SC-200 Respond to security incidents Practice Question
A security analyst receives an alert in Microsoft Defender XDR indicating that a user account was compromised. The analyst needs to isolate the affected device to prevent lateral movement. Which action should the analyst take first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Initiate device isolation from Microsoft Defender for Endpoint
Initiating device isolation in Microsoft Defender for Endpoint immediately contains the compromised device, preventing lateral movement. Option A is wrong because a full antimalware scan does not isolate the device and may not stop ongoing malicious activity. Option C is wrong because resetting the user's password does not isolate the device; it only revokes access to cloud resources. Option D is wrong because creating a custom detection rule in Microsoft Sentinel does not take immediate action to contain the threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antimalware scan on the device
Why it's wrong here
Running a full antimalware scan is a reactive detection and remediation step, not a containment control; it scans the local filesystem while the device remains fully connected to the network, allowing the threat to continue lateral movement or command-and-control traffic during the scan. It also can take extended time and may miss in-memory or zero-day threats, so it fails to stop the immediate attacker objective.
- ✓
Initiate device isolation from Microsoft Defender for Endpoint
Why this is correct
Initiating device isolation from Microsoft Defender for Endpoint is the immediate containment action because it severs the compromised device's network connections—both wired and wireless—while preserving a secure channel to the Defender for Endpoint service for ongoing investigation and remediation. This prevents the attacker from moving laterally, exfiltrating data, or communicating with C2, effectively containing the breach at the endpoint.
- ✗
Reset the user's password in Microsoft Entra ID
Why it's wrong here
Resetting the user's password in Microsoft Entra ID revokes a compromised identity's credentials, preventing unauthorized cloud and on-premises sign-ins, but it leaves the already-compromised endpoint with full network access. If malware or a malicious session is active on that device, it can continue spreading or stealing data; therefore, password reset is a necessary post-containment step, not a containment action.
- ✗
Create a custom detection rule in Microsoft Sentinel
Why it's wrong here
Creating a custom detection rule in Microsoft Sentinel would apply only to future data being ingested into the SIEM, generating a new alert when conditions match—it has no programmatic effect on the current alert or the compromised device. It is a proactive hunting and detection mechanism, whereas the immediate need is to stop the active threat at the source, which only an endpoint-level containment action can do.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.