live response, so evidence integrity is preserved without sacrificing containment.

  • ✓

    Isolate the affected devices from the network

    Why this is correct

    Using Defender for Endpoint's Device Isolation action immediately blocks all incoming and outgoing network communication from the compromised host, severing SMB, RDP, and other channels that ransomware typically uses for lateral movement and share encryption. This is an instantaneous, platform-level boundary that works even if the malware's process continues to run locally, and it can be reversed quickly after the investigation when the analyst determines the device is safe. Isolation is the most direct manual containment step in a ransomware event because it prevents the attack from spreading beyond the initially infected machines.

  • ✗

    Run a full antivirus scan on all endpoints

    Why it's wrong here

    Running a full signature-based antivirus scan across every endpoint is reactive and does not halt ransomware that is already executing, because the malware can continue encrypting files while the scan runs and may only be detected after substantial damage. Modern ransomware often employs fileless techniques, PowerShell abuse, or living-off-the-land binaries that cannot be reliably identified by classic AV signatures alone. Additionally, launching scans org-wide consumes disk and network I/O and competes with the already-encrypted traffic, delaying the critical containment actions such as isolating the compromised device or invoking automated investigation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.