SC-200 Respond to security incidents Practice Question
During a ransomware incident, the security team needs to prevent the encryption of files while allowing the investigation to continue. Which feature in Microsoft Defender for Endpoint should be used to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Controlled folder access.
Controlled folder access (CFA) blocks unauthorized applications from modifying files in protected folders, which is exactly what ransomware does. ASR rules are broader and may not target file encryption specifically. Device isolation disconnects the device from the network but stops the investigation. Custom detection rules are reactive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Controlled folder access.
Why this is correct
Controlled folder access (CFA) in Microsoft Defender for Endpoint is the correct proactive control because it uses a Windows kernel mini-filter to intercept file-write and delete operations, blocking any process that is not on an approved allowlist from modifying files inside protected directories. This directly stops ransomware from encrypting user data in real time, even if the malware has already executed. CFA can be configured via Intune or group policy and provides a targeted, low-disruption defense that preserves forensic data and remote remediation capabilities.
- ✗
Device isolation.
Why it's wrong here
Device isolation is incorrect for this scenario because while it disconnects the compromised device from the network, it does not stop a ransomware process that is already running locally from continuing to encrypt files on the disk. Isolation also severs remote management channels, hindering live investigation and the ability to apply a mitigation like controlled folder access. It is a reactive containment measure, not a preventive file-encryption block, and is unnecessary if CFA can be enabled immediately to halt encryption without losing visibility.
- ✗
Attack surface reduction (ASR) rules.
Why it's wrong here
Attack surface reduction (ASR) rules are not the right choice here because they focus on preventing initial access and common attack techniques—such as blocking Office applications from launching child processes, preventing credential theft from LSASS, or blocking executable content from email—but they do not regulate individual file write or encryption operations. A ransomware binary that bypasses these generic behavioral rules can still encrypt files because ASR rules lack the fine-grained per-folder, per-process allowlisting that CFA provides. ASR complements CFA, but it is not a dedicated ransomware-encryption blocker.
- ✗
Custom detection rules.
Why it's wrong here
Custom detection rules are fundamentally detective, not preventive: they query telemetry in Microsoft 365 Defender or Microsoft Sentinel to identify suspicious patterns like mass file renames or rapid file extension changes after the fact. While these rules can trigger alerts and initiate automated actions, they cannot stop a ransomware process from encrypting files at the file-system level in the moment, because they operate on logs and analytics rather than file I/O interception. Thus they may help detect a compromise, but they do not actively block encryption and are not a substitute for CFA.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.