SC-200 Respond to security incidents Practice Question
An incident in Microsoft Defender XDR involves a device that is suspected to be infected with ransomware. The device is online and actively encrypting files. Which action should you take to contain the threat?
⚠ Common exam trap
Test-takers frequently choose 'Run a full antivirus scan' (Option C) because they think detection must precede containment, but the SC-200 exam emphasizes that immediate containment (isolation) is the priority when active encryption is observed, not scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the device from the network
Isolating the device from the network (Option A) is the correct immediate action because it stops the ransomware from communicating with its command-and-control (C2) server and prevents further lateral movement or encryption of network shares. In Microsoft Defender for Endpoint, device isolation blocks all inbound and outbound traffic at the OS kernel level, while still allowing the device to remain online for forensic analysis and remediation. This containment strategy is critical when the device is actively encrypting files, as it halts the attack's spread without losing the ability to investigate or remediate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate the device from the network
Why this is correct
Device isolation in Microsoft Defender for Endpoint severs all external network connections while maintaining a secure channel to the MDE cloud so the security team can continue monitoring and issuing commands. This containment action immediately stops the attacker from using the compromised host to propagate over SMB, PsExec, or other protocols, and prevents ransomware from encrypting remote file shares. Isolation is reversible once forensic collection is complete, making it the correct first step in the incident response workflow.
- ✗
Disable the user's account
Why it's wrong here
Disabling the user's account targets the identity that happened to log in to the device, not the malicious code or persistence mechanisms already running on that host. Attackers frequently maintain remote access through scheduled tasks, services, or injected processes that continue to operate even when the user cannot authenticate, so the device remains a threat. This action can also lock out a legitimate user unnecessarily and should be reserved for later if credential compromise is confirmed, not used as a containment measure.
- ✗
Run a full antivirus scan on the device
Why it's wrong here
A full antivirus scan is fundamentally a detection and remediation tool, not a containment action, because it does nothing to disconnect the compromised device from the network or interrupt the attacker's command-and-control channel. While the scan runs, ransomware can continue encrypting local files and propagating to network shares, and advanced malware often uses fileless or polymorphic techniques that evade signature-based scanning. Scanning is best performed after isolation to identify and clean up remnants, not during the initial response when the priority is stopping the threat.
- ✗
Collect a memory dump from the device
Why it's wrong here
Collecting a memory dump is a forensic step meant to preserve volatile evidence—such as injected code or active network connections—for later analysis, and it does not halt an ongoing attack. Performing an uncontained live acquisition gives the attacker time to finish encryption or exfiltration and may even be detected by the malware, causing it to wipe or disrupt evidence. The correct sequence is to isolate the device first, then collect memory in a stable and safe environment, making this an after-containment activity.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.