SC-200 Respond to security incidents Practice Question
An incident in Microsoft Sentinel involves a phishing campaign that delivered a malicious macro-enabled document. The document was opened by 15 users. Which playbook action should be triggered automatically to contain the threat?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the file hash using Microsoft Defender for Endpoint
The automatic playbook action should block the file hash at the endpoint to prevent further execution. Isolating devices may be too aggressive. Blocking sender IP is not effective against phishing. Disabling user accounts is not direct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Isolate all affected devices from the network
Why it's wrong here
Isolating all affected devices from the network is a strong containment step, but it is disproportionately disruptive in this scenario. If the phishing campaign's only identified artifact is a known malicious file, blocking its hash in Microsoft Defender for Endpoint will prevent the file from running on any device, achieving the same containment goal without severing the user's access to email, intranet, or cloud resources. Isolation also interferes with remote investigation and remediation tasks, since the device may lose connectivity to the APIs needed for EDR telemetry. It is better reserved for situations where the endpoint's behavior is actively malicious and cannot be stopped by a file-level indicator.
- ✗
Block the sender's IP address on the email gateway
Why it's wrong here
Blocking the sender's IP on the email gateway is ineffective here because the phishing message has already been delivered to the user's mailbox, and the actual threat is the attached file, not the envelope. Attackers routinely forge sender addresses or relay through compromised or cloud-based infrastructure, making a single IP a transient and unreliable indicator. In Microsoft Sentinel, the relevant indicator of compromise is the file hash confirmed by Defender for Endpoint; applying an IP block only prevents future mail from that specific sender while leaving the already-delivered malicious file active. This action does nothing to stop existing copies of the document from executing on recipients' devices.
- ✓
Block the file hash using Microsoft Defender for Endpoint
Why this is correct
Blocking the file hash with Microsoft Defender for Endpoint is the correct immediate containment because it targets the exact malicious artifact that triggered the incident. Defenders can add the SHA-256 hash as a custom file indicator in the Microsoft 365 Defender portal, which instructs the endpoint sensor to block execution and sometimes prevent the file from being written to disk, across all enrolled devices. This is non-disruptive to user productivity, reversible once the threat is confirmed eliminated, and aligns with the automatic response capabilities in Microsoft Sentinel when connected to a playbook. Because the file is the vector, a file-level block nullifies the attack regardless of how the file arrives in the future.
- ✗
Disable the user accounts of those who opened the document
Why it's wrong here
Disabling the user accounts of those who opened the document is unnecessary and overly broad in this context because the attack does not compromise credentials or authenticate with the user's identity. Blocking the file hash already neutralizes the payload, so there is no ongoing threat from that mailbox or account; disabling the account would interfere with business operations without adding security value. Account disablement might only be justified if there were signs of credential harvesting or if the document attempted to steal authentication tokens. Without evidence of privilege misuse, the correct remediation is to block the file and run an antivirus scan on the affected devices.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.