SC-200 Respond to security incidents Practice Question
During a ransomware incident, security team needs to prevent encryption while preserving forensic data. Which action best achieves this balance?
⚠ Common exam trap
Watch out — candidates often confuse 'preserving forensic data' with keeping systems powered on (Option D), failing to realize that memory snapshots require a controlled capture before isolation, and that micro-segmentation specifically targets file server access to stop encryption at the network layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable network micro-segmentation to isolate affected systems from file servers and take memory snapshots.
Network micro-segmentation (e.g., using Azure Network Security Groups or software-defined networking) isolates affected systems from file servers, halting lateral movement and preventing encryption of shared data, while memory snapshots (e.g., via Azure VM snapshots or live memory acquisition tools like WinPmem) preserve volatile forensic evidence such as encryption keys or process artifacts. This balances containment with forensic preservation, unlike destructive actions like shutdown or disconnection that lose memory data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shut down all affected servers immediately.
Why it's wrong here
Immediate shutdown may halt encryption but also destroys volatile memory that often contains the ransomware payload, encryption keys, and active network connections needed for forensic investigation. Powering off abruptly can also cause file system inconsistencies and lose the opportunity to capture the attack chain, hindering root-cause analysis and recovery.
- ✗
Run a full antivirus scan on all endpoints.
Why it's wrong here
Running a full antivirus scan relies on signatures and heuristics, which are often ineffective against zero-day or polymorphic ransomware, and does nothing to stop the encryption process already underway. The scan consumes computational resources and time, delaying more decisive containment actions like network isolation, and it fails to prevent lateral movement or further file encryption, so it is not a viable response.
- ✓
Enable network micro-segmentation to isolate affected systems from file servers and take memory snapshots.
Why this is correct
Network micro-segmentation enforces granular access control at the workload level, so even if a host is compromised, it cannot reach file servers or other critical systems, halting lateral movement and additional encryption. Taking memory snapshots contemporaneously preserves volatile forensic evidence such as encryption keys and process artifacts, which are vital for identifying the ransomware variant and potentially recovering data without paying the ransom. This approach provides both containment and evidence preservation.
- ✗
Disconnect the network but leave systems running.
Why it's wrong here
Disconnecting the network limits network-based propagation but leaves the ransomware process running locally, so it can continue encrypting files on mounted volumes and any attached storage. The lack of memory acquisition means crucial volatile evidence is lost, and if the host has external communication through other channels or automates encryption on a timer, the disruption is insufficient. Similarly, without network connectivity, security teams also lose remote management capabilities, complicating response.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.