Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst receives an alert in Microsoft Defender XDR indicating a possible credential theft attempt from an external IP. The analyst wants to isolate the affected device immediately while preserving forensic data. What should the analyst do?

⚠ Common exam trap

Candidates often confuse 'contain device' (which only restricts communication with other managed devices) with full network isolation, leading them to choose Option A instead of the correct live response isolation command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate a live response session on the device and run the 'isolate device' command.

Initiating a live response session and running the 'isolate device' command in Microsoft Defender for Endpoint immediately disconnects the device from the network (both internal and external) while preserving forensic data on the endpoint. This action stops the ongoing credential theft attempt without destroying volatile evidence, which is critical for subsequent investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft Defender for Endpoint to 'contain device' from the device inventory.

    Why it's wrong here

    The 'Contain device' action in Microsoft Defender for Endpoint places the endpoint into a containment state that restricts communications with other devices, but it does not provide an interactive remote shell or the ability to run forensic commands. It is primarily designed to limit lateral movement during an investigation, not to collect volatile evidence such as running processes, network connections, or memory artifacts. Moreover, containment is less stringent than full isolation and leaves the device with some network connectivity, so it does not fully stop an active attacker's command-and-control channel or data exfiltration.

  • ✗

    Disable the user account in Microsoft Entra ID.

    Why it's wrong here

    Disabling the user account in Microsoft Entra ID revokes cloud-based authentication and prevents that specific identity from signing in, but it does not physically or logically isolate the compromised endpoint. The device remains connected to the network and can still be used by other local accounts, cached credentials, or the attacker's persistence mechanisms (e.g., a service running as SYSTEM). Disabling the account also provides no forensic visibility into the device and does nothing to stop ongoing malware execution, lateral movement, or exfiltration that is already underway from the device itself.

  • ✓

    Initiate a live response session on the device and run the 'isolate device' command.

    Why this is correct

    Initiating a live response session and running the 'isolate device' command is the correct action because live response gives the analyst a remote shell on the endpoint, enabling collection of volatile evidence (processes, network connections, persistence artifacts) before the environment changes. The 'isolate device' command disconnects the device from the network and blocks inbound and outbound communication except for the connection to the Microsoft Defender for Endpoint service, which keeps management and forensic collection channels open. This combination contains the immediate threat by cutting off the attacker's network access while preserving forensically sound data needed for deeper investigation.

  • ✗

    Reset the user's password and enforce sign-out.

    Why it's wrong here

    Resetting the user's password and enforcing sign-out invalidates the compromised user's current authentication tokens and forces reauthentication, but it does not address the fact that the endpoint itself is compromised and still network-connected. Malware already running on the device can continue to execute, the attacker may have alternate credentials or a stolen token that is unaffected by the password change, and local persistence mechanisms (scheduled tasks, services, registry run keys) remain active. This action is an identity-focused mitigation, not a device-containment or evidence-preservation step, so it fails to stop lateral movement or data exfiltration originating from the compromised host.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst receives an alert in Microsoft Defender XDR indicating that a user account was compromised. The analyst needs to isolate the affected device to prevent lateral movement. Which action should the analyst take first?

medium
  • A.Run a full antimalware scan on the device
  • ✓ B.Initiate device isolation from Microsoft Defender for Endpoint
  • C.Reset the user's password in Microsoft Entra ID
  • D.Create a custom detection rule in Microsoft Sentinel

Why B: Initiating device isolation in Microsoft Defender for Endpoint immediately contains the compromised device, preventing lateral movement. Option A is wrong because a full antimalware scan does not isolate the device and may not stop ongoing malicious activity. Option C is wrong because resetting the user's password does not isolate the device; it only revokes access to cloud resources. Option D is wrong because creating a custom detection rule in Microsoft Sentinel does not take immediate action to contain the threat.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.