Courseiva

SC-200 Respond to security incidents Practice Question

A SOC analyst is responding to a ransomware incident. The analyst identifies that the ransomware encrypted files on a file share and left a ransom note. The analyst needs to prevent the ransomware from spreading to other shares. Which action should the analyst take first?

⚠ Common exam trap

A common mix-up: candidates confuse containment actions with recovery or eradication steps, mistakenly choosing to restore files or run a scan first, when the correct first action is to isolate the compromised device to stop the spread.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the server from the network using Microsoft Defender for Endpoint's device isolation.

The immediate priority in a ransomware incident is containment to prevent lateral movement and further encryption. Microsoft Defender for Endpoint's device isolation feature disconnects the compromised server from the network while allowing communication with the Defender for Cloud backend, stopping the ransomware from spreading to other shares. This aligns with the NIST incident response framework's containment phase, which must occur before eradication or recovery actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Revoke the user's access to the file share.

    Why it's wrong here

    Revoking the user's access cannot stop the already-executing ransomware process; the malicious binary holds a valid access token and will continue encrypting files under its current privileges. The process is resident on the server, so clearing the share permission merely blocks new interactive logons and does not affect the running threat. Containment must be performed at the endpoint/process level, not through folder-level ACLs.

  • ✗

    Run a full antivirus scan on the server.

    Why it's wrong here

    A full antivirus scan relies on signature and heuristics matching and does not provide immediate containment of an active ransomware process; modern ransomware can be polymorphic, fileless, or memory-resident, so the scan may miss it while it continues encrypting. Scanning also produces heavy I/O on the server, potentially slowing the forensic response, and the malware may disable or alter AV services before the scan completes. Threat hunting and blocking execution would require EDR response actions, not a scheduled scan.

  • ✗

    Restore the encrypted files from backup.

    Why it's wrong here

    Restoring encrypted files from backup is the correct recovery step, but it is premature before containment; the server is still actively encrypting data, so restored files would immediately be re-encrypted by the live ransomware process. Backup restoration also does nothing to halt the malware's command-and-control traffic or stop it from propagating through SMB to other hosts. The SOC must first isolate the device to stop active encryption and then perform recovery from clean backups.

  • ✓

    Isolate the server from the network using Microsoft Defender for Endpoint's device isolation.

    Why this is correct

    Microsoft Defender for Endpoint's device isolation applies an OS-level network security policy at the client that blocks all inbound and outbound traffic other than the Defender service itself, effectively severing the ransomware's command-and-control channel and preventing further server-side or lateral encryption. This is the immediately effective containment action because it does not rely on terminating the process or cleaning files first. The SOC can then inspect processes, stop the malicious binary, and later restore data from backup in a clean state.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.