SC-200 Perform threat hunting Practice Question
During a threat hunt, you discover a PowerShell script that downloads and executes a payload from a known malicious URL. The script was run on multiple workstations. Which Microsoft Defender XDR action should you take to contain the threat?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Initiate a device isolation on the affected workstations using Microsoft Defender for Endpoint.
Device isolation in Microsoft Defender for Endpoint immediately contains the threat by disconnecting the affected workstations from the network, preventing further spread or command-and-control communication. Option A only scans but does not prevent re-infection if the payload is still active. Option B blocks the URL but does not remediate already infected machines. Option D is about detection in Sentinel, not containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on all affected workstations.
Why it's wrong here
A full antivirus scan detects and removes files but does not terminate the running malicious process, isolate the hosts, or prevent reinfection from the malicious URL. Scanning is appropriate for routine hygiene or post-incident verification, not for immediate containment of an active, executing threat across multiple endpoints.
- ✗
Add the URL to the custom indicator list in Microsoft Defender XDR.
Why it's wrong here
Adding the URL to the indicator list blocks future connections to that address, but the script has already executed and the payload is resident on the workstations, so containment is incomplete. Indicators suit proactive blocking of known infrastructure before execution, not remediating hosts already compromised.
- ✓
Initiate a device isolation on the affected workstations using Microsoft Defender for Endpoint.
Why this is correct
Device isolation severs network connectivity while preserving the endpoint for investigation, immediately halting the malicious PowerShell script's payload execution and preventing lateral movement across the affected workstations. This directly contains the active threat identified during the hunt.
- ✗
Create a custom detection rule in Microsoft Sentinel.
Why it's wrong here
A Microsoft Sentinel custom detection rule generates alerts on matching telemetry but does not isolate endpoints or block execution, so the running payload persists. It is the right tool for ongoing scheduled hunting queries across log data, not for immediate containment of active malware on multiple workstations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.