SC-200 Respond to security incidents Practice Question
During a ransomware response in Microsoft Defender XDR, you identify that multiple devices are communicating with a known C2 server over port 443. You need to block this communication across all devices immediately. What is the most effective course of action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an indicator of compromise (IoC) in Microsoft Defender for Endpoint with action 'Block'
Creating an indicator of compromise in Microsoft Defender for Endpoint with action 'Block' is the most effective immediate action. The indicator is enforced by the Defender for Endpoint sensor and blocks the known C2 IP or domain across all onboarded devices, regardless of network location. Option A applies only to email and collaboration content. Option B only blocks traffic that passes through the firewall and may miss remote devices or non-firewall paths. Option D applies only to cloud app sessions, not general C2 network traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the C2 server domain to the Microsoft Defender for Office 365 Tenant Allow/Block List
Why it's wrong here
The Tenant Allow/Block List in Microsoft Defender for Office 365 applies to email and collaboration content, not to endpoint network traffic or C2 communication.
- ✗
Create a firewall rule to block outbound traffic to the C2 server IP address
Why it's wrong here
A firewall rule blocks only traffic passing through that firewall and is not managed from Microsoft Defender XDR; it may not cover all devices, especially those outside the corporate network.
- ✓
Create an indicator of compromise (IoC) in Microsoft Defender for Endpoint with action 'Block'
Why this is correct
A Defender for Endpoint indicator with action 'Block' blocks the malicious IP or domain on all onboarded endpoints immediately through Network Protection, regardless of where the devices connect.
- ✗
Add the C2 server URL to the custom indicator list in Microsoft Defender for Cloud Apps
Why it's wrong here
Custom indicators in Microsoft Defender for Cloud Apps apply only to cloud app traffic and session controls, not to general command-and-control network communication.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.