Courseiva

SC-200 Respond to security incidents Practice Question

During an incident, you need to prevent a malicious process from running on all endpoints using Microsoft Defender for Endpoint. The process is not yet detected by antivirus signatures. Which action should you use?

⚠ Common exam trap

Candidates often confuse 'collect investigation package' or 'Live Response' as proactive blocking tools, when in fact they are post-incident forensic or single-endpoint actions, not scalable prevention mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an indicator to block the process

Microsoft Defender for Endpoint allows you to create custom indicators of compromise (IoCs) to block or allow specific processes, files, or behaviors. Since the malicious process is not yet detected by antivirus signatures, adding an indicator to block the process file hash or certificate is the most direct and immediate action to prevent it from running on all endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run antivirus scan

    Why it's wrong here

    Running an antivirus scan is a reactive, detection-based action that relies on known signatures, heuristics, and cloud reputation. It may fail to identify an unknown or zero-day malicious process, and scanning does not actively prevent the process from executing because it often occurs after the threat is already running. In Microsoft Defender, an antivirus scan alone cannot enforce a persistent block on a specific file hash or process.

  • ✓

    Add an indicator to block the process

    Why this is correct

    Adding an indicator of compromise (IoC) in Microsoft 365 Defender with the action 'Alert and block' or 'Block' immediately prevents the malicious process from running on any onboarded device. This indicator can be a file hash, signing certificate, or other process attribute, and the block is enforced by the Defender for Endpoint sensor in real time. Unlike scanning, this is a proactive, organization-wide prevention control that stops execution before or during launch.

  • ✗

    Collect investigation package

    Why it's wrong here

    Collecting an investigation package gathers a compressed archive of forensic data, including process memory, registry keys, and event logs, but it does not affect the runtime state of the malicious process. The package is used for offline analysis and does not contain any actions to block or terminate a process. This makes it a post-incident data collection step, not a containment measure.

  • ✗

    Initiate Live Response

    Why it's wrong here

    Initiating Live Response opens an interactive remote shell on the compromised device, allowing an analyst to manually inspect and execute remediation commands such as killing a process or deleting a file. However, it is not an automated prevention control; the block only applies for the duration of the session and depends on the analyst's manual intervention. In contrast, adding an indicator provides a persistent, policy-driven block that does not rely on real-time operator action.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.