Courseiva

SC-200 Respond to security incidents Practice Question

An incident in Microsoft Sentinel involves a phishing campaign that delivered a malicious macro-enabled document. The document was opened by 15 users. Which playbook action should be triggered automatically to contain the threat?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block the file hash using Microsoft Defender for Endpoint

The automatic playbook action should block the file hash at the endpoint to prevent further execution. Isolating devices may be too aggressive. Blocking sender IP is not effective against phishing. Disabling user accounts is not direct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Isolate all affected devices from the network

    Why it's wrong here

    Isolating all affected devices from the network is a strong containment step, but it is disproportionately disruptive in this scenario. If the phishing campaign's only identified artifact is a known malicious file, blocking its hash in Microsoft Defender for Endpoint will prevent the file from running on any device, achieving the same containment goal without severing the user's access to email, intranet, or cloud resources. Isolation also interferes with remote investigation and remediation tasks, since the device may lose connectivity to the APIs needed for EDR telemetry. It is better reserved for situations where the endpoint's behavior is actively malicious and cannot be stopped by a file-level indicator.

  • ✗

    Block the sender's IP address on the email gateway

    Why it's wrong here

    Blocking the sender's IP on the email gateway is ineffective here because the phishing message has already been delivered to the user's mailbox, and the actual threat is the attached file, not the envelope. Attackers routinely forge sender addresses or relay through compromised or cloud-based infrastructure, making a single IP a transient and unreliable indicator. In Microsoft Sentinel, the relevant indicator of compromise is the file hash confirmed by Defender for Endpoint; applying an IP block only prevents future mail from that specific sender while leaving the already-delivered malicious file active. This action does nothing to stop existing copies of the document from executing on recipients' devices.

  • ✓

    Block the file hash using Microsoft Defender for Endpoint

    Why this is correct

    Blocking the file hash with Microsoft Defender for Endpoint is the correct immediate containment because it targets the exact malicious artifact that triggered the incident. Defenders can add the SHA-256 hash as a custom file indicator in the Microsoft 365 Defender portal, which instructs the endpoint sensor to block execution and sometimes prevent the file from being written to disk, across all enrolled devices. This is non-disruptive to user productivity, reversible once the threat is confirmed eliminated, and aligns with the automatic response capabilities in Microsoft Sentinel when connected to a playbook. Because the file is the vector, a file-level block nullifies the attack regardless of how the file arrives in the future.

  • ✗

    Disable the user accounts of those who opened the document

    Why it's wrong here

    Disabling the user accounts of those who opened the document is unnecessary and overly broad in this context because the attack does not compromise credentials or authenticate with the user's identity. Blocking the file hash already neutralizes the payload, so there is no ongoing threat from that mailbox or account; disabling the account would interfere with business operations without adding security value. Account disablement might only be justified if there were signs of credential harvesting or if the document attempted to steal authentication tokens. Without evidence of privilege misuse, the correct remediation is to block the file and run an antivirus scan on the affected devices.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.